<feed xmlns="http://www.w3.org/2005/Atom">
  <title>The runZero Platform on runZero</title>
  <link href="https://www.runzero.com/docs/index.xml" rel="self"/>
  <link href="https://www.runzero.com/docs/"/>
  <updated>2026-06-05T22:22:47+00:00</updated>
  <id>https://www.runzero.com/docs/</id>
  <generator>Hugo -- gohugo.io</generator>
  <entry>
    <title type="html"><![CDATA[Early Scanner release notes]]></title>
    <link href="https://www.runzero.com/docs/release-notes-scanner/"/>
    <id>https://www.runzero.com/docs/release-notes-scanner/</id>
      
      <published>2025-01-15T16:14:41+00:00</published>
      <updated>2025-01-15T16:14:41+00:00</updated>
      <summary type="html"><![CDATA[<h2 id="scanner-release-notes-prior-to-179">Scanner release notes prior to 1.7.9</h2>
<p>Starting with version 1.7.9 all release notes have been <a href="/docs/release-notes/">consolidated</a> into one page.</p>
<h3 id="v178">v1.7.8</h3>
<p><code>2020-05-23</code></p>
<ul>
<li>Fingerprint updates.</li>
</ul>
<h3 id="v177">v1.7.7</h3>
<p><code>2020-05-22</code></p>
<ul>
<li>Fingerprint updates.</li>
</ul>
<h3 id="v176">v1.7.6</h3>
<p><code>2020-05-14</code></p>
<ul>
<li>Corrects inconsistent use of the new service attributes when processing the dynamic MAC address filter.</li>
</ul>
<h3 id="v175">v1.7.5</h3>
<p><code>2020-05-14</code></p>
<ul>
<li>Asset and Service attributes have been normalized. All keys are now camelCase and most service attributes are now prefixed by the protocol name.</li>
</ul>
<h3 id="v174">v1.7.4</h3>
<p><code>2020-05-13</code></p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Early Explorer release notes]]></title>
    <link href="https://www.runzero.com/docs/release-notes-agent/"/>
    <id>https://www.runzero.com/docs/release-notes-agent/</id>
      
      <published>2025-01-15T16:14:41+00:00</published>
      <updated>2025-01-15T16:14:41+00:00</updated>
      <summary type="html"><![CDATA[<h2 id="explorer-release-notes-prior-to-179">Explorer release notes prior to 1.7.9</h2>
<p>Starting with version 1.7.9 all release notes have been <a href="/docs/release-notes/">consolidated</a> into one page.</p>
<h3 id="v178">v1.7.8</h3>
<p><code>2020-05-23</code></p>
<ul>
<li>Fingerprint updates.</li>
</ul>
<h3 id="v177">v1.7.7</h3>
<p><code>2020-05-22</code></p>
<ul>
<li>Fingerprint updates.</li>
</ul>
<h3 id="v176">v1.7.6</h3>
<p><code>2020-05-14</code></p>
<ul>
<li>Corrects inconsistent use of the new service attributes when processing the dynamic MAC address filter.</li>
</ul>
<h3 id="v175">v1.7.5</h3>
<p><code>2020-05-14</code></p>
<ul>
<li>Asset and Service attributes have been normalized. All keys are now camelCase and most service attributes are now prefixed by the protocol name.</li>
</ul>
<h3 id="v174">v1.7.4</h3>
<p><code>2020-05-13</code></p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Early Console release notes]]></title>
    <link href="https://www.runzero.com/docs/release-notes-console/"/>
    <id>https://www.runzero.com/docs/release-notes-console/</id>
      
      <published>2025-01-15T16:14:41+00:00</published>
      <updated>2025-01-15T16:14:41+00:00</updated>
      <summary type="html"><![CDATA[<h2 id="console-release-notes-prior-to-179">Console release notes prior to 1.7.9</h2>
<p>Please see the current <a href="/docs/release-notes/">release notes</a> for recent updates.</p>
<h3 id="v178">v1.7.8</h3>
<p><code>2020-05-23</code></p>
<ul>
<li>The pre-login style has been updated.</li>
<li>The account registration flow has been updated to provide a smoother activation experience.</li>
</ul>
<h3 id="v177">v1.7.7</h3>
<p><code>2020-05-17</code></p>
<ul>
<li>Restricted user accounts may now be assigned roles within multiple organizations.</li>
</ul>
<h3 id="v176">v1.7.6</h3>
<p><code>2020-05-14</code></p>
<ul>
<li>Asset and Service attributes have been normalized. All keys are now camelCase and most service attributes are now prefixed by the protocol name.</li>
</ul>
<h3 id="v175">v1.7.5</h3>
<p><code>2020-05-13</code></p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Archived release notes]]></title>
    <link href="https://www.runzero.com/docs/release-notes-archive/"/>
    <id>https://www.runzero.com/docs/release-notes-archive/</id>
      
      <published>2025-01-19T12:09:42+00:00</published>
      <updated>2025-01-19T12:09:42+00:00</updated>
      <summary type="html"><![CDATA[<h2 id="release-notes-prior-to-2024">Release notes prior to 2024</h2>
<h3 id="402312221">4.0.231222.1</h3>
<p><code>2023-12-22</code></p>
<ul>
<li>A bug that incorrectly set empty private IP ranges instead of default values has been resolved.</li>
<li>A bug that prevented stale Azure scale set attributes from being cleared has been resolved.</li>
</ul>
<h3 id="402312220">4.0.231222.0</h3>
<p><code>2023-12-22</code></p>
<ul>
<li>A bug causing duplicate line items in CSV exports of site configurations has been resolved.</li>
<li>Most modal interfaces in the UI can now be dismissed using the escape key.</li>
<li>MAC address assignment for certain HP servers with iLO devices has been improved.</li>
<li>Fingerprint improvements.</li>
</ul>
<h3 id="402312200">4.0.231220.0</h3>
<p><code>2023-12-20</code></p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Release notes]]></title>
    <link href="https://www.runzero.com/docs/release-notes/"/>
    <id>https://www.runzero.com/docs/release-notes/</id>
      
      <published>2026-06-05T22:22:47+00:00</published>
      <updated>2026-06-05T22:22:47+00:00</updated>
      <summary type="html"><![CDATA[<div class="rn-grid">
<div class="rn-card" id="492606041">
  <div class="rn-card-header"><span class="rn-version">4.9.260604.1</span><time class="rn-date" datetime="2026-06-04">Jun 4, 2026</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>This console-only release addressed a bug in hosted external scan scheduling.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="492606040">
  <div class="rn-card-header"><span class="rn-version">4.9.260604.0</span><time class="rn-date" datetime="2026-06-04">Jun 4, 2026</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Stale integration attribute and vulnerability expiration settings now support client-level defaults, which can be updated by superusers.</li>
      <li>The site-updated event now includes details about what changes were made to the site.</li>
      <li>An issue that could cause the scanner to incorrectly identify MCP services in rare cases has been resolved.</li>
      <li>An issue that could cause tasks to fail with message explorer timeout when the initial upload fails has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="492606020">
  <div class="rn-card-header"><span class="rn-version">4.9.260602.0</span><time class="rn-date" datetime="2026-06-02">Jun 2, 2026</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Custom dashboards now have widgets available to show vulnerability counts.</li>
      <li>An issue that caused the Export dropdown on asset attribute analysis reports to be partially obscured has been resolved.</li>
      <li>An issue that could result in incorrectly merging certain models of Cisco IP phones has been resolved.</li>
      <li>An issue that could cause incomplete data collection from BACnet devices has been resolved.</li>
      <li>An issue that could cause Windows explorers to crash while taking screenshots has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="492605290">
  <div class="rn-card-header"><span class="rn-version">4.9.260529.0</span><time class="rn-date" datetime="2026-05-29">May 29, 2026</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that could cause findings updates to fail has been resolved.</li>
      <li>The performance of vulnerability exports for certain queries has been greatly improved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="492605280">
  <div class="rn-card-header"><span class="rn-version">4.9.260528.0</span><time class="rn-date" datetime="2026-05-28">May 28, 2026</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>The account and organization API endpoints for creating and updating an organization now support a new field, expiration_settings. The fields expiration_integration_attributes, keep_latest_integration_attributes, and expiration_vulnerabilities are being deprecated in favor of the new field.</li>
      <li>The runZero console now allows the attribute and vulnerability expiration settings to be left blank to use default values when creating or editing an organization.</li>
      <li>An issue that could cause an inaccurate Instances count in the Findings table has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="492605260">
  <div class="rn-card-header"><span class="rn-version">4.9.260526.0</span><time class="rn-date" datetime="2026-05-26">May 26, 2026</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>The Shodan integration now supports the ability to selectively exclude tags from assets.</li>
      <li>runZero now offers the ability to configure which integrations can modify asset OS, hardware, and device type.</li>
      <li>An issue that could cause the CLI scanner to return truncated scan results has been resolved.</li>
      <li>An issue that allowed bogus arp.mac data into scan results has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="492605212">
  <div class="rn-card-header"><span class="rn-version">4.9.260521.2</span><time class="rn-date" datetime="2026-05-21">May 21, 2026</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Protocol negotiation is now skipped by default for TCP ports 9042 and 9160.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="492605211">
  <div class="rn-card-header"><span class="rn-version">4.9.260521.1</span><time class="rn-date" datetime="2026-05-21">May 21, 2026</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that could cause Windows explorers to crash during high-speed scans has been resolved.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="492605210">
  <div class="rn-card-header"><span class="rn-version">4.9.260521.0</span><time class="rn-date" datetime="2026-05-21">May 21, 2026</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>The AWS integration&rsquo;s VPC assets are now enriched with VPC endpoints data.</li>
      <li>An issue that prevented the enrollment of TOTP tokens has been resolved.</li>
      <li>An issue that caused scan and passive sampling tasks to duplicate assets in some circumstances has been resolved.</li>
      <li>An issue that prevented empty sites from being removed has been resolved.</li>
      <li>An issue that caused the &ldquo;Set asset comments&rdquo; and &ldquo;Set asset tags&rdquo; buttons to be removed from the Modify action within the asset inventory has been resolved.</li>
      <li>An issue that could cause the CrowdStrike integration credential verification to fail has been resolved.</li>
      <li>An issue that could cause Windows explorers to crash while taking screenshots has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="492605190">
  <div class="rn-card-header"><span class="rn-version">4.9.260519.0</span><time class="rn-date" datetime="2026-05-19">May 19, 2026</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Users with the User role may now delete individual assets.</li>
      <li>The AWS integration now processes VPC assets from connected accounts.</li>
      <li>The performance of asset queries that use the <code>vuln_exploitable</code> keyword has been improved.</li>
      <li>An issue affecting Time-based One Time Password (TOTP) multi-factor authentication (MFA) has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="492605140">
  <div class="rn-card-header"><span class="rn-version">4.9.260514.0</span><time class="rn-date" datetime="2026-05-14">May 14, 2026</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that could result in multi-source AWS ELBs maintaining old IP addresses has been resolved.</li>
      <li>The scanner now scans additional DTLS ports (12346, 12366, 12386, 12406, 12426).</li>
      <li>An issue that caused the Export dropdown on the Asset Risk Report to be partially obscured has been resolved.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="492605120">
  <div class="rn-card-header"><span class="rn-version">4.9.260512.0</span><time class="rn-date" datetime="2026-05-12">May 12, 2026</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>The vulnerability inventory now displays details when hovering over a vulnerability group name.</li>
      <li>The Explorer details page now includes an option to download Explorer system logs.</li>
      <li>An issue that could prevent the Overview dashboard from loading in My Organizations view has been resolved.</li>
      <li>An issue that could cause the task details page to display negative scan and data acquisition durations has been resolved.</li>
      <li>An issue that caused errors when sorting by Explorer Groups on the Explorer list page has been resolved.</li>
      <li>An issue that prevented &ldquo;findings-with-instances&rdquo; alert rules from filtering by risk has been resolved.</li>
      <li>An issue that caused &ldquo;findings-with-instances&rdquo; alert rules that were configured to notify when the vulnerability count decreases to instead notify when it increases has been resolved.</li>
      <li>An issue that caused the total result count to be inaccurate after deleting or merging assets in the asset inventory has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="492605110">
  <div class="rn-card-header"><span class="rn-version">4.9.260511.0</span><time class="rn-date" datetime="2026-05-11">May 11, 2026</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>The scanner now detects network disruption and automatically lowers the send rate to accommodate.</li>
      <li>The NetBox integration now supports a wide range of server versions (4.0 - 4.5).</li>
      <li>The Query-Assets MCP tool now has the option to export services, attributes, and foreign attributes.</li>
      <li>An issue that could result in tasks failing to process in low disk space scenarios has been resolved.</li>
      <li>An issue that could prevent cloud-based integrations from using configured proxies via Explorers has been resolved.</li>
      <li>An issue that could result in custom integration data continuing to report assets even after a definition was removed has been resolved.</li>
      <li>An issue that could result in assets mismerging when IPv6 NA/NS requests are proxied by the router has been resolved.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="492605081">
  <div class="rn-card-header"><span class="rn-version">4.9.260508.1</span><time class="rn-date" datetime="2026-05-08">May 8, 2026</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that could result in assets failing to merge has been resolved. This was a race condition that primarily affected passive traffic sampling and IPv6 link-local scans.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="492605080">
  <div class="rn-card-header"><span class="rn-version">4.9.260508.0</span><time class="rn-date" datetime="2026-05-08">May 8, 2026</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>The Rapid7 InsightVM Cloud integration now handles larger data objects.</li>
      <li>The single-count custom widget now includes a value delta for the time period of the dashboard.</li>
      <li>The CLI scanner tool will now warn when run without the appropriate network permissions.</li>
      <li>The embedded version of <code>npcap</code> provided with Windows Explorers has been updated to v1.88.</li>
      <li>An issue that could cause certain error messages from integrations to report a misleading &ldquo;API unreachable&rdquo; message has been resolved.</li>
      <li>An issue that prevented the display of the Avaya OS icon within the product has been resolved.</li>
      <li>An issue that could cause Oracle ILOM devices to be displayed with an HP logo within the product has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="492605040">
  <div class="rn-card-header"><span class="rn-version">4.9.260504.0</span><time class="rn-date" datetime="2026-05-04">May 4, 2026</time></div>
  <div class="rn-card-body">
    <div class="rn-section-label">Integrations</div>
    <ul class="rn-items">
      <li>The AWS integration now reports FSx assets.</li>
      <li>The CrowdStrike connector now supports more retries when hitting transient 401 responses.</li>
    </ul>
    <div class="rn-section-label">User experience</div>
    <ul class="rn-items">
      <li>The Asset Inventory CSV report now includes the VLAN column.</li>
      <li>Users with Annotator role access may now add asset comments in addition to tags.</li>
      <li>The Network Maps now treat <code>eol:true</code> as meaning the later of the OS EOL or EOL Extended dates.</li>
    </ul>
    <div class="rn-section-label">Scanner</div>
    <ul class="rn-items">
      <li>The scanner no longer reports Siemens S7Comm virtual modules (&ldquo;Firmware&rdquo;) as sub-assets.</li>
      <li>The scanner now randomizes TCP ports to reduce pressure on transparent proxies.</li>
      <li>The scanner now uses less system resources and handles screenshots more reliably.</li>
      <li>The scanner now reports screenshots for non-NLA RDP (Windows) and no-auth VNC.</li>
      <li>The scanner now spends less time on network &ldquo;tar pits&rdquo; (hundreds of bogus services).</li>
      <li>The scanner now reports application-layer data for SSL 2.0 wrapped services.</li>
      <li>The scanner now handshakes PQC hybrid ciphers for SSH services.</li>
    </ul>
    <div class="rn-section-label"><svg width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M8 2l1.88 1.88M14.12 3.88L16 2M9 7.13v-1a3.003 3.003 0 116 0v1M12 20c-3.3 0-6-2.7-6-6v-3a4 4 0 014-4h4a4 4 0 014 4v3c0 3.3-2.7 6-6 6M12 20v-9M6.53 9C4.6 8.8 3 7.1 3 5M6 13H2M6 17l-4 1M17.47 9c1.93-.2 3.53-1.9 3.53-4M18 13h4M18 17l4 1"/></svg> Bug fixes</div>
    <ul class="rn-items">
      <li>An issue that could result in single-source AWS ELBs maintaining old IP addresses has been resolved.</li>
      <li>An issue that could result in ARP results reporting mangled IPs has been resolved.</li>
      <li>An issue that could lead to duplicate GeoIP asset attribute values has been resolved.</li>
      <li>An issue that could lead to stale Chrome processes during scans has been resolved.</li>
      <li>An issue that could result in invalid SNMP versions being reported has been resolved.</li>
      <li>An issue that could cause Certificates to not correctly sort by Subject or Subject Key ID has been resolved.</li>
    </ul>
    <div class="rn-section-label"><svg width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M14 2H6a2 2 0 00-2 2v16a2 2 0 002 2h12a2 2 0 002-2V8z"/><polyline points="14 2 14 8 20 8"/><line x1="16" y1="13" x2="8" y2="13"/><line x1="16" y1="17" x2="8" y2="17"/></svg> Content updates</div>
    <ul class="rn-items">
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="492604301">
  <div class="rn-card-header"><span class="rn-version">4.9.260430.1</span><time class="rn-date" datetime="2026-04-30">Apr 30, 2026</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that could cause dashboard widgets to render with an incorrect chart height has been resolved.</li>
      <li>An issue that could result in Custom Integration Scripts throwing an error when comparing <code>IPAddress</code> values has been resolved.</li>
      <li>An issue that could cause the Custom Integration Scripts code editor to render incorrectly in dark mode has been resolved.</li>
      <li>An issue that could cause inventory tables to sort by unavailable columns has been resolved.</li>
      <li>The scanner worker group size is now decoupled from the configured scan rate to improve resource usage.</li>
      <li>The scanner now completes web screenshots faster on machines with generous memory but low CPU core counts.</li>
      <li>The scanner now uses less resources during the HTTP and vulnerability scan phases.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="492604300">
  <div class="rn-card-header"><span class="rn-version">4.9.260430.0</span><time class="rn-date" datetime="2026-04-30">Apr 30, 2026</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>The runZero 4.9 release is live! This version is focused on OT, attack graphs, and segmentation analysis.</li>
      <li>The Network Maps (2D/3D) now render unmapped MACs and unscanned traceroute hops by default.</li>
      <li>An issue that could lead to SNMP v3 reporting a username when none was specified has been resolved.</li>
      <li>The scanner now uses significantly less resources while also reducing scan times.</li>
      <li>Tags can now be used to manually specify geo locations: (ex: geo.City=Austin/TX/USA).</li>
      <li>Assets with geolocation data now link to the World Map from the inventory icon fields.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="482604290">
  <div class="rn-card-header"><span class="rn-version">4.8.260429.0</span><time class="rn-date" datetime="2026-04-29">Apr 29, 2026</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An additional issue with SCTP exceeding task rate limits has been resolved. The SCTP protocol is now disabled by default as a precaution and can be re-enabled via the scan configuration probes page (mark <code>sctp-tenable</code> as <code>true</code> to re-enable).</li>
      <li>The <code>mtconnect</code> protocol is now used to collect default device information when available.</li>
      <li>The Ethernet/IP CIP protocol stack now identifies a wider range of modules, including CNCs.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402604282">
  <div class="rn-card-header"><span class="rn-version">4.0.260428.2</span><time class="rn-date" datetime="2026-04-28">Apr 28, 2026</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue with SNMP <code>sysObjectID</code> normalization that could prevent asset matching has been resolved.</li>
      <li>An issue that could result in larger-than-necessary scan files has been resolved.</li>
      <li>The scanner now deduplicates the output of DCERPC and EPM protocol enumeration.</li>
      <li>The <code>S7</code> source has been folded into the existing <code>S7Comm</code> definition.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402604281">
  <div class="rn-card-header"><span class="rn-version">4.0.260428.1</span><time class="rn-date" datetime="2026-04-28">Apr 28, 2026</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402604280">
  <div class="rn-card-header"><span class="rn-version">4.0.260428.0</span><time class="rn-date" datetime="2026-04-28">Apr 28, 2026</time></div>
  <div class="rn-card-body">
    <div class="rn-section-label"><svg width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M8 2l1.88 1.88M14.12 3.88L16 2M9 7.13v-1a3.003 3.003 0 116 0v1M12 20c-3.3 0-6-2.7-6-6v-3a4 4 0 014-4h4a4 4 0 014 4v3c0 3.3-2.7 6-6 6M12 20v-9M6.53 9C4.6 8.8 3 7.1 3 5M6 13H2M6 17l-4 1M17.47 9c1.93-.2 3.53-1.9 3.53-4M18 13h4M18 17l4 1"/></svg> Bug fixes</div>
    <ul class="rn-items">
      <li>Two issues were resolved with the new SCTP protocol implementation, both of which could lead to network disruption.</li>
      <li>The first issue impacted environments where the configured scan rate was close to the network limit. The root cause was a misconfiguration of the rate limiter that treated SCTP separately from the rest of the scan traffic, which could lead to scans running at 1.5x to 2.0x of the configured rate. The fix was a correction to use the shared rate limiter as intended.</li>
      <li>The second issue impacted stateful middle-boxes with low session limits and long timeouts for SCTP flows. The SCTP INIT scan did not proactively reset sessions; this could lead to quickly growing session counts and disruption of other flows once the device limit was reached. The fix was to implement proactively tear-down of SCTP sessions, similar to how runZero handles TCP SYN scans.</li>
      <li>An issue that could result in asset inventory links returning a not-found error when in My Organizations mode has been resolved.</li>
      <li>An issue that could lead to slow exports of the software and vulnerabilities table has been resolved.</li>
      <li>An issue that could result in DCERPM EPM results not being captured completely has been resolved.</li>
    </ul>
    <div class="rn-section-label">General updates</div>
    <ul class="rn-items">
      <li>LDAP-sourced Active Directory records and CrowdStrike endpoint records now use the <code>objectGUID</code> and <code>objectSid</code> attributes for matching and merging.</li>
    </ul>
    <div class="rn-section-label"><svg width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M14 2H6a2 2 0 00-2 2v16a2 2 0 002 2h12a2 2 0 002-2V8z"/><polyline points="14 2 14 8 20 8"/><line x1="16" y1="13" x2="8" y2="13"/><line x1="16" y1="17" x2="8" y2="17"/></svg> Content updates</div>
    <ul class="rn-items">
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402604260">
  <div class="rn-card-header"><span class="rn-version">4.0.260426.0</span><time class="rn-date" datetime="2026-04-26">Apr 26, 2026</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>The Organizational Overview Report, Network Map, and World Map have been updated.</li>
      <li>Fingerprint improvements.</li>
      <li>4.0.260426.0</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402604230">
  <div class="rn-card-header"><span class="rn-version">4.0.260423.0</span><time class="rn-date" datetime="2026-04-23">Apr 23, 2026</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>The platform now includes a native integration for Rapid7&rsquo;s InsightVM Cloud.</li>
      <li>The assets and services inventory search now support comma-delimited values for the <code>protocols</code> keyword.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402604210">
  <div class="rn-card-header"><span class="rn-version">4.0.260421.0</span><time class="rn-date" datetime="2026-04-21">Apr 21, 2026</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Two additional issues that could cause Explorer processes to abort on Windows have been resolved.</li>
      <li>The specific fields that contribute to an outlier score are now tracked in asset attributes.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402604201">
  <div class="rn-card-header"><span class="rn-version">4.0.260420.1</span><time class="rn-date" datetime="2026-04-20">Apr 20, 2026</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that could prevent TCP diagnostics from being reported in the task data has been resolved.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="40260200">
  <div class="rn-card-header"><span class="rn-version">4.0.26020.0</span><time class="rn-date" datetime="2026-04-17">Apr 17, 2026</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Two issues that could cause Explorer processes to abort on Windows have been resolved.</li>
      <li>An issue that could prevent email delivery due to provider rate limits has been addressed.</li>
      <li>An issue that could prevent Unmerge actions from being completed has been resolved.</li>
      <li>New maps are in preview; find them under the Manage menu of the asset details page.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402604170">
  <div class="rn-card-header"><span class="rn-version">4.0.260417.0</span><time class="rn-date" datetime="2026-04-17">Apr 17, 2026</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that could cause Windows Explorers to crash mid-scan has been addressed and all binaries are now built with the Go 1.26.2 toolchain. The root cause was a race condition leading to stack corruption in the TCP connection tracking logic.</li>
      <li>An issue that could cause some saved software queries to error when run as part of a metrics task has been resolved.</li>
      <li>An issue that could prevent integration searches from working with capital letters has been resolved.</li>
      <li>An issue that could result in self-hosted upgrades showing a migration error has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402604160">
  <div class="rn-card-header"><span class="rn-version">4.0.260416.0</span><time class="rn-date" datetime="2026-04-16">Apr 16, 2026</time></div>
  <div class="rn-card-body">
    <div class="rn-section-label"><svg width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><polygon points="12 2 15.09 8.26 22 9.27 17 14.14 18.18 21.02 12 17.77 5.82 21.02 7 14.14 2 9.27 8.91 8.26 12 2"/></svg> Features</div>
    <ul class="rn-items">
      <li>The runZero console now offers the ability to switch between three themes: Classic, light, and dark mode.</li>
    </ul>
    <div class="rn-section-label"><svg width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M12 22s8-4 8-10V5l-8-3-8 3v7c0 6 8 10 8 10z"/></svg> Security</div>
    <ul class="rn-items">
      <li>An issue that could allow a dashboard configuration to be viewed from outside of the authorized organization scope has been resolved.</li>
    </ul>
    <div class="rn-section-label"><svg width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M8 2l1.88 1.88M14.12 3.88L16 2M9 7.13v-1a3.003 3.003 0 116 0v1M12 20c-3.3 0-6-2.7-6-6v-3a4 4 0 014-4h4a4 4 0 014 4v3c0 3.3-2.7 6-6 6M12 20v-9M6.53 9C4.6 8.8 3 7.1 3 5M6 13H2M6 17l-4 1M17.47 9c1.93-.2 3.53-1.9 3.53-4M18 13h4M18 17l4 1"/></svg> Bug fixes</div>
    <ul class="rn-items">
      <li>An issue that could cause the Windows Explorer service to crash mid-scan has been mitigated by a switch back to the Go 1.25 runtime for production builds while we continue to investigate.</li>
      <li>An issue that prevented the Shodan integration from running all queries has been resolved.</li>
      <li>A performance issue with the Software inventory has been resolved.</li>
    </ul>
    <div class="rn-section-label"><svg width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M14 2H6a2 2 0 00-2 2v16a2 2 0 002 2h12a2 2 0 002-2V8z"/><polyline points="14 2 14 8 20 8"/><line x1="16" y1="13" x2="8" y2="13"/><line x1="16" y1="17" x2="8" y2="17"/></svg> Content updates</div>
    <ul class="rn-items">
      <li>OS reporting now takes into account the &ldquo;os-release&rdquo; OID for Linux systems running net-snmp.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402604140">
  <div class="rn-card-header"><span class="rn-version">4.0.260414.0</span><time class="rn-date" datetime="2026-04-14">Apr 14, 2026</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>The Wiz integration now supports filtering assets by cloud provider.</li>
      <li>The scan template form now represents the &ldquo;Additional security tests&rdquo; options the same way as the standard form.</li>
      <li>Scan configured from a template now use the template settings for &ldquo;Additional security tests&rdquo;.</li>
      <li>An issue that caused API-created scan tasks to store an incorrect start time due to timezone conversion has been resolved.</li>
      <li>Additional issues that could lead to the Explorer service crashing during scans has been resolved.</li>
      <li>An issue that caused the vulnerability inventory by asset index to show vulnerabilities that has been suppressed by group has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402604100">
  <div class="rn-card-header"><span class="rn-version">4.0.260410.0</span><time class="rn-date" datetime="2026-04-10">Apr 10, 2026</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>The display order of asset host names can now be configured at the account and organization level.</li>
      <li>Operating System End of Life (EOL) dates for Microsoft Windows Desktops now default to the Enterprise edition values unless a more specific edition is reported.</li>
      <li>Operating System End of Life (EOL) information for Microsoft Windows Server has been improved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402604070">
  <div class="rn-card-header"><span class="rn-version">4.0.260407.0</span><time class="rn-date" datetime="2026-04-07">Apr 7, 2026</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Improved handling of ARP data for asset correlation, using only the latest available data when appropriate.</li>
      <li>The software inventory now provides an organization name for each software group.</li>
      <li>An issue that could result in incorrect SharePoint version collection has been resolved.</li>
      <li>An issue that showed the incorrect icon color for Explorers without screenshot capabilities has been resolved.</li>
      <li>An issue that caused some NetBox assets to merge incorrectly has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402604020">
  <div class="rn-card-header"><span class="rn-version">4.0.260402.0</span><time class="rn-date" datetime="2026-04-02">Apr 2, 2026</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>The InsightVM integration now provides more detail in authentication errors.</li>
      <li>The performance of and reliability of Explorers has been improved.</li>
      <li>An issue that caused suppressed vulnerabilities to incorrectly reappear with updated scan results has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402604012">
  <div class="rn-card-header"><span class="rn-version">4.0.260401.2</span><time class="rn-date" datetime="2026-04-01">Apr 1, 2026</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that could prevent self-hosted installations from upgrading correctly has been resolved.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402604010">
  <div class="rn-card-header"><span class="rn-version">4.0.260401.0</span><time class="rn-date" datetime="2026-04-01">Apr 1, 2026</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that prevented overlapping site subnets from being configured has been resolved.</li>
      <li>An issue that prevented sub-asset enumeration for IPv6 OT services has been resolved.</li>
      <li>An issue that could result in scan tasks crashing during technology detection has been resolved.</li>
      <li>An issue that led to the CrowdStrike integration using the wrong retry timer has been resolved.</li>
      <li>An issue that could cause the asset grid to disappear when selecting an asset with a deleted custom integrations has been resolved.</li>
      <li>An issue that resulted in the Subnet report double-counting some addresses has been resolved.</li>
      <li>An issue that prevented <code>Select All</code> from working on the Software By Asset view has been resolved.</li>
      <li>An issue that led to the date picker overflowing the container has been resolved.</li>
      <li>Assets identified through BACnet, CIP, MODBUS and KNXnet gateways are now temporarily excluded from license counts while we improve the configurability of this feature.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402603310">
  <div class="rn-card-header"><span class="rn-version">4.0.260331.0</span><time class="rn-date" datetime="2026-03-31">Mar 31, 2026</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that prevented the software tab on the asset details screen from loading has been resolved.</li>
      <li>An issue that prevented the services inventory from loading has been resolved.</li>
      <li>An issue that prevented software queries from calculating results has been resolved.</li>
      <li>An issue that prevented service queries from calculating results has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402603301">
  <div class="rn-card-header"><span class="rn-version">4.0.260330.1</span><time class="rn-date" datetime="2026-03-30">Mar 30, 2026</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402603300">
  <div class="rn-card-header"><span class="rn-version">4.0.260330.0</span><time class="rn-date" datetime="2026-03-30">Mar 30, 2026</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Assets are now identified through network-reachable BACnet, CIP, MODBUS and KNXnet gateway devices.</li>
      <li>Assets are now automatically placed into a Category (IT, OT, IoT) and OT assets are assigned Functions.</li>
      <li>An issue that caused Explorers deployed on Windows hosts to log &ldquo;Failed to write to log&rdquo; error messages has been resolved.</li>
      <li>An issue that could cause Explorers running on Windows to crash under certain scenarios has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402603290">
  <div class="rn-card-header"><span class="rn-version">4.0.260329.0</span><time class="rn-date" datetime="2026-03-29">Mar 29, 2026</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that resulted in zero-byte downloads for Windows executables has been resolved.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402603271">
  <div class="rn-card-header"><span class="rn-version">4.0.260327.1</span><time class="rn-date" datetime="2026-03-27">Mar 27, 2026</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402603270">
  <div class="rn-card-header"><span class="rn-version">4.0.260327.0</span><time class="rn-date" datetime="2026-03-27">Mar 27, 2026</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>The merge logic has been updated to avoid incorrectly merging assets with conflicting Intune hardware data.</li>
      <li>An issue that caused failed recurring tasks to create events with incorrect metadata has been resolved.</li>
      <li>An issue that could cause the console to run out of memory when serving Explorer or scanner binaries and large content updates has been resolved.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402603260">
  <div class="rn-card-header"><span class="rn-version">4.0.260326.0</span><time class="rn-date" datetime="2026-03-26">Mar 26, 2026</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>runZero now offers an optional API key IP address allowlist which can be configured in the Account Settings section of your console.</li>
      <li>The InsightVM integration now supports the ability to import asset tags.</li>
      <li>The Tanium integration now filters additional invalid attribute values.</li>
      <li>The Active Directory integration now includes Referrals in LDAP search error messages, if available.</li>
      <li>The performance of loading the Tasks page has been improved.</li>
      <li>An issue where cross-site aggregate query metrics could fail to be populated has been resolved.</li>
      <li>An issue that prevented users from creating new dashboards has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402603230">
  <div class="rn-card-header"><span class="rn-version">4.0.260323.0</span><time class="rn-date" datetime="2026-03-23">Mar 23, 2026</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>The runZero Risk Management dashboard is now the default view when no other dashboard has been selected.</li>
      <li>The LDAP integration now includes extension attributes in its available data.</li>
      <li>An issue that prevented images from displaying in specific sections of the console has been resolved.</li>
      <li>An issue that prevented the BACnet probe from pulling data from the BACnet Broadcast Management Device (BBMD) and the Foreign Device Table (FDT) has been resolved.</li>
      <li>An issue that caused the user avatars in the team tables to render incorrectly has been resolved.</li>
      <li>An issue where suppressed vulnerabilities would not be returned when queried in metrics calculations has been addressed.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402603180">
  <div class="rn-card-header"><span class="rn-version">4.0.260318.0</span><time class="rn-date" datetime="2026-03-18">Mar 18, 2026</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>The asset view now offers <code>Unmerge</code> and <code>Export as task data</code> actions under the <code>Manage</code> menu.</li>
      <li>The scanner now supports the Atlas Copco Open Protocol for device discovery.</li>
      <li>The scanner now provides additional detail for the IPMI protocol.</li>
      <li>The scanner now skips screenshots for TLS versions unsupported by Chrome.</li>
      <li>The scanner now enumerates the backplane of Ethernet/IP CIP services automatically, reporting any visible assets.</li>
      <li>Operating System End of Life (EOL) data for Microsoft Windows and HP/HPE iLO has been updated.</li>
      <li>The web console <a href="https://help.runzero.com/docs/troubleshooting-supported-browsers/">minimum supported browser version</a> has been updated to Chrome 123 (March 2024).</li>
      <li>An issue that could prevent tasks from being rescheduled when console disk space is low has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402603120">
  <div class="rn-card-header"><span class="rn-version">4.0.260312.0</span><time class="rn-date" datetime="2026-03-12">Mar 12, 2026</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that caused the AWS integration to trim the role prefix from the ARN has been resolved.</li>
      <li>An issue that caused the self-hosted console return an error when the <code>AWS_CA_BUNDLE</code> environment variable is set has been resolved.</li>
      <li>An issue that caused the self-hosted console to remove the systemd service during manual restarts has been resolved.</li>
      <li>An issue that caused the self-hosted console to print an error on startup has been resolved.</li>
      <li>An issue that could prevent in empty notification templates being sent has been resolved.</li>
      <li>An issue causing excessive software record refreshes during task processing has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402603110">
  <div class="rn-card-header"><span class="rn-version">4.0.260311.0</span><time class="rn-date" datetime="2026-03-11">Mar 11, 2026</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>The scanner now covers additional default ports for the BACnet protocol.</li>
      <li>The <code>Known Exploited Vulnerability</code> finding has been retired in favor of direct vulnerability inventory queries (<code>kev:true</code>).</li>
      <li>The self-hosted console will suggest email as an alternative if the fingerprint exceeds the maximum size.</li>
      <li>The SentinelOne integration now supports a longer timeout for API calls (5 minutes).</li>
      <li>The Tanium integration asset matching behavior is now more accurate</li>
      <li>The LDAP integration&rsquo;s import of directory groups is now much faster.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402603071">
  <div class="rn-card-header"><span class="rn-version">4.0.260307.1</span><time class="rn-date" datetime="2026-03-07">Mar 7, 2026</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Integration tasks with significant software records now process faster after an initial sync.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402603070">
  <div class="rn-card-header"><span class="rn-version">4.0.260307.0</span><time class="rn-date" datetime="2026-03-07">Mar 7, 2026</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>The performance of <code>software:</code> searches from the asset inventory has been improved.</li>
      <li>A bug that could result in valid SSH endpoints being removed during ghost asset filtering has been resolved.</li>
      <li>A bug that prevented the NetBox integration from connecting to some 4.2.x versions has been resolved.</li>
      <li>A bug that allowed excessive <code>domain:</code> keywords to be supplied during scan configuration has been resolved.</li>
      <li>A bug that prevented the Shodan integration from resolving scan targets when configured as part of a scan task has been resolved.</li>
      <li>A bug that could result in an Explorer registering as a new instance during an upgrade has been resolved.</li>
      <li>A bug that could lead to inconsistent fingerprinting via BACnet has been resolved.</li>
      <li>Fingerprinting has been improved for assets imported from Dragos.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402603041">
  <div class="rn-card-header"><span class="rn-version">4.0.260304.1</span><time class="rn-date" datetime="2026-03-04">Mar 4, 2026</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Performance improvements.</li>
      <li>Merge logic improvements.</li>
      <li>Phantom device detection has been improved.</li>
      <li>Shodan integration tasks that do not find any results are now logged, but do not fail.</li>
      <li>Accessibility of navigation items within dropdown menus has been improved.</li>
    </ul>
    <div class="rn-section-label"><svg width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M14 2H6a2 2 0 00-2 2v16a2 2 0 002 2h12a2 2 0 002-2V8z"/><polyline points="14 2 14 8 20 8"/><line x1="16" y1="13" x2="8" y2="13"/><line x1="16" y1="17" x2="8" y2="17"/></svg> Content updates</div>
    <ul class="rn-items">
      <li>Fingerprint improvements.</li>
    </ul>
    <div class="rn-section-label"><svg width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M8 2l1.88 1.88M14.12 3.88L16 2M9 7.13v-1a3.003 3.003 0 116 0v1M12 20c-3.3 0-6-2.7-6-6v-3a4 4 0 014-4h4a4 4 0 014 4v3c0 3.3-2.7 6-6 6M12 20v-9M6.53 9C4.6 8.8 3 7.1 3 5M6 13H2M6 17l-4 1M17.47 9c1.93-.2 3.53-1.9 3.53-4M18 13h4M18 17l4 1"/></svg> Bug fixes</div>
    <ul class="rn-items">
      <li>An issue preventing some inventory searches linked to outliers from returning the expected results has been resolved.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402603020">
  <div class="rn-card-header"><span class="rn-version">4.0.260302.0</span><time class="rn-date" datetime="2026-03-02">Mar 2, 2026</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>A bug that could result in CrowdStrike fingerprinting not being applied to assets has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402603010">
  <div class="rn-card-header"><span class="rn-version">4.0.260301.0</span><time class="rn-date" datetime="2026-03-01">Mar 1, 2026</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that could cause Explorer processes to crash during a scan has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402602220">
  <div class="rn-card-header"><span class="rn-version">4.0.260222.0</span><time class="rn-date" datetime="2026-02-22">Feb 22, 2026</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>The matching engine now uses hostnames from Rapid7 and Tanium sources to break matches.</li>
      <li>An issue that could cause Explorer processes to crash during a scan has been resolved.</li>
      <li>An issue where excessive memory was used by large vulnerability processing tasks has been resolved.</li>
      <li>An issue that could result in incomplete IPMI enumeration has been resolved.</li>
      <li>The scanner now skips protocol discovery for the Microsoft SQL Server replication service.</li>
      <li>Protocol handling was improved for IDENTD, Daytime, RIP, STUN, and TURN services.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402602190">
  <div class="rn-card-header"><span class="rn-version">4.0.260219.0</span><time class="rn-date" datetime="2026-02-19">Feb 19, 2026</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>The asset inventory search now allows results to be filtered by vulnerability suppression state.</li>
      <li>An issue where scan scheduling grace period settings from scan templates were not being applied has been resolved.</li>
      <li>An issue where old software records were not being properly removed has been resolved.</li>
      <li>The platform now supports a larger limit on asset vulnerability records.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402602181">
  <div class="rn-card-header"><span class="rn-version">4.0.260218.1</span><time class="rn-date" datetime="2026-02-18">Feb 18, 2026</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that prevented the stale integration attribute cleanup task from completing has been resolved.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402602180">
  <div class="rn-card-header"><span class="rn-version">4.0.260218.0</span><time class="rn-date" datetime="2026-02-18">Feb 18, 2026</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>The AWS integration now supports roles with non-default paths for the IAM Role credential type.</li>
      <li>The SNMP probe now trims whitespace from v3 credentials to avoid inadvertant misconfigurations.</li>
      <li>The PAN API probe data is now used in the Layer-2 topology report.</li>
      <li>The performance of the explorer details view has been improved.</li>
    </ul>
    <div class="rn-section-label"><svg width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M14 2H6a2 2 0 00-2 2v16a2 2 0 002 2h12a2 2 0 002-2V8z"/><polyline points="14 2 14 8 20 8"/><line x1="16" y1="13" x2="8" y2="13"/><line x1="16" y1="17" x2="8" y2="17"/></svg> Content updates</div>
    <ul class="rn-items">
      <li>Fingerprint improvements.</li>
    </ul>
    <div class="rn-section-label"><svg width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M8 2l1.88 1.88M14.12 3.88L16 2M9 7.13v-1a3.003 3.003 0 116 0v1M12 20c-3.3 0-6-2.7-6-6v-3a4 4 0 014-4h4a4 4 0 014 4v3c0 3.3-2.7 6-6 6M12 20v-9M6.53 9C4.6 8.8 3 7.1 3 5M6 13H2M6 17l-4 1M17.47 9c1.93-.2 3.53-1.9 3.53-4M18 13h4M18 17l4 1"/></svg> Bug fixes</div>
    <ul class="rn-items">
      <li>An issue that could result in addresses being incorrectly removed from an asset&rsquo;s Addresses Extra list has been resolved.</li>
      <li>An issue that prevented services from using the latest fingerprints when manually refingerprinting assets has been resolved.</li>
      <li>An issue that prevented the IEC 60870-5-104 probe from operating as expected has been resolved.</li>
      <li>An issue that could prevent some MDNS data from being applied to assets as expected has been resolved.</li>
      <li>An issue that prevented TOTP MFA tokens from being deleted by the &ldquo;Reset security tokens&rdquo; user action has been resolved.</li>
      <li>An issue that could prevent the speedtest results table from rendering has been resolved.</li>
      <li>An issue that could cause a scan task to report the error <code>scan data is unavailable</code> has been resolved.</li>
      <li>An issue that could cause LDAP connector scan tasks to hang when the service is unreachable was resolved.</li>
      <li>An issue that caused assets discovered through the MECM integration to be mis-merged with assets discovered in other Microsoft integrations has been resolved.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402602130">
  <div class="rn-card-header"><span class="rn-version">4.0.260213.0</span><time class="rn-date" datetime="2026-02-13">Feb 13, 2026</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Performance of loading the scan creation page has been improved.</li>
      <li>The subnet import action on the site edit page will now provide error messages if the chosen file is malformed or incorrect.</li>
      <li>The scanner can better detect and filter bogus MSSQL responses from Azure firewalls.</li>
      <li>The runZero Service Graph Connector’s asset export API now defaults to a page size of 1,000.</li>
    </ul>
    <div class="rn-section-label"><svg width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M14 2H6a2 2 0 00-2 2v16a2 2 0 002 2h12a2 2 0 002-2V8z"/><polyline points="14 2 14 8 20 8"/><line x1="16" y1="13" x2="8" y2="13"/><line x1="16" y1="17" x2="8" y2="17"/></svg> Content updates</div>
    <ul class="rn-items">
      <li>Fingerprint improvements.</li>
    </ul>
    <div class="rn-section-label"><svg width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M8 2l1.88 1.88M14.12 3.88L16 2M9 7.13v-1a3.003 3.003 0 116 0v1M12 20c-3.3 0-6-2.7-6-6v-3a4 4 0 014-4h4a4 4 0 014 4v3c0 3.3-2.7 6-6 6M12 20v-9M6.53 9C4.6 8.8 3 7.1 3 5M6 13H2M6 17l-4 1M17.47 9c1.93-.2 3.53-1.9 3.53-4M18 13h4M18 17l4 1"/></svg> Bug fixes</div>
    <ul class="rn-items">
      <li>An issue causing tasks to show an inaccurate &ldquo;Assets ignored&rdquo; count in the change summary has been resolved.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402602110">
  <div class="rn-card-header"><span class="rn-version">4.0.260211.0</span><time class="rn-date" datetime="2026-02-11">Feb 11, 2026</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>The site options on the import page are now sorted alphabetically.</li>
    </ul>
    <div class="rn-section-label"><svg width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M14 2H6a2 2 0 00-2 2v16a2 2 0 002 2h12a2 2 0 002-2V8z"/><polyline points="14 2 14 8 20 8"/><line x1="16" y1="13" x2="8" y2="13"/><line x1="16" y1="17" x2="8" y2="17"/></svg> Content updates</div>
    <ul class="rn-items">
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402602100">
  <div class="rn-card-header"><span class="rn-version">4.0.260210.0</span><time class="rn-date" datetime="2026-02-10">Feb 10, 2026</time></div>
  <div class="rn-card-body">
    <div class="rn-section-label"><svg width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M12 22s8-4 8-10V5l-8-3-8 3v7c0 6 8 10 8 10z"/></svg> Security updates</div>
    <ul class="rn-items">
      <li>An issue that could allow a credential to be updated and used for a task from outside of the authorized organization scope has been resolved.</li>
    </ul>
    <div class="rn-section-label"><svg width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M14 2H6a2 2 0 00-2 2v16a2 2 0 002 2h12a2 2 0 002-2V8z"/><polyline points="14 2 14 8 20 8"/><line x1="16" y1="13" x2="8" y2="13"/><line x1="16" y1="17" x2="8" y2="17"/></svg> Content updates</div>
    <ul class="rn-items">
      <li>Data extraction from LLMNR sources has been improved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
    <div class="rn-section-label"><svg width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M8 2l1.88 1.88M14.12 3.88L16 2M9 7.13v-1a3.003 3.003 0 116 0v1M12 20c-3.3 0-6-2.7-6-6v-3a4 4 0 014-4h4a4 4 0 014 4v3c0 3.3-2.7 6-6 6M12 20v-9M6.53 9C4.6 8.8 3 7.1 3 5M6 13H2M6 17l-4 1M17.47 9c1.93-.2 3.53-1.9 3.53-4M18 13h4M18 17l4 1"/></svg> Bug fixes</div>
    <ul class="rn-items">
      <li>A bug that could result in missing collection of CLDAP responses has been resolved.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402602090">
  <div class="rn-card-header"><span class="rn-version">4.0.260209.0</span><time class="rn-date" datetime="2026-02-09">Feb 9, 2026</time></div>
  <div class="rn-card-body">
    <div class="rn-section-label"><svg width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M14 2H6a2 2 0 00-2 2v16a2 2 0 002 2h12a2 2 0 002-2V8z"/><polyline points="14 2 14 8 20 8"/><line x1="16" y1="13" x2="8" y2="13"/><line x1="16" y1="17" x2="8" y2="17"/></svg> Content updates</div>
    <ul class="rn-items">
      <li>Fingerprinting and data extraction from CDP sources has been improved.</li>
      <li>The scanner now supports a <code>redact-secrets</code> option for the IPMI probe.</li>
      <li>Fingerprint improvements.</li>
    </ul>
    <div class="rn-section-label"><svg width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M8 2l1.88 1.88M14.12 3.88L16 2M9 7.13v-1a3.003 3.003 0 116 0v1M12 20c-3.3 0-6-2.7-6-6v-3a4 4 0 014-4h4a4 4 0 014 4v3c0 3.3-2.7 6-6 6M12 20v-9M6.53 9C4.6 8.8 3 7.1 3 5M6 13H2M6 17l-4 1M17.47 9c1.93-.2 3.53-1.9 3.53-4M18 13h4M18 17l4 1"/></svg> Bug fixes</div>
    <ul class="rn-items">
      <li>An issue that prevented previously scanned assets from being marked offline as expected has been resolved.</li>
      <li>An issue where incorrect vulnerability counts could be returned from metrics calculations has been resolved.</li>
      <li>An issue where AWS integration tasks running with IAM-console credentials within EC2 could not access AWS GovCloud regions has been resolved.</li>
      <li>SNMP-reported interface MACs are skipped if the LAA bit is set and other non-LAA MACs are present in the interface list.</li>
      <li>A bug that could result in HP iLOs being categorized as Server and not BMC has been resolved.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402602080">
  <div class="rn-card-header"><span class="rn-version">4.0.260208.0</span><time class="rn-date" datetime="2026-02-08">Feb 8, 2026</time></div>
  <div class="rn-card-body">
    <div class="rn-section-label"><svg width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M12 22s8-4 8-10V5l-8-3-8 3v7c0 6 8 10 8 10z"/></svg> Security updates</div>
    <ul class="rn-items">
      <li>An issue that could allow access to explorer groups from outside of the authorized organization scope has been resolved.</li>
    </ul>
    <div class="rn-section-label"><svg width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M14 2H6a2 2 0 00-2 2v16a2 2 0 002 2h12a2 2 0 002-2V8z"/><polyline points="14 2 14 8 20 8"/><line x1="16" y1="13" x2="8" y2="13"/><line x1="16" y1="17" x2="8" y2="17"/></svg> Content updates</div>
    <ul class="rn-items">
      <li>The scanner reports additional UDP protocols, including echo, daytime, cldap, iec104, llmnr, qotd, stun, time, turn, and zebra.</li>
      <li>The scanner reports new IPMI attributes, including cipher zero support, RAKP hash disclosure, and weak passwords found via RAKP.</li>
      <li>New queries have been added to report vulnerabilities associated with the new IPMI service attributes.</li>
      <li>The scanner supports a new option for the SNMP probe: <code>debug-scope</code>. When provided an IP address or CIDR, full diagnostics logs of the SNMP session are recorded into the scan task file.</li>
      <li>Improved normalization for hardware values received through the NetBox integration.</li>
      <li>Fingerprint improvements.</li>
    </ul>
    <div class="rn-section-label"><svg width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M8 2l1.88 1.88M14.12 3.88L16 2M9 7.13v-1a3.003 3.003 0 116 0v1M12 20c-3.3 0-6-2.7-6-6v-3a4 4 0 014-4h4a4 4 0 014 4v3c0 3.3-2.7 6-6 6M12 20v-9M6.53 9C4.6 8.8 3 7.1 3 5M6 13H2M6 17l-4 1M17.47 9c1.93-.2 3.53-1.9 3.53-4M18 13h4M18 17l4 1"/></svg> Bug fixes</div>
    <ul class="rn-items">
      <li>An issue that could prevent custom fingerprints from being used in all situations has been resolved.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402602060">
  <div class="rn-card-header"><span class="rn-version">4.0.260206.0</span><time class="rn-date" datetime="2026-02-06">Feb 6, 2026</time></div>
  <div class="rn-card-body">
    <div class="rn-section-label"><svg width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M12 22s8-4 8-10V5l-8-3-8 3v7c0 6 8 10 8 10z"/></svg> Security updates</div>
    <ul class="rn-items">
      <li>An issue that could expose records outside of the authorized organization scope through the MCP endpoints has been resolved.</li>
      <li>The runZero platform has fully adopted v2 of the AWS Go SDK, addressing potential risk with the out-of-support v1 library.</li>
    </ul>
    <div class="rn-section-label"><svg width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M14 2H6a2 2 0 00-2 2v16a2 2 0 002 2h12a2 2 0 002-2V8z"/><polyline points="14 2 14 8 20 8"/><line x1="16" y1="13" x2="8" y2="13"/><line x1="16" y1="17" x2="8" y2="17"/></svg> Content updates</div>
    <ul class="rn-items">
      <li>Fingerprint improvements for Telerik, Cockpit, RustDesk, Home Assistant OS, and Tenable Core.</li>
      <li>Improved device type normalization for free-form values ingested through integrations.</li>
    </ul>
    <div class="rn-section-label"><svg width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M8 2l1.88 1.88M14.12 3.88L16 2M9 7.13v-1a3.003 3.003 0 116 0v1M12 20c-3.3 0-6-2.7-6-6v-3a4 4 0 014-4h4a4 4 0 014 4v3c0 3.3-2.7 6-6 6M12 20v-9M6.53 9C4.6 8.8 3 7.1 3 5M6 13H2M6 17l-4 1M17.47 9c1.93-.2 3.53-1.9 3.53-4M18 13h4M18 17l4 1"/></svg> Bug fixes</div>
    <ul class="rn-items">
      <li>An issue that could result in dashboard vulnerability metrics not matching the underlying queries has been resolved.</li>
      <li>An issue that prevented the scanner from collecting Palo Alto Networks TLS thumbprints has been resolved.</li>
      <li>An issue that could lead to UX issues when viewing an Explorer with a long web screenshot diagnostic message has been resolved.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402602050">
  <div class="rn-card-header"><span class="rn-version">4.0.260205.0</span><time class="rn-date" datetime="2026-02-05">Feb 5, 2026</time></div>
  <div class="rn-card-body">
    <div class="rn-section-label"><svg width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M12 22s8-4 8-10V5l-8-3-8 3v7c0 6 8 10 8 10z"/></svg> Security updates</div>
    <ul class="rn-items">
      <li>An issue that could expose task information outside of the authorized organization scope has been resolved.</li>
    </ul>
    <div class="rn-section-label"><svg width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M14 2H6a2 2 0 00-2 2v16a2 2 0 002 2h12a2 2 0 002-2V8z"/><polyline points="14 2 14 8 20 8"/><line x1="16" y1="13" x2="8" y2="13"/><line x1="16" y1="17" x2="8" y2="17"/></svg> Content updates</div>
    <ul class="rn-items">
      <li>The scanner now identifies and reports detailed version information for exposed MCP servers.</li>
      <li>The NetBox connector now better normalizes free-form operating system values.</li>
      <li>Fingerprint improvements.</li>
    </ul>
    <div class="rn-section-label"><svg width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M8 2l1.88 1.88M14.12 3.88L16 2M9 7.13v-1a3.003 3.003 0 116 0v1M12 20c-3.3 0-6-2.7-6-6v-3a4 4 0 014-4h4a4 4 0 014 4v3c0 3.3-2.7 6-6 6M12 20v-9M6.53 9C4.6 8.8 3 7.1 3 5M6 13H2M6 17l-4 1M17.47 9c1.93-.2 3.53-1.9 3.53-4M18 13h4M18 17l4 1"/></svg> Bug fixes</div>
    <ul class="rn-items">
      <li>An issue that regressed the onboarded status filter for Microsoft Defender connections has been resolved.</li>
      <li>An issue that resulted in only a single subnet tag being applied to a matching asset has been resolved.</li>
      <li>An issue that could result in slow loads of the scan configuration page has been resolved.</li>
      <li>An issue that led to SNMP warnings being reported as errors has been resolved.</li>
      <li>The bundled npcap driver has been updated to v1.87, this resolves a potential BSoD in NPF_DoTap().</li>
      <li>The asset inventory now deprioritizes hostnames with the <code>.localdomain</code> and <code>.crestron</code> suffixes.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402602042">
  <div class="rn-card-header"><span class="rn-version">4.0.260204.2</span><time class="rn-date" datetime="2026-02-04">Feb 4, 2026</time></div>
  <div class="rn-card-body">
    <div class="rn-section-label"><svg width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M12 22s8-4 8-10V5l-8-3-8 3v7c0 6 8 10 8 10z"/></svg> Security updates</div>
    <ul class="rn-items">
      <li>An issue that could allow an authorized to view the clear-text secrets for a subset of credential types and fields has been resolved.</li>
    </ul>
    <div class="rn-section-label"><svg width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M14 2H6a2 2 0 00-2 2v16a2 2 0 002 2h12a2 2 0 002-2V8z"/><polyline points="14 2 14 8 20 8"/><line x1="16" y1="13" x2="8" y2="13"/><line x1="16" y1="17" x2="8" y2="17"/></svg> Content updates</div>
    <ul class="rn-items">
      <li>Fingerprint improvements.</li>
    </ul>
    <div class="rn-section-label"><svg width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M8 2l1.88 1.88M14.12 3.88L16 2M9 7.13v-1a3.003 3.003 0 116 0v1M12 20c-3.3 0-6-2.7-6-6v-3a4 4 0 014-4h4a4 4 0 014 4v3c0 3.3-2.7 6-6 6M12 20v-9M6.53 9C4.6 8.8 3 7.1 3 5M6 13H2M6 17l-4 1M17.47 9c1.93-.2 3.53-1.9 3.53-4M18 13h4M18 17l4 1"/></svg> Bug fixes</div>
    <ul class="rn-items">
      <li>An issue preventing the task inspection card on the task overview from automatically refreshing has been resolved.</li>
      <li>An issue causing the Explorer speed test results to include speed tests from other Explorers within the organization has been resolved.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402602041">
  <div class="rn-card-header"><span class="rn-version">4.0.260204.1</span><time class="rn-date" datetime="2026-02-04">Feb 4, 2026</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>A site name column has been added to the &ldquo;Software inventory&rdquo; table.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402602040">
  <div class="rn-card-header"><span class="rn-version">4.0.260204.0</span><time class="rn-date" datetime="2026-02-04">Feb 4, 2026</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that could cause scan processing to fail with an error has been resolved.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402602030">
  <div class="rn-card-header"><span class="rn-version">4.0.260203.0</span><time class="rn-date" datetime="2026-02-03">Feb 3, 2026</time></div>
  <div class="rn-card-body">
    <div class="rn-section-label"><svg width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M12 22s8-4 8-10V5l-8-3-8 3v7c0 6 8 10 8 10z"/></svg> Security updates</div>
    <ul class="rn-items">
      <li>An issue that allowed MCP agents to access certificate information from outside of their authorized organization scope has been resolved.</li>
      <li>An issue that allowed administrators to create and update users outside of their authorized organization scope has been resolved.</li>
      <li>An issue that could prevent session inactivity timeouts from triggering due to automatic page reloading has been resolved.</li>
      <li>An issue that could allow a user with access to a credential to view sensitive fields through an API response has been resolved.</li>
    </ul>
    <div class="rn-section-label"><svg width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M14 2H6a2 2 0 00-2 2v16a2 2 0 002 2h12a2 2 0 002-2V8z"/><polyline points="14 2 14 8 20 8"/><line x1="16" y1="13" x2="8" y2="13"/><line x1="16" y1="17" x2="8" y2="17"/></svg> Content updates</div>
    <ul class="rn-items">
      <li>Fingerprint improvements.</li>
    </ul>
    <div class="rn-section-label"><svg width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M8 2l1.88 1.88M14.12 3.88L16 2M9 7.13v-1a3.003 3.003 0 116 0v1M12 20c-3.3 0-6-2.7-6-6v-3a4 4 0 014-4h4a4 4 0 014 4v3c0 3.3-2.7 6-6 6M12 20v-9M6.53 9C4.6 8.8 3 7.1 3 5M6 13H2M6 17l-4 1M17.47 9c1.93-.2 3.53-1.9 3.53-4M18 13h4M18 17l4 1"/></svg> Bug fixes</div>
    <ul class="rn-items">
      <li>An issue that could cause metric counts to not match live search results in some circumstances has been resolved.</li>
      <li>An issue that could lead to excessive memory use in scan tasks that enable web screenshots has been resolved.</li>
      <li>An issue that could result in <code>scan data is unavailable</code> errors for large Explorer-run tasks has been resolved.</li>
      <li>An issue that could trigger a console stack trace when deleting the last organization within an account has been resolved.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402602020">
  <div class="rn-card-header"><span class="rn-version">4.0.260202.0</span><time class="rn-date" datetime="2026-02-02">Feb 2, 2026</time></div>
  <div class="rn-card-body">
    <div class="rn-section-label"><svg width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><polygon points="12 2 15.09 8.26 22 9.27 17 14.14 18.18 21.02 12 17.77 5.82 21.02 7 14.14 2 9.27 8.91 8.26 12 2"/></svg> New features</div>
    <ul class="rn-items">
      <li>Internet speed tests can be requested from any deployed Explorer. These tests can be run on-demand as well on a recurring schedule.</li>
      <li>Users may now re-fingerprint assets in bulk from the Asset Inventory using the new &ldquo;Refingerprint assets&rdquo; action within the &ldquo;Modify&rdquo; action menu.</li>
    </ul>
    <div class="rn-section-label"><svg width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M12 22s8-4 8-10V5l-8-3-8 3v7c0 6 8 10 8 10z"/></svg> Security updates</div>
    <ul class="rn-items">
      <li>An issue that allowed MCP agents to access remediation and asset information from outside of the authorized organization scope has been resolved.</li>
      <li>An issue that allowed all-organization administrators to promote accounts to superuser status has been resolved.</li>
    </ul>
    <div class="rn-section-label"><svg width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M14 2H6a2 2 0 00-2 2v16a2 2 0 002 2h12a2 2 0 002-2V8z"/><polyline points="14 2 14 8 20 8"/><line x1="16" y1="13" x2="8" y2="13"/><line x1="16" y1="17" x2="8" y2="17"/></svg> Content updates</div>
    <ul class="rn-items">
      <li>Fingerprint improvements.</li>
    </ul>
    <div class="rn-section-label"><svg width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M8 2l1.88 1.88M14.12 3.88L16 2M9 7.13v-1a3.003 3.003 0 116 0v1M12 20c-3.3 0-6-2.7-6-6v-3a4 4 0 014-4h4a4 4 0 014 4v3c0 3.3-2.7 6-6 6M12 20v-9M6.53 9C4.6 8.8 3 7.1 3 5M6 13H2M6 17l-4 1M17.47 9c1.93-.2 3.53-1.9 3.53-4M18 13h4M18 17l4 1"/></svg> Bug fixes</div>
    <ul class="rn-items">
      <li>An issue that could cause site subnet tags on an asset to be inadvertently cleared has been resolved.</li>
      <li>An issue that could cause scans to stall for up to fifteen minutes has been resolved.</li>
      <li>An issue that could cause the scanner to stall during initialization on MacOS has been resolved.</li>
      <li>An issue that could cause tasks to stall while stopping in certain rare cases has been resolved.</li>
      <li>An issue that could cause tasks to stall at 99% in certain rare situations has been resolved.</li>
      <li>An issue that could result in resource leaks during screenshot capture has been resolved.</li>
      <li>An issue that could prevent a custom integration task from re-importing correctly has been resolved.</li>
      <li>An issue that could prevent NetBox imports from including certain assets has been resolved.</li>
      <li>An issue that could lead to custom integration warnings when no integration was specified has been resolved.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402601290">
  <div class="rn-card-header"><span class="rn-version">4.0.260129.0</span><time class="rn-date" datetime="2026-01-29">Jan 29, 2026</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402601280">
  <div class="rn-card-header"><span class="rn-version">4.0.260128.0</span><time class="rn-date" datetime="2026-01-28">Jan 28, 2026</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>The scanner now supports a new &ldquo;strategy&rdquo; probe that can be used to adjust the target order. Setting the &ldquo;scan-sequential&rdquo; option will switch from randomized target ordering to linear sequential scans. This option can help when assessing large networks with low DHCP lease times.</li>
      <li>An issue where saved queries containing &ldquo;OR&rdquo; operators could fail to complete or result in incorrect values has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402601271">
  <div class="rn-card-header"><span class="rn-version">4.0.260127.1</span><time class="rn-date" datetime="2026-01-27">Jan 27, 2026</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Security: This update resolves an internally-identified issue that could have allowed a user to observe an organization&rsquo;s details from outside of the authorized organization scope.</li>
      <li>An issue that could cause scans to take longer than expected in the SYN phase has been resolved.</li>
      <li>An issue that could result in <code>scan data is unavailable</code> errors for large Explorer-run tasks has been resolved.</li>
      <li>An issue that could present a browser detection error even when screenshots are available has been resolved.</li>
      <li>An issue where vulnerability links from the asset details page lead to <code>certificate_id</code> queries instead of <code>asset_id</code> queries has been resolved.</li>
      <li>An issue where scans using valid SNMP v3 credentials could return incomplete information has been resolved.</li>
      <li>A cosmetic issue with the display of large browser detection warning messages has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402601270">
  <div class="rn-card-header"><span class="rn-version">4.0.260127.0</span><time class="rn-date" datetime="2026-01-27">Jan 27, 2026</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>The attribute fp.os.cpe23 has been added to the asset CSV export format.</li>
      <li>The scanner can now detect and filter bogus MSSQL responses from Azure firewalls.</li>
      <li>The most recent search query on a datagrid page is now re-populated when returning to the page using the browser forward and back controls.</li>
      <li>An issue where ignored asset counts were over-reported has been resolved.</li>
      <li>An issue causing an incorrect link for the vulnerability count column in the asset inventory has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402601260">
  <div class="rn-card-header"><span class="rn-version">4.0.260126.0</span><time class="rn-date" datetime="2026-01-26">Jan 26, 2026</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Security: This update resolves an internally-identified issue that could have allowed an Explorer within an account to be selected from outside of the authorized organization scope.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402601233">
  <div class="rn-card-header"><span class="rn-version">4.0.260123.3</span><time class="rn-date" datetime="2026-01-23">Jan 23, 2026</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that could prevent runZero from syncing data from NetBox instances with custom field values has been resolved.</li>
      <li>An issue that could cause slow query performance for <code>alive</code> inventory queries has been resolved.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402601232">
  <div class="rn-card-header"><span class="rn-version">4.0.260123.2</span><time class="rn-date" datetime="2026-01-23">Jan 23, 2026</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that could cause slow performance for the vulnerability groups inventory has been resolved.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402601231">
  <div class="rn-card-header"><span class="rn-version">4.0.260123.1</span><time class="rn-date" datetime="2026-01-23">Jan 23, 2026</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Security: This update fixes an SQL injection vulnerability introduced in version 4.0.260123.0 related to saved queries.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402601230">
  <div class="rn-card-header"><span class="rn-version">4.0.260123.0</span><time class="rn-date" datetime="2026-01-23">Jan 23, 2026</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Explorers now monitor available disk space and terminate tasks early if less than 250MiB remains free.</li>
      <li>The performance of vulnerability queries that are limited to risk and source keywords has been improved.</li>
      <li>An issue that prevented file import tasks from importing custom integration data correctly has been resolved.</li>
      <li>An issue that omitted some vulnerabilities with multiple CVEs from the results when searching vulnerability groups by CVE has been resolved.</li>
      <li>An issue that prevented Microsoft SQL Server protocol discovery in some cases where encryption was required has been resolved.</li>
      <li>An issue that prevented sorting credentials by ID has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402601202">
  <div class="rn-card-header"><span class="rn-version">4.0.260120.2</span><time class="rn-date" datetime="2026-01-20">Jan 20, 2026</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>The scanner now identifies and tries to work around network interfaces that don&rsquo;t apply BPF rules correctly.</li>
      <li>The match and merge behavior has been improved for SNMP devices and Azure database instances.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402601201">
  <div class="rn-card-header"><span class="rn-version">4.0.260120.1</span><time class="rn-date" datetime="2026-01-20">Jan 20, 2026</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue preventing queries using the <code>organization</code> keyword from being created, updated, or imported has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402601200">
  <div class="rn-card-header"><span class="rn-version">4.0.260120.0</span><time class="rn-date" datetime="2026-01-20">Jan 20, 2026</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that could prevent the scanner from capturing web screenshots has been resolved.</li>
      <li>An issue that could prevent asset merges from succeeding in some cases has been resolved.</li>
      <li>The scanner will now ignore bogus FTP service replies from Zscaler systems.</li>
      <li>The Palo Alto Networks connector now reports additional diagnostic data.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402601181">
  <div class="rn-card-header"><span class="rn-version">4.0.260118.1</span><time class="rn-date" datetime="2026-01-18">Jan 18, 2026</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that could lead to a memory leak in long-running scan tasks that enable web screenshots has been resolved.</li>
      <li>An issue that could prevent asset merges from succeeding in some cases has been resolved.</li>
      <li>The scanner will now better manage memory use in low-memory conditions.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402601180">
  <div class="rn-card-header"><span class="rn-version">4.0.260118.0</span><time class="rn-date" datetime="2026-01-18">Jan 18, 2026</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>The Wiz integration now merges similar vulnerability reports within the same system.</li>
      <li>The NetBox integration now supports versions 4.3.0 and newer.</li>
      <li>An issue that could prevent CrowdStrike syncs from completing during a session refresh has been resolved.</li>
      <li>An issue that could cause runZero Explorers to ping the IMDSv2 service outside of AWS has been resolved.</li>
      <li>Operating system normalization improvements.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402601150">
  <div class="rn-card-header"><span class="rn-version">4.0.260115.0</span><time class="rn-date" datetime="2026-01-15">Jan 15, 2026</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Recent user data has been added for Microsoft MECM connector tasks.</li>
      <li>An issue that could cause hosted scans to use excessive memory when capturing screenshots has been resolved.</li>
      <li>An issue that could cause search buttons to be incorrectly shown for image attributes has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402601140">
  <div class="rn-card-header"><span class="rn-version">4.0.260114.0</span><time class="rn-date" datetime="2026-01-14">Jan 14, 2026</time></div>
  <div class="rn-card-body">
    <div class="rn-section-label">This release improves the scanner&#39;s ability to capture web screenshots</div>
    <ul class="rn-items">
      <li>The scanner now uses the Chrome Debug Protocol by default, falling back to the original headless <code>--screenshot</code> command-line method if necessary.</li>
      <li>The scanner now supports a wider range of browsers, including many variants of Chromium, as well as Microsoft Edge when running on Windows.</li>
      <li>The scanner now supports environment variables for controlling which version of Chromium is used, including automatic installation.</li>
      <li>The scanner now runs the browser with reduced privileges and within a sandbox when possible.</li>
      <li>The scanner now collects the names of global javascript objects from the browser environment.</li>
      <li>This release also addresses bugs with the previous web screenshot functionality:</li>
      <li>The scanner now disables the browser sandbox on Linux platforms where user namespaces have been disabled and no appropriate AppArmor profile or setuid sandbox helper is present.</li>
      <li>The scanner will complete a self-test at the start of each task and skip web screenshots if initialization fails, avoiding repeated browser crashes.</li>
      <li>The scanner now prevents the browser from writing write core dumps to disk on crash.</li>
    </ul>
    <div class="rn-section-label">In addition to the web screenshot updates</div>
    <ul class="rn-items">
      <li>The Windows Explorer now captures runtime exceptions into a <code>.err</code> file in the executable directory.</li>
      <li>An issue that could result in dashboard metrics not taking into account vulnerability suppressions has been resolved.</li>
      <li>An issue that could prevent LDAP integrations from completing when using trusted TLS certificates has been resolved.</li>
      <li>An issue that could result in partial collection of TCP service information has been resolved.</li>
      <li>An issue that could result in erroneous reporting of MongoDB on port 27017 has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402601100">
  <div class="rn-card-header"><span class="rn-version">4.0.260110.0</span><time class="rn-date" datetime="2026-01-10">Jan 10, 2026</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that could result in out-of-scope IPv6 addresses being reported for scan tasks has been resolved.</li>
      <li>An issue that could lead to the certificate inventory falling out of sync with services has been resolved.</li>
      <li>An issue that could prevent TCP collection from completing in scans has been resolved.</li>
      <li>The individual task size limit was increased from 40GB to 100GB to handle larger vulnerability exports.</li>
      <li>Active vulnerability scans for critical vulnerabilities now include non-HTTP services.</li>
      <li>End-of-Life data is now shown for the Solaris operating system.</li>
      <li>Starlark scripts now support HS256 cryptographic operations.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402601071">
  <div class="rn-card-header"><span class="rn-version">4.0.260107.1</span><time class="rn-date" datetime="2026-01-07">Jan 7, 2026</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that could result in slow or incomplete enumeration of Windows RDP services has been resolved.</li>
      <li>An issue that could prevent Azure GCC partitions from authenticating correctly has been resolved.</li>
      <li>A performance issue when processing assets with large numbers of MAC addresses has been resolved.</li>
      <li>An issue where asset matching failed when the capitalization of a Windows hostname changed has been resolved.</li>
      <li>An issue that could lead to stale asset removal being excessively slow in large environments has been resolved.</li>
      <li>The bundled npcap driver has been updated to v1.86.</li>
      <li>Fingerprinting improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402601070">
  <div class="rn-card-header"><span class="rn-version">4.0.260107.0</span><time class="rn-date" datetime="2026-01-07">Jan 7, 2026</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that could prevent the scanner from detecting recent versions of MongoDB&rsquo;s wire protocol has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402601060">
  <div class="rn-card-header"><span class="rn-version">4.0.260106.0</span><time class="rn-date" datetime="2026-01-06">Jan 6, 2026</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that could prevent IAM role authentication from succeeding has been resolved.</li>
      <li>Tasks that process extremely large vulnerability exports now use less disk space.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402601050">
  <div class="rn-card-header"><span class="rn-version">4.0.260105.0</span><time class="rn-date" datetime="2026-01-05">Jan 5, 2026</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that could result in the hosted scanner ignoring assets with internal IPs has been resolved.</li>
      <li>An issue where the Azure GCC integration used the wrong endpoint has been resolved.</li>
      <li>The scanner now collects detailed statistics for every TCP connection.</li>
      <li>The AWS integration now collects additional information for failed logins.</li>
      <li>The API now allows task credentials to be specified within scan templates.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402512310">
  <div class="rn-card-header"><span class="rn-version">4.0.251231.0</span><time class="rn-date" datetime="2025-12-31">Dec 31, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that could lead to over-merging of assets in passive sampling tasks has been resolved.</li>
      <li>The Google Workspace integration now reports an asset-level serial number attribute.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402512301">
  <div class="rn-card-header"><span class="rn-version">4.0.251230.1</span><time class="rn-date" datetime="2025-12-30">Dec 30, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Task processing now better handles ARP proxies for asset matching on small network segments.</li>
      <li>An issue that could lead to inconsistent SNMP fingerprinting in rare situations has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402512300">
  <div class="rn-card-header"><span class="rn-version">4.0.251230.0</span><time class="rn-date" datetime="2025-12-30">Dec 30, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Scan task processing is significantly faster and reduces instances of ghost assets when specific firewalls are present.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402512280">
  <div class="rn-card-header"><span class="rn-version">4.0.251228.0</span><time class="rn-date" datetime="2025-12-28">Dec 28, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that could result in out-of-scope assets being marked as offine has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402512240">
  <div class="rn-card-header"><span class="rn-version">4.0.251224.0</span><time class="rn-date" datetime="2025-12-24">Dec 24, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Self-hosted installations now correctly remove old binaries during updates when installed in a non-default location.</li>
      <li>An issue that could prevent the Findings view from loading in All Organizations mode has been resolved.</li>
      <li>An issue that could cause tasks to show greater than 100% completion been resolved.</li>
      <li>An issue that could prevent the findings-with-instances event rule from saving the Risk filter has been resolved.</li>
      <li>The text &ldquo;Assets updated by task&rdquo; in task details has been updated to reflect that this is the number of observed assets, not the changed count.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402512220">
  <div class="rn-card-header"><span class="rn-version">4.0.251222.0</span><time class="rn-date" datetime="2025-12-22">Dec 22, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that could result in passive sampling tasks clearing services from unmatched site assets has been resolved.</li>
      <li>Self-hosted customers can now specify a proxy for AWS integrations with the <code>HTTPS_PROXY_AWS</code> setting.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402512211">
  <div class="rn-card-header"><span class="rn-version">4.0.251221.1</span><time class="rn-date" datetime="2025-12-21">Dec 21, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that could result in passive sampling tasks marking scanned assets as offline has been resolved.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402512210">
  <div class="rn-card-header"><span class="rn-version">4.0.251221.0</span><time class="rn-date" datetime="2025-12-21">Dec 21, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Large scan and passive sampling tasks are now processed faster.</li>
      <li>An issue that could result in CrowdStrike tasks aborting early when the remote endpoint was slow to respond has been resolved.</li>
      <li>An issue in the handling of hostname-based matching for systems named <code>test</code> has been resolved.</li>
      <li>Fingerprint improvements</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402512181">
  <div class="rn-card-header"><span class="rn-version">4.0.251218.1</span><time class="rn-date" datetime="2025-12-18">Dec 18, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Passive sampling, PCAP import, and reprocessed tasks now handle IP address reassignments more accurately.</li>
      <li>The merge behavior for long hostnames with truncated NetBIOS responses has been improved.</li>
      <li>An issue that could result in large scan grace periods wrapping to negative has been resolved.</li>
      <li>Fingerprint improvements</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402512180">
  <div class="rn-card-header"><span class="rn-version">4.0.251218.0</span><time class="rn-date" datetime="2025-12-18">Dec 18, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that could result in default login tests running when they were not explicitly enabled has been resolved.</li>
      <li>An issue that resulted in DNS requests being sent with brackets in the hostname has been resolved.</li>
      <li>The merge behavior for NetBIOS responses from multi-homed assets has been improved.</li>
      <li>The Findings inventory now loads much faster for large organizations.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402512170">
  <div class="rn-card-header"><span class="rn-version">4.0.251217.0</span><time class="rn-date" datetime="2025-12-17">Dec 17, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue which prevented the widget library modal search from showing custom widgets has been resolved.</li>
      <li>An issue which showed an incorrect icon for the Huawei iBMC OS has been resolved.</li>
      <li>An issue that prevented creating, updating, or automatic running of saved certificate queries has been resolved.</li>
      <li>An issue that prevented setting or exporting tags with a value consisting of a single double-quote character <code>&quot;</code> has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402512160">
  <div class="rn-card-header"><span class="rn-version">4.0.251216.0</span><time class="rn-date" datetime="2025-12-16">Dec 16, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Added the ability to search services by a related certificate.</li>
      <li>An issue that could cause the asset attribute <code>runZeroLastScanTS</code> to contain invalid data has been resolved.</li>
      <li>An issue that could prevent OS EOL from being asserted during manual merging or refingerprinting has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402512120">
  <div class="rn-card-header"><span class="rn-version">4.0.251212.0</span><time class="rn-date" datetime="2025-12-12">Dec 12, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Security: This update fixes two security issues identified by our external assessment partner. The first was a SQL injection vulnerability in the autocomplete backend and the second was related to improper access control for custom dashboards and widgets.</li>
      <li>Findings, Vulnerability Groups, and Vulnerabilities now support <a href="https://www.runzero.com/blog/vulnerability-management-suppressions/">suppressions</a>.</li>
      <li>Custom Integration scripts can now read HTTP response headers using the <code>http</code> or <code>requests</code> modules. They can be accessed as <code>response.headers[&quot;Header-Name&quot;]</code> and return a string array.</li>
      <li>The CrowdStrike integration now includes the CrowdStrike ExPRT Rating attribute when applicable.</li>
      <li>End-of-Life tracking has been improved for Windows versions where the network response returns incorrect version information.</li>
      <li>The self-hosted installer now defaults to using PostgreSQL 18 (up from 16).</li>
      <li>Alert rules can now be configured for certificate queries, using the event type <code>certificate-query-results</code>.</li>
      <li>An issue that could cause a blank dashboard to be created when deleting a dashboard has been resolved.</li>
      <li>An issue that could prevented some Tenable attributes from processing properly has been resolved.</li>
      <li>An issue that could lead to incorrect asset fingerprinting after a manual merge has been resolved.</li>
      <li>An issue that prevented the runZeroLastScanTS attribute from being set for imported scan data has been resolved.</li>
      <li>Performance improvements.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402512090">
  <div class="rn-card-header"><span class="rn-version">4.0.251209.0</span><time class="rn-date" datetime="2025-12-09">Dec 9, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>The Microsoft InTune integration now supports optionally retrieving LAPS information for assets.</li>
      <li>Merge logic has been improved for the Wiz integration.</li>
      <li>An issue that caused the Groups data table to have a broken layout has been resolved.</li>
      <li>Performance improvements.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402512080">
  <div class="rn-card-header"><span class="rn-version">4.0.251208.0</span><time class="rn-date" datetime="2025-12-08">Dec 8, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Security: This update fixes an open-redirect issue in the <code>next</code> parameter that was identified by our external assessment partner.</li>
      <li>An issue that could lead to stale Software Counts on assets has been resolved.</li>
      <li>The scanner now captures LLDP attributes via SNMP.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402512061">
  <div class="rn-card-header"><span class="rn-version">4.0.251206.1</span><time class="rn-date" datetime="2025-12-06">Dec 6, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>The Tenable integration now supports WAS vulnerability imports.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402512060">
  <div class="rn-card-header"><span class="rn-version">4.0.251206.0</span><time class="rn-date" datetime="2025-12-06">Dec 6, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Security: This update fixes two open-redirect issues in the <code>next</code> parameter that were identified by our external assessment partner.</li>
      <li>The performance of job processing for exceptionally large assets has been improved.</li>
      <li>An issue that could result in User Groups not being shown has been resolved.</li>
      <li>The MCP server now uses organization_id consistently between tools.</li>
      <li>Fingerprint improvements.</li>
      <li>Note that this is a Console-only update (no new Explorers or CLI).</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402512040">
  <div class="rn-card-header"><span class="rn-version">4.0.251204.0</span><time class="rn-date" datetime="2025-12-04">Dec 4, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that could cause the scanner to crash in rare cases has been resolved.</li>
      <li>An issue preventing the HTTP <code>X-Powered-By</code> headers from populating has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402512030">
  <div class="rn-card-header"><span class="rn-version">4.0.251203.0</span><time class="rn-date" datetime="2025-12-03">Dec 3, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that could result in an invalid domain name being extracted from Active Directory integration data has been resolved.</li>
      <li>An issue that caused some assets with integration data to merge incorrectly during scan tasks has been resolved.</li>
      <li>Performance improvements.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402512020">
  <div class="rn-card-header"><span class="rn-version">4.0.251202.0</span><time class="rn-date" datetime="2025-12-02">Dec 2, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Security: This update builds on Go v1.25.5, which includes security fixes related to TLS validation.</li>
      <li>Inventory search of asset attributes now specifically handle version comparison queries.</li>
      <li>An issue that prevented the user profile notification email from being set correctly has been resolved.</li>
      <li>An issue that could lead to incorrect TLS stack fingerprinting has been resolved.</li>
      <li>An issue that prevented Defender vulnerability imports from setting Risk correctly has been resolved.</li>
      <li>An issue that could lead to task data corruption due to <code>deflate</code> errors has been resolved.</li>
      <li>The Wiz integration now works around the 10,000 result limit for assets by switching to the report API.</li>
      <li>The Prisma integration now more accurately matches and merges assets by host name.</li>
      <li>Various performance improvements across the user interface and processing backend.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402512010">
  <div class="rn-card-header"><span class="rn-version">4.0.251201.0</span><time class="rn-date" datetime="2025-12-01">Dec 1, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Security: This update fixes two security issues found during internal review. Both issues were introduced in the 4.0.251120.0 release and (ironically) were related to the upcoming vulnerability suppression feature. The first issue is a SQL injection vulnerability in the <code>suppressed</code> search keyword. The second issue could allow vulnerability suppression rules to be applied to records outside of the authorized organizations if the unique ID records were known.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402511280">
  <div class="rn-card-header"><span class="rn-version">4.0.251128.0</span><time class="rn-date" datetime="2025-11-28">Nov 28, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that could result in excessive cpu and disk usage for pcap imports has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402511262">
  <div class="rn-card-header"><span class="rn-version">4.0.251126.2</span><time class="rn-date" datetime="2025-11-26">Nov 26, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Security: This update fixes an issue that could allow a user without an all-organization role to view the organization hierarchy.</li>
      <li>Qualys syncs now retry more often in the case of connection drops and timeouts.</li>
      <li>TLS fingerprinting now specifically flags services using Go 1.25.0 or newer.</li>
      <li>Console tasks interrupted by lack of disk space now retry automatically.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402511261">
  <div class="rn-card-header"><span class="rn-version">4.0.251126.1</span><time class="rn-date" datetime="2025-11-26">Nov 26, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402511260">
  <div class="rn-card-header"><span class="rn-version">4.0.251126.0</span><time class="rn-date" datetime="2025-11-26">Nov 26, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that could cause errors when existing TLS certificates are associated with new services has been resolved.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402511251">
  <div class="rn-card-header"><span class="rn-version">4.0.251125.1</span><time class="rn-date" datetime="2025-11-25">Nov 25, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that could cause errors when recording TLS certificates has been resolved.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402511250">
  <div class="rn-card-header"><span class="rn-version">4.0.251125.0</span><time class="rn-date" datetime="2025-11-25">Nov 25, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>The Explorer now reports an error when trying to use IAM role credentials outside of an AWS environment.</li>
      <li>The Certificates inventory now supports the <code>risk</code> and <code>ocsp_stapling</code> keywords as well as sorting on <code>risk</code>.</li>
      <li>An issue that could prevent queries with organization keywords from setting dashboard metrics has been resolved.</li>
      <li>An issue that could cause the console to use excessive disk space during processing has been resolved.</li>
      <li>An issue that could lead to a stale risk score for updated TLS findings has been resolved.</li>
      <li>A bogus MAC presented by some printer models will no longer be used for matching (Wave7 Optics).</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402511221">
  <div class="rn-card-header"><span class="rn-version">4.0.251122.1</span><time class="rn-date" datetime="2025-11-22">Nov 22, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that could prevent removal of stale software group entries has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402511210">
  <div class="rn-card-header"><span class="rn-version">4.0.251121.0</span><time class="rn-date" datetime="2025-11-21">Nov 21, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>The Prisma integration has been updated to support three new assets types: Azure Scale Set VM, Azure SQL VM, and Azure SQL Database.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402511202">
  <div class="rn-card-header"><span class="rn-version">4.0.251120.2</span><time class="rn-date" datetime="2025-11-20">Nov 20, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Performance improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402511201">
  <div class="rn-card-header"><span class="rn-version">4.0.251120.1</span><time class="rn-date" datetime="2025-11-20">Nov 20, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that could cause issues during runZero console updates has been resolved.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402511200">
  <div class="rn-card-header"><span class="rn-version">4.0.251120.0</span><time class="rn-date" datetime="2025-11-20">Nov 20, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>The keyword &ldquo;risk&rdquo; is now a searchable term in the certificate inventory.</li>
      <li>Updated <code>npcap</code> to version 1.85.</li>
      <li>An issue that may cause existing certificates found before v4.0.251118.0 to not be properly related to its services has been resolved.</li>
      <li>An issue with asserting End of Life for a subset of Windows LTSC versions in Tanium data has been resolved.</li>
      <li>An issue causing Windows edition information to be missing from assets fingerprinted from LDAP data has been resolved.</li>
      <li>An issue that could prevent users with the User role from creating integration tasks has been resolved.</li>
      <li>Failures related to AWS IAM Role operations outside of an AWS context have been clarified.</li>
      <li>An issue that caused the &ldquo;Include CIDRs&rdquo; and &ldquo;Include Site Names&rdquo; NetBox integration parameters to be missing from the CLI scanner has been resolved.</li>
      <li>An issue preventing tooltips from showing correctly in the certificate details page has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402511180">
  <div class="rn-card-header"><span class="rn-version">4.0.251118.0</span><time class="rn-date" datetime="2025-11-18">Nov 18, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>The Tenable integration can now optionally exclude Tenable Agent data.</li>
      <li>Certificates now track <code>OCSP stapling</code> and <code>name constraints</code> fields along with new search keywords.</li>
      <li>Certificates now track a <code>risk</code> field, which can be overridden and used for search, similarly to asset risk.</li>
      <li>An issue that could cause the scanner to crash abruptly in rare situations has been resolved.</li>
      <li>An issue that could cause duplicate Tenable Security Center assets in some circumstances has been resolved.</li>
      <li>An issue that caused the screen to flash when downloading a certificate PEM has been resolved.</li>
      <li>An issue that prevented indicator icons from animating correctly has been resolved.</li>
      <li>An issue that caused tooltips to show on fully displayed card titles has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402511140">
  <div class="rn-card-header"><span class="rn-version">4.0.251114.0</span><time class="rn-date" datetime="2025-11-14">Nov 14, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>The NetBox integration now supports the ability to override asset information from custom fields.</li>
      <li>The NetBox integration now offers searchable <code>TS</code> variants of the <code>Date</code> and <code>Date &amp; Time</code> fields.</li>
      <li>Asset matching of third-party integration data now merges into the most recently-seen scanned asset.</li>
      <li>An issue that could prevent metrics calculation from completing in some cases has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402511132">
  <div class="rn-card-header"><span class="rn-version">4.0.251113.2</span><time class="rn-date" datetime="2025-11-13">Nov 13, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that could cause TLS enumeration to abort early has been resolved.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402511131">
  <div class="rn-card-header"><span class="rn-version">4.0.251113.1</span><time class="rn-date" datetime="2025-11-13">Nov 13, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that could cause search errors when searching for certain values in numeric fields has been resolved.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402511130">
  <div class="rn-card-header"><span class="rn-version">4.0.251113.0</span><time class="rn-date" datetime="2025-11-13">Nov 13, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that could prevent the task details page asset change log from being fully displayed has been resolved.</li>
      <li>An issue that causes the <code>site:scope</code> keyword to not be respected in the scan exclusions when the <code>defaults</code> keyword was specified as well has been resolved.</li>
      <li>Improved logic for merging assets by hostname.</li>
      <li>An issue that could cause mismerged assets when processing scan tasks has been resolved.</li>
      <li>An issue that caused scan results to fail when processing has been resolved.</li>
      <li>An issue that resulted in verification errors for Azure Client Secret credentials in the GCC environment has been resolved.</li>
      <li>An issue that caused the Qualys integration to not retry on a connectivity error has been resolved.</li>
      <li>An issue that prevented task collection logs from being recorded has been resolved.</li>
      <li>An issue that could cause scans to freeze in rare cases has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402511050">
  <div class="rn-card-header"><span class="rn-version">4.0.251105.0</span><time class="rn-date" datetime="2025-11-05">Nov 5, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Added a new <code>associated vulnerabilities</code> field to the certificates inventory that shows the count of certificate vulnerabilities related to the associated services.</li>
      <li>Added a <code>validity_period</code> attribute to certificates in the Certificates Inventory that displays the lifetime of a certificate.</li>
      <li>An issue causing baseline goals using certificate queries to fail has been resolved.</li>
      <li>An issue where manually merging assets with integration data could result in duplicate assets when the integration runs again in certain circumstances has been resolved.</li>
      <li>An issue causing Explorers to appear as new on restart in self-hosted installations has been resolved.</li>
      <li>Improved merge logic for the Tenable Security Center integration.</li>
      <li>Fingerprint improvements.</li>
      <li>MCP improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402511030">
  <div class="rn-card-header"><span class="rn-version">4.0.251103.0</span><time class="rn-date" datetime="2025-11-03">Nov 3, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>The Meraki integration has been improved to better handle hostnames with spaces.</li>
      <li>An issue that caused a panic when processing Active Directory / LDAP data has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402510310">
  <div class="rn-card-header"><span class="rn-version">4.0.251031.0</span><time class="rn-date" datetime="2025-10-31">Oct 31, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that caused users to not be able to select hosted zones on the scan page has been resolved.</li>
      <li>If an asset has duplicate copies of attributes from an integration, they will now be cleaned up during task processing for that integration.</li>
      <li>An issue with the Crowdstrike integration that caused assets to be incorrectly skipped due to an incorrect last seen filter has been resolved.</li>
      <li>An issue has been resolved that may cause certificate details to not be displayed when related services have already been removed.</li>
      <li>Fingerprint improvements.</li>
      <li>MCP improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402510300">
  <div class="rn-card-header"><span class="rn-version">4.0.251030.0</span><time class="rn-date" datetime="2025-10-30">Oct 30, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that prevented navigating from the linked &ldquo;Matches&rdquo; column on the queries list for certificate queries to the pre-filtered certificate list has been resolved.</li>
      <li>An issue that caused template scans to fail to be created has been resolved.</li>
      <li>An issue that prevented custom integration icons from displaying in software data grids has been resolved.</li>
      <li>An issue that could cause the scanner to stall in rare cases has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402510280">
  <div class="rn-card-header"><span class="rn-version">4.0.251028.0</span><time class="rn-date" datetime="2025-10-28">Oct 28, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Organization and account administrators may now modify and reorder the attribute list used to determine default asset ownership on a per-organization or account-level basis.</li>
      <li>The AWS integration can now import from multiple AWS accounts without using AWS Organizations via a new AWS IAM Role credential type.</li>
      <li>A new &ldquo;Report incorrectly merged asset&rdquo; action has been added to the hamburger menu on the asset details page to allow quicker support contact when viewing an asset believed to be incorrectly merged.</li>
      <li>A new <code>Certificate and TLS Service Risks</code> finding has been added that groups queries from Certificates and TLS Services that contribute to Certificate Risk.</li>
      <li>Added the ability to search services by all certificates in the certificate chain using their <code>sha256</code>, <code>sha1</code>, or <code>bk_hash</code> attributes.</li>
      <li>An issue which prevented a certificate&rsquo;s extended key usage from displaying correctly has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402510230">
  <div class="rn-card-header"><span class="rn-version">4.0.251023.0</span><time class="rn-date" datetime="2025-10-23">Oct 23, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Ownership information is now included in software CSV exports.</li>
      <li>The <code>start_scan</code> tool has been added to the runZero MCP service.</li>
      <li>When processing assets, <code>@tanium.dev.lastLoggedInUser</code> is now included in the list of attributes used to determine default ownership for an asset.</li>
      <li>An issue that prevented data collection from TLS wrapped services in some cases has been resolved.</li>
      <li>An issue the prevented asserting Proxmox EOL information has been resolved.</li>
      <li>Phantom device detection has been improved.</li>
      <li>Merge logic improvements.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402510210">
  <div class="rn-card-header"><span class="rn-version">4.0.251021.0</span><time class="rn-date" datetime="2025-10-21">Oct 21, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Certificates now show associated services, assets, and vulnerabilities. Multiple search terms have been added, and an enhanced UI is introduced.</li>
      <li>Support for Explorer Groups has been added to the public scan API endpoint.</li>
      <li>An issue which limited the duration of the TLS socket in a ztls handshake has been resolved.</li>
      <li>An issue which affected performance in integrating with Nuclei has been resolved.</li>
      <li>An issue which prevented changes in dashboard custom widgets from persisting without reloading the app in the browser has been resolved.</li>
      <li>An issue that could prevent recent LAPS schema attributes from being discovered has been resolved.</li>
      <li>An issue that caused the subnet sampling parameters for a scan to not be persisted has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402510170">
  <div class="rn-card-header"><span class="rn-version">4.0.251017.0</span><time class="rn-date" datetime="2025-10-17">Oct 17, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that caused tasks to stay in the <code>New</code> state and never get scheduled if a runZero Explorer upgrade failed has been resolved.</li>
      <li>An issue that could cause runZero scans to stall in a partially-completed state has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402510160">
  <div class="rn-card-header"><span class="rn-version">4.0.251016.0</span><time class="rn-date" datetime="2025-10-16">Oct 16, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>The services inventory now supports searching by certificate_id.</li>
      <li>The certificates inventory now supports shorthand search for attributes of <code>pk_parameters:</code> fields, such as <code>rsa_exponent:65537</code>.</li>
      <li>The &ldquo;Refingerprint asset&rdquo; action is now always available on the asset details page.</li>
      <li>The ability to create new sites within an organization must be requested via support for new customer accounts. Existing customer accounts can still create sites.</li>
      <li>Meraki IP addresses used for internal purposes are now filtered out of asset records.</li>
      <li>An issue causing foreign attribute names on the Asset detail page to overflow over the displayed value has been resolved.</li>
      <li>An issue that prevented screenshots and favicon images from being displayed on the asset details page has been resolved.</li>
      <li>An issue that caused analysis tasks to run for a new organization with no completed tasks has been resolved.</li>
      <li>An issue that caused some query links to work incorrectly in the Rapid Response Alert emails has been resolved.</li>
      <li>An issue that could cause Qualys tasks to fail with &ldquo;unexpected EOF&rdquo; errors has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402510151">
  <div class="rn-card-header"><span class="rn-version">4.0.251015.1</span><time class="rn-date" datetime="2025-10-15">Oct 15, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that could cause self-hosted installations of the runZero console to have issues updating has been resolved.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402510150">
  <div class="rn-card-header"><span class="rn-version">4.0.251015.0</span><time class="rn-date" datetime="2025-10-15">Oct 15, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>The forms for NetBox, Intune, Meraki, Miradore, Google Workspace, Censys, LDAP, Shodan and AzureAD integration tasks have been updated for a consistent user experience and to allow selection of Explorer groups for running tasks.</li>
      <li>Serial numbers have been added to SentinelOne integration device attributes.</li>
      <li>An issue that prevented running passive scans on a network interface without assigned IP addresses has been resolved.</li>
      <li>An issue causing incorrect OS fingerprinting from Qualys data has been resolved.</li>
      <li>An issue that prevented sorting vulnerabilities by finding name when viewing asset details has been resolved.</li>
      <li>An issue that prevented the <code>echo-filter-spoofed-responses</code> probe option from functioning properly has been resolved.</li>
      <li>The <code>echo-filter-spoofed-responses</code> probe option has been renamed to <code>echo-ignore-icmp-only-internal-hosts</code>.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402510080">
  <div class="rn-card-header"><span class="rn-version">4.0.251008.0</span><time class="rn-date" datetime="2025-10-08">Oct 8, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>A system configuration option to disable CSRF protection has been added for self-hosted instances.</li>
      <li>An issue that prevented asset attribute reports from loading has been resolved.</li>
      <li>An issue that caused some vulnerabilities to be removed when two assets merged together has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402510072">
  <div class="rn-card-header"><span class="rn-version">4.0.251007.2</span><time class="rn-date" datetime="2025-10-07">Oct 7, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that caused <code>duplicate key</code> errors in some scan tasks has been resolved.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402510071">
  <div class="rn-card-header"><span class="rn-version">4.0.251007.1</span><time class="rn-date" datetime="2025-10-07">Oct 7, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Certificates may now be queried by the &ldquo;signature&rdquo; and &ldquo;public_key&rdquo;.</li>
      <li>The Microsoft Configuration Manager (MECM) integration now supports filtering by device collection ID.</li>
      <li>An issue in MCP query syntax for wireless providing the incorrect keys has been resolved.</li>
      <li>An issue that could result in incorrect asset software when processing Wiz integration data has been resolved.</li>
      <li>An issue that prevented vulnerability detection dates from updating after an asset is scanned has been resolved.</li>
      <li>An issue that prevented remediated vulnerabilities from being removed after scanning has been resolved.</li>
      <li>An issue that could cause unexpected merge behavior during integration tasks has been resolved.</li>
      <li>An issue that prevented stale AWS assets from being removed when the relevant task option is enabled has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402510070">
  <div class="rn-card-header"><span class="rn-version">4.0.251007.0</span><time class="rn-date" datetime="2025-10-07">Oct 7, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that could cause scans to stall in certain situations has been resolved.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402510030">
  <div class="rn-card-header"><span class="rn-version">4.0.251003.0</span><time class="rn-date" datetime="2025-10-03">Oct 3, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Custom integration scripts can now use <code>trust_device_type</code>, <code>trust_os</code> and <code>trust_os_version</code> attributes on the <code>ImportAsset</code> object to set an asset&rsquo;s fingerprint even if the custom values cannot be normalized via runZero&rsquo;s fingerprint engine.</li>
      <li>AWS IAM credentials can now be configured with a static external ID at the account level.</li>
      <li>An issue that prevented creating baseline goals against the certificates inventory has been resolved.</li>
      <li>An issue that could cause the connector form to fail to select the configured Explorer option when editing recurring connector tasks has been resolved.</li>
      <li>An issue that prevented editing a recurring connector task to stop running it on an Explorer has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402510010">
  <div class="rn-card-header"><span class="rn-version">4.0.251001.0</span><time class="rn-date" datetime="2025-10-01">Oct 1, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>The new Explorer groups feature allows you to create logical groupings of explorers that will intelligently schedule tasks amongst themselves.</li>
      <li>An issue that prevented Azure Government credentials from validating successfully has been resolved.</li>
      <li>An issue that caused MECM tasks to hang for a long period of time after the task was stopped has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402509300">
  <div class="rn-card-header"><span class="rn-version">4.0.250930.0</span><time class="rn-date" datetime="2025-09-30">Sep 30, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>The following MCP tools were added: <code>list_sites</code>, <code>query_directory_group</code>, and <code>query_wireless</code>.</li>
      <li>The vulnerability inventory by asset can now be searched by certificate attributes, including ID, type, serial, public key, signature, fingerprint, subject, issuer, and key usage.</li>
      <li>The Qualys integration now collects data with multiple parallel threads when available.</li>
      <li>An issue that caused the Rapid Response alert emails to be sent once per site with results instead of once per organization has been resolved.</li>
      <li>An issue that could result in slow CSV software exports has been resolved.</li>
      <li>An issue where searching for certificates by the <code>is_ca</code> field did not work correctly has been resolved.</li>
      <li>An issue causing the runZero Console&rsquo;s CSP policy to block custom JavaScript in self-hosted environments has been resolved.</li>
      <li>An issue that caused the site configuration page to display subnet tag key names that contain underscores incorrectly formatted has been resolved.</li>
      <li>An issue that caused some integrations not to be recognized as active has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402509260">
  <div class="rn-card-header"><span class="rn-version">4.0.250926.0</span><time class="rn-date" datetime="2025-09-26">Sep 26, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Assets can now be searched by certificate attributes, including ID, type, serial, public key, signature, fingerprint, subject, issuer, and key usage.</li>
      <li>The Prisma integration has been updated to support Azure VMs, GCP VMs, Azure Load Balancers, Azure SQL Server, and Azure Cosmos DB.</li>
      <li>Hostname matching logic has been improved.</li>
      <li>An issue that prevented the display of custom widgets for the certificate query type has been resolved.</li>
      <li>An issue that caused the MAC vendor to be incorrectly identified from airplay devices/services has been resolved.</li>
      <li>An issue that could result in invalid characters being sent during IPV6 DNS requests has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402509241">
  <div class="rn-card-header"><span class="rn-version">4.0.250924.1</span><time class="rn-date" datetime="2025-09-24">Sep 24, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that could result in service cleanup failing when the database is heavily loaded has been resolved.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402509240">
  <div class="rn-card-header"><span class="rn-version">4.0.250924.0</span><time class="rn-date" datetime="2025-09-24">Sep 24, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Enabled certificate queries to apply a vulnerability record to matching assets.</li>
      <li>An issue that could result in an empty &ldquo;References&rdquo; section in the vulnerability details view has been resolved.</li>
      <li>An issue that caused the Findings list page and Findings detail pages to load slowly has been resolved.</li>
      <li>An issue that could prevent some assets from merging as expected during integration processing has been resolved.</li>
      <li>An issue that where invalid SNMP responses could result in assets having incorrect hostnames has been resolved.</li>
      <li>An issue where copying a Dragos task could omit values in the subnet filter input has been resolved.</li>
      <li>The Tanium integration has been updated to improve filtering of bad data during data collection.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402509221">
  <div class="rn-card-header"><span class="rn-version">4.0.250922.1</span><time class="rn-date" datetime="2025-09-22">Sep 22, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that could cause the console service to restart during heavy processing has been resolved.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402509220">
  <div class="rn-card-header"><span class="rn-version">4.0.250922.0</span><time class="rn-date" datetime="2025-09-22">Sep 22, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>The site configuration page has been improved to add a CSV import feature for configuring subnets.</li>
      <li>The MECM integration now imports information about the last software patch applied via MECM in three new attributes: <code>lastSoftwarePatchTitle</code>, <code>lastSoftwarePatchArticleID</code>, and <code>lastSoftwarePatchTime</code>.</li>
      <li>The Wiz integration now includes a task parameter to allow customizing what Wiz resource types are imported into runZero.</li>
      <li>Two new attributes were added to the Wiz integration, <code>@wiz.dev.resourceType</code> and <code>@wiz.dev.resourceApiType</code>, corresponding to the Wiz resource type.</li>
      <li>Azure Client Secret credentials now have the ability to include / exclude user-specified subscription IDs, along with various other improvements around service verification.</li>
      <li>Self-hosted customers can now disable all public API endpoints by setting the <code>RUNZERO_DISABLE_PUBLIC_APIS</code> value to <code>true</code> in <code>/etc/runzero/config</code>.</li>
      <li>An issue preventing the license expiration warning from displaying suggested actions to a superuser has been resolved.</li>
      <li>An issue that could prevent assets from merging as expected when processing Qualys integration tasks has been resolved.</li>
      <li>Asset fingerprinting from Tanium data has been improved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402509180">
  <div class="rn-card-header"><span class="rn-version">4.0.250918.0</span><time class="rn-date" datetime="2025-09-18">Sep 18, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that prevented the self-hosted installer from completing on certain RHEL versions and variants has been resolved.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402509172">
  <div class="rn-card-header"><span class="rn-version">4.0.250917.2</span><time class="rn-date" datetime="2025-09-17">Sep 17, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that prevented some AWS tasks from completing has been resolved.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402509171">
  <div class="rn-card-header"><span class="rn-version">4.0.250917.1</span><time class="rn-date" datetime="2025-09-17">Sep 17, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that prevented Tenable Nessus scans from completing has been resolved.</li>
      <li>An issue that caused some Qualys tasks to fail has been resolved.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402509170">
  <div class="rn-card-header"><span class="rn-version">4.0.250917.0</span><time class="rn-date" datetime="2025-09-17">Sep 17, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>The Dragos integration now allows the use of TLS thumbprints within the credential configuration.</li>
      <li>Removed the option to apply a vulnerability record to matching assets for certificate queries.</li>
      <li>Memory management has been improved to prevent tasks with a large amount of vulnerability data from failing due to memory exhaustion.</li>
      <li>Improvements to how the scanner interacts with certain OT devices.</li>
      <li>An issue causing certificate queries matches to not be calculated has been resolved.</li>
      <li>An issue that could prevent a scan from running and cause an &ldquo;explorer failed to queue task&rdquo; error has been resolved.</li>
      <li>An issue that could cause assets with Qualys data to merge incorrectly in some circumstances has been resolved.</li>
      <li>An issue preventing users with no default role from creating &ldquo;Email runZero users&rdquo; alert channels for organizations they have access to has been resolved.</li>
      <li>An issue that could prevent copying Wiz integration tasks has been resolved.</li>
      <li>An issue that caused incorrect vulnerability counts on assets has been resolved.</li>
      <li>An issue that could cause the task tables from displaying rows has been resolved.</li>
      <li>An issue causing Rapid Response alert emails to be completely illegible in Classic Outlook has been resolved.</li>
      <li>An issue that prevented viewing the Findings list resulting in an &ldquo;array size exceeds the maximum allowed&rdquo; has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402509120">
  <div class="rn-card-header"><span class="rn-version">4.0.250912.0</span><time class="rn-date" datetime="2025-09-12">Sep 12, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>The MCP server now supports retrieving vulnerabilities.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402509100">
  <div class="rn-card-header"><span class="rn-version">4.0.250910.0</span><time class="rn-date" datetime="2025-09-10">Sep 10, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>The &ldquo;Fingerprint Only&rdquo; integration task option has been replaced by separate options to disable the import of software and/or vulnerabilities for CrowdStrike, MS365Defender, SentinelOne, Wiz, Tenable, Rapid7 InsightVM, and Qualys.</li>
      <li>The Dragos integration has been updated to filter asset results by subnets.</li>
      <li>All superuser accounts in trial and platform licensed tenants have been subscribed to automatic email alerts whenever a Rapid Response query&rsquo;s match count is greater than zero. These alerts can be turned off by disabling the appropriate rule on the alert rules page, and specific users can be excluded from these alerts by adding them to the &ldquo;Excluded users&rdquo; field of the appropriate alert channel.</li>
      <li>The Rapid Response MCP tool has been updated to function in offline environments.</li>
      <li>An issue that could result in an error when manually merging assets has been resolved.</li>
      <li>An issue that limited the number of top metrics to 10 in the Organization overview report has been resolved.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402509080">
  <div class="rn-card-header"><span class="rn-version">4.0.250908.0</span><time class="rn-date" datetime="2025-09-08">Sep 8, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Certificate queries can now be saved to the query library and support searching on fields <code>signature_algorithm_insecure</code>, <code>public_key_insecure</code>, <code>public_key_algorithm</code>, <code>public_key_bits</code>, <code>pk_parameters</code>, <code>signature_algorithm</code>, <code>key_usage</code>, <code>ext_key_usage</code>, <code>version</code>, <code>ocsp_server</code>, <code>crl_distribution_points</code>, and <code>issuing_certificate_url</code>.</li>
      <li>The Rapid7 InsightVM integration now has the ability to filter results by InsightVM site name using regex pattern matching.</li>
      <li>Custom integrations that run on hosted Explorers no longer have a script size limit.</li>
      <li>The ability to copy a user&rsquo;s invitation link to clipboard has been removed.</li>
      <li>Assets can now be searched by a <code>finding_code</code> term on the Assets page and via the assets API.</li>
      <li>The Qualys integration now supports excluding assets with certain tags during import.</li>
      <li>Updating Licensed entity details now displays a save confirmation dialog.</li>
      <li>The MCP server now supports retrieving query findings.</li>
      <li>Asset export APIs no longer include a <code>finding_count</code> attribute.</li>
      <li>An issue causing SSO group access details to not display unless the user was logged in has been resolved.</li>
      <li>An issue preventing the ability to hide a certificate from view has been resolved.</li>
      <li>An issue preventing updating the query on a saved query goal or custom widget has been resolved.</li>
      <li>An issue that prevented some Wiz serverless assets from merging with AWS assets has been resolved.</li>
      <li>An issue preventing selecting all rows in a table has been resolved.</li>
      <li>An issue that could cause an asset to be duplicated during task processing in some circumstances has been resolved.</li>
      <li>An issue causing the &ldquo;Latest Rapid Response&rdquo; dashboard widget to display data from all sites despite selecting a site filter has been resolved.</li>
      <li>An issue that resulted in duplicate findings being returned from findings APIs has been resolved.</li>
      <li>An issue that caused widget history charts to display inaccurate timestamps has been resolved.</li>
      <li>An issue that could provide confusing table contents in the current organization team table has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402509040">
  <div class="rn-card-header"><span class="rn-version">4.0.250904.0</span><time class="rn-date" datetime="2025-09-04">Sep 4, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402509020">
  <div class="rn-card-header"><span class="rn-version">4.0.250902.0</span><time class="rn-date" datetime="2025-09-02">Sep 2, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>runZero now integrates with the Dragos platform.</li>
      <li>Vulnerability details now include additional enrichment and offer an improved user experience.</li>
      <li>The Tanium integration now supports skipping software and vulnerabilities.</li>
      <li>An issue causing assets with hostnames of 3 or fewer characters to merge unexpectedly has been resolved.</li>
      <li>An issue that could cause recurring tasks to schedule duplicate sub-tasks has been resolved.</li>
      <li>An issue that prevented site CSV import error messages from being displayed has been resolved.</li>
      <li>An issue that could cause Qualys connections to fail when the initial response is slow has been resolved.</li>
      <li>An issue that prevented the Wiz integration from importing some types of assets has been resolved.</li>
      <li>An issue that prevented some Meraki assets from merging as expected has been resolved.</li>
      <li>Fingerprint improvements.</li>
      <li>Merge logic improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402509010">
  <div class="rn-card-header"><span class="rn-version">4.0.250901.0</span><time class="rn-date" datetime="2025-09-01">Sep 1, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402508281">
  <div class="rn-card-header"><span class="rn-version">4.0.250828.1</span><time class="rn-date" datetime="2025-08-28">Aug 28, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402508280">
  <div class="rn-card-header"><span class="rn-version">4.0.250828.0</span><time class="rn-date" datetime="2025-08-28">Aug 28, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that prevented SNMPv3 credentials from being updated with an empty context has been resolved.</li>
      <li>An issue preventing users from viewing the details page of certificates that lack a subject has been resolved.</li>
      <li>An issue that resulted in missing start times for recurring connector tasks running on the console has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402508261">
  <div class="rn-card-header"><span class="rn-version">4.0.250826.1</span><time class="rn-date" datetime="2025-08-26">Aug 26, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that resulted in malformed asset type fields for unmanaged Meraki assets has been resolved.</li>
      <li>The heuristics for asset type selection between tablets, laptops, and desktops have been improved.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402508260">
  <div class="rn-card-header"><span class="rn-version">4.0.250826.0</span><time class="rn-date" datetime="2025-08-26">Aug 26, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that prevented AWS and Wiz tasks from automatically removing unseen assets has been resolved.</li>
      <li>An issue that prevented a scan template&rsquo;s Exclude Hosts configuration option from being respected when changing sites has been resolved.</li>
      <li>An issue where newly discovered assets with missing addresses can cause the &ldquo;Newly discovered assets&rdquo; table to fail to show properly after an integration task has been resolved.</li>
      <li>An issue that caused Meraki assets to merge incorrectly in some circumstances has been resolved.</li>
      <li>An issue that occurred when removing a custom integration or source from assets has been resolved.</li>
      <li>An issue that caused duplicate software and vulnerability groups has been resolved.</li>
      <li>An issue that allowed custom integrations to be removed from assets across tenants without enforcing permissions has been resolved.</li>
      <li>An issue that could cause multiple connector tasks to be processed at the same time has been resolved.</li>
      <li>Scans now include safe checks for many remotely exploitable critical vulnerabilities by default.</li>
      <li>Explorer scan concurrency can now be updated via the runZero Organization API.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402508200">
  <div class="rn-card-header"><span class="rn-version">4.0.250820.0</span><time class="rn-date" datetime="2025-08-20">Aug 20, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Goals, alert rules, alert channels, and alert templates can now optionally have new organizations automatically assigned to them if &ldquo;Automatically add new organizations&rdquo; is selected in their options.</li>
      <li>The runZero-managed Risk Management dashboard&rsquo;s Latest Rapid Response widget has been updated to include a paginated carousel of the five most recent Rapid Response posts.</li>
      <li>An issue that could cause the Active Directory integration to fail to collect data in large environments has been resolved.</li>
      <li>An issue that could prevent the Switch Topology Report from loading has been resolved.</li>
      <li>An issue that could cause integration tasks to end prematurely before finishing data ingestion has been resolved.</li>
      <li>An issue that blocked AWS IAM Role credential external ID creation has been resolved.</li>
      <li>An issue that could cause certificates to not show in scan results has been resolved.</li>
      <li>An issue affecting querying inventory via MCP from some models has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402508180">
  <div class="rn-card-header"><span class="rn-version">4.0.250818.0</span><time class="rn-date" datetime="2025-08-18">Aug 18, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Shared dashboards can now be viewed in &ldquo;My organizations&rdquo; mode.</li>
      <li>An issue that caused the organization search keyword to be ignored in some inventory searches has been resolved.</li>
      <li>An issue that could cause tasks to be marked as ‘Failed to queue’ has been resolved.</li>
      <li>An issue causing a deadlock in the hub messaging system has been resolved.</li>
      <li>A regression preventing tooltips from appearing on some table cells in data tables throughout the console has been resolved.</li>
      <li>Fingerprint improvements.</li>
      <li>Beginning shortly after the release of runZero v4.0.250818.0, a small subset of active customers registered to the US region will be enrolled in automatic Rapid Response Matches alerting as part of a phased roll-out. Customers in other regions, including self-hosted customers, will automatically be enrolled at a later date.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402508141">
  <div class="rn-card-header"><span class="rn-version">4.0.250814.1</span><time class="rn-date" datetime="2025-08-14">Aug 14, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that could cause Explorers to disconnect and reconnect repeatedly has been resolved.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402508140">
  <div class="rn-card-header"><span class="rn-version">4.0.250814.0</span><time class="rn-date" datetime="2025-08-14">Aug 14, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Performance and user experience of the Switch Topology Report has been improved.</li>
      <li>Rendering performance of the data tables throughout the product has been improved.</li>
      <li>The Explorer deploy page now displays the currently active organization in the page header.</li>
      <li>The documented minimum operating system requirements for the runZero Explorer and CLI tool have been updated.</li>
      <li>An issue that could cause the Explorer/Scanner to use excessive memory when scanning HTTP endpoints has been resolved.</li>
      <li>An issue that could cause the Explorer service to fail to start when the service was marked interactive has been resolved.</li>
      <li>An issue that could cause tasks to be marked as &lsquo;Failed to queue&rsquo; has been resolved.</li>
      <li>An issue that could cause asset searches to generate an invalid query has been resolved.</li>
      <li>An issue that could limit the number of returned software results has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402508111">
  <div class="rn-card-header"><span class="rn-version">4.0.250811.1</span><time class="rn-date" datetime="2025-08-11">Aug 11, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that could cause tasks to freeze when running has been resolved.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402508110">
  <div class="rn-card-header"><span class="rn-version">4.0.250811.0</span><time class="rn-date" datetime="2025-08-11">Aug 11, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>The layout of regions in the AWS configuration form has been improved.</li>
      <li>An issue that could cause the <code>runZeroLastScanTS</code> attribute to be removed in some cases has been resolved.</li>
      <li>An issue where an asset&rsquo;s type could be incorrectly initialized as its method of detection in some cases has been resolved.</li>
      <li>An issue that caused the runZero Splunk add-on to import all assets regardless of the last sync has been resolved.</li>
      <li>An issue that prevented saving event templates with invalid Mustache template syntax has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402508080">
  <div class="rn-card-header"><span class="rn-version">4.0.250808.0</span><time class="rn-date" datetime="2025-08-08">Aug 8, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>All users across the platform may now create event rules for the following events:</li>
      <li><code>rapid-response-published</code> - triggered when one or more Rapid Response queries are published, updated, or removed from the console.</li>
      <li><code>rapid-response-with-matches</code> - triggered when a Rapid Response query&rsquo;s results change.</li>
      <li><code>findings-with-instances</code> - triggered when findings instance counts are updated.</li>
      <li>An issue causing the progress bar in the Switch Topology Report to not be hidden when the report has completed loading has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402508070">
  <div class="rn-card-header"><span class="rn-version">4.0.250807.0</span><time class="rn-date" datetime="2025-08-07">Aug 7, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue causing the progress bar in the Switch Topology Report to delay showing has been resolved.</li>
      <li>An issue with inventory search with multiple organizations has been resolved.</li>
      <li>Performance improvements.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402508050">
  <div class="rn-card-header"><span class="rn-version">4.0.250805.0</span><time class="rn-date" datetime="2025-08-05">Aug 5, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Asset matching has been improved by now considering hardware information, when available.</li>
      <li>The Qualys integration now allows for filtering assets that have not been scanned for a configurable time period.</li>
      <li>AWS integration now supports cross-account AWS roles for authentication.</li>
      <li>Experimental MCP server now available. It is an opt-in extension where users may bring their own LLM to interact with their runZero deployment.</li>
      <li>Tenable assets with agents will now have their agent health property shown as N/A when an invalid agent health property is received instead of omitting the agent health property from the asset.</li>
      <li>Fingerprint improvements.</li>
      <li>An issue that could cause online Explorers to disappear from the Explorers list has been resolved.</li>
      <li>An issue that caused subdomain expansion to return false domains for several domains has been resolved.</li>
      <li>An issue that could cause Nessus-reported vulnerabilities to have stale descriptions has been resolved.</li>
      <li>An issue in the network bridges report that caused the site to be deselected when changing the filter has been resolved.</li>
      <li>An issue that prevented the vulnerability table on the Asset Details page from sorting by finding name has been resolved.</li>
      <li>An issue that could cause the inventory table to crash with an error message when viewing data containing invalid country codes has been resolved.</li>
      <li>An issue that could cause a copied custom integration task to show an error and fail before the task could run has been resolved.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402508011">
  <div class="rn-card-header"><span class="rn-version">4.0.250801.1</span><time class="rn-date" datetime="2025-08-01">Aug 1, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that could cause some explorers that were online to be missing in the explorer view has been resolved.</li>
      <li>Improved merge logic memory usage.</li>
      <li>Updated the embedded npcap version to 1.83.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402508010">
  <div class="rn-card-header"><span class="rn-version">4.0.250801.0</span><time class="rn-date" datetime="2025-08-01">Aug 1, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that could cause scan tasks to stall in a partially-completed state under certain conditions has been resolved.</li>
      <li>Fingerprint improvements.</li>
      <li>Security update: This release includes a minor fix for an internally-discovered bug in dashboard and goal permissions, where one user may be able to retrieve the dashboard or goal configuration of another user.  This is only theoretically possible if they could guess the v4 random UUID of this entry, which is not visible cross-user in these scenarios. We do not believe this exposes sensitive data in any typical configuration and we have no evidence of it being exploited.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402507311">
  <div class="rn-card-header"><span class="rn-version">4.0.250731.1</span><time class="rn-date" datetime="2025-07-31">Jul 31, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Added the <code>insecure_check_verify</code> option to the http_post and Session custom integration script libraries.</li>
      <li>Combined the <code>Metrics</code> and <code>Query metrics, vulnerabilities, and findings</code> background tasks into a single streamlined task.</li>
      <li>Fixed an issue that prevented removal of some stale AWS assets.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402507310">
  <div class="rn-card-header"><span class="rn-version">4.0.250731.0</span><time class="rn-date" datetime="2025-07-31">Jul 31, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that could cause some integration tasks to freeze and restart during processing has been resolved.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402507300">
  <div class="rn-card-header"><span class="rn-version">4.0.250730.0</span><time class="rn-date" datetime="2025-07-30">Jul 30, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that could cause integrations to report duplicate assets has been resolved.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402507291">
  <div class="rn-card-header"><span class="rn-version">4.0.250729.1</span><time class="rn-date" datetime="2025-07-29">Jul 29, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that caused some tasks to fail during processing has been resolved.</li>
      <li>An issue that could trigger a search error when pivoting from the goal creation/edit page to the inventory has been resolved.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402507290">
  <div class="rn-card-header"><span class="rn-version">4.0.250729.0</span><time class="rn-date" datetime="2025-07-29">Jul 29, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Custom integration tasks now have the option to exclude unknown assets from the scan results.</li>
      <li>When the &ldquo;delete stale assets&rdquo; option of an AWS integration task is enabled, only stale assets from the AWS accounts associated with the current task will be removed.</li>
      <li>External users can now be selected as targets for &ldquo;Email runZero users&rdquo; channels.</li>
      <li>Users may now specify a &ldquo;Notification email&rdquo; address in their profile.</li>
      <li>This alternative email address is only used in place of the user&rsquo;s sign-in email address when the user is chosen as a recipient for an &ldquo;Email runZero users&rdquo; type alert channel. This address is <em>not</em> used for any account alerts, such as sign-in links or password reset emails.</li>
      <li>Merge behavior has been improved to reduce incorrect merges or duplicate asset records due to docking stations.</li>
      <li>Merge behavior has been improved to utilize hardware vendor data when available in order to reduce incorrect merges or duplicate asset records.</li>
      <li>An issue that caused some findings export API calls to fail has been resolved.</li>
      <li>An issue that caused some timestamps from Prisma Cloud assets to be incorrect has been resolved.</li>
      <li>An issue that prevented <code>software</code> keywords from working in asset inventory has been resolved.</li>
      <li>An issue that could cause software groups to be outdated in certain circumstances has been resolved.</li>
      <li>An issue that prevented saving the &ldquo;Excludes&rdquo; parameter in scan templates has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402507240">
  <div class="rn-card-header"><span class="rn-version">4.0.250724.0</span><time class="rn-date" datetime="2025-07-24">Jul 24, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Introducing Baseline Goals: Goals can now be scoped to specific inventory subsets, allowing customers to set goals against a subset of assets. For more information, see <a href="https://help.runzero.com/docs/goal-tracking/">documentation</a>.</li>
      <li>The UX for selecting vulnerability checks has been updated and now defaults to detecting and reporting exposed web panels.</li>
      <li>Additional security check categories can now be selected from the scan configuration page.</li>
      <li>The scanner now detects and reports exposed web admin panels by default.</li>
      <li>An issue that resulted in incorrect query totals has been resolved.</li>
      <li>Improved fingerprinting of Microsoft SharePoint products and versions.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402507210">
  <div class="rn-card-header"><span class="rn-version">4.0.250721.0</span><time class="rn-date" datetime="2025-07-21">Jul 21, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>The software inventory now supports filtering by organization ID or name with the <code>organization:</code> search term, and by site ID or name with the <code>site:</code> search term.</li>
      <li>The vulnerability inventory now supports filtering by organization ID or name with the <code>organization:</code> search term.</li>
      <li>Customers importing asset data into Splunk can now specify a search filter of <code>$checkpoint:ignore</code> to force Splunk to re-ingest all assets instead of just assets that were created/updated since the last sync.</li>
      <li>Assets discovered by the Tenable.io integration will now have <code>agentHealth</code> and <code>lastAgentHealthCheckTS</code> values shown when an agent is installed on an asset.</li>
      <li>An issue that caused vulnerabilities on an asset to repeatedly duplicate instances has been resolved.</li>
      <li>Normalization of assets of the type &ldquo;Human-machine interface&rdquo; has been improved.</li>
      <li>Fingerprint improvements.</li>
      <li>Performance improvements.</li>
      <li>Merge logic improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402507170">
  <div class="rn-card-header"><span class="rn-version">4.0.250717.0</span><time class="rn-date" datetime="2025-07-17">Jul 17, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>The alert channel type &ldquo;Email runZero users&rdquo; has been made generally available, allowing users to configure channels that email chosen runZero users.</li>
      <li>A column displaying each site&rsquo;s last updated time has been added to the Sites list view.</li>
      <li>Merge logic has been improved to detect duplicate names across different domains and avoid incorrect merging.</li>
      <li>An issue that resulted in missing counts in the goal detail page has been resolved.</li>
      <li>An issue that resulted in inconsistent goal progress has been resolved.</li>
      <li>An issue that prevented goals from being updated if the current organization was not selected for the goal has been resolved.</li>
      <li>An issue that caused task parameters to not be copied accurately for recurring or copied NetBox tasks has been resolved.</li>
      <li>An issue that prevented assets from merging correctly based on hostnames in some circumstances has been resolved.</li>
      <li>Performance and fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402507140">
  <div class="rn-card-header"><span class="rn-version">4.0.250714.0</span><time class="rn-date" datetime="2025-07-14">Jul 14, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Typographical errors in outlier count in the Asset Details page have been fixed.</li>
      <li>An issue that could result in Asset services not being correctly removed in certain limited cases has been resolved.</li>
      <li>An issue that caused the Microsoft Defender probe to filter out all vulnerabilities has been resolved.</li>
      <li>Performance and fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402507110">
  <div class="rn-card-header"><span class="rn-version">4.0.250711.0</span><time class="rn-date" datetime="2025-07-11">Jul 11, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that caused self-hosted instances using SMTP authentication method of &ldquo;none&rdquo; to incorrectly return an error stating &ldquo;unsupported SMTP authentication method&rdquo; has been resolved.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402507100">
  <div class="rn-card-header"><span class="rn-version">4.0.250710.0</span><time class="rn-date" datetime="2025-07-10">Jul 10, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>The Rapid Response dashboard widget now links to the correct search for software matches.</li>
      <li>An issue that caused metrics for queries returning zero results for a site to be saved with an incorrect total has been resolved.</li>
      <li>An issue that prevented refreshing authentication tokens for Palo Alto Networks&rsquo; Prisma Cloud integration has been resolved.</li>
      <li>Scanner improvements.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402507091">
  <div class="rn-card-header"><span class="rn-version">4.0.250709.1</span><time class="rn-date" datetime="2025-07-09">Jul 9, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that could cause out-of-memory conditions for Palo Alto Networks&rsquo; Prisma Cloud integration has been resolved.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402507090">
  <div class="rn-card-header"><span class="rn-version">4.0.250709.0</span><time class="rn-date" datetime="2025-07-09">Jul 9, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that could cause memory exhaustion to fail tasks instead of rescheduling them has been resolved.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402507082">
  <div class="rn-card-header"><span class="rn-version">4.0.250708.2</span><time class="rn-date" datetime="2025-07-08">Jul 8, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that caused a panic when processing Microsoft Defender data has been resolved.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402507081">
  <div class="rn-card-header"><span class="rn-version">4.0.250708.1</span><time class="rn-date" datetime="2025-07-08">Jul 8, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that caused scanner to panic has been resolved.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402507080">
  <div class="rn-card-header"><span class="rn-version">4.0.250708.0</span><time class="rn-date" datetime="2025-07-08">Jul 8, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>CrowdStrike data collection has been improved to be more memory efficient.</li>
      <li>Connectors now explicitly prefer merging devices into assets with a runZero source.</li>
      <li>Wiz reports are now compressed during upload from integration tasks.</li>
      <li>An issue that resulted in certain error messages in Microsoft SQL Server logs has been resolved.</li>
      <li>An issue that resulted in incorrect TLS fingerprinting of Microsoft SQL Server endpoints has been resolved.</li>
      <li>An issue that caused vulnerabilities detected via passive scanning to duplicate themselves during data processing has been resolved.</li>
      <li>An issue that caused a panic in the event of an unrecognized SMTP authentication method has been resolved.</li>
      <li>An issue that resulted in asset risk rank regression has been resolved.</li>
      <li>An issue that caused the &ldquo;last calculated&rdquo; timestamp on the dashboards page to be incorrect has been resolved.</li>
      <li>An issue that prevented Community Licensed users from navigating to the Organization Settings page has been resolved.</li>
      <li>An issue that caused the group assignment form to pre-select incorrect groups for selected users has been resolved.</li>
      <li>Scanner improvements.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402507010">
  <div class="rn-card-header"><span class="rn-version">4.0.250701.0</span><time class="rn-date" datetime="2025-07-01">Jul 1, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402506300">
  <div class="rn-card-header"><span class="rn-version">4.0.250630.0</span><time class="rn-date" datetime="2025-06-30">Jun 30, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>The &ldquo;delete stale&rdquo; integration option description for the AWS and Wiz integrations has been revised to clarify that it enables the deletion of all AWS or Wiz assets not seen by the currently running task.</li>
      <li>An issue that caused <code>last_seen</code> attributes to show up in event templates as a number instead of a date has been resolved.</li>
      <li>An issue that prevented community users from creating an organization when no organizations exists has been resolved.</li>
      <li>An issue that caused metrics analysis tasks to be repetitively scheduled in a loop has been resolved.</li>
      <li>An issue that caused slow queries to show up as errors in task logs has been resolved.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402506271">
  <div class="rn-card-header"><span class="rn-version">4.0.250627.1</span><time class="rn-date" datetime="2025-06-27">Jun 27, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that could result in some metrics tasks containing many &ldquo;duplicate query in metric data&rdquo; errors has been resolved.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402506270">
  <div class="rn-card-header"><span class="rn-version">4.0.250627.0</span><time class="rn-date" datetime="2025-06-27">Jun 27, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that prevented downloading the self-hosted version of runZero in the EU region has been resolved.</li>
      <li>The metrics calculation process has been improved.</li>
      <li>Discovery of embedded IP-to-serial devices has been improved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402506260">
  <div class="rn-card-header"><span class="rn-version">4.0.250626.0</span><time class="rn-date" datetime="2025-06-26">Jun 26, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Email Alerts now have improved support for JSON-formatted attachments.</li>
      <li>An issue loading dashboards with header widgets has been resolved.</li>
      <li>An issue preventing asset information from appearing in the RFC1918 report in some cases has been resolved.</li>
      <li>An issue causing Tenable.io integration tasks to incorrectly import INFO level vulnerabilties when configured to omit importing all vulnerabilities (i.e. &ldquo;fingerprint-only&rdquo;) has been resolved.</li>
      <li>Phantom device detection has been improved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402506250">
  <div class="rn-card-header"><span class="rn-version">4.0.250625.0</span><time class="rn-date" datetime="2025-06-25">Jun 25, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue causing projects to not correctly analyze vulnerabilities, findings, and query match counts has been resolved.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402506231">
  <div class="rn-card-header"><span class="rn-version">4.0.250623.1</span><time class="rn-date" datetime="2025-06-23">Jun 23, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that could cause some scans to fail when scanning certain devices has been resolved.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402506230">
  <div class="rn-card-header"><span class="rn-version">4.0.250623.0</span><time class="rn-date" datetime="2025-06-23">Jun 23, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that sometimes prevented Microsoft Intune tasks from completing has been resolved.</li>
      <li>Issues that could result in certain printers experiencing issues during a runZero scan have been resolved.</li>
      <li>An issue that could cause tasks to hang at 99% or fail with error task lost to explorer restart in certain uncommon situations has been resolved.</li>
      <li>An issue that prevented stale vulnerabilities from being deleted in certain circumstances has been resolved.</li>
      <li>Fingerprint and performance improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402506220">
  <div class="rn-card-header"><span class="rn-version">4.0.250622.0</span><time class="rn-date" datetime="2025-06-22">Jun 22, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that caused <code>agent-offline</code> events to be sent repeatedly every four hours has been resolved.  Only one <code>agent-offline</code> event will be sent each time an explorer goes offline.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402506200">
  <div class="rn-card-header"><span class="rn-version">4.0.250620.0</span><time class="rn-date" datetime="2025-06-20">Jun 20, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>The NetBox integration now supports filtering by site names and CIDRs.</li>
      <li>First-page loading speed for software, software groups, vulnerability groups, and findings instances tables has been improved.</li>
      <li>An issue that caused some software records to be duplicated has been resolved.</li>
      <li>An issue that could cause metric and vulnerability tasks to error has been resolved.</li>
      <li>An issue that could prevent sending an invitation email to new users has been resolved.</li>
      <li>An issue that caused <code>agent-offline</code> events to be sent even though explorers reconnected has been resolved.</li>
      <li>An issue that caused scan task tags to be applied incorrectly in some cases has been resolved.</li>
      <li>Merge logic improvements.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402506160">
  <div class="rn-card-header"><span class="rn-version">4.0.250616.0</span><time class="rn-date" datetime="2025-06-16">Jun 16, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>The goal details page has been redesigned to provide more information on goal progress.</li>
      <li>The goal creation workflow UI has been redesigned to streamline the process of editing and creating goals.</li>
      <li>Users with an inherited or explicit role of User or above within the selected organization can now manage goals, consistent with the functionality in alert rules, channels and templates.</li>
      <li>Goals that were previously configured to be &ldquo;global&rdquo; have been updated to apply to all currently-existing organizations and will no longer be associated with new or future organizations unless explicitly configured as such, consistent with the functionality in alert rules, channels and templates.</li>
      <li>Task statistics now display total count of software and vulnerability records that were created.</li>
      <li>An issue that caused the display name for the default asset ownership type to be shown as a nil UUID has been fixed.</li>
      <li>Invalid device detection improvements.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402506110">
  <div class="rn-card-header"><span class="rn-version">4.0.250611.0</span><time class="rn-date" datetime="2025-06-11">Jun 11, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Operating System End of Life (EOL) information for Microsoft Windows LTSC has been improved.</li>
      <li>Data retention can now be configured per site.</li>
      <li>Wiz integration tasks now have an option to delete stale Wiz assets after each sync.</li>
      <li>The Tenable.io integration has new separate options for disabling vulnerability import and disabling software import.</li>
      <li>Asset search has been updated to support filtering by missing <code>ownership_type</code> and missing <code>mac_countries</code>.</li>
      <li>When taking screenshots, Chrome is launched with the <code>--disable-breakpad</code> option.</li>
      <li>An issue with the Meraki integration that caused First Seen and Last Seen to be set incorrectly has been resolved.</li>
      <li>An issue that caused incorrect display of <code>ownership_type</code> information on dashboards has been resolved.</li>
      <li>Merge logic improvements.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402506100">
  <div class="rn-card-header"><span class="rn-version">4.0.250610.0</span><time class="rn-date" datetime="2025-06-10">Jun 10, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that could cause scans to stall when interrogating Microsoft SQL Server using TDS 8.0 has been resolved.</li>
      <li>An issue that could lead to out-of-memory conditions on self-hosted consoles with large connector tasks has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402506061">
  <div class="rn-card-header"><span class="rn-version">4.0.250606.1</span><time class="rn-date" datetime="2025-06-06">Jun 6, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that could cause finding generation to fail for sites in certain situations has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402506060">
  <div class="rn-card-header"><span class="rn-version">4.0.250606.0</span><time class="rn-date" datetime="2025-06-06">Jun 6, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>runZero scans can now check for default logins, you can find details in our <a href="https://help.runzero.com/docs/em-vulnerability-management/#runzero--nuclei">documentation</a>.</li>
      <li>The Prisma integration has been updated to support importing assets from AWS.</li>
      <li>Vulnerability displays will no longer show empty information cards when no further information is available.</li>
      <li>Performance improvements for certificate inventory searches, particularly for subject, authority and SAN DNS names.</li>
      <li>Merge logic improvements.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402506041">
  <div class="rn-card-header"><span class="rn-version">4.0.250604.1</span><time class="rn-date" datetime="2025-06-04">Jun 4, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Security: An issue that could allow MFA bypass during the password reset process has been resolved. This issue was identified internally and did not affect users who authenticate through SSO.</li>
      <li>An issue that prevented the <code>mac_countries</code> keyword from matching correctly has been resolved.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402506040">
  <div class="rn-card-header"><span class="rn-version">4.0.250604.0</span><time class="rn-date" datetime="2025-06-04">Jun 4, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>TOTP is now supported as a new MFA option in addition to existing WebAuthn and Passkey support.</li>
      <li>Scan tasks created via templates now carry over the <code>site:scope</code> keyword from the template.</li>
      <li>An issue that caused dashboard widgets to display incorrectly when no data is available has been resolved.</li>
      <li>An issue that prevented screenshots from being captured for some services has been resolved.</li>
      <li>Passive sampling tasks that are interrupted by active scans are no longer shown as failed.</li>
      <li>Link-local IPv6 and APIPA IPv4 addresses are no longer shown first in the addresses column of the inventory views.</li>
      <li>MAC addresses with the LAA bit set are no longer resolved to OUI vendors when the source is known to use random values.</li>
      <li>MAC addresses from virtual machine prefixes no longer assert a MAC Country field.</li>
      <li>Merge logic improvements.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402505300">
  <div class="rn-card-header"><span class="rn-version">4.0.250530.0</span><time class="rn-date" datetime="2025-05-30">May 30, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>The Vulnerabilities Inventory now includes a column for any associated Finding.</li>
      <li>The confirmation dialog for deleting an Explorer now indicates if tasks will be affected, with a link to view any affected tasks.</li>
      <li>The Asset Inventory now provides a <code>MAC Countries</code> column that lists which countries are associated with device MAC addresses.</li>
      <li>The Asset Attributes now include values for <code>mac.mfgCountries</code> and <code>mac.mfgAddresses</code>.</li>
      <li>The Asset Inventory now accepts searches by MAC Country using the syntax <code>mac.mfgCountries:US</code>.</li>
      <li>An issue that caused some integration data not to expire according to organization settings has been resolved.</li>
      <li>View-only users are no longer shown a <code>Share</code> action when this functionality is not available to them.</li>
      <li>Outdated browsers will now receive a warning during the sign-in process.</li>
      <li>Tag values are now fully UTF-8 safe and round-trip correctly via tasks.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402505291">
  <div class="rn-card-header"><span class="rn-version">4.0.250529.1</span><time class="rn-date" datetime="2025-05-29">May 29, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>The runZero console&rsquo;s content security policy header has been temporarily relaxed to resolve an issue where FireFox ESR would refuse to load icon images.</li>
      <li>A banner will now notify superusers when the SAML certificate being used for single sign-on (SSO) will expire soon.</li>
      <li>An issue that prevented PII attributes from being excluded when integrations were configured to run on an explorer has been resolved.</li>
      <li>Performance improvements.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402505290">
  <div class="rn-card-header"><span class="rn-version">4.0.250529.0</span><time class="rn-date" datetime="2025-05-29">May 29, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402505270">
  <div class="rn-card-header"><span class="rn-version">4.0.250527.0</span><time class="rn-date" datetime="2025-05-27">May 27, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>TLS certificates no longer used by any service are now automatically deleted from your certificate inventory.</li>
      <li>The design of the progress bar has been updated.</li>
      <li>An issue preventing tables on the risk management dashboard from sorting has been resolved.</li>
      <li>An issue that caused the GCP integration to log errors instead of warnings when some projects didn&rsquo;t have certain features enabled has been resolved.</li>
      <li>An issue causing invalid country flag display in the certificate inventory has been fixed.</li>
      <li>An issue that caused some Azure integrations to fail has been resolved.</li>
      <li>An issue where the error was not reported when scan results failed to upload has been fixed.</li>
      <li>Identification of progressive web applications has been improved.</li>
      <li>Phantom device detection improved.</li>
      <li>Merge logic improvements.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402505240">
  <div class="rn-card-header"><span class="rn-version">4.0.250524.0</span><time class="rn-date" datetime="2025-05-24">May 24, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that could cause CrowdStrike tasks to fail has been resolved.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402505210">
  <div class="rn-card-header"><span class="rn-version">4.0.250521.0</span><time class="rn-date" datetime="2025-05-21">May 21, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that was causing findings to not be filtered by asset when following a link from the assets details page has been resolved.</li>
      <li>An issue that was allowing CrowdStrike auth tokens to expire has been resolved.</li>
      <li>An issue that could prevent stale integration attributes from being cleaned up according to organization settings has been resolved.</li>
      <li>The Prisma integration has been updated to fix incorrect request methods and improve logging.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402505160">
  <div class="rn-card-header"><span class="rn-version">4.0.250516.0</span><time class="rn-date" datetime="2025-05-16">May 16, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Normalization of the software version information from the CrowdStrike integration has been improved.</li>
      <li>Detection of web-interception mechanisms has been improved.</li>
      <li>An issue that could cause integration tasks to merge assets incorrectly in some cases has been resolved.</li>
      <li>An issue that was causing user-set asset criticality values to be overwritten as &ldquo;Unset&rdquo; has been resolved.</li>
      <li>An issue that caused Wiz integration tasks run on explorers to fail when importing a large number of assets has been resolved.</li>
      <li>An issue that prevented referencing <code>organization.name</code> in event templates was resolved.</li>
      <li>An issue that could cause alert rules to save the current organization in their scope unexpectedly when editing a rule has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402505140">
  <div class="rn-card-header"><span class="rn-version">4.0.250514.0</span><time class="rn-date" datetime="2025-05-14">May 14, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Custom integration scripts can now utilize gzip compression and decompression.</li>
      <li>An issue that caused undesired center justification in table columns has been resolved.</li>
      <li>An issue preventing Alerting Rules from being edited after creation has been resolved.</li>
      <li>An issue that could allow integration tasks to merge assets incorrectly in some cases has been resolved.</li>
      <li>An issue that caused intermittently inaccurate risk levels for &ldquo;Top findings&rdquo; in the Risk Management dashboard has been resolved.</li>
      <li>An issue that caused the names of risk levels to not be capitalized on the Risk Management Dashboard has been resolved.</li>
      <li>An issue that caused assets to be recreated when importing AWS assets with the <code>Automatically delete stale AWS assets</code> option enabled has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402505130">
  <div class="rn-card-header"><span class="rn-version">4.0.250513.0</span><time class="rn-date" datetime="2025-05-13">May 13, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>User API endpoints now include information about default, assigned, and effective roles.</li>
      <li>The Microsoft 365 Defender integration now imports the <code>avMode</code> attribute and only sets the EDR name when <code>avMode</code> is Active.</li>
      <li>The Qualys integration now allows filtering assets by Network IDs.</li>
      <li>Custom integration scripts can now call crypto hashing functions including <code>sha256</code>, <code>sha512</code>, <code>sha1</code> and <code>md5</code>.</li>
      <li>Custom integration scripts can now export asset data to a json.gz file that can be imported into a runZero organization.</li>
      <li>Dashboards now include a footer showing the last time data used in the dashboard was updated.</li>
      <li>An issue that resulted in inaccurate information on the finding details page&rsquo;s Overview section when viewing &ldquo;My organizations&rdquo; has been resolved.</li>
      <li>An issue that prevented recalculating metrics in &ldquo;My Organizations&rdquo; mode has been resolved.</li>
      <li>An issue that prevented some Risk Management dashboard widgets from displaying results in &ldquo;My Organizations&rdquo; mode has been resolved.</li>
      <li>An issue that could cause passive-scanned assets to lose IP addresses when merging with integration assets has been resolved.</li>
      <li>An issue that prevented importing Asset CSVs containing spaces in owner values has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402505080">
  <div class="rn-card-header"><span class="rn-version">4.0.250508.0</span><time class="rn-date" datetime="2025-05-08">May 8, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>The custom integration script editor now includes autocomplete hints for Starlark and runZero-provided libraries.</li>
      <li>Performance of the certificate inventory has been improved.</li>
      <li>An issue that could cause content updates to fail for some self-hosted customers has been resolved.</li>
      <li>An issue that could prevent integration data from updating correctly in some circumstances has been resolved.</li>
      <li>An issue that limited the number of applications collected from the SentinelOne integration has been resolved.</li>
      <li>Asset merging improvements.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402505060">
  <div class="rn-card-header"><span class="rn-version">4.0.250506.0</span><time class="rn-date" datetime="2025-05-06">May 6, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue preventing the deletion and updating of Explorers from the details view Manage menu has been resolved.</li>
      <li>An issue preventing the finding details view from displaying related runZero blog references has been resolved.</li>
      <li>The vulnerability details view now includes links to runZero Rapid Response posts as well as related references.</li>
      <li>An issue that could cause the network bridges and asset route pathing reports to cut off parts of the graph has been resolved.</li>
      <li>An issue that could cause some integration attributes to be dropped when merging assets has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402505050">
  <div class="rn-card-header"><span class="rn-version">4.0.250505.0</span><time class="rn-date" datetime="2025-05-05">May 5, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Personally identifiable information (PII) or other attributes may now be excluded from data collection for some integrations.  See our <a href="https://help.runzero.com/docs/integrations-inbound/#excluding-integration-attributes">excluding integration attributes</a> documentation for more details.</li>
      <li>The vulnerability collection performance of the SentinelOne integration has been improved.</li>
      <li>Custom integration scripts now consider a <code>None</code> return value as success.</li>
      <li>Custom integration scripts can now use limited <code>session</code>-like functionality for making HTTP requests.</li>
      <li>Custom integration scripts can now use base64 encoding and decoding functions.</li>
      <li>The npcap version is now listed on the Explorer details page when the Explorer is installed on Windows.</li>
      <li>The npcap installers have been updated to version 1.82.</li>
      <li>An issue that prevented errors from being returned when exporting data has been resolved.</li>
      <li>An issue that caused CVE overlay data (for example, KEV membership) to not be reflected accurately has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402504300">
  <div class="rn-card-header"><span class="rn-version">4.0.250430.0</span><time class="rn-date" datetime="2025-04-30">Apr 30, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>The SentinelOne integration has been updated to improve performance.</li>
      <li>An issue that prevented exporting vulnerabilities has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402504280">
  <div class="rn-card-header"><span class="rn-version">4.0.250428.0</span><time class="rn-date" datetime="2025-04-28">Apr 28, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Two new keywords have been added to the scan configuration discovery and exclude scope fields: <code>site:scope</code> which expands to the default site scope, and <code>site:exclusions</code> which expands to the exclusions set in the site configuration.</li>
      <li>The Tenable Integration Task form has been updated.</li>
      <li>Event log performance was improved.</li>
      <li>Phantom device detection improvements.</li>
      <li>An issue that prevented persistence of inventory table preferences has been resolved.</li>
      <li>An issue that could prevent NetBox assets from merging on IP address has been resolved.</li>
      <li>An issue that could prevent alert channel details from loading in some situations has been resolved.</li>
      <li>An issue that prevented searching Integration attribute data using wildcards in certain cases has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402504220">
  <div class="rn-card-header"><span class="rn-version">4.0.250422.0</span><time class="rn-date" datetime="2025-04-22">Apr 22, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that resulted in duplicate <code>assets-expired</code> events in the event log has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402504210">
  <div class="rn-card-header"><span class="rn-version">4.0.250421.0</span><time class="rn-date" datetime="2025-04-21">Apr 21, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue resulting in reporting an incorrect OS version for fingerprinting of CrowdStrike integration data has been resolved.</li>
      <li>An issue leading to duplicate asset icons and screenshots has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402504180">
  <div class="rn-card-header"><span class="rn-version">4.0.250418.0</span><time class="rn-date" datetime="2025-04-18">Apr 18, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>The SentinelOne integration has been updated to support importing vulnerabilities.</li>
      <li>An issue causing the &ldquo;Findings by category&rdquo; header on the runZero Risk dashboard to render incorrectly has been resolved.</li>
      <li>An issue that caused vulnerabilities without categories to display details incorrectly has been resolved.</li>
      <li>An issue that caused the directory users and groups to not be linked for Google Workspace, Azure AD, and LDAP has been resolved.</li>
      <li>An issue that could cause an explorer to be marked as inactive after a reinstall has been resolved.</li>
      <li>User interface improvements.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402504150">
  <div class="rn-card-header"><span class="rn-version">4.0.250415.0</span><time class="rn-date" datetime="2025-04-15">Apr 15, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>CSV export of certificates was improved for better compatibility with spreadsheet software.</li>
      <li>The findings export now includes the fields <code>instance_count</code> and <code>risk_rank_value</code>. The fields <code>vulnerability_count</code> and <code>risk_score</code> have been removed, and the field <code>risk_rank</code> now shows the risk label.</li>
      <li>The NetBox integration no longer filters assets that are older than the Organization&rsquo;s stale asset threshold.</li>
      <li>Minor UX enhancement to the Certificate Details page.</li>
      <li>An issue causing the &ldquo;Internet accessible assets&rdquo; widget on the Risk Management dashboard to display an incorrect current count has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402504140">
  <div class="rn-card-header"><span class="rn-version">4.0.250414.0</span><time class="rn-date" datetime="2025-04-14">Apr 14, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Searching the asset inventory for software now supports less-than or greater-than software version queries. See the <a href="https://help.runzero.com/docs/search-query-assets/#assets-software">Asset Inventory search keywords documentation</a> for more information.</li>
      <li>Certificates inventory can now be searched by <code>last_seen</code>, <code>valid_from</code>, and <code>valid_until</code> keywords.</li>
      <li>The API endpoints for <code>/account/users</code> and <code>/account/users/{user_id}</code> now include the names and IDs of groups that users are members of.</li>
      <li>The inventory export APIs now support gzip Content-Encoding compression when requested via the Accept-Encoding header.</li>
      <li>An issue causing the &ldquo;High risk findings&rdquo; widget on the Risk Management dashboard to display an incorrect current count has been resolved.</li>
      <li>An issue causing the Queries list to display incorrect finding codes has been resolved.</li>
      <li>An issue causing duplicate <code>assets-expired</code> events to be written to the audit log has been resolved.</li>
      <li>An issue where servers were incorrectly identified as printers in rare cases has been resolved.</li>
      <li>Asset discovery improvements.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402504101">
  <div class="rn-card-header"><span class="rn-version">4.0.250410.1</span><time class="rn-date" datetime="2025-04-10">Apr 10, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that could cause importing of vulnerability information from Microsoft Defender to fail has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402504100">
  <div class="rn-card-header"><span class="rn-version">4.0.250410.0</span><time class="rn-date" datetime="2025-04-10">Apr 10, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>The Microsoft 365 Defender integration now has task options to filter importing vulnerabilities by severity.</li>
      <li>The Microsoft 365 Defender integration can now optionally exclude importing software and vulnerabilities.</li>
      <li>The Rapid Response dashboard widget has been updated to clarify when assets are potentially impacted vs actually impacted.</li>
      <li>An issue that caused assets with no vulnerabilities or findings to be shown as Info risk instead of None has been resolved.</li>
      <li>An issue that prevented the Microsoft 365 Defender integration from pulling software without CPEs has been resolved.</li>
      <li>An issue that could cause some vulnerabilities to disappear after successive Microsoft 365 Defender tasks has been resolved.</li>
      <li>An issue that prevented importing certain assets from Wiz has been resolved.</li>
      <li>An issue that could cause integration attributes to be removed from assets has been resolved.</li>
      <li>In accordance with feedback from our annual security audit, a low-severity improvement has been made to the runZero Console&rsquo;s content security policy (CSP).</li>
      <li>Asset merging improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402504090">
  <div class="rn-card-header"><span class="rn-version">4.0.250409.0</span><time class="rn-date" datetime="2025-04-09">Apr 9, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>The NetBox integration now handles virtual machines, interfaces, and clusters more consistently.</li>
      <li>The NetBox integration now uses fuzzy matching for OS and HW mappings.</li>
      <li>The alerts rules page data table now displays columns for channel and template.</li>
      <li>The alert rule details page now displays the channel and template attributes.</li>
      <li>An issue that could cause errors when gathering screenshots has been resolved.</li>
      <li>Asset merging improvements.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402504070">
  <div class="rn-card-header"><span class="rn-version">4.0.250407.0</span><time class="rn-date" datetime="2025-04-07">Apr 7, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Performance of the Asset Details page has been improved.</li>
      <li>An issue that could cause tasks assigned to hosted explorers to be delayed has been resolved.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402504050">
  <div class="rn-card-header"><span class="rn-version">4.0.250405.0</span><time class="rn-date" datetime="2025-04-05">Apr 5, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402504041">
  <div class="rn-card-header"><span class="rn-version">4.0.250404.1</span><time class="rn-date" datetime="2025-04-04">Apr 4, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that could result in printers printing garbage output when their IPv6 addresses are scanned has been resolved.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402504040">
  <div class="rn-card-header"><span class="rn-version">4.0.250404.0</span><time class="rn-date" datetime="2025-04-04">Apr 4, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>The Microsoft 365 Defender integration has been updated to support pulling software and vulnerabilities.</li>
      <li>New public APIs for findings and certificates inventory are now available.  See the <a href="https://app.swaggerhub.com/apis/runZero/runZero/">API documentation</a> for more information.</li>
      <li>An issue that failed to detect and report encrypted protocols running on non-standard ports has been resolved.</li>
      <li>An issue that caused a page reload when navigating to a Certificate Details page has been resolved.</li>
      <li>An issue that prevented searching the Vulnerability Inventory by Asset for CVEs has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402504020">
  <div class="rn-card-header"><span class="rn-version">4.0.250402.0</span><time class="rn-date" datetime="2025-04-02">Apr 2, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>The NetBox integration now supports importing virtual machines and asset criticality, along with other fixes.</li>
      <li>An issue preventing an icon from showing on the Certificate Details page was resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402504010">
  <div class="rn-card-header"><span class="rn-version">4.0.250401.0</span><time class="rn-date" datetime="2025-04-01">Apr 1, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>CSRF protection was improved.</li>
      <li>User Public API endpoints now include a field, <code>mfa_enabled</code>, indicating if the user has enabled and is required to use MFA to log in.</li>
      <li>An issue preventing the scanner from fingerprinting services on sensitive ports has been resolved.</li>
      <li>An issue that caused some browsers to freeze when viewing the Risk Management dashboard has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402503310">
  <div class="rn-card-header"><span class="rn-version">4.0.250331.0</span><time class="rn-date" datetime="2025-03-31">Mar 31, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Performance of the Risk Management dashboard has been improved.</li>
      <li>An issue that caused the VMware ESXi OS version information to be truncated on some assets has been resolved.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402503300">
  <div class="rn-card-header"><span class="rn-version">4.0.250330.0</span><time class="rn-date" datetime="2025-03-30">Mar 30, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that could result in excessive logging with misconfigured Windows adapters has been resolved.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402503290">
  <div class="rn-card-header"><span class="rn-version">4.0.250329.0</span><time class="rn-date" datetime="2025-03-29">Mar 29, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that prevented services from populating in certain circumstances has been resolved.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402503280">
  <div class="rn-card-header"><span class="rn-version">4.0.250328.0</span><time class="rn-date" datetime="2025-03-28">Mar 28, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Users can now create custom widgets for their dashboards with text of their choosing, rendered as a subset of Markdown/CommonMark.</li>
      <li>The collection performance of the Google Workspace integration has been improved.</li>
      <li>Vulnerability details are now displayed in their own page with a linkable URL.</li>
      <li>An issue that could incorrectly remove integration attributes has been resolved.</li>
      <li>An issue that incorrectly tracked a VMware ESXi asset&rsquo;s full name attribute has been resolved.</li>
      <li>An issue that caused the findings page to take a long time to load has been resolved.</li>
      <li>An issue that could cause console errors when searching for certificates using numeric values has been resolved.</li>
      <li>An issue that resulted in errors when searching the directory users and groups by organization ID has been resolved.</li>
      <li>An issue that prevented Info-level findings from displaying in the Findings overview dashboard widget has been resolved.</li>
      <li>An issue that caused incorrect &ldquo;What&rsquo;s Changed&rdquo; values on the Risk Management dashboard has been resolved.</li>
      <li>Asset merging improvements.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402503250">
  <div class="rn-card-header"><span class="rn-version">4.0.250325.0</span><time class="rn-date" datetime="2025-03-25">Mar 25, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>The code for detecting self-signed certificates was improved for better accuracy.</li>
      <li>The collection performance of the Google Workspace integration has been improved.</li>
      <li>An issue that resulted in duplicate findings listed for a single organization has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402503241">
  <div class="rn-card-header"><span class="rn-version">4.0.250324.1</span><time class="rn-date" datetime="2025-03-24">Mar 24, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue resulting reporting an incorrect source for fingerprinting of CrowdStrike integration data has been resolved.</li>
      <li>An issue resulting in scans triggering printer output has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402503240">
  <div class="rn-card-header"><span class="rn-version">4.0.250324.0</span><time class="rn-date" datetime="2025-03-24">Mar 24, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Introducing Risk Findings, a new feature that provides a comprehensive view of risk.  Findings group vulnerabilities, misconfigurations and best practices into a curated list of actionable items, allowing you to prioritize and remediate the most critical risk in your environment.  To learn more, see our <a href="https://help.runzero.com/docs/understanding-findings/">Risk Findings documentation</a>.</li>
      <li>Introducing the Risk Management dashboard, a new dashboard showing an overview of risk in your environment.</li>
      <li>Introducing Certificates Inventory, a new inventory type that allows you to quickly view and search all of the TLS and SSH certificates in your environment.  To learn more, see our <a href="https://help.runzero.com/docs/certificates-inventory/">Certificate Inventory documentation</a>.</li>
      <li>The &ldquo;None&rdquo; Risk Rank has been renamed to &ldquo;Info&rdquo;.</li>
      <li>SentinelOne integration now processes hostnames with spaces correctly.</li>
      <li>Custom integrations now process hostnames with spaces correctly. Multiple hostnames must be separated by a tab character.</li>
      <li>An issue that resulted in duplicate records for some vulnerabilities has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402503170">
  <div class="rn-card-header"><span class="rn-version">4.0.250317.0</span><time class="rn-date" datetime="2025-03-17">Mar 17, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>A dashboard list page has been added, showing all dashboards the current user has access to.</li>
      <li>Added support for passing an optional <code>timeout=&lt;seconds&gt;</code> parameter to <code>http.get</code> and <code>http.post</code> requests in custom integration scripts.</li>
      <li>Added support for using <code>HEAD</code>, <code>PATCH</code>, <code>PUT</code>, and <code>DELETE</code> HTTP methods in custom integration scripts.</li>
      <li>Added support for searching Meraki <code>firstSeen</code> and <code>lastSeen</code> attributes as timestamps.</li>
      <li>Added new <code>snmp.interfaceAddrsMap</code>, <code>snmp.interfaceAliasesMap</code>, <code>snmp.interfaceNamesMap</code>, and <code>snmp.interfaceMacsMap</code> attributes containing SNMP network data indexed by interface index.</li>
      <li>Users will now be shown a helpful message if they cannot login via SSO due to an expired SAML certificate.</li>
      <li>Dashboard widgets now show the date range covered in the widget.</li>
      <li>An issue that caused Rapid7 InsightVM vulnerabilities to not sync the Exploitable flag correctly has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402503070">
  <div class="rn-card-header"><span class="rn-version">4.0.250307.0</span><time class="rn-date" datetime="2025-03-07">Mar 7, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Several minor graphical issues in the user interface have been resolved.</li>
      <li>An issue preventing filling in additional comments in the query builder feedback menu has been resolved.</li>
      <li>The AWS integration now imports tags for RDS instances.</li>
      <li>The Nessus integration will now continue processing data from other scans, even if an error occurs while ingesting data from one scan.</li>
      <li>Performance improvements.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402503050">
  <div class="rn-card-header"><span class="rn-version">4.0.250305.0</span><time class="rn-date" datetime="2025-03-05">Mar 5, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>The calculation of the last seen value for Active Directory computers has been improved.</li>
      <li>An issue that caused dashboard widgets to align incorrectly at certain browser sizes has been resolved.</li>
      <li>An issue preventing sorting team user tables by ID has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402503031">
  <div class="rn-card-header"><span class="rn-version">4.0.250303.1</span><time class="rn-date" datetime="2025-03-03">Mar 3, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Performance improvements for KEV-based vulnerability queries.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402503030">
  <div class="rn-card-header"><span class="rn-version">4.0.250303.0</span><time class="rn-date" datetime="2025-03-03">Mar 3, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that prevented self-hosted deployments from the EU SaaS console from installing has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402502280">
  <div class="rn-card-header"><span class="rn-version">4.0.250228.0</span><time class="rn-date" datetime="2025-02-28">Feb 28, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Merge logic for the Tanium integration when multiple environments are present has been improved.</li>
      <li>IP address collection from the Tanium integration has been improved.</li>
      <li>An issue that resulted in most users on the team datagrid showing as &ldquo;pending&rdquo; status has been resolved.</li>
      <li>An issue with host name expansion of scan targets has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402502260">
  <div class="rn-card-header"><span class="rn-version">4.0.250226.0</span><time class="rn-date" datetime="2025-02-26">Feb 26, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>The API now supports setting organization vulnerability expiration configuration parameters.</li>
      <li>An issue that could cause some stale data expiration settings set via the API not to take effect has been resolved.</li>
      <li>HTTP actions in custom integration scripts no longer have a timeout.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402502210">
  <div class="rn-card-header"><span class="rn-version">4.0.250221.0</span><time class="rn-date" datetime="2025-02-21">Feb 21, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Performance improvements.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402502191">
  <div class="rn-card-header"><span class="rn-version">4.0.250219.1</span><time class="rn-date" datetime="2025-02-19">Feb 19, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that could prevent metrics and query counts from updating has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402502190">
  <div class="rn-card-header"><span class="rn-version">4.0.250219.0</span><time class="rn-date" datetime="2025-02-19">Feb 19, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>runZero scans now record the last time that they detected an asset in the asset attributes.</li>
      <li>Performance improvements.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402502140">
  <div class="rn-card-header"><span class="rn-version">4.0.250214.0</span><time class="rn-date" datetime="2025-02-14">Feb 14, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402502131">
  <div class="rn-card-header"><span class="rn-version">4.0.250213.1</span><time class="rn-date" datetime="2025-02-13">Feb 13, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Self-hosted installations configured with SSO-only logins now automatically redirect to the IdP.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402502130">
  <div class="rn-card-header"><span class="rn-version">4.0.250213.0</span><time class="rn-date" datetime="2025-02-13">Feb 13, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue in hostname collection that could result in invalid asset hostnames and merges has been resolved.</li>
      <li>An issue preventing drill-down from dashboards&rsquo; most- and least-seen charts has been resolved.</li>
      <li>The organization API now allows the stale integration attribute setting for an organization to be modified.</li>
      <li>Matching assets from the SentinelOne integration has been improved.</li>
      <li>The <code>type:</code> asset search keyword now performs a fuzzy search by default, similar to other search keywords.</li>
      <li>Log events for tasks starting and failing are now labeled with the task name.</li>
      <li>The default HTTP timeout for custom integration script requests has been extended to 5 minutes.</li>
      <li>Performance improvements.</li>
      <li>Asset merging improvements.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402502090">
  <div class="rn-card-header"><span class="rn-version">4.0.250209.0</span><time class="rn-date" datetime="2025-02-09">Feb 9, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Performance improvements.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402502080">
  <div class="rn-card-header"><span class="rn-version">4.0.250208.0</span><time class="rn-date" datetime="2025-02-08">Feb 8, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Performance improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402502073">
  <div class="rn-card-header"><span class="rn-version">4.0.250207.3</span><time class="rn-date" datetime="2025-02-07">Feb 7, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Performance improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402502072">
  <div class="rn-card-header"><span class="rn-version">4.0.250207.2</span><time class="rn-date" datetime="2025-02-07">Feb 7, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that could result in an error being displayed when creating a new project for some editions of runZero has been resolved.</li>
      <li>An issue that could cause a metrics recalculation task to issue spurious warnings has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402502070">
  <div class="rn-card-header"><span class="rn-version">4.0.250207.0</span><time class="rn-date" datetime="2025-02-07">Feb 7, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Organizations now support setting thresholds to automatically expire stale integration and vulnerability data.</li>
      <li>Merge logic for the Tenable Security Center integration has been improved.</li>
      <li>Merge logic for Windows assets with multiple interfaces has been improved.</li>
      <li>The display of errors for query widgets on the dashboard has been improved.</li>
      <li>Filtering of invalid data from the Qualys integration has been improved.</li>
      <li>All available templates are now shown on the scan templates page.</li>
      <li>The APIs used to fetch CrowdStrike applications have been updated to improve collection performance.</li>
      <li>An issue that caused stale protocols to remain on services has been resolved.</li>
      <li>An issue that prevented services from different vhosts on the same IP/port/protocol combination from being displayed on the asset details page has been resolved.</li>
      <li>An issue that prevented seeing the full asset comment in the asset datagrid has been resolved.</li>
      <li>An issue that could cause invalid Steam protocol probe responses has been resolved.</li>
      <li>An issue that could cause higher-than-expected asset risk for certain SSL-related vulnerabilities has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402502031">
  <div class="rn-card-header"><span class="rn-version">4.0.250203.1</span><time class="rn-date" datetime="2025-02-03">Feb 3, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that could cause scan processing to fail with an error has been fixed.</li>
      <li>An issue that prevented the retrieval of Tanium vulnerability data after the paging data limit is exceeded has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402502030">
  <div class="rn-card-header"><span class="rn-version">4.0.250203.0</span><time class="rn-date" datetime="2025-02-03">Feb 3, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that caused missing hostname/IP combinations for some assets on the Switch Topology report has been resolved.</li>
      <li>An issue that caused runZero to report SMB v2 as available on certain Samba configurations has been resolved.</li>
      <li>An issue that caused hosted zone tasks to get stuck in a Scheduled state has been resolved.</li>
      <li>An issue that prevented running scans using a hosted zone for some community users has been resolved.</li>
      <li>An issue that sometimes caused task details to show a negative task duration has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402501301">
  <div class="rn-card-header"><span class="rn-version">4.0.250130.1</span><time class="rn-date" datetime="2025-01-30">Jan 30, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue preventing specific organization administrators from modifying asset tags has been resolved.</li>
      <li>An issue that prevented using the quick-bookmark buttons on the reports pages has been resolved.</li>
      <li>The quick-bookmark buttons on the reports pages no longer indicate whether or not they&rsquo;re already bookmarked.</li>
      <li>Merge avoidance logic for certain integration combinations has been improved.</li>
      <li>Asset merging improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402501300">
  <div class="rn-card-header"><span class="rn-version">4.0.250130.0</span><time class="rn-date" datetime="2025-01-30">Jan 30, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that caused dashboard duplication and creation to work incorrectly has been resolved.</li>
      <li>An issue preventing filtering in the dashboard share menu has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402501290">
  <div class="rn-card-header"><span class="rn-version">4.0.250129.0</span><time class="rn-date" datetime="2025-01-29">Jan 29, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Users can now create multiple dashboards, share them to organizations in which they have User privileges or higher, and set a preferred dashboard in their profile settings. Any personal or runZero managed dashboard can be selected as a preferred dashboard.</li>
      <li>Organization administrators can now set a default dashboard on a per-organization basis. Any dashboard shared to the organization or any runZero managed dashboard can be selected as a default dashboard.</li>
      <li>An issue that prevented query links on dashboards from respecting the &ldquo;Search live assets&rdquo; attribute has been resolved.</li>
      <li>An issue that prevented the change report from being visible on the Task Details page has been resolved.</li>
      <li>An issue preventing the scanner from collecting arp cache data from Palo Alto Networks devices using self-signed certificates has been resolved.</li>
      <li>Merge logic for assets observed via both Wiz and AWS has been improved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402501270">
  <div class="rn-card-header"><span class="rn-version">4.0.250127.0</span><time class="rn-date" datetime="2025-01-27">Jan 27, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Self-hosted instances now check for updated content and queries every 5 minutes in online mode.</li>
      <li>Recurring tasks can now be set to a multiple of minutes.</li>
      <li>An issue that caused runZero to report SMB v1 as available on certain Samba configurations has been resolved.</li>
      <li>An issue that prevented Explorer-run InsightVM tasks from running with certain self-signed certificates has been resolved.</li>
      <li>An issue that prevented some integrations from working when a non-standard port number was specified has been resolved.</li>
      <li>An issue that prevented runZero from connecting to InsightVM installations that use a TLS certificate with a negative serial number has been resolved.</li>
      <li>An issue that prevented certain Crowdstrike vulnerabilities from being associated with an asset has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402501240">
  <div class="rn-card-header"><span class="rn-version">4.0.250124.0</span><time class="rn-date" datetime="2025-01-24">Jan 24, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>If site subnets have been defined, newly created scans will target the dynamic &ldquo;defaults&rdquo; scope.</li>
      <li>The custom integration script editor is now resizable.</li>
      <li>An issue that prevented connecting to some versions of InsightVM has been resolved.</li>
      <li>An issue that was causing broken links in the Switch Topology Report has been resolved.</li>
      <li>Merge avoidance logic for certain RDP related corner cases has been improved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402501230">
  <div class="rn-card-header"><span class="rn-version">4.0.250123.0</span><time class="rn-date" datetime="2025-01-23">Jan 23, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue preventing the Meraki integration from retrying requests has been resolved.</li>
      <li>An issue that would cause an asset&rsquo;s extra addresses to be missing has been resolved.</li>
      <li>Operating System End of Life (EoL) coverage and accuracy has been improved.</li>
      <li>Asset merging improvements.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402501220">
  <div class="rn-card-header"><span class="rn-version">4.0.250122.0</span><time class="rn-date" datetime="2025-01-22">Jan 22, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>The iSCSI protocol is now supported for asset discovery.</li>
      <li>Reporting of Meraki integration errors has been improved.</li>
      <li>An issue that caused some dashboard widgets to not update properly has been resolved.</li>
      <li>An issue that prevented custom dashboard widgets displaying system queries to non-admin users has been resolved.</li>
      <li>An issue that prevented Palo Alto Networks credentials from appearing in the scan configuration has been resolved.</li>
      <li>Fingerprint improvements.</li>
      <li>This release also includes the following fixes for low-severity findings from our annual third-party source code audit and security assessment:</li>
      <li>New password hashes, login tokens, reset password tokens, and new account invite tokens are now stored using the argon2id one-way hashing algorithm.  Prior to this release, hashes were generated using the bcrypt hashing algorithm.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402501200">
  <div class="rn-card-header"><span class="rn-version">4.0.250120.0</span><time class="rn-date" datetime="2025-01-20">Jan 20, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that could result in inaccurate metrics display has been resolved.</li>
      <li>Asset merging improvements.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402501170">
  <div class="rn-card-header"><span class="rn-version">4.0.250117.0</span><time class="rn-date" datetime="2025-01-17">Jan 17, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Operating System End of Life (EoL) coverage and accuracy has been improved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402501160">
  <div class="rn-card-header"><span class="rn-version">4.0.250116.0</span><time class="rn-date" datetime="2025-01-16">Jan 16, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Layer 2 topology calculations have been improved.</li>
      <li>The task details page has been improved.</li>
      <li>The asset details page now includes the date the asset record was created in the runZero database. This information is also available via a new optional column in the asset inventory.</li>
      <li>Intune integration performance has been improved.</li>
      <li>Operating System End of Life (EoL) information is now available for Linux Mint.</li>
      <li>Credentials are now allowed to be re-used across multiple recurring tasks. runZero still recommends limiting credentials to a single recurring tasks in most situations to avoid duplicate asset ingestion.</li>
      <li>An issue that could result in inaccurate query metric representation on the dashboard has been resolved.</li>
      <li>An issue that prevented the Meraki integration from paginating Meraki resources has been resolved.</li>
      <li>An issue that caused the <code>NO_PROXY</code> environment variable to be ignored on self-hosted consoles has been resolved.</li>
      <li>Fingerprint improvements.</li>
      <li>This release also includes the following fixes for low-severity findings from our annual third-party source code audit and security assessment:</li>
      <li>An issue that allowed Explorer information to be listed across organizations within the same tenant if the requester had knowledge of the Explorer&rsquo;s ID has been resolved.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402501130">
  <div class="rn-card-header"><span class="rn-version">4.0.250113.0</span><time class="rn-date" datetime="2025-01-13">Jan 13, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Vulnerability reporting from the Inside Out Attack Surface Management feature is more accurate and adjusted for severity based on the type of exposure.</li>
      <li>Fingerprinting devices via the Matter IoT protocol is now supported.</li>
      <li>The Service Location Protocol (SLP) is now supported for device probing.</li>
      <li>The Tenable integration now records MAC addresses even if they don&rsquo;t have an associated IP address.</li>
      <li>Unmapped MACs are now grouped by interface in the Layer2 information section of the asset details page.</li>
      <li>A flatten_json module with a flatten method can be used when authoring Custom Integration Scripts.</li>
      <li>An issue that prevented organization roles from being saved when creating or updating a group via the API has been resolved.</li>
      <li>An issue that prevented ingesting some assets from Tanium has been resolved.</li>
      <li>An issue that impacted the ability to retry timed-out requests in some connectors has been resolved.</li>
      <li>An issue that could cause a task to repeatedly retry when the task data was improperly formatted has been resolved.</li>
      <li>An issue that prevented setting some asset values in custom integration scripts has been resolved.</li>
      <li>An issue that prevented selecting ‘no parent’ when editing a project with a consulting license has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402501060">
  <div class="rn-card-header"><span class="rn-version">4.0.250106.0</span><time class="rn-date" datetime="2025-01-06">Jan 6, 2025</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Custom Integration Scripts can now run directly on runZero Explorers and be triggered by runZero tasks.  To learn more, see our <a href="https://help.runzero.com/docs/custom-integration-scripts/">custom integration scripts documentation</a>.</li>
      <li>Vulnerability records are now created for potentially exposed internal assets (Inside Out Attack Surface Management) and misuse of shared encryption keys.</li>
      <li>AWS integration task configuration forms have a new look and feel.</li>
      <li>An issue that could result in a scanning deadlock when using maximum scan durations has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402412230">
  <div class="rn-card-header"><span class="rn-version">4.0.241223.0</span><time class="rn-date" datetime="2024-12-23">Dec 23, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that would cause devices discovered by the Tenable integration to not properly merge has been resolved.</li>
      <li>An issue that caused the list of Explorers to not be sorted correctly when configuring alert rules has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402412192">
  <div class="rn-card-header"><span class="rn-version">4.0.241219.2</span><time class="rn-date" datetime="2024-12-19">Dec 19, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>The runZero CLI is now available for download for all license tiers. Specific functionality is still based on your license and entitlements.</li>
      <li>Integrations run through an Explorer now use proxy settings in all cases.</li>
      <li>Explorer upgrades now strictly validate versions and update URLs.</li>
      <li>Added export APIs for export tasks.</li>
      <li>Scan tasks created via console now support an optional scan duration limit.</li>
      <li>The Getting Started Guide has been revamped with additional content.</li>
      <li>Intune logging has been improved.</li>
      <li>Custom multi-query widgets&rsquo; data sources list can now be reordered with drag and drop.</li>
      <li>An issue preventing users from changing their name or email when SSO is required but the user is not enrolled in SSO has been resolved.</li>
      <li>An issue that could cause the alert rule inventory query preview button to unexpectedly URL-encode search strings has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402412170">
  <div class="rn-card-header"><span class="rn-version">4.0.241217.0</span><time class="rn-date" datetime="2024-12-17">Dec 17, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Merge avoidance logic for integration data has been improved.</li>
      <li>An issue that would cause all software for the entire organization to be displayed in the software section of the asset screen has been fixed.</li>
      <li>An issue that caused the &ldquo;Copy as a new scan template&rdquo; button to be displayed for tasks that the action is not available for has been resolved.</li>
      <li>An issue where stale IP addresses resolved through DNS were not periodically removed was resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402412130">
  <div class="rn-card-header"><span class="rn-version">4.0.241213.0</span><time class="rn-date" datetime="2024-12-13">Dec 13, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that would cause exporting software without a filter to fail has been fixed.</li>
      <li>An issue that caused an application error when uploading an invalid IDP metadata.xml in SSO Settings has been fixed.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402412120">
  <div class="rn-card-header"><span class="rn-version">4.0.241212.0</span><time class="rn-date" datetime="2024-12-12">Dec 12, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Alert rules for inventory query event types now include a button to preview the configured query in the inventory.</li>
      <li>The loading overlay on the data tables throughout the product has been improved for more clarity.</li>
      <li>An issue that prevented the delivery of scan alerts through Slack has been resolved.</li>
      <li>An issue where the alert error tooltip message wasn&rsquo;t being rendered has been resolved.</li>
      <li>An issue preventing the discovery scope field on the task inspection card from appearing has been resolved.</li>
      <li>An issue causing the task inspection card to sometimes take longer than expected to load has been resolved.</li>
      <li>An issue that prevented Wiz connectors from working with Wiz API credentials scoped to specific projects has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402412100">
  <div class="rn-card-header"><span class="rn-version">4.0.241210.0</span><time class="rn-date" datetime="2024-12-10">Dec 10, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that caused some event rules, channels and templates to be hidden has been resolved.</li>
      <li>An issue that prevented alert rules from saving the query condition has been resolved.</li>
      <li>An issue that prevented event templates, channels, and rules from being removed when an organization is removed has been resolved.</li>
      <li>An issue that prevented some form &ldquo;Back&rdquo; buttons from functioning correctly has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402412091">
  <div class="rn-card-header"><span class="rn-version">4.0.241209.1</span><time class="rn-date" datetime="2024-12-09">Dec 9, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>The navigation menus have been redesigned for ease of use.  User settings and sign out buttons are now located in the top right of the application.</li>
      <li>Alerts, rules, channels and templates are now scoped to one or more organizations allowing organization-level users to edit alert rules.  See our <a href="https://help.runzero.com/docs/managing-alerts/">alerts documentation</a> for more information.</li>
      <li>Asset merge avoidance logic for custom integration data has been improved.</li>
      <li>An issue in merge logic for Tenable Security Center data has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402412060">
  <div class="rn-card-header"><span class="rn-version">4.0.241206.0</span><time class="rn-date" datetime="2024-12-06">Dec 6, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that prevented some forms from functioning correctly has been resolved.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402412051">
  <div class="rn-card-header"><span class="rn-version">4.0.241205.1</span><time class="rn-date" datetime="2024-12-05">Dec 5, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that prevented some dashboard drill down pages from displaying has been resolved.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402412050">
  <div class="rn-card-header"><span class="rn-version">4.0.241205.0</span><time class="rn-date" datetime="2024-12-05">Dec 5, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Scans now probe Palo Alto Networks firewalls for ARP cache information.</li>
      <li>An issue that allowed configuring the Wiz integration with no API URL has been resolved.</li>
      <li>An issue in hostname collection that could result in invalid asset hostnames and mergers has been resolved.</li>
      <li>Our annual third-party source code audit and security assessment is in progress. This release includes fixes for the following issues:</li>
      <li>Content-Security-Policy headers have been made more strict.</li>
      <li>An XSS vulnerability was identified in the Asset Ownership form.</li>
      <li>A few minor weaknesses were identified in the password reset flow.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402412030">
  <div class="rn-card-header"><span class="rn-version">4.0.241203.0</span><time class="rn-date" datetime="2024-12-03">Dec 3, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Assets discovered via CIP backplane enumeration are now better displayed.</li>
      <li>Scan discovery scope has been added to the task inspection card on the task overview page.</li>
      <li>Improved discoverability of Fortinet appliances using the FortiGate to FortiManager (FGFM) protocol.</li>
      <li>Detection of bulk responses from Fortinet network filtering and interception products has been improved.</li>
      <li>An issue which delayed sample tasks from starting once a scan completed has been fixed.</li>
      <li>An issue that prevented exporting asset attribute reports for foreign attributes has been fixed.</li>
      <li>An issue that caused Tenable tasks to occasionally ignore their filter settings has been resolved.</li>
      <li>An issue that could cause inconsistent task inspection card state on the task overview page has been resolved.</li>
      <li>An issue that could cause Explorers with identical host IDs to replace Explorers in another organization has been resolved.</li>
      <li>An issue that could cause invalid events to be shown on the events page has been resolved.</li>
      <li>An issue resulting in assets retaining invalid serial numbers from filtered services has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402411250">
  <div class="rn-card-header"><span class="rn-version">4.0.241125.0</span><time class="rn-date" datetime="2024-11-25">Nov 25, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402411230">
  <div class="rn-card-header"><span class="rn-version">4.0.241123.0</span><time class="rn-date" datetime="2024-11-23">Nov 23, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that could result in excessive error reporting under low memory conditions has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402411220">
  <div class="rn-card-header"><span class="rn-version">4.0.241122.0</span><time class="rn-date" datetime="2024-11-22">Nov 22, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Assets with more than 128 ports open are no longer excluded from asset lists.</li>
      <li>The load time of dashboards when assets have many tags has been improved.</li>
      <li>The speed of loading the explorers list has been improved.</li>
      <li>An issue that would cause tasks to report spurious download errors has been corrected.</li>
      <li>An issue that could prevent rDNS names from being assigned as an asset name has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402411200">
  <div class="rn-card-header"><span class="rn-version">4.0.241120.0</span><time class="rn-date" datetime="2024-11-20">Nov 20, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Tenable merge rules have been refined to reduce duplicate assets.</li>
      <li>Connection-related error messages for the Active Directory (LDAP) integration have been improved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402411180">
  <div class="rn-card-header"><span class="rn-version">4.0.241118.0</span><time class="rn-date" datetime="2024-11-18">Nov 18, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Intune data collection speed has been improved.</li>
      <li>Qualys integration logging has been improved.</li>
      <li>An issue occasionally causing unprocessed sample tasks to overload the task queue has been fixed.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402411140">
  <div class="rn-card-header"><span class="rn-version">4.0.241114.0</span><time class="rn-date" datetime="2024-11-14">Nov 14, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>runZero now supports the Hikvision SADP protocol.</li>
      <li>Microsoft Azure and Intune connections now complete faster.</li>
      <li>Recent tasks can now be easily reprocessed to take advantage of updates to asset merge logic.</li>
      <li>An issue that could prevent Shodan devices from being merged into existing assets has been resolved.</li>
      <li>An issue that could cause explorers to unregister due to operational issues with runZero&rsquo;s platform has been resolved.</li>
      <li>An issue that caused <code>api-export</code> events to be logged as <code>api-organization</code> events has been fixed. The <code>api-export</code> events generated between versions 4.0.241022.0 and 4.0.241114.0 were logged as <code>api-organization</code> events.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402411090">
  <div class="rn-card-header"><span class="rn-version">4.0.241109.0</span><time class="rn-date" datetime="2024-11-09">Nov 9, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that could prevent Qualys jobs from completing in some cases has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402411060">
  <div class="rn-card-header"><span class="rn-version">4.0.241106.0</span><time class="rn-date" datetime="2024-11-06">Nov 6, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that could cause Assets to have duplicate foreign data attribute sets has been resolved.</li>
      <li>The CLI scanner <code>--output-raw</code> option now produces gzipped output and disables output directory creation.</li>
      <li>The CLI scanner now supports the <code>link4</code> and <code>link6</code> scan targets for local network ranges.</li>
      <li>The CLI scanner help output now omits redundant host-ping/subnet-ping options.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402411012">
  <div class="rn-card-header"><span class="rn-version">4.0.241101.2</span><time class="rn-date" datetime="2024-11-01">Nov 1, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that could prevent enumeration of buggy TLS ECDH implementations has been resolved.</li>
      <li>The scanner now reports SNMP interface aliases in addition to names.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402411011">
  <div class="rn-card-header"><span class="rn-version">4.0.241101.1</span><time class="rn-date" datetime="2024-11-01">Nov 1, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that would prevent assets scanned over certain VPNs from merging correctly has been resolved.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402411010">
  <div class="rn-card-header"><span class="rn-version">4.0.241101.0</span><time class="rn-date" datetime="2024-11-01">Nov 1, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>The event details modal now displays links to source and target objects.</li>
      <li>The events data grid page now includes an Organization column.</li>
      <li>The Tanium integration now retrieves endpoints&rsquo; Custom Tags when available.</li>
      <li>The switch topology export options have been expanded to include the entire graph.</li>
      <li>IP address ingestion via the CrowdStrike integration has been improved.</li>
      <li>The metrics recalculation actions found on the task overview and dashboard have been improved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402410290">
  <div class="rn-card-header"><span class="rn-version">4.0.241029.0</span><time class="rn-date" datetime="2024-10-29">Oct 29, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that could cause the GCP integration to attempt to retrieve resources from deleted projects has been resolved.</li>
      <li>Fingerprinting of Comtrol IO-Link devices is now supported.</li>
      <li>The FortiGate to FortiManager (FGFM) protocol is now supported for asset discovery.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402410250">
  <div class="rn-card-header"><span class="rn-version">4.0.241025.0</span><time class="rn-date" datetime="2024-10-25">Oct 25, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Enhanced the task details page view for recurring tasks.</li>
      <li>Information about whether individual users are required to use SSO is now displayed more clearly.</li>
      <li>An issue involving processing of UTF-8 BOM sequences in CSV files has been resolved.</li>
      <li>An issue causing broken links in the Switch Topology report has been resolved.</li>
      <li>An issue preventing access to the standard query library from the EU region has been resolved.</li>
      <li>An issue that could cause assets with stale service data to be fingerprinted incorrectly has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402410230">
  <div class="rn-card-header"><span class="rn-version">4.0.241023.0</span><time class="rn-date" datetime="2024-10-23">Oct 23, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Backplane enumeration of OT devices using CIP over EtherNet/IP is now supported.</li>
      <li>CSV exports can now include Unicode characters.</li>
      <li>An issue that caused an error after editing organization settings has been fixed.</li>
      <li>An issue that prevented &ldquo;SSO Required&rdquo; login restrictions from being enforced on existing user accounts has been resolved.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402410220">
  <div class="rn-card-header"><span class="rn-version">4.0.241022.0</span><time class="rn-date" datetime="2024-10-22">Oct 22, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>runZero now supports the creation of multiple export tokens.</li>
      <li>Newly created export tokens now show creation information and allow setting a description.</li>
      <li>Windows binaries are now exclusively signed with our runZero code signing certificate. The old Rumble code signing certificate has been retired.</li>
      <li>The service inventory view &ldquo;Summary&rdquo; column has been renamed &ldquo;Service response&rdquo; to better represent the data.</li>
      <li>An issue involving use of asset tags in alert templates has been fixed.</li>
      <li>An issue in parsing tags set to have no value has been fixed.</li>
      <li>An issue causing tags to get dropped from event rule data has been fixed.</li>
      <li>An issue in formatting tag changes in the event log has been fixed.</li>
      <li>An issue that prevented very long Explorer names from being fully visible on the Explorer details page has been resolved.</li>
      <li>An issue impacting fingerprinting when an asset had certain integration sources has been resolved.</li>
      <li>An issue in asset hostname collection from integration data has been resolved.</li>
      <li>An issue causing Windows Subsystem for Linux (WSL) guests observed in MS 365 Defender data to be merged with their hosts has been resolved.</li>
      <li>Merge avoidance logic for integration data has been improved.</li>
      <li>Asset merging improvements.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402410160">
  <div class="rn-card-header"><span class="rn-version">4.0.241016.0</span><time class="rn-date" datetime="2024-10-16">Oct 16, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue causing current organization to be inconsistent when opening links in the console has been resolved.</li>
      <li>An issue causing the task card on the Explorer details page to show tasks from other Explorers when multiple Explorers with the same name are present in the organization has been resolved.</li>
      <li>An issue involving email invites from users with punctuation characters in their names was fixed.</li>
      <li>An issue that prevented exporting vulnerabilities from the UI when filtering by site has been resolved.</li>
      <li>An issue that prevented viewing recurring task details when no subtasks existed has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402410150">
  <div class="rn-card-header"><span class="rn-version">4.0.241015.0</span><time class="rn-date" datetime="2024-10-15">Oct 15, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>runZero now integrates with NetBox.</li>
      <li>Added new duration and average duration columns to the Completed and Recurring task list pages. This allows viewing and sorting tasks by duration.</li>
      <li>Added a quick link to login with SSO for self-hosted installs.</li>
      <li>The dashboard menu now includes an option to recalculate dashboard metrics.</li>
      <li>Individual assets can now be refingerprinted using the latest fingerprint database directly from the asset details page.</li>
      <li>An issue preventing users from being redirected to a newly-created organization or project after creating one has been resolved.</li>
      <li>An issue preventing the &ldquo;Switch to&rdquo; button in the organization table from working has been resolved.</li>
      <li>An issue causing invalid asset links in the organization comparison report has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402410100">
  <div class="rn-card-header"><span class="rn-version">4.0.241010.0</span><time class="rn-date" datetime="2024-10-10">Oct 10, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that prevented logging in via SSO when a first name or last name was missing has been resolved.</li>
      <li>An issue that allowed clicking on disabled project settings has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402410090">
  <div class="rn-card-header"><span class="rn-version">4.0.241009.0</span><time class="rn-date" datetime="2024-10-09">Oct 9, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>The active console region is now displayed on the login page.</li>
      <li>Improved memory efficiency when exporting assets to Splunk via the runZero Splunk Add-on (requires v3.1.0 or greater of the add-on).</li>
      <li>An issue preventing querying for assets with multiple CVE matches from the vulnerability inventory page has been resolved.</li>
      <li>Explorers older than v4.0 have been phased out and can no longer connect to the console.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402410030">
  <div class="rn-card-header"><span class="rn-version">4.0.241003.0</span><time class="rn-date" datetime="2024-10-03">Oct 3, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue resulting in incorrect Software Inventory population in certain limited situations has been resolved.</li>
      <li>An issue resulting in incorrect asset Type assertions in limited situations has been resolved.</li>
      <li>Fingerprinting of Apple macOS from CrowdStrike data has been improved.</li>
      <li>Asset merging improvements.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402410010">
  <div class="rn-card-header"><span class="rn-version">4.0.241001.0</span><time class="rn-date" datetime="2024-10-01">Oct 1, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that prevented NOT and OR operators in queries on the site/organization report has been resolved.</li>
      <li>An issue resulting in incorrect Operating System End of Life (EoL) values for Red Hat Enterprise Linux has been resolved.</li>
      <li>An issue that could require some users to enter their email address twice on login has been resolved.</li>
      <li>A new search keyword <code>first_seen_task</code> allows searching for assets first seen by a particular task.</li>
      <li>The serial number coverage in the asset CSV export was expanded to include additional protocols and devices.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402409270">
  <div class="rn-card-header"><span class="rn-version">4.0.240927.0</span><time class="rn-date" datetime="2024-09-27">Sep 27, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Explorer TLS settings are now configurable via <code>TLS_VERSION_MIN</code> and <code>TLS_VERSION_MAX</code> parameters.</li>
      <li>Software and Vulnerability inventory queries can now be saved to the query library.</li>
      <li>Vulnerability groups now support searching by site ID or site name.</li>
      <li>An issue that prevented the task status icon and associated error/warning logs from updating when selecting different tasks has been resolved.</li>
      <li>Asset merging improvements.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402409260">
  <div class="rn-card-header"><span class="rn-version">4.0.240926.0</span><time class="rn-date" datetime="2024-09-26">Sep 26, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>runZero scans now include the CUPS (IPP) Browser protocol as a new probe on UDP/631.</li>
      <li>An issue that could lead to incorrect matching between Tenable sources has been resolved.</li>
      <li>Any error messages from the SSO process are now prominently displayed.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402409250">
  <div class="rn-card-header"><span class="rn-version">4.0.240925.0</span><time class="rn-date" datetime="2024-09-25">Sep 25, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue resulting in malformed query when pivoting from grouped vulnerabilities with multiple CVEs has been resolved.</li>
      <li>An issue that resulted in sending invalid JSON in some events that reference organization.id or site.id has been resolved.</li>
      <li>An issue that could cause Wiz connections to report that results were not found even when using correct service account credentials has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402409241">
  <div class="rn-card-header"><span class="rn-version">4.0.240924.1</span><time class="rn-date" datetime="2024-09-24">Sep 24, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that could lead to an error message in scan logs from short rpcbind replies has been resolved.</li>
      <li>The Site ID and Organization ID fields in event messages are now formatted as strings and not byte arrays.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402409240">
  <div class="rn-card-header"><span class="rn-version">4.0.240924.0</span><time class="rn-date" datetime="2024-09-24">Sep 24, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue causing single-sign-on to fail with the error &ldquo;Email address &hellip; is already in use&rdquo; has been resolved.</li>
      <li>An issue preventing the OS CPE value from being displayed in the Asset inventory has been resolved.</li>
      <li>The Oracle Solaris Service Tag protocol is now supported for asset discovery.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402409230">
  <div class="rn-card-header"><span class="rn-version">4.0.240923.0</span><time class="rn-date" datetime="2024-09-23">Sep 23, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Introduced a new login screen.</li>
      <li>runZero now integrates with Tanium API Gateway.</li>
      <li>The API now supports the bulk removal of a custom integration source from a list of assets.</li>
      <li>Begin signing Windows binaries with our new runZero, Inc. code signing certificate. We are currently dual signing with the old and new certificates.</li>
      <li>The speed of navigating to subsequent pages in inventory tables has been improved.</li>
      <li>Improved performance of the Wiz integration.</li>
      <li>Minor UI enhancement to better provide event rule errors via tooltip within table.</li>
      <li>An issue preventing event channels from displaying in the Channels list if the user who created them no longer exists has been resolved.</li>
      <li>Upgraded npcap to v1.80.</li>
      <li>An issue that could prevent Wiz vulnerability data from being processed has been resolved.</li>
      <li>An issue in UUID handling in event rules was fixed.</li>
      <li>An issue that prevented importing some Wiz assets that were created more than 180 days ago has been resolved.</li>
      <li>An issue that resulted in incorrect directory user and group membership counts has been resolved.</li>
      <li>The Wiz integration now properly syncs when the Wiz Service Account credential is limited to specific projects.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402409210">
  <div class="rn-card-header"><span class="rn-version">4.0.240921.0</span><time class="rn-date" datetime="2024-09-21">Sep 21, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Asset merging improvements.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402409190">
  <div class="rn-card-header"><span class="rn-version">4.0.240919.0</span><time class="rn-date" datetime="2024-09-19">Sep 19, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Asset merging improvements.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402409180">
  <div class="rn-card-header"><span class="rn-version">4.0.240918.0</span><time class="rn-date" datetime="2024-09-18">Sep 18, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>A race condition that could lead to incorrect asset matching has been resolved.</li>
      <li>An issue that could lead to integration attributes not being updated has been resolved.</li>
      <li>An issue that prevented all-organization admins from managing alerts has been resolved.</li>
      <li>The PCWORX protocol is now supported.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402409172">
  <div class="rn-card-header"><span class="rn-version">4.0.240917.2</span><time class="rn-date" datetime="2024-09-17">Sep 17, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that could cause Crowdstrike tasks to fail and retry has been fixed.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402409171">
  <div class="rn-card-header"><span class="rn-version">4.0.240917.1</span><time class="rn-date" datetime="2024-09-17">Sep 17, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>runZero now integrates with Microsoft Endpoint Configuration Manager (MECM).</li>
      <li>The self-hosted platform now supports ARM64 (aarch64) on Linux.</li>
      <li>Imported scan data now reports the correct scan times in the task view.</li>
      <li>CrowdStrike device last seen fields can now be queried as relative timestamps.</li>
      <li>The performance of the CrowdStrike integration has been improved.</li>
      <li>An issue that could prevent self-hosted from installing on newer versions of Alma Linux has been resolved.</li>
      <li>An issue in the display of the access summary of some users has been resolved.</li>
      <li>An issue that prevented querying directory user and group attributes with relative time queries has been fixed.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402409102">
  <div class="rn-card-header"><span class="rn-version">4.0.240910.2</span><time class="rn-date" datetime="2024-09-10">Sep 10, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that could prevent login link authentication from working has been resolved.</li>
      <li>An issue that left temporary files in Explorer temp directories has been resolved.</li>
      <li>An issue that prevented My Orgs from working with a large number of organizations has been resolved.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402409090">
  <div class="rn-card-header"><span class="rn-version">4.0.240909.0</span><time class="rn-date" datetime="2024-09-09">Sep 9, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>The login process has been redesigned for a smoother user experience.</li>
      <li>An issue that could cause confusing navigation behavior when viewing different organizations in separate browser tabs has been resolved.</li>
      <li>Asset merging improvements.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402409070">
  <div class="rn-card-header"><span class="rn-version">4.0.240907.0</span><time class="rn-date" datetime="2024-09-07">Sep 7, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Asset correlation has been improved for Meraki, ChromeOS, and SentinelOne sources.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402409041">
  <div class="rn-card-header"><span class="rn-version">4.0.240904.1</span><time class="rn-date" datetime="2024-09-04">Sep 4, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that could result in tasks that import software records failing has been fixed.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402409040">
  <div class="rn-card-header"><span class="rn-version">4.0.240904.0</span><time class="rn-date" datetime="2024-09-04">Sep 4, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that could cause daily recurring tasks to incorrectly be scheduled after modification has been resolved.</li>
      <li>Assets can now be identified using the Automatic Tank Gauge protocol.</li>
      <li>Fingerprinting of Dell iDRAC devices has been improved.</li>
      <li>The RFC1918 scan options are now available from the RFC 1918 reports page.</li>
      <li>Asset merging logic has been improved.</li>
      <li>Performance of foreign data integrations has been improved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402409020">
  <div class="rn-card-header"><span class="rn-version">4.0.240902.0</span><time class="rn-date" datetime="2024-09-02">Sep 2, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that could lead to incorrect correlation due to hardcoded device-side MAC addresses has been resolved.</li>
      <li>Bogus network responses for PPTP and FTP services are now ignored.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402408290">
  <div class="rn-card-header"><span class="rn-version">4.0.240829.0</span><time class="rn-date" datetime="2024-08-29">Aug 29, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue with certain versions of Chrome that could cause the creation of large numbers of temporary files has been fixed.</li>
      <li>An issue that could result in setting an incorrect asset Type based on integration data has been resolved.</li>
      <li>An issue that could cause recurring tasks to create a new subtask when modifying properties other than &ldquo;Start time&rdquo; or &ldquo;Scan frequency&rdquo; has been resolved.</li>
      <li>Time and date values in searches now support relative times in more cases.</li>
      <li>Improved handling of API request retries for integrations.</li>
      <li>JSON alert templates now render arrays and objects as JSON arrays and JSON objects, without needing to loop through fields or values.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402408260">
  <div class="rn-card-header"><span class="rn-version">4.0.240826.0</span><time class="rn-date" datetime="2024-08-26">Aug 26, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that could cause custom integration attributes to be deleted during asset merging has been fixed.</li>
      <li>An issue that could result in large numbers of attributes attached to assets in some situations has been fixed.</li>
      <li>The performance of the CrowdStrike integration has been improved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402408251">
  <div class="rn-card-header"><span class="rn-version">4.0.240825.1</span><time class="rn-date" datetime="2024-08-25">Aug 25, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that could result in integration source attributes not aging out during merges has been resolved.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402408250">
  <div class="rn-card-header"><span class="rn-version">4.0.240825.0</span><time class="rn-date" datetime="2024-08-25">Aug 25, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Scan and passive discovery tasks now complete faster for large sites.</li>
      <li>CrowdStrike integration tasks now complete faster.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402408220">
  <div class="rn-card-header"><span class="rn-version">4.0.240822.0</span><time class="rn-date" datetime="2024-08-22">Aug 22, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Operating System End of Life (EoL) coverage has been improved for Cisco IOS XE, IBM AIX, Juniper Junos OS, and Palo Alto Networks PAN-OS.</li>
      <li>Integration-source asset processing now avoids matching assets with excessive attribute sets.</li>
      <li>Self-hosted installations now track performance profiles per task automatically.</li>
      <li>The asset inventory now supports the foreign_attribute_count keyword.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402408200">
  <div class="rn-card-header"><span class="rn-version">4.0.240820.0</span><time class="rn-date" datetime="2024-08-20">Aug 20, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>A new system query for assets past OS Extended End of Life has been added to the library.</li>
      <li>Passive sampling tasks can now identify Avast, Bitdefender, Carbon Black, ESET, Kaspersky, McAfee, SentinelOne, and Trellix AV/EDR products.</li>
      <li>The Alerts page has been redesigned for ease of use.</li>
      <li>Asset merging performance has been improved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402408170">
  <div class="rn-card-header"><span class="rn-version">4.0.240817.0</span><time class="rn-date" datetime="2024-08-17">Aug 17, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that could result in bad matches due to blank foreign IDs has been resolved. Assets that had conflicting source data due to blank foreign ID matching will rebuild as part of normal job processing.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402408160">
  <div class="rn-card-header"><span class="rn-version">4.0.240816.0</span><time class="rn-date" datetime="2024-08-16">Aug 16, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>The self-hosted installer now supports custom installation and temporary directory paths.</li>
      <li>The self-hosted installer now supports systems with disabled or restricted sudo.</li>
      <li>The self-hosted console now supports text-format logging via the LOG_FORMAT=text configuration parameter.</li>
      <li>Asset merging performance has been improved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402408140">
  <div class="rn-card-header"><span class="rn-version">4.0.240814.0</span><time class="rn-date" datetime="2024-08-14">Aug 14, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>The Meraki integration now supports filtering the imported assets by organization name and/or ID.</li>
      <li>The Qualys integration now supports filtering the imported assets by tags.</li>
      <li>The Operating System icons in the Asset Inventory view have been improved.</li>
      <li>License utilization is now available as a percentage on the license information page.</li>
      <li>Directory group CSV exports now include the directory_group_user_count field at the end of the existing column set.</li>
      <li>The Switch topology report has been redesigned for ease of use.</li>
      <li>An issue that could cause multi-homed hosts to be missing links in the Switch topology report has been resolved.</li>
      <li>Fingerprinting logic has been improved so as to better account for certain source combinations.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402408110">
  <div class="rn-card-header"><span class="rn-version">4.0.240811.0</span><time class="rn-date" datetime="2024-08-11">Aug 11, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that prevented software vendor searches by prefix with wildcards from working was fixed.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402408090">
  <div class="rn-card-header"><span class="rn-version">4.0.240809.0</span><time class="rn-date" datetime="2024-08-09">Aug 9, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>The Alert Templates page has been redesigned for ease of use.</li>
      <li>An issue which caused valid JSON event rule templates to be rejected has been fixed.</li>
      <li>An issue causing MAC and IP address mapping information to be dropped from custom integration device data was fixed.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402408070">
  <div class="rn-card-header"><span class="rn-version">4.0.240807.0</span><time class="rn-date" datetime="2024-08-07">Aug 7, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>The Alert Rules page has been redesigned for ease of use.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402408030">
  <div class="rn-card-header"><span class="rn-version">4.0.240803.0</span><time class="rn-date" datetime="2024-08-03">Aug 3, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Azure and GCP subscription IDs are now also stored in the top-level asset attributes.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402408020">
  <div class="rn-card-header"><span class="rn-version">4.0.240802.0</span><time class="rn-date" datetime="2024-08-02">Aug 2, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that could prevent the Tenable Security Center from importing data has been resolved.</li>
      <li>The dashboard now supports filtering trending widgets by a customizable date range.</li>
      <li>Improved detection of invalid services.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402407311">
  <div class="rn-card-header"><span class="rn-version">4.0.240731.1</span><time class="rn-date" datetime="2024-07-31">Jul 31, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that could lead to HTTP service data ordering being incorrect has been resolved.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402407310">
  <div class="rn-card-header"><span class="rn-version">4.0.240731.0</span><time class="rn-date" datetime="2024-07-31">Jul 31, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that could reduce performance of large task processing has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402407300">
  <div class="rn-card-header"><span class="rn-version">4.0.240730.0</span><time class="rn-date" datetime="2024-07-30">Jul 30, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402407291">
  <div class="rn-card-header"><span class="rn-version">4.0.240729.1</span><time class="rn-date" datetime="2024-07-29">Jul 29, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that could prevent the CrowdStrike integration from running from an Explorer has been resolved.</li>
      <li>The matching engine for integration-sourced assets is now faster, more accurate, and better at merging related devices.</li>
      <li>SSH enumeration now results in more consistently-named fields.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402407290">
  <div class="rn-card-header"><span class="rn-version">4.0.240729.0</span><time class="rn-date" datetime="2024-07-29">Jul 29, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>The Meraki integration now supports filtering by VLAN and SSID.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402407270">
  <div class="rn-card-header"><span class="rn-version">4.0.240727.0</span><time class="rn-date" datetime="2024-07-27">Jul 27, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that prevented vulnerability group exports from applying the search filter has been resolved.</li>
      <li>SSH enumeration now captures all host keys as well as server extensions.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402407260">
  <div class="rn-card-header"><span class="rn-version">4.0.240726.0</span><time class="rn-date" datetime="2024-07-26">Jul 26, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that prevented checkbox states from persisting in some cases has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402407250">
  <div class="rn-card-header"><span class="rn-version">4.0.240725.0</span><time class="rn-date" datetime="2024-07-25">Jul 25, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Discovery of devices using the TwinCAT ADS protocol is now supported.</li>
      <li>Asset risk, vulnerability, and outlier fields are now available for use in Event templates.</li>
      <li>Temporary directory selection for Explorers has been improved.</li>
      <li>An issue preventing the display of integration data fetch durations has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402407220">
  <div class="rn-card-header"><span class="rn-version">4.0.240722.0</span><time class="rn-date" datetime="2024-07-22">Jul 22, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that could result in vulnerabilites not being calculated when software entries were not present has been fixed.</li>
      <li>Name-based asset matching has been significantly improved and now uses more sources and trusts PTR records less.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402407190">
  <div class="rn-card-header"><span class="rn-version">4.0.240719.0</span><time class="rn-date" datetime="2024-07-19">Jul 19, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue regarding the Tenable Security Center integration risk filter has been resolved.</li>
      <li>Merging of VMware assets has been improved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402407180">
  <div class="rn-card-header"><span class="rn-version">4.0.240718.0</span><time class="rn-date" datetime="2024-07-18">Jul 18, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that caused the Goals Overview dashboard widget to display an incorrect number of days worth of data instead of the selected timeframe has been resolved.</li>
      <li>Network topology calculation is now faster and runs as part of the metrics analysis task and not inline with normal task processing.</li>
      <li>Additional Crowdstrike device data is available for users with access to Crowdstrike&rsquo;s Discover API.</li>
      <li>CrowdStrike, InTune, Tenable, and Wiz integrations are now faster at processing large datasets.</li>
      <li>The Asset ID and Organization ID are now shown on their respective details pages.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402407160">
  <div class="rn-card-header"><span class="rn-version">4.0.240716.0</span><time class="rn-date" datetime="2024-07-16">Jul 16, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>The CLI scanner now correctly supports the <code>--import-pcap</code> option.</li>
      <li>Hosts with only some of their addresses excluded will now match existing assets during merge.</li>
      <li>Meraki-connector sourced assets now report the wired-side MAC for better correlation.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402407151">
  <div class="rn-card-header"><span class="rn-version">4.0.240715.1</span><time class="rn-date" datetime="2024-07-15">Jul 15, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Connectors now use fast-fallback to IPv4 for non-responsive IPv6 endpoints.</li>
      <li>A performance regression with topology calculation has been resolved.</li>
      <li>The Tenable connector now supports filtering by source and tag.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402407150">
  <div class="rn-card-header"><span class="rn-version">4.0.240715.0</span><time class="rn-date" datetime="2024-07-15">Jul 15, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402407120">
  <div class="rn-card-header"><span class="rn-version">4.0.240712.0</span><time class="rn-date" datetime="2024-07-12">Jul 12, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Performance of the Crowdstrike integration has been improved.</li>
      <li>An issue that prevented inventory table preferences from persisting throughout the product has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402407070">
  <div class="rn-card-header"><span class="rn-version">4.0.240707.0</span><time class="rn-date" datetime="2024-07-07">Jul 7, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Support for searching for assets and vulnerabilities by VulnCheck KEV membership has been added.</li>
      <li>The CrowdStrike integration now retrieves more detailed information.</li>
      <li>An issue that could prevent users with community licenses from initiating hosted scans has been fixed.</li>
      <li>An issue that could cause VMware guest operating systems to be incorrectly fingerprinted has been fixed.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402407020">
  <div class="rn-card-header"><span class="rn-version">4.0.240702.0</span><time class="rn-date" datetime="2024-07-02">Jul 2, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that could cause asset type to be set to <code>Desktop</code> incorrectly has been fixed.</li>
      <li>An issue that could cause certain virtual machine types to not merge properly has been fixed.</li>
      <li>An issue that could cause certain version comparison queries to not be parsed correctly has been fixed.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402406280">
  <div class="rn-card-header"><span class="rn-version">4.0.240628.0</span><time class="rn-date" datetime="2024-06-28">Jun 28, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Version fields across the product are now sortable semantically and can be filtered using the operators <code>&gt;, &gt;=, &lt;, &lt;=, =</code>.</li>
      <li>The Meraki integration now supports filtering on specific networks by name or ID.</li>
      <li>The scanner now supports the Canon BJNP protocol.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402406270">
  <div class="rn-card-header"><span class="rn-version">4.0.240627.0</span><time class="rn-date" datetime="2024-06-27">Jun 27, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>EPSS scores for vulnerabilities are now searchable with the <code>epss_score</code> keyword.</li>
      <li>The vulnerability information page now shows more information about CISA KEV membership and EPSS scores for vulnerabilities that have relevant information.</li>
      <li>The Asset Ownership report now supports up to 15,000 owners at a time.</li>
      <li>Major performance improvements in vulnerability search.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402406261">
  <div class="rn-card-header"><span class="rn-version">4.0.240626.1</span><time class="rn-date" datetime="2024-06-26">Jun 26, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>The Meraki integration now populates the switch topology report.</li>
      <li>VMware guests will now link correctly when observed between different ESXi servers and vCenter endpoints.</li>
      <li>The Intune integration now supports an optional filter for devices.</li>
      <li>The search option for the Azure AD integration has been deprecated.</li>
      <li>An issue causing custom widgets to drill down into inventory views with an incorrect <code>alive:t</code> filter despite the query&rsquo;s configuration has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402406220">
  <div class="rn-card-header"><span class="rn-version">4.0.240622.0</span><time class="rn-date" datetime="2024-06-22">Jun 22, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that could lead to incomplete MSSQL enumeration has been resolved.</li>
      <li>An issue that could result in the wrong IP address being assigned to a CrowdStrike record has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402406210">
  <div class="rn-card-header"><span class="rn-version">4.0.240621.0</span><time class="rn-date" datetime="2024-06-21">Jun 21, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue in the Organization Overview report has been fixed and the report speed was improved.</li>
      <li>Custom widgets based on queries have been added to the dashboard. Users can create custom widgets from the widget library on the dashboard, or from the query library.</li>
      <li>Improved discovery and data collection from Microsoft SQL Server endpoints.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402406200">
  <div class="rn-card-header"><span class="rn-version">4.0.240620.0</span><time class="rn-date" datetime="2024-06-20">Jun 20, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402406192">
  <div class="rn-card-header"><span class="rn-version">4.0.240619.2</span><time class="rn-date" datetime="2024-06-19">Jun 19, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Improved logging for CrowdStrike connection errors.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402406191">
  <div class="rn-card-header"><span class="rn-version">4.0.240619.1</span><time class="rn-date" datetime="2024-06-19">Jun 19, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that could prevent CrowdStrike credentials from successfully validating has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402406190">
  <div class="rn-card-header"><span class="rn-version">4.0.240619.0</span><time class="rn-date" datetime="2024-06-19">Jun 19, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that could prevent Azure integrations from being created has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402406180">
  <div class="rn-card-header"><span class="rn-version">4.0.240618.0</span><time class="rn-date" datetime="2024-06-18">Jun 18, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Passive traffic sampling is now more accurate at detecting syslog clients.</li>
      <li>The scanner now supports providing scan options via a JSON formatted configuration file.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402406160">
  <div class="rn-card-header"><span class="rn-version">4.0.240616.0</span><time class="rn-date" datetime="2024-06-16">Jun 16, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>The Export API endpoints now support POST requests with application/x-www-form-urlencoded parameters. This allows for larger search queries and field filters to be specified.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402406140">
  <div class="rn-card-header"><span class="rn-version">4.0.240614.0</span><time class="rn-date" datetime="2024-06-14">Jun 14, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that could result in stalled scans in some situations has been fixed.</li>
      <li>x.509 serial number values in tls.serial will no longer have the leading zero removed.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402406130">
  <div class="rn-card-header"><span class="rn-version">4.0.240613.0</span><time class="rn-date" datetime="2024-06-13">Jun 13, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that could prevent non-Windows installations of the runZero Explorer from restarting has been resolved.</li>
      <li>An issue that could result in stale MAC addresses accruing on Tenable assets has been resolved.</li>
      <li>An issue that could result in long timeouts for CrowdStrike tasks with invalid credentials has been resolved.</li>
      <li>An issue that prevented custom integration attribute links from returning results with mix-cased integration names has been resolved.</li>
      <li>Fingerprinting for Azure VMs now prefers the Azure HW assertion over other sources.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402406120">
  <div class="rn-card-header"><span class="rn-version">4.0.240612.0</span><time class="rn-date" datetime="2024-06-12">Jun 12, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that could cause the Meraki integration to error has been resolved.</li>
      <li>An issue that could cause incorrect data to display on the dashboard&rsquo;s most and least seen widgets when toggling the view has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402406100">
  <div class="rn-card-header"><span class="rn-version">4.0.240610.0</span><time class="rn-date" datetime="2024-06-10">Jun 10, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>A visual bug making some toggles in the UI appear incorrectly has been resolved.</li>
      <li>An issue that could prevent Intune devices from being synced has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402406070">
  <div class="rn-card-header"><span class="rn-version">4.0.240607.0</span><time class="rn-date" datetime="2024-06-07">Jun 7, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Improved discovery and data collection from Microsoft SQL Server endpoints.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402406061">
  <div class="rn-card-header"><span class="rn-version">4.0.240606.1</span><time class="rn-date" datetime="2024-06-06">Jun 6, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that could cause the Intune integration to skip syncing certain devices has been resolved.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402406060">
  <div class="rn-card-header"><span class="rn-version">4.0.240606.0</span><time class="rn-date" datetime="2024-06-06">Jun 6, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that could result in new Explorer installations on Windows not including npcap has been resolved.</li>
      <li>An issue that could result in connector tasks being stuck in &ldquo;stopping&rdquo; status has been resolved.</li>
      <li>Users with no access permissions are no longer allowed to view the account&rsquo;s superusers.</li>
      <li>Organization hierarchies are now supported up to four levels deep.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402406050">
  <div class="rn-card-header"><span class="rn-version">4.0.240605.0</span><time class="rn-date" datetime="2024-06-05">Jun 5, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Support for searching for assets and vulnerabilities by CISA KEV membership has been added.</li>
      <li>Performance improvements.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402406030">
  <div class="rn-card-header"><span class="rn-version">4.0.240603.0</span><time class="rn-date" datetime="2024-06-03">Jun 3, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>The Defender integration now supports filtering assets that have not been fully onboarded.</li>
      <li>The Defender integration now supports the Graph API filter parameter when running as a scanner probe.</li>
      <li>The Events view is no longer limited to the previous 30 days of records.</li>
      <li>The Explorer now uses consistent file names during the upgrade process.</li>
      <li>An issue that prevented the Defender and Intune configuration from validating when specifying a new Azure credential has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402405310">
  <div class="rn-card-header"><span class="rn-version">4.0.240531.0</span><time class="rn-date" datetime="2024-05-31">May 31, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Discovery of devices using the XDMCP protocol is now supported.</li>
      <li>An issue that could cause incorrect OS CPE generation has been resolved.</li>
      <li>OS version information in Fortinet FortiOS CPE values has been improved.</li>
      <li>Operating System End of Life (EoL) information is now available for Fortinet FortiOS.</li>
      <li>Asset merge logic has been improved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402405300">
  <div class="rn-card-header"><span class="rn-version">4.0.240530.0</span><time class="rn-date" datetime="2024-05-30">May 30, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that could show a &ldquo;user not found&rdquo; error in API-submitted import jobs has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402405291">
  <div class="rn-card-header"><span class="rn-version">4.0.240529.1</span><time class="rn-date" datetime="2024-05-29">May 29, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>runZero now integrates with Meraki. This initial support syncs Devices and Clients to your runZero inventory.</li>
      <li>An issue that could result in an &ldquo;invalid query&rdquo; message shown in the self-hosted query library has been resolved.</li>
      <li>An issue that could result in incorrect display of Punycode-encoded hostnames has been resolved.</li>
      <li>An issue that could lead to incorrectly assigned MAC addresses due to cross-VLAN mDNS relays in traffic sampling has been resolved.</li>
      <li>An issue that could lead to invalid MAC address attributes from Defender 365 sources has been resolved.</li>
      <li>An issue that could lead to runZero scan results being attached to not-onboarded Defender 365 assets instead of onboarded assets has been resolved.</li>
      <li>An issue that could result in assets being marked as Laptops instead of Desktops has been resolved.</li>
      <li>An issue that could result in multiple passive sampling tasks being scheduled on the same Explorer has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402405240">
  <div class="rn-card-header"><span class="rn-version">4.0.240524.0</span><time class="rn-date" datetime="2024-05-24">May 24, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>The dashboard now supports theater/kiosk mode and fullscreen display options.</li>
      <li>The dashboard widget library now includes a customizable bookmarks widget, that can be used to jump to your favorite reports and views in runZero or to external web sites.</li>
      <li>An issue that could prevent users with organization-specific roles from editing asset tags has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402405220">
  <div class="rn-card-header"><span class="rn-version">4.0.240522.0</span><time class="rn-date" datetime="2024-05-22">May 22, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Performance improvements.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402405190">
  <div class="rn-card-header"><span class="rn-version">4.0.240519.0</span><time class="rn-date" datetime="2024-05-19">May 19, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>The domain: scan target keyword now returns substantially more results for most domains.</li>
      <li>The scanner now treats in-scope addresses found by SNMP as primary addresses.</li>
      <li>The scanner no longer adds reflected IP addresses in L2TP hostname responses.</li>
      <li>The scanner no longer merges specific Netgear switches unintentionally.</li>
      <li>The AzureAD (EntraID) connector now supports the $search and $filter parameters for the Microsoft Graph API.</li>
      <li>The LDAP connector now syncs additional fields, including employeeID, ms-Mcs-AdmPwdExpirationTime, and ms-LAPS-PasswordExpirationTime.</li>
      <li>The CrowdStrike connector now provides better OS fingerprinting during multi-source asset processing.</li>
      <li>The Qualys connector is now more resilient with transient network and service timeouts.</li>
      <li>The Qualys connector now prioritizes Agent-based operating system fingerprints.</li>
      <li>The Custom Integration SDK can now ingest ipAddresses, ipAddressesExtra, and macAddresses fields directly without the presence of a NetworkInterface structure.</li>
      <li>An issue that could prevent the Tenable connector from exporting data has been resolved.</li>
      <li>An issue that could result in stale asset attributes after passive discovery has been resolved.</li>
      <li>An issue that could result in stale service summary columns has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402405160">
  <div class="rn-card-header"><span class="rn-version">4.0.240516.0</span><time class="rn-date" datetime="2024-05-16">May 16, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402405140">
  <div class="rn-card-header"><span class="rn-version">4.0.240514.0</span><time class="rn-date" datetime="2024-05-14">May 14, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Filtering of bogus responses, particularly from interception features of Fortinet gear, has been greatly improved.</li>
      <li>Improved logging for Azure and Intune integrations.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402405080">
  <div class="rn-card-header"><span class="rn-version">4.0.240508.0</span><time class="rn-date" datetime="2024-05-08">May 8, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that could result in unexpected Wiz authentication errors being included in task logs has been resolved.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402405030">
  <div class="rn-card-header"><span class="rn-version">4.0.240503.0</span><time class="rn-date" datetime="2024-05-03">May 3, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Creating hosted zone scan tasks via API no longer fails if the site has no non-hosted explorers.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402405010">
  <div class="rn-card-header"><span class="rn-version">4.0.240501.0</span><time class="rn-date" datetime="2024-05-01">May 1, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402404290">
  <div class="rn-card-header"><span class="rn-version">4.0.240429.0</span><time class="rn-date" datetime="2024-04-29">Apr 29, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Improved handling of large vulnerability results in the CrowdStrike integration.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402404250">
  <div class="rn-card-header"><span class="rn-version">4.0.240425.0</span><time class="rn-date" datetime="2024-04-25">Apr 25, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402404240">
  <div class="rn-card-header"><span class="rn-version">4.0.240424.0</span><time class="rn-date" datetime="2024-04-24">Apr 24, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402404230">
  <div class="rn-card-header"><span class="rn-version">4.0.240423.0</span><time class="rn-date" datetime="2024-04-23">Apr 23, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that prevented SSO users from setting a password when SSO was disabled at the runZero account level has been resolved.</li>
      <li>Operating System End of Life (EoL) information is now available for SUSE Enterprise Linux and Apple tvOS.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402404190">
  <div class="rn-card-header"><span class="rn-version">4.0.240419.0</span><time class="rn-date" datetime="2024-04-19">Apr 19, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Fingerprinting of assets based on Microsoft 365 Defender data has been improved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402404170">
  <div class="rn-card-header"><span class="rn-version">4.0.240417.0</span><time class="rn-date" datetime="2024-04-17">Apr 17, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Accessibility improvements.</li>
      <li>An issue that could result in errors when deleting a site has been resolved.</li>
      <li>An issue that could cause Wiz tasks to error has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402404110">
  <div class="rn-card-header"><span class="rn-version">4.0.240411.0</span><time class="rn-date" datetime="2024-04-11">Apr 11, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>runZero customers can now sync asset, software, and vulnerability data from Wiz.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402404100">
  <div class="rn-card-header"><span class="rn-version">4.0.240410.0</span><time class="rn-date" datetime="2024-04-10">Apr 10, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>The runZero dashboard has been improved to better respond to browser window resizing.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402404080">
  <div class="rn-card-header"><span class="rn-version">4.0.240408.0</span><time class="rn-date" datetime="2024-04-08">Apr 8, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Data collection from slow SSH services has been improved.</li>
      <li>Fortinet devices are now less likely to cause duplicate assets when traffic is collected using traffic sampling.</li>
      <li>The runZero Explorer now silently skips non-ethernet-like utun (tunnel) interfaces on macOS.</li>
      <li>An issue preventing the &ldquo;User details&rdquo; page for external users from loading has been resolved.</li>
      <li>An issue that could lead to errors when changing email address was fixed.</li>
      <li>An issue that could lead to errors when deleting a user was fixed.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402404050">
  <div class="rn-card-header"><span class="rn-version">4.0.240405.0</span><time class="rn-date" datetime="2024-04-05">Apr 5, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>The profile settings page has been redesigned.</li>
      <li>Names can now be given to multi-factor authentication tokens when enrolling new tokens.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402404040">
  <div class="rn-card-header"><span class="rn-version">4.0.240404.0</span><time class="rn-date" datetime="2024-04-04">Apr 4, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402404030">
  <div class="rn-card-header"><span class="rn-version">4.0.240403.0</span><time class="rn-date" datetime="2024-04-03">Apr 3, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that prevented proper click through from the Query Insights dashboard widget to the appropriate inventory view was fixed.</li>
      <li>Matching of MAC addresses of Fortinet firewall devices was improved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402404020">
  <div class="rn-card-header"><span class="rn-version">4.0.240402.0</span><time class="rn-date" datetime="2024-04-02">Apr 2, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402404010">
  <div class="rn-card-header"><span class="rn-version">4.0.240401.0</span><time class="rn-date" datetime="2024-04-01">Apr 1, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>The layout of the runZero dashboard is now fully customizable.</li>
      <li>The runZero dashboard now supports exporting views as CSV and PNG.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402403310">
  <div class="rn-card-header"><span class="rn-version">4.0.240331.0</span><time class="rn-date" datetime="2024-03-31">Mar 31, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Integration task processing is now much faster for assets with large numbers of MAC addresses.</li>
      <li>An issue that could result in assets accumulating link-local IPv6 addresses has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402403290">
  <div class="rn-card-header"><span class="rn-version">4.0.240329.0</span><time class="rn-date" datetime="2024-03-29">Mar 29, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>The &ldquo;Contact runZero support&rdquo; menu has been redesigned.</li>
      <li>An issue that could cause the services attribute report to fail has been resolved.</li>
      <li>An issue that could cause hostnames with spaces to be turned into multiple hostnames when imported from the AzureAD connector has been resolved.</li>
      <li>Improved logging for the Intune integration.</li>
      <li>UI improvements.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402403270">
  <div class="rn-card-header"><span class="rn-version">4.0.240327.0</span><time class="rn-date" datetime="2024-03-27">Mar 27, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Tenable connector data processing is now significantly faster for devices with large numbers of MAC addresses.</li>
      <li>An issue that could result in the self-hosted updater showing a SQL error during startup has been resolved.</li>
      <li>An issue that could cause scans running on Windows Explorers to accidentially terminate unrelated processes has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402403260">
  <div class="rn-card-header"><span class="rn-version">4.0.240326.0</span><time class="rn-date" datetime="2024-03-26">Mar 26, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>The CrowdStrike connector now only imports actively installed software.</li>
      <li>The CrowdStrike connector now handles large software and vulnerability results reliably.</li>
      <li>The CrowdStrike connector now better filters system accounts from the lastInteractiveUser attribute.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402403250">
  <div class="rn-card-header"><span class="rn-version">4.0.240325.0</span><time class="rn-date" datetime="2024-03-25">Mar 25, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402403200">
  <div class="rn-card-header"><span class="rn-version">4.0.240320.0</span><time class="rn-date" datetime="2024-03-20">Mar 20, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402403180">
  <div class="rn-card-header"><span class="rn-version">4.0.240318.0</span><time class="rn-date" datetime="2024-03-18">Mar 18, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Task ID is now visible when inspecting a task on the task overview page and on the task details page.</li>
      <li>An issue with calculating mid-scan progress for connector tasks running on Explorers has been resolved.</li>
      <li>An issue that could cause service start issues after upgrading self-hosted runZero instances has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402403140">
  <div class="rn-card-header"><span class="rn-version">4.0.240314.0</span><time class="rn-date" datetime="2024-03-14">Mar 14, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Colors throughout the product have been tweaked to improve accessibility, legibility, and consistency.</li>
      <li>Tables in the product can now be configured to prefer a mono-spaced variant of the table font.</li>
      <li>Tables throughout the product now allow users to choose text casing preference, available via the &ldquo;Prefs&rdquo; dropdown.</li>
      <li>An issue that could prevent updates to Directory Users / Groups has been resolved.</li>
      <li>An issue that could cause the &ldquo;concurrency&rdquo; setting on Explorers to be incorrectly changed when editing an Explorer&rsquo;s settings has been resolved.</li>
      <li>Accessibility improvements.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402403110">
  <div class="rn-card-header"><span class="rn-version">4.0.240311.0</span><time class="rn-date" datetime="2024-03-11">Mar 11, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue with processing malformed header data from RTSP responses has been resolved.</li>
      <li>The runZero CLI now completes faster for local networks.</li>
      <li>Self-hosted customers can now unbind SSO from a user account using the runzeroctl user reset command.</li>
      <li>Self-hosted customers can now change the SSO mode using the runzeroctl sso-mode <em>mode</em> command.</li>
      <li>Accessibility improvements.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402403080">
  <div class="rn-card-header"><span class="rn-version">4.0.240308.0</span><time class="rn-date" datetime="2024-03-08">Mar 8, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that could cause short keywords to not show any autocomplete suggestions in the query builder has been resolved.</li>
      <li>Long fields in Nmap XML exports of asset data are no longer truncated.</li>
      <li>Probing devices using EtherNet/IP is now supported over UDP.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402403060">
  <div class="rn-card-header"><span class="rn-version">4.0.240306.0</span><time class="rn-date" datetime="2024-03-06">Mar 6, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that could prevent new self hosted installations or updating existing installations has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402403051">
  <div class="rn-card-header"><span class="rn-version">4.0.240305.1</span><time class="rn-date" datetime="2024-03-05">Mar 5, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that could result in incorrect asset merging in certain situations has been resolved.</li>
      <li>An issue that could result in delayed analysis for busy Organizations has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402403050">
  <div class="rn-card-header"><span class="rn-version">4.0.240305.0</span><time class="rn-date" datetime="2024-03-05">Mar 5, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402403040">
  <div class="rn-card-header"><span class="rn-version">4.0.240304.0</span><time class="rn-date" datetime="2024-03-04">Mar 4, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402403010">
  <div class="rn-card-header"><span class="rn-version">4.0.240301.0</span><time class="rn-date" datetime="2024-03-01">Mar 1, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>A new &ldquo;serialNumbers&rdquo; column has been added to the asset CSV export. This field contains serial numbers observed during scanning, along with the protocol used to discover the serial number.</li>
      <li>An issue that could cause incorrect attack surface assignment to assets discovered by traffic sampling has been fixed.</li>
      <li>An issue which caused some task errors and warnings to fail to display has been fixed.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402402280">
  <div class="rn-card-header"><span class="rn-version">4.0.240228.0</span><time class="rn-date" datetime="2024-02-28">Feb 28, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that could prevent sites from being created per project for the Google Cloud Platform integration has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402402260">
  <div class="rn-card-header"><span class="rn-version">4.0.240226.0</span><time class="rn-date" datetime="2024-02-26">Feb 26, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue impacting Operating System End of Life (EoL) assertions for certain versions of Microsoft Windows and Linux distributions has been resolved.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402402230">
  <div class="rn-card-header"><span class="rn-version">4.0.240223.0</span><time class="rn-date" datetime="2024-02-23">Feb 23, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that could cause organization statistics to become out of date in organizations with frequent and concurrent tasks has been resolved.</li>
      <li>Operating System End of Life (EoL) information is now available for Apple iOS and iPadOS as well as CentOS Stream.</li>
      <li>Operating System Extended End of Life (EoL) generation has been improved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402402210">
  <div class="rn-card-header"><span class="rn-version">4.0.240221.0</span><time class="rn-date" datetime="2024-02-21">Feb 21, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>The vulnerability inventory is now much faster for large organizations.</li>
      <li>Fingerprinting of devices via BGP is now supported.</li>
      <li>Tenable integration performance has been improved.</li>
      <li>An issue that could cause the asset and service attribute reports to fail has been resolved.</li>
      <li>An issue causing some credential form fields to disappear when modifying an existing credential has been resolved.</li>
      <li>An issue with the query format of site-filtered insights has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402402180">
  <div class="rn-card-header"><span class="rn-version">4.0.240218.0</span><time class="rn-date" datetime="2024-02-18">Feb 18, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Software inventory is now calcuated as part of metrics, reducing task processing time.</li>
      <li>An issue that prevented the Organization picker from working on some pages has been resolved.</li>
      <li>Saved queries in the search suggestions menu are now ordered by when they were last updated.</li>
      <li>Improved asset correlation logic for devices with wired and wireless interfaces.</li>
      <li>Improved OS detection logic when considering multiple data sources.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402402160">
  <div class="rn-card-header"><span class="rn-version">4.0.240216.0</span><time class="rn-date" datetime="2024-02-16">Feb 16, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Improved correlation behavior for assets with information from NTLMSSP or Qualys.</li>
      <li>Search query and query builder autocomplete results have been improved for shorter sets of input.</li>
      <li>An issue preventing the parent-organization-picker from appearing on the organization create and edit pages has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402402140">
  <div class="rn-card-header"><span class="rn-version">4.0.240214.0</span><time class="rn-date" datetime="2024-02-14">Feb 14, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Improved protocol detection during traffic sampling.</li>
      <li>The alert event type emitted after a client switch has changed from &ldquo;login&rdquo; to &ldquo;client-switched&rdquo;.</li>
      <li>The &ldquo;Site&rdquo; column has been removed from the software groups table.</li>
      <li>An issue where the software inventory sometimes failed to update after a task has been resolved.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402402130">
  <div class="rn-card-header"><span class="rn-version">4.0.240213.0</span><time class="rn-date" datetime="2024-02-13">Feb 13, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>The Software Inventory is now much faster for large organizations.</li>
      <li>An issue that could result in stale service attributes persisting through rescans has been resolved.</li>
      <li>The <code>LOG_FORMAT</code> and <code>LOG_MAX_LENGTH</code> configuration values were renamed to <code>RUNZERO_LOG_FORMAT</code> and <code>RUNZERO_LOG_MAX_LENGTH</code> respectively. The old values will continue to work but are deprecated.</li>
      <li>The request timeout for the Qualys integration has been decreased.</li>
      <li>TCP stack based OS fingerprinting has been improved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402402080">
  <div class="rn-card-header"><span class="rn-version">4.0.240208.0</span><time class="rn-date" datetime="2024-02-08">Feb 8, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue with adding addresses for Custom Integration assets without MACs has been resolved.</li>
      <li>The request timeout for the Qualys integration has been increased.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402402070">
  <div class="rn-card-header"><span class="rn-version">4.0.240207.0</span><time class="rn-date" datetime="2024-02-07">Feb 7, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Additional data points for result count and sent/received data have been added to the Tasks CSV export.</li>
      <li>An issue with the display format of site subnet tags on assets has been resolved.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402402060">
  <div class="rn-card-header"><span class="rn-version">4.0.240206.0</span><time class="rn-date" datetime="2024-02-06">Feb 6, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Improved performance on the Software inventory table.</li>
      <li>Additional fields added to Query Builder autocomplete.</li>
      <li>An issue that prevented Site Subnet information from exporting with Assets has been resolved.</li>
      <li>An issue with data missing from the default email template for alerts has been resolved.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402402050">
  <div class="rn-card-header"><span class="rn-version">4.0.240205.0</span><time class="rn-date" datetime="2024-02-05">Feb 5, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Filtering of hostnames collected from TLS X.509 certificates has been improved.</li>
      <li>An issue that could cause overlapping subnets to apply another Site&rsquo;s subnet tags has been resolved.</li>
      <li>An issue that could result in incorrect asset correlation between HP iLOs and their servers has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402402020">
  <div class="rn-card-header"><span class="rn-version">4.0.240202.0</span><time class="rn-date" datetime="2024-02-02">Feb 2, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Performance of Tenable.io connector tasks when only a subset of Severity/Risk values are selected has been improved.</li>
      <li>An issue that allowed users with the Administrator role to downgrade their own permissions has been resolved.</li>
      <li>An issue that could prevent Nessus attributes from being fully hydrated by runZero has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402401310">
  <div class="rn-card-header"><span class="rn-version">4.0.240131.0</span><time class="rn-date" datetime="2024-01-31">Jan 31, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402401290">
  <div class="rn-card-header"><span class="rn-version">4.0.240129.0</span><time class="rn-date" datetime="2024-01-29">Jan 29, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>A query builder is now available, accessible from most datagrids by clicking the &ldquo;Query builder&rdquo; button to the right of the search bar.</li>
      <li>An issue which caused some out-of-date service information to remain on assets has been resolved.</li>
      <li>An issue which caused service information to be incorrectly removed from assets that were offline during a scan has been resolved.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402401260">
  <div class="rn-card-header"><span class="rn-version">4.0.240126.0</span><time class="rn-date" datetime="2024-01-26">Jan 26, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Discovery of devices using the DNP3 protocol is now supported.</li>
      <li>Operating System End of Life (EoL) information is now available for Oracle Linux.</li>
      <li>Page break locations in the overview report have been improved.</li>
      <li>Operating System End of Life (EoL) generation for Red Hat Enterprise Linux and CentOS Linux has been improved.</li>
      <li>Assets with no known address are now labeled with &ldquo;Unknown&rdquo; for their address rather than &ldquo;Unscanned&rdquo;.</li>
      <li>The bundled npcap driver has been updated to version 1.79.</li>
      <li>An issue that could prevent last task details from correctly displaying on the Sites datatable has been resolved.</li>
      <li>An issue that prevented the expansion of dropdown menu sub-menus using keyboard navigation has been resolved.</li>
      <li>An issue that could result in certain OS fingerprinting data not being updated has been resolved.</li>
      <li>An issue that could prevent creating new Azure Credentials via the Azure connector configuration page has been resolved.</li>
      <li>An issue causing Tenable.io integration tasks to import vulnerability data even when no severity or risk levels were selected has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402401240">
  <div class="rn-card-header"><span class="rn-version">4.0.240124.0</span><time class="rn-date" datetime="2024-01-24">Jan 24, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that could result in hidden fields on the SNMP v3 Credentials form has been resolved.</li>
      <li>Fingerprinting of Red Hat Enterprise Linux derivatives when limited data is available has been improved.</li>
      <li>Additional fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402401220">
  <div class="rn-card-header"><span class="rn-version">4.0.240122.0</span><time class="rn-date" datetime="2024-01-22">Jan 22, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>The datagrid search bar has been improved to show recent queries and available queries from the query library.</li>
      <li>Fingerprinting of Red Hat Enterprise Linux and derivatives from Tenable product data has been improved.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402401190">
  <div class="rn-card-header"><span class="rn-version">4.0.240119.0</span><time class="rn-date" datetime="2024-01-19">Jan 19, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Fixed an issue that prevented the &ldquo;Edit user permissions&rdquo; modal from working correctly.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402401170">
  <div class="rn-card-header"><span class="rn-version">4.0.240117.0</span><time class="rn-date" datetime="2024-01-17">Jan 17, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Fixed an issue where custom integration task data could not be re-imported.</li>
      <li>Fixed an issue where Nessus imports could fail due to Nessus response size.</li>
      <li>Fingerprinting of Red Hat Enterprise Linux derivatives such as CentOS, Rocky Linux, and Oracle Linux has been improved.</li>
      <li>Fingerprint improvements.</li>
      <li>Accessibility improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402401120">
  <div class="rn-card-header"><span class="rn-version">4.0.240112.0</span><time class="rn-date" datetime="2024-01-12">Jan 12, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Site column has been added to all tasks lists in the task overview.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402401100">
  <div class="rn-card-header"><span class="rn-version">4.0.240110.0</span><time class="rn-date" datetime="2024-01-10">Jan 10, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>The Nmap XML export now uses the minimum and maximum asset last_seen timestamps as the start and stop times.</li>
      <li>An issue that could prevent stale services from being cleared from updated Assets has been resolved.</li>
      <li>A resource leak that affects self-hosted customers with transparent huge pages (THP) enabled has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402401090">
  <div class="rn-card-header"><span class="rn-version">4.0.240109.0</span><time class="rn-date" datetime="2024-01-09">Jan 9, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Tenable Security Center tasks now only retrieve records updated since the previous sync.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402401050">
  <div class="rn-card-header"><span class="rn-version">4.0.240105.0</span><time class="rn-date" datetime="2024-01-05">Jan 5, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>An issue that prevented the API for creating passive sampling tasks from working as documented was fixed.</li>
      <li>An issue that could cause inventory grids to disappear when using Firefox and resizing the window below a certain point has been resolved.</li>
      <li>Improved error handling for Tenable, Tenable Security Center, and CrowdStrike integrations.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
<div class="rn-card" id="402401030">
  <div class="rn-card-header"><span class="rn-version">4.0.240103.0</span><time class="rn-date" datetime="2024-01-03">Jan 3, 2024</time></div>
  <div class="rn-card-body">
    <ul class="rn-items">
      <li>Improved correlation for assets sourced from the Censys and Shodan integrations.</li>
      <li>An issue that incorrectly logged certain task failures as &rsquo;explorer failed to queue task&rsquo; has been resolved.</li>
      <li>Fingerprint improvements.</li>
    </ul>
  </div>
</div>
</div>
<p class="rn-archive-link">Release notes prior to 2024 can be found in the <a href="https://help.runzero.com/docs/release-notes-archive/#402312200">release notes archive</a>.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[runZero data dictionary]]></title>
    <link href="https://www.runzero.com/docs/data-dictionary/"/>
    <id>https://www.runzero.com/docs/data-dictionary/</id>
      
      <published>2025-01-14T23:53:33+00:00</published>
      <updated>2025-01-14T23:53:33+00:00</updated>
      <summary type="html"><![CDATA[<p>runZero discovers and catalogs the following fields from known <span class="book-index" data-book-index="protocols">protocols</span> and <span class="book-index" data-book-index="services">services</span>:</p>
<table class='table table-sm table-bordered w-auto data-dictionary'><thead><tr><th>Protocol</th><th>Attribute name</th><th>Data type</th><th>Single-value</th></tr></thead>
<tbody>
<tr><td>acop</td><td><code>acop.cellID</code></td><td>string</td><td>true</td></tr>
<tr><td>acop</td><td><code>acop.channelID</code></td><td>string</td><td>true</td></tr>
<tr><td>acop</td><td><code>acop.clientID</code></td><td>string</td><td>true</td></tr>
<tr><td>acop</td><td><code>acop.controllerName</code></td><td>string</td><td>true</td></tr>
<tr><td>acop</td><td><code>acop.controllerSerial</code></td><td>string</td><td>true</td></tr>
<tr><td>acop</td><td><code>acop.controllerTime</code></td><td>string</td><td>true</td></tr>
<tr><td>acop</td><td><code>acop.controllerVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>acop</td><td><code>acop.error</code></td><td>string</td><td>true</td></tr>
<tr><td>acop</td><td><code>acop.opVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>acop</td><td><code>acop.rbuType</code></td><td>string</td><td>true</td></tr>
<tr><td>acop</td><td><code>acop.revision</code></td><td>string</td><td>true</td></tr>
<tr><td>acop</td><td><code>acop.stationID</code></td><td>string</td><td>true</td></tr>
<tr><td>acop</td><td><code>acop.stationName</code></td><td>string</td><td>true</td></tr>
<tr><td>acop</td><td><code>acop.supplierCode</code></td><td>string</td><td>true</td></tr>
<tr><td>acop</td><td><code>acop.supportLinking</code></td><td>numeric</td><td>true</td></tr>
<tr><td>acop</td><td><code>acop.supportSeqNum</code></td><td>numeric</td><td>true</td></tr>
<tr><td>acop</td><td><code>acop.systemSubtype</code></td><td>string</td><td>true</td></tr>
<tr><td>acop</td><td><code>acop.systemType</code></td><td>string</td><td>true</td></tr>
<tr><td>acop</td><td><code>acop.toolData</code></td><td>string</td><td>true</td></tr>
<tr><td>acop</td><td><code>acop.toolVersion</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
</tbody>
<tbody>
<tr><td>activemq</td><td><code>activemq.jvm.vendor</code></td><td>string</td><td>true</td></tr>
<tr><td>activemq</td><td><code>activemq.jvm.version</code></td><td>string</td><td>true</td></tr>
<tr><td>activemq</td><td><code>activemq.os</code></td><td>string</td><td>true</td></tr>
<tr><td>activemq</td><td><code>activemq.protocolVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>activemq</td><td><code>activemq.wireformat.data</code></td><td>string</td><td>true</td></tr>
<tr><td>activemq</td><td><code>activemq.wireformat.version</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>adb</td><td><code>adb.access</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>ads</td><td><code>ads.deviceName</code></td><td>string</td><td>true</td></tr>
<tr><td>ads</td><td><code>ads.routeCount</code></td><td>numeric</td><td>true</td></tr>
<tr><td>ads</td><td><code>ads.routes</code></td><td>string</td><td>true</td></tr>
<tr><td>ads</td><td><code>ads.version</code></td><td>string</td><td>true</td></tr>
<tr><td>ads</td><td><code>ads.versionBuild</code></td><td>string</td><td>true</td></tr>
<tr><td>ads</td><td><code>ads.versionMajor</code></td><td>string</td><td>true</td></tr>
<tr><td>ads</td><td><code>ads.versionMinor</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>airplay</td><td><code>airplay.build</code></td><td>numeric</td><td>true</td></tr>
<tr><td>airplay</td><td><code>airplay.canRecordScreenStream</code></td><td>boolean</td><td>true</td></tr>
<tr><td>airplay</td><td><code>airplay.deviceID</code></td><td>string</td><td>true</td></tr>
<tr><td>airplay</td><td><code>airplay.features</code></td><td>numeric</td><td>true</td></tr>
<tr><td>airplay</td><td><code>airplay.featuresEx</code></td><td>string</td><td>true</td></tr>
<tr><td>airplay</td><td><code>airplay.firmwareBuildDate</code></td><td>string</td><td>true</td></tr>
<tr><td>airplay</td><td><code>airplay.firmwareRevision</code></td><td>numeric</td><td>true</td></tr>
<tr><td>airplay</td><td><code>airplay.hardwareRevision</code></td><td>numeric</td><td>true</td></tr>
<tr><td>airplay</td><td><code>airplay.hasUDPMirroringSupport</code></td><td>boolean</td><td>true</td></tr>
<tr><td>airplay</td><td><code>airplay.initialVolume</code></td><td>numeric</td><td>true</td></tr>
<tr><td>airplay</td><td><code>airplay.keepAliveLowPower</code></td><td>boolean</td><td>true</td></tr>
<tr><td>airplay</td><td><code>airplay.keepAliveSendStatsAsBody</code></td><td>boolean</td><td>true</td></tr>
<tr><td>airplay</td><td><code>airplay.macAddress</code></td><td>string</td><td>true</td></tr>
<tr><td>airplay</td><td><code>airplay.manufacturer</code></td><td>string</td><td>true</td></tr>
<tr><td>airplay</td><td><code>airplay.model</code></td><td>string</td><td>true</td></tr>
<tr><td>airplay</td><td><code>airplay.name</code></td><td>string</td><td>true</td></tr>
<tr><td>airplay</td><td><code>airplay.osBuildVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>airplay</td><td><code>airplay.osinfo</code></td><td>string</td><td>true</td></tr>
<tr><td>airplay</td><td><code>airplay.pi</code></td><td>uuid</td><td>true</td></tr>
<tr><td>airplay</td><td><code>airplay.pk</code></td><td>string</td><td>true</td></tr>
<tr><td>airplay</td><td><code>airplay.playbackCapabilities</code></td><td>string</td><td>false</td></tr>
<tr><td>airplay</td><td><code>airplay.protocolVersion</code></td><td>numeric</td><td>true</td></tr>
<tr><td>airplay</td><td><code>airplay.ptpinfo</code></td><td>string</td><td>true</td></tr>
<tr><td>airplay</td><td><code>airplay.receiverHDRCapability</code></td><td>string</td><td>true</td></tr>
<tr><td>airplay</td><td><code>airplay.screenDemoMode</code></td><td>boolean</td><td>true</td></tr>
<tr><td>airplay</td><td><code>airplay.sdk</code></td><td>string</td><td>true</td></tr>
<tr><td>airplay</td><td><code>airplay.senderAddress</code></td><td>string</td><td>true</td></tr>
<tr><td>airplay</td><td><code>airplay.sourceVersion</code></td><td>numeric</td><td>true</td></tr>
<tr><td>airplay</td><td><code>airplay.statusFlags</code></td><td>string</td><td>true</td></tr>
<tr><td>airplay</td><td><code>airplay.supportedFormats</code></td><td>string</td><td>true</td></tr>
<tr><td>airplay</td><td><code>airplay.volumeControlType</code></td><td>numeric</td><td>true</td></tr>
<tr><td>airplay</td><td><code>airplay.vv</code></td><td>numeric</td><td>true</td></tr>
<tr><td>airplay</td><td><code>apache.serverInfo</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
</tbody>
<tbody>
<tr><td>amqp</td><td><code>amqp.capabilities</code></td><td>string</td><td>true</td></tr>
<tr><td>amqp</td><td><code>amqp.clusterName</code></td><td>string</td><td>true</td></tr>
<tr><td>amqp</td><td><code>amqp.copyright</code></td><td>string</td><td>true</td></tr>
<tr><td>amqp</td><td><code>amqp.frameType</code></td><td>string</td><td>true</td></tr>
<tr><td>amqp</td><td><code>amqp.information</code></td><td>string</td><td>true</td></tr>
<tr><td>amqp</td><td><code>amqp.locales</code></td><td>string</td><td>true</td></tr>
<tr><td>amqp</td><td><code>amqp.mechanisms</code></td><td>string</td><td>true</td></tr>
<tr><td>amqp</td><td><code>amqp.platform</code></td><td>string</td><td>true</td></tr>
<tr><td>amqp</td><td><code>amqp.product</code></td><td>string</td><td>true</td></tr>
<tr><td>amqp</td><td><code>amqp.protocolID</code></td><td>string</td><td>true</td></tr>
<tr><td>amqp</td><td><code>amqp.protocolMajor</code></td><td>string</td><td>true</td></tr>
<tr><td>amqp</td><td><code>amqp.protocolMinor</code></td><td>string</td><td>true</td></tr>
<tr><td>amqp</td><td><code>amqp.protocolRevision</code></td><td>string</td><td>true</td></tr>
<tr><td>amqp</td><td><code>amqp.protocolVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>amqp</td><td><code>amqp.saslRequired</code></td><td>string</td><td>true</td></tr>
<tr><td>amqp</td><td><code>amqp.serverVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>amqp</td><td><code>amqp.tlsRequired</code></td><td>string</td><td>true</td></tr>
<tr><td>amqp</td><td><code>amqp.version</code></td><td>string</td><td>true</td></tr>
<tr><td>amqp</td><td><code>amqp.versionMajor</code></td><td>string</td><td>true</td></tr>
<tr><td>amqp</td><td><code>amqp.versionMinor</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>anydesk</td><td><code>anydesk.certIssuer</code></td><td>string</td><td>true</td></tr>
<tr><td>anydesk</td><td><code>anydesk.certSubject</code></td><td>string</td><td>true</td></tr>
<tr><td>anydesk</td><td><code>anydesk.selfSigned</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
</tbody>
<tbody>
</tbody>
<tbody>
<tr><td>atg</td><td><code>atg.cpe</code></td><td>string</td><td>true</td></tr>
<tr><td>atg</td><td><code>atg.functionCode</code></td><td>string</td><td>true</td></tr>
<tr><td>atg</td><td><code>atg.modile</code></td><td>string</td><td>true</td></tr>
<tr><td>atg</td><td><code>atg.module</code></td><td>string</td><td>true</td></tr>
<tr><td>atg</td><td><code>atg.products</code></td><td>numeric</td><td>true</td></tr>
<tr><td>atg</td><td><code>atg.software</code></td><td>string</td><td>true</td></tr>
<tr><td>atg</td><td><code>atg.stationName</code></td><td>string</td><td>true</td></tr>
<tr><td>atg</td><td><code>atg.tankCount</code></td><td>numeric</td><td>true</td></tr>
<tr><td>atg</td><td><code>atg.version</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
</tbody>
<tbody>
<tr><td>bacnet</td><td><code>bacnet.address</code></td><td>string</td><td>true</td></tr>
<tr><td>bacnet</td><td><code>bacnet.bbmd</code></td><td>string</td><td>false</td></tr>
<tr><td>bacnet</td><td><code>bacnet.bbmdTable</code></td><td>string</td><td>true</td></tr>
<tr><td>bacnet</td><td><code>bacnet.databaseRevision</code></td><td>string</td><td>true</td></tr>
<tr><td>bacnet</td><td><code>bacnet.decodeWarning</code></td><td>string</td><td>false</td></tr>
<tr><td>bacnet</td><td><code>bacnet.deviceCount</code></td><td>numeric</td><td>true</td></tr>
<tr><td>bacnet</td><td><code>bacnet.deviceType</code></td><td>string</td><td>true</td></tr>
<tr><td>bacnet</td><td><code>bacnet.fdt</code></td><td>string</td><td>false</td></tr>
<tr><td>bacnet</td><td><code>bacnet.foreignDeviceRegistered</code></td><td>string</td><td>true</td></tr>
<tr><td>bacnet</td><td><code>bacnet.foreignDeviceTable</code></td><td>string</td><td>true</td></tr>
<tr><td>bacnet</td><td><code>bacnet.gateway</code></td><td>string</td><td>true</td></tr>
<tr><td>bacnet</td><td><code>bacnet.iHave</code></td><td>string</td><td>false</td></tr>
<tr><td>bacnet</td><td><code>bacnet.instance</code></td><td>string</td><td>true</td></tr>
<tr><td>bacnet</td><td><code>bacnet.instanceID</code></td><td>string</td><td>true</td></tr>
<tr><td>bacnet</td><td><code>bacnet.maxAPDU</code></td><td>string</td><td>true</td></tr>
<tr><td>bacnet</td><td><code>bacnet.maxApdu</code></td><td>string</td><td>true</td></tr>
<tr><td>bacnet</td><td><code>bacnet.maxApduLengthAccepted</code></td><td>string</td><td>true</td></tr>
<tr><td>bacnet</td><td><code>bacnet.modelName</code></td><td>string</td><td>true</td></tr>
<tr><td>bacnet</td><td><code>bacnet.network</code></td><td>string</td><td>true</td></tr>
<tr><td>bacnet</td><td><code>bacnet.objectCount</code></td><td>numeric</td><td>true</td></tr>
<tr><td>bacnet</td><td><code>bacnet.pid</code></td><td>string</td><td>false</td></tr>
<tr><td>bacnet</td><td><code>bacnet.port</code></td><td>numeric</td><td>true</td></tr>
<tr><td>bacnet</td><td><code>bacnet.profileName</code></td><td>string</td><td>true</td></tr>
<tr><td>bacnet</td><td><code>bacnet.protocolRevision</code></td><td>string</td><td>true</td></tr>
<tr><td>bacnet</td><td><code>bacnet.readFailure</code></td><td>string</td><td>false</td></tr>
<tr><td>bacnet</td><td><code>bacnet.remote</code></td><td>string</td><td>true</td></tr>
<tr><td>bacnet</td><td><code>bacnet.remoteDevice</code></td><td>string</td><td>false</td></tr>
<tr><td>bacnet</td><td><code>bacnet.remoteDeviceCount</code></td><td>numeric</td><td>true</td></tr>
<tr><td>bacnet</td><td><code>bacnet.route</code></td><td>string</td><td>true</td></tr>
<tr><td>bacnet</td><td><code>bacnet.routerNetwork</code></td><td>string</td><td>false</td></tr>
<tr><td>bacnet</td><td><code>bacnet.routerNetworks</code></td><td>string</td><td>true</td></tr>
<tr><td>bacnet</td><td><code>bacnet.routingEntries</code></td><td>string</td><td>true</td></tr>
<tr><td>bacnet</td><td><code>bacnet.routingEntry</code></td><td>string</td><td>false</td></tr>
<tr><td>bacnet</td><td><code>bacnet.segmentation</code></td><td>string</td><td>true</td></tr>
<tr><td>bacnet</td><td><code>bacnet.segmentationSupported</code></td><td>numeric</td><td>true</td></tr>
<tr><td>bacnet</td><td><code>bacnet.serialNumber</code></td><td>string</td><td>true</td></tr>
<tr><td>bacnet</td><td><code>bacnet.systemStatus</code></td><td>string</td><td>true</td></tr>
<tr><td>bacnet</td><td><code>bacnet.target</code></td><td>string</td><td>true</td></tr>
<tr><td>bacnet</td><td><code>bacnet.vendorID</code></td><td>string</td><td>true</td></tr>
<tr><td>bacnet</td><td><code>bacnet.vendorIDLookup</code></td><td>string</td><td>true</td></tr>
<tr><td>bacnet</td><td><code>bacnet.vendorLookup</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>banner</td><td><code>banner.banner</code></td><td>string</td><td>true</td></tr>
<tr><td>banner</td><td><code>banner.binary</code></td><td>string</td><td>true</td></tr>
<tr><td>banner</td><td><code>banner.entropy</code></td><td>string</td><td>true</td></tr>
<tr><td>banner</td><td><code>banner.hexPrefix</code></td><td>string</td><td>true</td></tr>
<tr><td>banner</td><td><code>banner.length</code></td><td>numeric</td><td>true</td></tr>
<tr><td>banner</td><td><code>banner.lines</code></td><td>string</td><td>true</td></tr>
<tr><td>banner</td><td><code>banner.printable</code></td><td>string</td><td>true</td></tr>
<tr><td>banner</td><td><code>banner.truncated</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>bedrock</td><td><code>bedrock.contents</code></td><td>string</td><td>true</td></tr>
<tr><td>bedrock</td><td><code>bedrock.guid</code></td><td>string</td><td>true</td></tr>
<tr><td>bedrock</td><td><code>bedrock.uptime</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>bgp</td><td><code>bgp.addressFamilies</code></td><td>string</td><td>true</td></tr>
<tr><td>bgp</td><td><code>bgp.asn</code></td><td>string</td><td>true</td></tr>
<tr><td>bgp</td><td><code>bgp.asn32</code></td><td>string</td><td>true</td></tr>
<tr><td>bgp</td><td><code>bgp.bgpID</code></td><td>string</td><td>true</td></tr>
<tr><td>bgp</td><td><code>bgp.capabilities</code></td><td>string</td><td>true</td></tr>
<tr><td>bgp</td><td><code>bgp.capabilityCount</code></td><td>numeric</td><td>true</td></tr>
<tr><td>bgp</td><td><code>bgp.error</code></td><td>string</td><td>true</td></tr>
<tr><td>bgp</td><td><code>bgp.holdTime</code></td><td>string</td><td>true</td></tr>
<tr><td>bgp</td><td><code>bgp.identifier</code></td><td>string</td><td>true</td></tr>
<tr><td>bgp</td><td><code>bgp.messageType</code></td><td>string</td><td>true</td></tr>
<tr><td>bgp</td><td><code>bgp.notificationCode</code></td><td>string</td><td>true</td></tr>
<tr><td>bgp</td><td><code>bgp.notificationCodeID</code></td><td>string</td><td>true</td></tr>
<tr><td>bgp</td><td><code>bgp.notificationSubcode</code></td><td>string</td><td>true</td></tr>
<tr><td>bgp</td><td><code>bgp.notificationSubcodeName</code></td><td>string</td><td>true</td></tr>
<tr><td>bgp</td><td><code>bgp.subCode</code></td><td>string</td><td>true</td></tr>
<tr><td>bgp</td><td><code>bgp.version</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>bitdefender-app</td><td><code>bitdefender.deviceID</code></td><td>string</td><td>true</td></tr>
<tr><td>bitdefender-app</td><td><code>bitdefender.hostname</code></td><td>string</td><td>true</td></tr>
<tr><td>bitdefender-app</td><td><code>bitdefender.model</code></td><td>string</td><td>true</td></tr>
<tr><td>bitdefender-app</td><td><code>bitdefender.os</code></td><td>string</td><td>true</td></tr>
<tr><td>bitdefender-app</td><td><code>bitdefender.type</code></td><td>string</td><td>true</td></tr>
<tr><td>bitdefender-app</td><td><code>service.product</code></td><td>string</td><td>true</td></tr>
<tr><td>bitdefender-app</td><td><code>service.vendor</code></td><td>string</td><td>true</td></tr>
<tr><td>bitdefender-app</td><td><code>service.version</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>bjnp</td><td><code>bjnp.ipv4</code></td><td>string</td><td>true</td></tr>
<tr><td>bjnp</td><td><code>bjnp.ipv6</code></td><td>string</td><td>true</td></tr>
<tr><td>bjnp</td><td><code>bjnp.macAddress</code></td><td>string</td><td>true</td></tr>
<tr><td>bjnp</td><td><code>bjnp.type</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>brother</td><td><code>brother.firmware.version</code></td><td>string</td><td>true</td></tr>
<tr><td>brother</td><td><code>brother.hostname</code></td><td>string</td><td>true</td></tr>
<tr><td>brother</td><td><code>brother.ip</code></td><td>string</td><td>true</td></tr>
<tr><td>brother</td><td><code>brother.mainFirmwareVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>brother</td><td><code>brother.modelName</code></td><td>string</td><td>true</td></tr>
<tr><td>brother</td><td><code>brother.scanner</code></td><td>string</td><td>true</td></tr>
<tr><td>brother</td><td><code>brother.serialNbr</code></td><td>string</td><td>true</td></tr>
<tr><td>brother</td><td><code>brother.sub1FirmwareVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>brother</td><td><code>brother.sub3FirmwareVersion</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
</tbody>
<tbody>
</tbody>
<tbody>
</tbody>
<tbody>
</tbody>
<tbody>
<tr><td>cacti</td><td><code>cacti.version</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>cassandra</td><td><code>cassandra.cluster</code></td><td>string</td><td>true</td></tr>
<tr><td>cassandra</td><td><code>cassandra.compression</code></td><td>string</td><td>true</td></tr>
<tr><td>cassandra</td><td><code>cassandra.confidence</code></td><td>string</td><td>true</td></tr>
<tr><td>cassandra</td><td><code>cassandra.cqlVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>cassandra</td><td><code>cassandra.protocolVersions</code></td><td>string</td><td>true</td></tr>
<tr><td>cassandra</td><td><code>cassandra.version</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>cdp</td><td><code>cdp.addresses</code></td><td>string</td><td>true</td></tr>
<tr><td>cdp</td><td><code>cdp.capabilities</code></td><td>string</td><td>true</td></tr>
<tr><td>cdp</td><td><code>cdp.checksum</code></td><td>string</td><td>true</td></tr>
<tr><td>cdp</td><td><code>cdp.deviceID</code></td><td>string</td><td>true</td></tr>
<tr><td>cdp</td><td><code>cdp.isHost</code></td><td>string</td><td>true</td></tr>
<tr><td>cdp</td><td><code>cdp.isIGMPCapable</code></td><td>string</td><td>true</td></tr>
<tr><td>cdp</td><td><code>cdp.isL2Switch</code></td><td>string</td><td>true</td></tr>
<tr><td>cdp</td><td><code>cdp.isL3Router</code></td><td>string</td><td>true</td></tr>
<tr><td>cdp</td><td><code>cdp.isRepeater</code></td><td>string</td><td>true</td></tr>
<tr><td>cdp</td><td><code>cdp.isSourceRouteBridge</code></td><td>string</td><td>true</td></tr>
<tr><td>cdp</td><td><code>cdp.isTransparentBridge</code></td><td>string</td><td>true</td></tr>
<tr><td>cdp</td><td><code>cdp.mgmtAddresses</code></td><td>string</td><td>true</td></tr>
<tr><td>cdp</td><td><code>cdp.nativeVLAN</code></td><td>string</td><td>true</td></tr>
<tr><td>cdp</td><td><code>cdp.osVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>cdp</td><td><code>cdp.platform</code></td><td>string</td><td>true</td></tr>
<tr><td>cdp</td><td><code>cdp.port</code></td><td>numeric</td><td>true</td></tr>
<tr><td>cdp</td><td><code>cdp.portID</code></td><td>numeric</td><td>true</td></tr>
<tr><td>cdp</td><td><code>cdp.powerConsumption</code></td><td>string</td><td>true</td></tr>
<tr><td>cdp</td><td><code>cdp.sysName</code></td><td>string</td><td>true</td></tr>
<tr><td>cdp</td><td><code>cdp.target</code></td><td>string</td><td>true</td></tr>
<tr><td>cdp</td><td><code>cdp.ttl</code></td><td>string</td><td>true</td></tr>
<tr><td>cdp</td><td><code>cdp.version</code></td><td>string</td><td>true</td></tr>
<tr><td>cdp</td><td><code>cdp.voipVLAN</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
</tbody>
<tbody>
<tr><td>chargen</td><td><code>chargen.osGuess</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>checkmk</td><td><code>banner</code></td><td>string</td><td>true</td></tr>
<tr><td>checkmk</td><td><code>checkmk.agentOS</code></td><td>string</td><td>true</td></tr>
<tr><td>checkmk</td><td><code>checkmk.arch</code></td><td>string</td><td>true</td></tr>
<tr><td>checkmk</td><td><code>checkmk.buildDate</code></td><td>string</td><td>true</td></tr>
<tr><td>checkmk</td><td><code>checkmk.hostname</code></td><td>string</td><td>true</td></tr>
<tr><td>checkmk</td><td><code>checkmk.osName</code></td><td>string</td><td>true</td></tr>
<tr><td>checkmk</td><td><code>checkmk.osType</code></td><td>string</td><td>true</td></tr>
<tr><td>checkmk</td><td><code>checkmk.osVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>checkmk</td><td><code>checkmk.version</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>chromecast</td><td><code>chromecast.buildVersion</code></td><td>numeric</td><td>true</td></tr>
<tr><td>chromecast</td><td><code>chromecast.capabilities</code></td><td>string</td><td>true</td></tr>
<tr><td>chromecast</td><td><code>chromecast.castBuildRevision</code></td><td>string</td><td>true</td></tr>
<tr><td>chromecast</td><td><code>chromecast.connected</code></td><td>bool</td><td>true</td></tr>
<tr><td>chromecast</td><td><code>chromecast.ethernetConnected</code></td><td>bool</td><td>true</td></tr>
<tr><td>chromecast</td><td><code>chromecast.generation</code></td><td>numeric</td><td>true</td></tr>
<tr><td>chromecast</td><td><code>chromecast.hasUpdate</code></td><td>bool</td><td>true</td></tr>
<tr><td>chromecast</td><td><code>chromecast.hotspotBssid</code></td><td>string</td><td>true</td></tr>
<tr><td>chromecast</td><td><code>chromecast.ipAddress</code></td><td>string</td><td>true</td></tr>
<tr><td>chromecast</td><td><code>chromecast.locale</code></td><td>string</td><td>true</td></tr>
<tr><td>chromecast</td><td><code>chromecast.location.countryCode</code></td><td>string</td><td>true</td></tr>
<tr><td>chromecast</td><td><code>chromecast.location.latitude</code></td><td>numeric</td><td>true</td></tr>
<tr><td>chromecast</td><td><code>chromecast.location.longitude</code></td><td>numeric</td><td>true</td></tr>
<tr><td>chromecast</td><td><code>chromecast.macAddress</code></td><td>string</td><td>true</td></tr>
<tr><td>chromecast</td><td><code>chromecast.name</code></td><td>string</td><td>true</td></tr>
<tr><td>chromecast</td><td><code>chromecast.optIn.crash</code></td><td>bool</td><td>true</td></tr>
<tr><td>chromecast</td><td><code>chromecast.optIn.opencast</code></td><td>bool</td><td>true</td></tr>
<tr><td>chromecast</td><td><code>chromecast.optIn.stats</code></td><td>bool</td><td>true</td></tr>
<tr><td>chromecast</td><td><code>chromecast.publicKey</code></td><td>string</td><td>true</td></tr>
<tr><td>chromecast</td><td><code>chromecast.releaseTrack</code></td><td>string</td><td>true</td></tr>
<tr><td>chromecast</td><td><code>chromecast.setupState</code></td><td>numeric</td><td>true</td></tr>
<tr><td>chromecast</td><td><code>chromecast.setupStats.historicallySucceeded</code></td><td>bool</td><td>true</td></tr>
<tr><td>chromecast</td><td><code>chromecast.setupStats.numCheckConnectivity</code></td><td>numeric</td><td>true</td></tr>
<tr><td>chromecast</td><td><code>chromecast.setupStats.numConnectWifi</code></td><td>numeric</td><td>true</td></tr>
<tr><td>chromecast</td><td><code>chromecast.setupStats.numConnectedWifiNotSaved</code></td><td>numeric</td><td>true</td></tr>
<tr><td>chromecast</td><td><code>chromecast.setupStats.numInitialEurekaInfo</code></td><td>numeric</td><td>true</td></tr>
<tr><td>chromecast</td><td><code>chromecast.setupStats.numObtainIpnumeric</code></td><td>true</td><td>false</td></tr>
<tr><td>chromecast</td><td><code>chromecast.ssdpUdn</code></td><td>string</td><td>true</td></tr>
<tr><td>chromecast</td><td><code>chromecast.ssid</code></td><td>string</td><td>true</td></tr>
<tr><td>chromecast</td><td><code>chromecast.timeFormat</code></td><td>numeric</td><td>true</td></tr>
<tr><td>chromecast</td><td><code>chromecast.timezone</code></td><td>string</td><td>true</td></tr>
<tr><td>chromecast</td><td><code>chromecast.tosAccepted</code></td><td>bool</td><td>true</td></tr>
<tr><td>chromecast</td><td><code>chromecast.umaClientId</code></td><td>string</td><td>true</td></tr>
<tr><td>chromecast</td><td><code>chromecast.uptime</code></td><td>numeric</td><td>true</td></tr>
<tr><td>chromecast</td><td><code>chromecast.version</code></td><td>numeric</td><td>true</td></tr>
<tr><td>chromecast</td><td><code>chromecast.wpaConfigured</code></td><td>bool</td><td>true</td></tr>
<tr><td>chromecast</td><td><code>chromecast.wpaId</code></td><td>numeric</td><td>true</td></tr>
<tr><td>chromecast</td><td><code>chromecast.wpaState</code></td><td>numeric</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>cip</td><td><code>cip.address</code></td><td>string</td><td>true</td></tr>
<tr><td>cip</td><td><code>cip.backplaneSlot</code></td><td>string</td><td>true</td></tr>
<tr><td>cip</td><td><code>cip.deviceType</code></td><td>string</td><td>true</td></tr>
<tr><td>cip</td><td><code>cip.deviceTypeID</code></td><td>string</td><td>true</td></tr>
<tr><td>cip</td><td><code>cip.discoveredPorts</code></td><td>numeric</td><td>true</td></tr>
<tr><td>cip</td><td><code>cip.ethernetLinkCount</code></td><td>numeric</td><td>true</td></tr>
<tr><td>cip</td><td><code>cip.gateway</code></td><td>string</td><td>true</td></tr>
<tr><td>cip</td><td><code>cip.gateway.ethernetLinkCount</code></td><td>numeric</td><td>true</td></tr>
<tr><td>cip</td><td><code>cip.gateway.ips</code></td><td>string</td><td>true</td></tr>
<tr><td>cip</td><td><code>cip.gateway.macs</code></td><td>string</td><td>true</td></tr>
<tr><td>cip</td><td><code>cip.gateway.tcpipInterfaceCount</code></td><td>numeric</td><td>true</td></tr>
<tr><td>cip</td><td><code>cip.id</code></td><td>string</td><td>true</td></tr>
<tr><td>cip</td><td><code>cip.identityPort</code></td><td>numeric</td><td>true</td></tr>
<tr><td>cip</td><td><code>cip.ips</code></td><td>string</td><td>true</td></tr>
<tr><td>cip</td><td><code>cip.macPairs</code></td><td>string</td><td>true</td></tr>
<tr><td>cip</td><td><code>cip.macs</code></td><td>string</td><td>true</td></tr>
<tr><td>cip</td><td><code>cip.moduleCount</code></td><td>numeric</td><td>true</td></tr>
<tr><td>cip</td><td><code>cip.moduleStatus</code></td><td>string</td><td>true</td></tr>
<tr><td>cip</td><td><code>cip.modules</code></td><td>string</td><td>false</td></tr>
<tr><td>cip</td><td><code>cip.port</code></td><td>numeric</td><td>true</td></tr>
<tr><td>cip</td><td><code>cip.product</code></td><td>string</td><td>true</td></tr>
<tr><td>cip</td><td><code>cip.productCode</code></td><td>string</td><td>true</td></tr>
<tr><td>cip</td><td><code>cip.productCodeName</code></td><td>string</td><td>true</td></tr>
<tr><td>cip</td><td><code>cip.productID</code></td><td>string</td><td>true</td></tr>
<tr><td>cip</td><td><code>cip.productName</code></td><td>string</td><td>true</td></tr>
<tr><td>cip</td><td><code>cip.revision</code></td><td>string</td><td>true</td></tr>
<tr><td>cip</td><td><code>cip.safetySupervisor</code></td><td>string</td><td>true</td></tr>
<tr><td>cip</td><td><code>cip.serialNumber</code></td><td>string</td><td>true</td></tr>
<tr><td>cip</td><td><code>cip.serialNumberHex</code></td><td>string</td><td>true</td></tr>
<tr><td>cip</td><td><code>cip.slotStatus</code></td><td>string</td><td>true</td></tr>
<tr><td>cip</td><td><code>cip.state</code></td><td>string</td><td>true</td></tr>
<tr><td>cip</td><td><code>cip.stateCode</code></td><td>string</td><td>true</td></tr>
<tr><td>cip</td><td><code>cip.status</code></td><td>string</td><td>true</td></tr>
<tr><td>cip</td><td><code>cip.statusCode</code></td><td>string</td><td>true</td></tr>
<tr><td>cip</td><td><code>cip.supportsCommunicationService</code></td><td>numeric</td><td>true</td></tr>
<tr><td>cip</td><td><code>cip.supportsTCPEncapsulation</code></td><td>numeric</td><td>true</td></tr>
<tr><td>cip</td><td><code>cip.supportsUDPEncapsulation</code></td><td>numeric</td><td>true</td></tr>
<tr><td>cip</td><td><code>cip.target</code></td><td>string</td><td>true</td></tr>
<tr><td>cip</td><td><code>cip.tcpipInterfaceCount</code></td><td>numeric</td><td>true</td></tr>
<tr><td>cip</td><td><code>cip.vendor</code></td><td>string</td><td>true</td></tr>
<tr><td>cip</td><td><code>cip.vendorID</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>cisco-phone</td><td><code>ciscocp.apploadid</code></td><td>string</td><td>true</td></tr>
<tr><td>cisco-phone</td><td><code>ciscocp.bootloadid</code></td><td>string</td><td>true</td></tr>
<tr><td>cisco-phone</td><td><code>ciscocp.hostname</code></td><td>string</td><td>true</td></tr>
<tr><td>cisco-phone</td><td><code>ciscocp.mac</code></td><td>string</td><td>true</td></tr>
<tr><td>cisco-phone</td><td><code>ciscocp.messagewaiting</code></td><td>string</td><td>true</td></tr>
<tr><td>cisco-phone</td><td><code>ciscocp.model</code></td><td>string</td><td>true</td></tr>
<tr><td>cisco-phone</td><td><code>ciscocp.phonedn</code></td><td>string</td><td>true</td></tr>
<tr><td>cisco-phone</td><td><code>ciscocp.revision</code></td><td>string</td><td>true</td></tr>
<tr><td>cisco-phone</td><td><code>ciscocp.serial</code></td><td>string</td><td>true</td></tr>
<tr><td>cisco-phone</td><td><code>ciscocp.series</code></td><td>string</td><td>true</td></tr>
<tr><td>cisco-phone</td><td><code>ciscocp.udi</code></td><td>string</td><td>true</td></tr>
<tr><td>cisco-phone</td><td><code>ciscocp.version</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>ciscosmi</td><td><code>ciscosmi.reply</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
</tbody>
<tbody>
<tr><td>citrixica</td><td><code>citrix.applications</code></td><td>string</td><td>true</td></tr>
<tr><td>citrixica</td><td><code>citrix.raw</code></td><td>string</td><td>true</td></tr>
<tr><td>citrixica</td><td><code>citrix.serverFarm</code></td><td>string</td><td>true</td></tr>
<tr><td>citrixica</td><td><code>citrixica.banner</code></td><td>string</td><td>true</td></tr>
<tr><td>citrixica</td><td><code>citrixica.cpe23</code></td><td>string</td><td>true</td></tr>
<tr><td>citrixica</td><td><code>citrixica.detected</code></td><td>boolean</td><td>true</td></tr>
<tr><td>citrixica</td><td><code>citrixica.doubleHeader</code></td><td>string</td><td>true</td></tr>
<tr><td>citrixica</td><td><code>citrixica.hexPrefix</code></td><td>string</td><td>true</td></tr>
<tr><td>citrixica</td><td><code>citrixica.length</code></td><td>numeric</td><td>true</td></tr>
<tr><td>citrixica</td><td><code>citrixica.port</code></td><td>numeric</td><td>true</td></tr>
<tr><td>citrixica</td><td><code>citrixica.signature</code></td><td>string</td><td>true</td></tr>
<tr><td>citrixica</td><td><code>citrixica.signatureRepeats</code></td><td>numeric</td><td>true</td></tr>
<tr><td>citrixica</td><td><code>citrixica.target</code></td><td>string</td><td>true</td></tr>
<tr><td>citrixica</td><td><code>citrixica.truncated</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
</tbody>
<tbody>
</tbody>
<tbody>
<tr><td>coap</td><td><code>coap.contentFormat</code></td><td>string</td><td>true</td></tr>
<tr><td>coap</td><td><code>coap.contentUnknown</code></td><td>string</td><td>true</td></tr>
<tr><td>coap</td><td><code>coap.encodedPayload</code></td><td>string</td><td>true</td></tr>
<tr><td>coap</td><td><code>coap.jsonData.cid</code></td><td>string</td><td>true</td></tr>
<tr><td>coap</td><td><code>coap.jsonData.name</code></td><td>string</td><td>true</td></tr>
<tr><td>coap</td><td><code>coap.jsonData.type</code></td><td>string</td><td>true</td></tr>
<tr><td>coap</td><td><code>coap.messageID</code></td><td>string</td><td>true</td></tr>
<tr><td>coap</td><td><code>coap.options</code></td><td>string</td><td>true</td></tr>
<tr><td>coap</td><td><code>coap.payload</code></td><td>string</td><td>true</td></tr>
<tr><td>coap</td><td><code>coap.resources</code></td><td>string</td><td>true</td></tr>
<tr><td>coap</td><td><code>coap.responseCode</code></td><td>string</td><td>true</td></tr>
<tr><td>coap</td><td><code>coap.token</code></td><td>string</td><td>true</td></tr>
<tr><td>coap</td><td><code>coap.type</code></td><td>string</td><td>true</td></tr>
<tr><td>coap</td><td><code>coap.version</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>cockpit</td><td><code>cockpit.os</code></td><td>string</td><td>true</td></tr>
<tr><td>cockpit</td><td><code>cockpit.variant</code></td><td>string</td><td>true</td></tr>
<tr><td>cockpit</td><td><code>cockpit.variantID</code></td><td>string</td><td>true</td></tr>
<tr><td>cockpit</td><td><code>host.name</code></td><td>string</td><td>false</td></tr>
</tbody>
<tbody>
<tr><td>codesys</td><td><code>codesys.banner</code></td><td>string</td><td>true</td></tr>
<tr><td>codesys</td><td><code>codesys.cpe23</code></td><td>string</td><td>true</td></tr>
<tr><td>codesys</td><td><code>codesys.format</code></td><td>string</td><td>true</td></tr>
<tr><td>codesys</td><td><code>codesys.osName</code></td><td>string</td><td>true</td></tr>
<tr><td>codesys</td><td><code>codesys.osType</code></td><td>string</td><td>true</td></tr>
<tr><td>codesys</td><td><code>codesys.productType</code></td><td>string</td><td>true</td></tr>
<tr><td>codesys</td><td><code>codesys.version</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>codesys2</td><td><code>codesys2.byteOrder</code></td><td>string</td><td>true</td></tr>
<tr><td>codesys2</td><td><code>codesys2.osType</code></td><td>string</td><td>true</td></tr>
<tr><td>codesys2</td><td><code>codesys2.osVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>codesys2</td><td><code>codesys2.vendor</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
</tbody>
<tbody>
</tbody>
<tbody>
</tbody>
<tbody>
<tr><td>comtrol</td><td><code>dnsServer</code></td><td>string</td><td>true</td></tr>
<tr><td>comtrol</td><td><code>gateway</code></td><td>string</td><td>true</td></tr>
<tr><td>comtrol</td><td><code>hostname</code></td><td>string</td><td>true</td></tr>
<tr><td>comtrol</td><td><code>ipAddress</code></td><td>string</td><td>true</td></tr>
<tr><td>comtrol</td><td><code>macAddress</code></td><td>string</td><td>true</td></tr>
<tr><td>comtrol</td><td><code>manufacturer</code></td><td>string</td><td>true</td></tr>
<tr><td>comtrol</td><td><code>modelName</code></td><td>string</td><td>true</td></tr>
<tr><td>comtrol</td><td><code>modelNumber</code></td><td>string</td><td>true</td></tr>
<tr><td>comtrol</td><td><code>netmask</code></td><td>string</td><td>true</td></tr>
<tr><td>comtrol</td><td><code>osVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>comtrol</td><td><code>serialNumber</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>confluence</td><td><code>confluence.baseURL</code></td><td>string</td><td>true</td></tr>
<tr><td>confluence</td><td><code>confluence.build</code></td><td>string</td><td>true</td></tr>
<tr><td>confluence</td><td><code>confluence.version</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>consul</td><td><code>consul.config.version</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>couchdb</td><td><code>couchdb.version</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>crestron</td><td><code>crestron.banner</code></td><td>string</td><td>true</td></tr>
<tr><td>crestron</td><td><code>crestron.buildDate</code></td><td>string</td><td>true</td></tr>
<tr><td>crestron</td><td><code>crestron.hostname</code></td><td>string</td><td>true</td></tr>
<tr><td>crestron</td><td><code>crestron.id</code></td><td>string</td><td>true</td></tr>
<tr><td>crestron</td><td><code>crestron.mac</code></td><td>string</td><td>true</td></tr>
<tr><td>crestron</td><td><code>crestron.model</code></td><td>string</td><td>true</td></tr>
<tr><td>crestron</td><td><code>crestron.version</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>crimsonv3</td><td><code>crimsonv3.manufacturer</code></td><td>string</td><td>true</td></tr>
<tr><td>crimsonv3</td><td><code>crimsonv3.model</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>crowd</td><td><code>crowd.version</code></td><td>string</td><td>true</td></tr>
<tr><td>crowd</td><td><code>service.product</code></td><td>string</td><td>true</td></tr>
<tr><td>crowd</td><td><code>service.vendor</code></td><td>string</td><td>true</td></tr>
<tr><td>crowd</td><td><code>service.version</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
</tbody>
<tbody>
</tbody>
<tbody>
</tbody>
<tbody>
<tr><td>daytime</td><td><code>daytime.osGuess</code></td><td>string</td><td>true</td></tr>
<tr><td>daytime</td><td><code>daytime.timestamp</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>db2</td><td><code>db2.database</code></td><td>string</td><td>true</td></tr>
<tr><td>db2</td><td><code>db2.extnam</code></td><td>string</td><td>true</td></tr>
<tr><td>db2</td><td><code>db2.hostname</code></td><td>string</td><td>true</td></tr>
<tr><td>db2</td><td><code>db2.instance</code></td><td>string</td><td>true</td></tr>
<tr><td>db2</td><td><code>db2.nodeName</code></td><td>string</td><td>true</td></tr>
<tr><td>db2</td><td><code>db2.port</code></td><td>numeric</td><td>true</td></tr>
<tr><td>db2</td><td><code>db2.raw</code></td><td>string</td><td>true</td></tr>
<tr><td>db2</td><td><code>db2.serverType</code></td><td>string</td><td>true</td></tr>
<tr><td>db2</td><td><code>db2.serviceName</code></td><td>string</td><td>true</td></tr>
<tr><td>db2</td><td><code>db2.srvnam</code></td><td>string</td><td>true</td></tr>
<tr><td>db2</td><td><code>db2.srvrlslv</code></td><td>string</td><td>true</td></tr>
<tr><td>db2</td><td><code>db2.version</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>dcerpc</td><td><code>dcerpc.accepted</code></td><td>string</td><td>true</td></tr>
<tr><td>dcerpc</td><td><code>dcerpc.acceptedContexts</code></td><td>numeric</td><td>true</td></tr>
<tr><td>dcerpc</td><td><code>dcerpc.assocGroup</code></td><td>string</td><td>true</td></tr>
<tr><td>dcerpc</td><td><code>dcerpc.authLength</code></td><td>string</td><td>true</td></tr>
<tr><td>dcerpc</td><td><code>dcerpc.byteOrder</code></td><td>string</td><td>true</td></tr>
<tr><td>dcerpc</td><td><code>dcerpc.callID</code></td><td>string</td><td>true</td></tr>
<tr><td>dcerpc</td><td><code>dcerpc.dataRep</code></td><td>string</td><td>true</td></tr>
<tr><td>dcerpc</td><td><code>dcerpc.fragLength</code></td><td>string</td><td>true</td></tr>
<tr><td>dcerpc</td><td><code>dcerpc.interface</code></td><td>string</td><td>true</td></tr>
<tr><td>dcerpc</td><td><code>dcerpc.interfaceUUID</code></td><td>string</td><td>true</td></tr>
<tr><td>dcerpc</td><td><code>dcerpc.interfaceVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>dcerpc</td><td><code>dcerpc.maxRecvFrag</code></td><td>string</td><td>true</td></tr>
<tr><td>dcerpc</td><td><code>dcerpc.maxXmitFrag</code></td><td>string</td><td>true</td></tr>
<tr><td>dcerpc</td><td><code>dcerpc.oxid.addresses</code></td><td>string</td><td>true</td></tr>
<tr><td>dcerpc</td><td><code>dcerpc.oxid.bindingCount</code></td><td>numeric</td><td>true</td></tr>
<tr><td>dcerpc</td><td><code>dcerpc.oxid.bindings</code></td><td>string</td><td>true</td></tr>
<tr><td>dcerpc</td><td><code>dcerpc.oxid.comVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>dcerpc</td><td><code>dcerpc.oxid.error</code></td><td>string</td><td>true</td></tr>
<tr><td>dcerpc</td><td><code>dcerpc.oxid.machineName</code></td><td>string</td><td>true</td></tr>
<tr><td>dcerpc</td><td><code>dcerpc.oxid.security</code></td><td>string</td><td>true</td></tr>
<tr><td>dcerpc</td><td><code>dcerpc.pduType</code></td><td>string</td><td>true</td></tr>
<tr><td>dcerpc</td><td><code>dcerpc.port</code></td><td>numeric</td><td>true</td></tr>
<tr><td>dcerpc</td><td><code>dcerpc.rejectReason</code></td><td>string</td><td>true</td></tr>
<tr><td>dcerpc</td><td><code>dcerpc.rejectReasonCode</code></td><td>string</td><td>true</td></tr>
<tr><td>dcerpc</td><td><code>dcerpc.rejectedContexts</code></td><td>numeric</td><td>true</td></tr>
<tr><td>dcerpc</td><td><code>dcerpc.secondaryAddr</code></td><td>string</td><td>true</td></tr>
<tr><td>dcerpc</td><td><code>dcerpc.serviceCount</code></td><td>numeric</td><td>true</td></tr>
<tr><td>dcerpc</td><td><code>dcerpc.services</code></td><td>string</td><td>true</td></tr>
<tr><td>dcerpc</td><td><code>dcerpc.target</code></td><td>string</td><td>true</td></tr>
<tr><td>dcerpc</td><td><code>dcerpc.version</code></td><td>string</td><td>true</td></tr>
<tr><td>dcerpc</td><td><code>epm.addrLen</code></td><td>numeric</td><td>true</td></tr>
<tr><td>dcerpc</td><td><code>epm.address</code></td><td>string</td><td>true</td></tr>
<tr><td>dcerpc</td><td><code>epm.assocGroup</code></td><td>string</td><td>true</td></tr>
<tr><td>dcerpc</td><td><code>epm.authRequired</code></td><td>string</td><td>true</td></tr>
<tr><td>dcerpc</td><td><code>epm.dataRep</code></td><td>string</td><td>true</td></tr>
<tr><td>dcerpc</td><td><code>epm.maxRecvFrag</code></td><td>numeric</td><td>true</td></tr>
<tr><td>dcerpc</td><td><code>epm.maxSendFrag</code></td><td>numeric</td><td>true</td></tr>
<tr><td>dcerpc</td><td><code>epm.oxid.addresses</code></td><td>string</td><td>true</td></tr>
<tr><td>dcerpc</td><td><code>epm.oxid.security</code></td><td>string</td><td>true</td></tr>
<tr><td>dcerpc</td><td><code>epm.oxidVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>dcerpc</td><td><code>epm.version</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>dhcp</td><td><code>dhcp.authentication</code></td><td>string</td><td>true</td></tr>
<tr><td>dhcp</td><td><code>dhcp.bootFile</code></td><td>string</td><td>true</td></tr>
<tr><td>dhcp</td><td><code>dhcp.broadcast</code></td><td>string</td><td>true</td></tr>
<tr><td>dhcp</td><td><code>dhcp.broadcastAddress</code></td><td>string</td><td>true</td></tr>
<tr><td>dhcp</td><td><code>dhcp.class</code></td><td>string</td><td>false</td></tr>
<tr><td>dhcp</td><td><code>dhcp.clientFqdn</code></td><td>string</td><td>true</td></tr>
<tr><td>dhcp</td><td><code>dhcp.clientIP</code></td><td>string</td><td>true</td></tr>
<tr><td>dhcp</td><td><code>dhcp.clientMAC</code></td><td>string</td><td>true</td></tr>
<tr><td>dhcp</td><td><code>dhcp.clientSystemArchitecture</code></td><td>string</td><td>false</td></tr>
<tr><td>dhcp</td><td><code>dhcp.clientSystemArchitectureCode</code></td><td>string</td><td>true</td></tr>
<tr><td>dhcp</td><td><code>dhcp.clientid.enterprise</code></td><td>string</td><td>false</td></tr>
<tr><td>dhcp</td><td><code>dhcp.domainName</code></td><td>string</td><td>true</td></tr>
<tr><td>dhcp</td><td><code>dhcp.domainNameServer</code></td><td>string</td><td>true</td></tr>
<tr><td>dhcp</td><td><code>dhcp.flags</code></td><td>string</td><td>true</td></tr>
<tr><td>dhcp</td><td><code>dhcp.hardwareAddressLength</code></td><td>string</td><td>true</td></tr>
<tr><td>dhcp</td><td><code>dhcp.hardwareType</code></td><td>string</td><td>true</td></tr>
<tr><td>dhcp</td><td><code>dhcp.hops</code></td><td>string</td><td>true</td></tr>
<tr><td>dhcp</td><td><code>dhcp.hostname</code></td><td>string</td><td>true</td></tr>
<tr><td>dhcp</td><td><code>dhcp.isRequest</code></td><td>string</td><td>true</td></tr>
<tr><td>dhcp</td><td><code>dhcp.leaseTime</code></td><td>string</td><td>true</td></tr>
<tr><td>dhcp</td><td><code>dhcp.leaseTimeFormatted</code></td><td>string</td><td>true</td></tr>
<tr><td>dhcp</td><td><code>dhcp.maximumMessageSize</code></td><td>string</td><td>true</td></tr>
<tr><td>dhcp</td><td><code>dhcp.message</code></td><td>string</td><td>true</td></tr>
<tr><td>dhcp</td><td><code>dhcp.messageType</code></td><td>string</td><td>true</td></tr>
<tr><td>dhcp</td><td><code>dhcp.messageTypeCode</code></td><td>string</td><td>true</td></tr>
<tr><td>dhcp</td><td><code>dhcp.nextServerIP</code></td><td>string</td><td>true</td></tr>
<tr><td>dhcp</td><td><code>dhcp.ntpServers</code></td><td>string</td><td>true</td></tr>
<tr><td>dhcp</td><td><code>dhcp.offeredIP</code></td><td>string</td><td>true</td></tr>
<tr><td>dhcp</td><td><code>dhcp.op</code></td><td>string</td><td>true</td></tr>
<tr><td>dhcp</td><td><code>dhcp.port</code></td><td>numeric</td><td>true</td></tr>
<tr><td>dhcp</td><td><code>dhcp.rebindingTime</code></td><td>string</td><td>true</td></tr>
<tr><td>dhcp</td><td><code>dhcp.rebindingTimeFormatted</code></td><td>string</td><td>true</td></tr>
<tr><td>dhcp</td><td><code>dhcp.relayAgentIP</code></td><td>string</td><td>true</td></tr>
<tr><td>dhcp</td><td><code>dhcp.relayAgentInformation</code></td><td>string</td><td>true</td></tr>
<tr><td>dhcp</td><td><code>dhcp.renewalTime</code></td><td>string</td><td>true</td></tr>
<tr><td>dhcp</td><td><code>dhcp.renewalTimeFormatted</code></td><td>string</td><td>true</td></tr>
<tr><td>dhcp</td><td><code>dhcp.router</code></td><td>string</td><td>true</td></tr>
<tr><td>dhcp</td><td><code>dhcp.seconds</code></td><td>string</td><td>true</td></tr>
<tr><td>dhcp</td><td><code>dhcp.serverIdentifier</code></td><td>string</td><td>true</td></tr>
<tr><td>dhcp</td><td><code>dhcp.serverName</code></td><td>string</td><td>true</td></tr>
<tr><td>dhcp</td><td><code>dhcp.subnetMask</code></td><td>string</td><td>true</td></tr>
<tr><td>dhcp</td><td><code>dhcp.target</code></td><td>string</td><td>true</td></tr>
<tr><td>dhcp</td><td><code>dhcp.tftpServerAddress</code></td><td>string</td><td>true</td></tr>
<tr><td>dhcp</td><td><code>dhcp.tftpServerName</code></td><td>string</td><td>true</td></tr>
<tr><td>dhcp</td><td><code>dhcp.transactionID</code></td><td>string</td><td>true</td></tr>
<tr><td>dhcp</td><td><code>dhcp.vendorClass</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>diameter</td><td><code>diameter.cpe</code></td><td>string</td><td>true</td></tr>
<tr><td>diameter</td><td><code>diameter.example.com</code></td><td>string</td><td>true</td></tr>
<tr><td>diameter</td><td><code>diameter.firmwareRevision</code></td><td>string</td><td>true</td></tr>
<tr><td>diameter</td><td><code>diameter.originHost</code></td><td>string</td><td>true</td></tr>
<tr><td>diameter</td><td><code>diameter.originRealm</code></td><td>string</td><td>true</td></tr>
<tr><td>diameter</td><td><code>diameter.productName</code></td><td>string</td><td>true</td></tr>
<tr><td>diameter</td><td><code>diameter.resultCode</code></td><td>string</td><td>true</td></tr>
<tr><td>diameter</td><td><code>diameter.vendor</code></td><td>string</td><td>true</td></tr>
<tr><td>diameter</td><td><code>diameter.vendorID</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>diametersctp</td><td><code>diameter.cpe</code></td><td>string</td><td>true</td></tr>
<tr><td>diametersctp</td><td><code>diameter.firmwareRevision</code></td><td>string</td><td>true</td></tr>
<tr><td>diametersctp</td><td><code>diameter.originHost</code></td><td>string</td><td>true</td></tr>
<tr><td>diametersctp</td><td><code>diameter.originRealm</code></td><td>string</td><td>true</td></tr>
<tr><td>diametersctp</td><td><code>diameter.productName</code></td><td>string</td><td>true</td></tr>
<tr><td>diametersctp</td><td><code>diameter.vendor</code></td><td>string</td><td>true</td></tr>
<tr><td>diametersctp</td><td><code>diameter.vendorID</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
</tbody>
<tbody>
<tr><td>dnp3</td><td><code>dnp3.destination</code></td><td>string</td><td>true</td></tr>
<tr><td>dnp3</td><td><code>dnp3.deviceID</code></td><td>string</td><td>true</td></tr>
<tr><td>dnp3</td><td><code>dnp3.deviceName</code></td><td>string</td><td>true</td></tr>
<tr><td>dnp3</td><td><code>dnp3.hardwareVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>dnp3</td><td><code>dnp3.location</code></td><td>string</td><td>true</td></tr>
<tr><td>dnp3</td><td><code>dnp3.manufacturer</code></td><td>string</td><td>true</td></tr>
<tr><td>dnp3</td><td><code>dnp3.model</code></td><td>string</td><td>true</td></tr>
<tr><td>dnp3</td><td><code>dnp3.owner</code></td><td>string</td><td>true</td></tr>
<tr><td>dnp3</td><td><code>dnp3.serialNumber</code></td><td>string</td><td>true</td></tr>
<tr><td>dnp3</td><td><code>dnp3.softwareVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>dnp3</td><td><code>dnp3.source</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>dns</td><td><code>dns.addrs</code></td><td>string</td><td>true</td></tr>
<tr><td>dns</td><td><code>dns.ancount</code></td><td>numeric</td><td>true</td></tr>
<tr><td>dns</td><td><code>dns.answerAddrs</code></td><td>string</td><td>true</td></tr>
<tr><td>dns</td><td><code>dns.answerNames</code></td><td>string</td><td>true</td></tr>
<tr><td>dns</td><td><code>dns.answerTXTs</code></td><td>string</td><td>true</td></tr>
<tr><td>dns</td><td><code>dns.answerTypes</code></td><td>string</td><td>true</td></tr>
<tr><td>dns</td><td><code>dns.authors.bind</code></td><td>string</td><td>true</td></tr>
<tr><td>dns</td><td><code>dns.edns0</code></td><td>string</td><td>true</td></tr>
<tr><td>dns</td><td><code>dns.edns0.cookie</code></td><td>string</td><td>true</td></tr>
<tr><td>dns</td><td><code>dns.edns0.nsid</code></td><td>string</td><td>true</td></tr>
<tr><td>dns</td><td><code>dns.edns0.subnet</code></td><td>string</td><td>true</td></tr>
<tr><td>dns</td><td><code>dns.edns0.udpSize</code></td><td>string</td><td>true</td></tr>
<tr><td>dns</td><td><code>dns.edns0.unknown</code></td><td>string</td><td>true</td></tr>
<tr><td>dns</td><td><code>dns.edns0.version</code></td><td>string</td><td>true</td></tr>
<tr><td>dns</td><td><code>dns.flags</code></td><td>string</td><td>true</td></tr>
<tr><td>dns</td><td><code>dns.hostname.bind</code></td><td>string</td><td>true</td></tr>
<tr><td>dns</td><td><code>dns.hostnameBind</code></td><td>string</td><td>true</td></tr>
<tr><td>dns</td><td><code>dns.id</code></td><td>string</td><td>true</td></tr>
<tr><td>dns</td><td><code>dns.id.server</code></td><td>string</td><td>true</td></tr>
<tr><td>dns</td><td><code>dns.idServer</code></td><td>string</td><td>true</td></tr>
<tr><td>dns</td><td><code>dns.isRequest</code></td><td>string</td><td>true</td></tr>
<tr><td>dns</td><td><code>dns.meraki</code></td><td>string</td><td>true</td></tr>
<tr><td>dns</td><td><code>dns.opcode</code></td><td>string</td><td>true</td></tr>
<tr><td>dns</td><td><code>dns.ptr</code></td><td>string</td><td>false</td></tr>
<tr><td>dns</td><td><code>dns.qdcount</code></td><td>numeric</td><td>true</td></tr>
<tr><td>dns</td><td><code>dns.rcode</code></td><td>string</td><td>true</td></tr>
<tr><td>dns</td><td><code>dns.recursion</code></td><td>string</td><td>true</td></tr>
<tr><td>dns</td><td><code>dns.resolvers</code></td><td>string</td><td>true</td></tr>
<tr><td>dns</td><td><code>dns.resolves</code></td><td>string</td><td>true</td></tr>
<tr><td>dns</td><td><code>dns.rtts</code></td><td>numeric</td><td>true</td></tr>
<tr><td>dns</td><td><code>dns.subnets</code></td><td>numeric</td><td>true</td></tr>
<tr><td>dns</td><td><code>dns.telco.epc</code></td><td>string</td><td>false</td></tr>
<tr><td>dns</td><td><code>dns.tracer</code></td><td>string</td><td>false</td></tr>
<tr><td>dns</td><td><code>dns.tracer.edns0</code></td><td>string</td><td>false</td></tr>
<tr><td>dns</td><td><code>dns.transport</code></td><td>string</td><td>true</td></tr>
<tr><td>dns</td><td><code>dns.version</code></td><td>string</td><td>true</td></tr>
<tr><td>dns</td><td><code>dns.version.bind</code></td><td>string</td><td>true</td></tr>
<tr><td>dns</td><td><code>dns.version.server</code></td><td>string</td><td>true</td></tr>
<tr><td>dns</td><td><code>dns.versionBind</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>docker</td><td><code>docker.architecture</code></td><td>string</td><td>true</td></tr>
<tr><td>docker</td><td><code>docker.dockerRootDir</code></td><td>string</td><td>true</td></tr>
<tr><td>docker</td><td><code>docker.kernelVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>docker</td><td><code>docker.memTotal</code></td><td>string</td><td>true</td></tr>
<tr><td>docker</td><td><code>docker.name</code></td><td>string</td><td>true</td></tr>
<tr><td>docker</td><td><code>docker.ncpu</code></td><td>string</td><td>true</td></tr>
<tr><td>docker</td><td><code>docker.operatingSystem</code></td><td>string</td><td>true</td></tr>
<tr><td>docker</td><td><code>docker.ostype</code></td><td>string</td><td>true</td></tr>
<tr><td>docker</td><td><code>docker.systemTime</code></td><td>string</td><td>true</td></tr>
<tr><td>docker</td><td><code>docker.version</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
</tbody>
<tbody>
</tbody>
<tbody>
</tbody>
<tbody>
</tbody>
<tbody>
<tr><td>dtls</td><td><code>dtls.alert</code></td><td>string</td><td>true</td></tr>
<tr><td>dtls</td><td><code>dtls.contentType</code></td><td>string</td><td>true</td></tr>
<tr><td>dtls</td><td><code>dtls.cookieLength</code></td><td>string</td><td>true</td></tr>
<tr><td>dtls</td><td><code>dtls.encapsulation</code></td><td>string</td><td>true</td></tr>
<tr><td>dtls</td><td><code>dtls.handshakeFragmentLength</code></td><td>string</td><td>true</td></tr>
<tr><td>dtls</td><td><code>dtls.handshakeFragmentOffset</code></td><td>string</td><td>true</td></tr>
<tr><td>dtls</td><td><code>dtls.handshakeLength</code></td><td>string</td><td>true</td></tr>
<tr><td>dtls</td><td><code>dtls.handshakeMessageSeq</code></td><td>string</td><td>true</td></tr>
<tr><td>dtls</td><td><code>dtls.handshakeType</code></td><td>string</td><td>true</td></tr>
<tr><td>dtls</td><td><code>dtls.recordEpoch</code></td><td>string</td><td>true</td></tr>
<tr><td>dtls</td><td><code>dtls.recordLength</code></td><td>string</td><td>true</td></tr>
<tr><td>dtls</td><td><code>dtls.recordSequence</code></td><td>string</td><td>true</td></tr>
<tr><td>dtls</td><td><code>dtls.serverVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>dtls</td><td><code>dtls.unknown</code></td><td>string</td><td>true</td></tr>
<tr><td>dtls</td><td><code>dtls.verifyCookie</code></td><td>string</td><td>true</td></tr>
<tr><td>dtls</td><td><code>dtls.version</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>echo</td><td><code>echo.data</code></td><td>string</td><td>true</td></tr>
<tr><td>echo</td><td><code>echo.match</code></td><td>string</td><td>true</td></tr>
<tr><td>echo</td><td><code>echo.probeHex</code></td><td>string</td><td>true</td></tr>
<tr><td>echo</td><td><code>echo.probeLength</code></td><td>string</td><td>true</td></tr>
<tr><td>echo</td><td><code>echo.responseHex</code></td><td>string</td><td>true</td></tr>
<tr><td>echo</td><td><code>echo.responseLength</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
</tbody>
<tbody>
</tbody>
<tbody>
<tr><td>elasticsearch</td><td><code>elasticsearch.version.number</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
</tbody>
<tbody>
</tbody>
<tbody>
<tr><td>epo</td><td><code>epo.guid</code></td><td>string</td><td>true</td></tr>
<tr><td>epo</td><td><code>epo.hostname</code></td><td>string</td><td>true</td></tr>
<tr><td>epo</td><td><code>epo.server</code></td><td>string</td><td>true</td></tr>
<tr><td>epo</td><td><code>epo.version</code></td><td>string</td><td>true</td></tr>
<tr><td>epo</td><td><code>mcafeeAgent.hostname</code></td><td>string</td><td>true</td></tr>
<tr><td>epo</td><td><code>mcafeeAgent.version</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>erlangdp</td><td><code>epmd.details</code></td><td>string</td><td>false</td></tr>
<tr><td>erlangdp</td><td><code>epmd.names</code></td><td>string</td><td>false</td></tr>
<tr><td>erlangdp</td><td><code>erldp.challenge</code></td><td>string</td><td>true</td></tr>
<tr><td>erlangdp</td><td><code>erldp.flags</code></td><td>string</td><td>true</td></tr>
<tr><td>erlangdp</td><td><code>erldp.hostname</code></td><td>string</td><td>true</td></tr>
<tr><td>erlangdp</td><td><code>erldp.node</code></td><td>string</td><td>true</td></tr>
<tr><td>erlangdp</td><td><code>erldp.status</code></td><td>string</td><td>true</td></tr>
<tr><td>erlangdp</td><td><code>erldp.version</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
</tbody>
<tbody>
</tbody>
<tbody>
<tr><td>etcd2</td><td><code>etcd2.access</code></td><td>string</td><td>true</td></tr>
<tr><td>etcd2</td><td><code>etcd2.keys</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>ethercat</td><td><code>ethercat.ado</code></td><td>string</td><td>true</td></tr>
<tr><td>ethercat</td><td><code>ethercat.adp</code></td><td>string</td><td>true</td></tr>
<tr><td>ethercat</td><td><code>ethercat.command</code></td><td>string</td><td>true</td></tr>
<tr><td>ethercat</td><td><code>ethercat.commandType</code></td><td>string</td><td>true</td></tr>
<tr><td>ethercat</td><td><code>ethercat.datagramCount</code></td><td>numeric</td><td>true</td></tr>
<tr><td>ethercat</td><td><code>ethercat.detected</code></td><td>boolean</td><td>true</td></tr>
<tr><td>ethercat</td><td><code>ethercat.index</code></td><td>string</td><td>true</td></tr>
<tr><td>ethercat</td><td><code>ethercat.workingCounter</code></td><td>numeric</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>fgfm</td><td><code>fgfm.deviceName</code></td><td>string</td><td>true</td></tr>
<tr><td>fgfm</td><td><code>fgfm.firmwareVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>fgfm</td><td><code>fgfm.mgmtIP</code></td><td>string</td><td>true</td></tr>
<tr><td>fgfm</td><td><code>fgfm.platform</code></td><td>string</td><td>true</td></tr>
<tr><td>fgfm</td><td><code>fgfm.serialNumber</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
</tbody>
<tbody>
</tbody>
<tbody>
<tr><td>firebird</td><td><code>firebird.opcode</code></td><td>string</td><td>true</td></tr>
<tr><td>firebird</td><td><code>firebird.protocolVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>firebird</td><td><code>firebird.version</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
</tbody>
<tbody>
</tbody>
<tbody>
<tr><td>fox</td><td><code>fox.appName</code></td><td>string</td><td>true</td></tr>
<tr><td>fox</td><td><code>fox.appVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>fox</td><td><code>fox.authAgent</code></td><td>string</td><td>true</td></tr>
<tr><td>fox</td><td><code>fox.brandId</code></td><td>string</td><td>true</td></tr>
<tr><td>fox</td><td><code>fox.cpe</code></td><td>string</td><td>true</td></tr>
<tr><td>fox</td><td><code>fox.hostAddress</code></td><td>string</td><td>true</td></tr>
<tr><td>fox</td><td><code>fox.hostId</code></td><td>string</td><td>true</td></tr>
<tr><td>fox</td><td><code>fox.hostname</code></td><td>string</td><td>true</td></tr>
<tr><td>fox</td><td><code>fox.language</code></td><td>string</td><td>true</td></tr>
<tr><td>fox</td><td><code>fox.osName</code></td><td>string</td><td>true</td></tr>
<tr><td>fox</td><td><code>fox.osVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>fox</td><td><code>fox.stationName</code></td><td>string</td><td>true</td></tr>
<tr><td>fox</td><td><code>fox.sysInfo</code></td><td>string</td><td>true</td></tr>
<tr><td>fox</td><td><code>fox.timeZone</code></td><td>string</td><td>true</td></tr>
<tr><td>fox</td><td><code>fox.vendor</code></td><td>string</td><td>true</td></tr>
<tr><td>fox</td><td><code>fox.version</code></td><td>string</td><td>true</td></tr>
<tr><td>fox</td><td><code>fox.vmName</code></td><td>string</td><td>true</td></tr>
<tr><td>fox</td><td><code>fox.vmUuid</code></td><td>string</td><td>true</td></tr>
<tr><td>fox</td><td><code>fox.vmVersion</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>ftp</td><td><code>ftp.anonymousAllowed</code></td><td>string</td><td>true</td></tr>
<tr><td>ftp</td><td><code>ftp.anonymousLoginCode</code></td><td>string</td><td>true</td></tr>
<tr><td>ftp</td><td><code>ftp.authMethods</code></td><td>string</td><td>true</td></tr>
<tr><td>ftp</td><td><code>ftp.banner</code></td><td>string</td><td>true</td></tr>
<tr><td>ftp</td><td><code>ftp.featureCount</code></td><td>numeric</td><td>true</td></tr>
<tr><td>ftp</td><td><code>ftp.features</code></td><td>string</td><td>true</td></tr>
<tr><td>ftp</td><td><code>ftp.statusCode</code></td><td>string</td><td>true</td></tr>
<tr><td>ftp</td><td><code>ftp.statusMessage</code></td><td>string</td><td>true</td></tr>
<tr><td>ftp</td><td><code>ftp.supportsExplicitTLS</code></td><td>numeric</td><td>true</td></tr>
<tr><td>ftp</td><td><code>ftp.system</code></td><td>string</td><td>true</td></tr>
<tr><td>ftp</td><td><code>ftp.systemStatusCode</code></td><td>string</td><td>true</td></tr>
<tr><td>ftp</td><td><code>ftp.systemType</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
</tbody>
<tbody>
<tr><td>gesrtp</td><td><code>gesrtp.cpe</code></td><td>string</td><td>true</td></tr>
<tr><td>gesrtp</td><td><code>gesrtp.deviceIndicator</code></td><td>string</td><td>true</td></tr>
<tr><td>gesrtp</td><td><code>gesrtp.plcName</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
</tbody>
<tbody>
<tr><td>git</td><td><code>git.branches</code></td><td>string</td><td>true</td></tr>
<tr><td>git</td><td><code>git.capabilities</code></td><td>string</td><td>true</td></tr>
<tr><td>git</td><td><code>git.headRef</code></td><td>string</td><td>true</td></tr>
<tr><td>git</td><td><code>git.protocolVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>git</td><td><code>git.refs</code></td><td>string</td><td>true</td></tr>
<tr><td>git</td><td><code>git.serverSoftware</code></td><td>string</td><td>true</td></tr>
<tr><td>git</td><td><code>git.tags</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>git-http</td><td><code>gitlab.manifest.hash</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>googlewifi</td><td><code>googleWifi.software.version</code></td><td>string</td><td>true</td></tr>
<tr><td>googlewifi</td><td><code>googleWifi.system.countryCode</code></td><td>string</td><td>true</td></tr>
<tr><td>googlewifi</td><td><code>googleWifi.system.hardwareID</code></td><td>string</td><td>true</td></tr>
<tr><td>googlewifi</td><td><code>googleWifi.system.modelID</code></td><td>string</td><td>true</td></tr>
<tr><td>googlewifi</td><td><code>googleWifi.wan.gateway</code></td><td>string</td><td>true</td></tr>
<tr><td>googlewifi</td><td><code>googleWifi.wan.localIP</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
</tbody>
<tbody>
<tr><td>gtpc</td><td><code>gtpc.restartCounter</code></td><td>numeric</td><td>true</td></tr>
<tr><td>gtpc</td><td><code>gtpc.teid</code></td><td>string</td><td>true</td></tr>
<tr><td>gtpc</td><td><code>gtpc.teidPresent</code></td><td>string</td><td>true</td></tr>
<tr><td>gtpc</td><td><code>gtpc.version</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>gtpprime</td><td><code>gtpprime.detected</code></td><td>boolean</td><td>true</td></tr>
<tr><td>gtpprime</td><td><code>gtpprime.pt</code></td><td>string</td><td>true</td></tr>
<tr><td>gtpprime</td><td><code>gtpprime.restartCounter</code></td><td>numeric</td><td>true</td></tr>
<tr><td>gtpprime</td><td><code>gtpprime.teid</code></td><td>string</td><td>true</td></tr>
<tr><td>gtpprime</td><td><code>gtpprime.version</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>gtpu</td><td><code>gtpu.detected</code></td><td>boolean</td><td>true</td></tr>
<tr><td>gtpu</td><td><code>gtpu.pt</code></td><td>string</td><td>true</td></tr>
<tr><td>gtpu</td><td><code>gtpu.restartCounter</code></td><td>numeric</td><td>true</td></tr>
<tr><td>gtpu</td><td><code>gtpu.sequenceNumber</code></td><td>string</td><td>true</td></tr>
<tr><td>gtpu</td><td><code>gtpu.teid</code></td><td>string</td><td>true</td></tr>
<tr><td>gtpu</td><td><code>gtpu.version</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
</tbody>
<tbody>
</tbody>
<tbody>
<tr><td>h323</td><td><code>h323.causeCode</code></td><td>string</td><td>true</td></tr>
<tr><td>h323</td><td><code>h323.causeDescription</code></td><td>string</td><td>true</td></tr>
<tr><td>h323</td><td><code>h323.messageType</code></td><td>string</td><td>true</td></tr>
<tr><td>h323</td><td><code>h323.product</code></td><td>string</td><td>true</td></tr>
<tr><td>h323</td><td><code>h323.vendor</code></td><td>string</td><td>true</td></tr>
<tr><td>h323</td><td><code>h323.version</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>hartip</td><td><code>hartip.inactivityTimeout</code></td><td>string</td><td>true</td></tr>
<tr><td>hartip</td><td><code>hartip.masterType</code></td><td>string</td><td>true</td></tr>
<tr><td>hartip</td><td><code>hartip.messageType</code></td><td>string</td><td>true</td></tr>
<tr><td>hartip</td><td><code>hartip.status</code></td><td>string</td><td>true</td></tr>
<tr><td>hartip</td><td><code>hartip.statusDescription</code></td><td>string</td><td>true</td></tr>
<tr><td>hartip</td><td><code>hartip.transactionID</code></td><td>string</td><td>true</td></tr>
<tr><td>hartip</td><td><code>hartip.version</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
</tbody>
<tbody>
<tr><td>hiddiscoveryd</td><td><code>hiddiscoveryd.address</code></td><td>string</td><td>true</td></tr>
<tr><td>hiddiscoveryd</td><td><code>hiddiscoveryd.hostname</code></td><td>string</td><td>true</td></tr>
<tr><td>hiddiscoveryd</td><td><code>hiddiscoveryd.mac</code></td><td>string</td><td>true</td></tr>
<tr><td>hiddiscoveryd</td><td><code>hiddiscoveryd.model</code></td><td>string</td><td>true</td></tr>
<tr><td>hiddiscoveryd</td><td><code>hiddiscoveryd.unpatchedVertXploit</code></td><td>string</td><td>true</td></tr>
<tr><td>hiddiscoveryd</td><td><code>hiddiscoveryd.version</code></td><td>string</td><td>true</td></tr>
<tr><td>hiddiscoveryd</td><td><code>hiddiscoveryd.versionDate</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>hikvision</td><td><code>hikvision.codebase.lastModified</code></td><td>string</td><td>true</td></tr>
<tr><td>hikvision</td><td><code>hikvision.codebase.platform</code></td><td>string</td><td>true</td></tr>
<tr><td>hikvision</td><td><code>hikvision.codebase.plugins</code></td><td>string</td><td>false</td></tr>
<tr><td>hikvision</td><td><code>hikvision.deviceCode</code></td><td>string</td><td>true</td></tr>
<tr><td>hikvision</td><td><code>hikvision.deviceType</code></td><td>string</td><td>true</td></tr>
<tr><td>hikvision</td><td><code>hikvision.firmwareVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>hikvision</td><td><code>hikvision.firmwareVersionEmbedded</code></td><td>string</td><td>true</td></tr>
<tr><td>hikvision</td><td><code>hikvision.loginPageLastModified</code></td><td>string</td><td>true</td></tr>
<tr><td>hikvision</td><td><code>hikvision.modelFamily</code></td><td>string</td><td>true</td></tr>
<tr><td>hikvision</td><td><code>hikvision.pluginVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>hikvision</td><td><code>hikvision.realm</code></td><td>string</td><td>true</td></tr>
<tr><td>hikvision</td><td><code>hikvision.webVersion</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
</tbody>
<tbody>
</tbody>
<tbody>
<tr><td>http</td><td><code>html.copyright</code></td><td>string</td><td>true</td></tr>
<tr><td>http</td><td><code>html.favicon</code></td><td>string</td><td>true</td></tr>
<tr><td>http</td><td><code>html.generator</code></td><td>string</td><td>true</td></tr>
<tr><td>http</td><td><code>html.title</code></td><td>string</td><td>true</td></tr>
<tr><td>http</td><td><code>http.body</code></td><td>numeric</td><td>true</td></tr>
<tr><td>http</td><td><code>http.body.mmh3</code></td><td>string</td><td>true</td></tr>
<tr><td>http</td><td><code>http.code</code></td><td>numeric</td><td>true</td></tr>
<tr><td>http</td><td><code>http.contentLength</code></td><td>string</td><td>true</td></tr>
<tr><td>http</td><td><code>http.contentType</code></td><td>string</td><td>true</td></tr>
<tr><td>http</td><td><code>http.head.acceptRanges</code></td><td>string</td><td>true</td></tr>
<tr><td>http</td><td><code>http.head.cacheControl</code></td><td>string</td><td>true</td></tr>
<tr><td>http</td><td><code>http.head.contentLength</code></td><td>numeric</td><td>true</td></tr>
<tr><td>http</td><td><code>http.head.contentSecurityPolicy</code></td><td>string</td><td>true</td></tr>
<tr><td>http</td><td><code>http.head.contentType</code></td><td>string</td><td>true</td></tr>
<tr><td>http</td><td><code>http.head.cookieNames</code></td><td>string</td><td>true</td></tr>
<tr><td>http</td><td><code>http.head.date</code></td><td>string</td><td>true</td></tr>
<tr><td>http</td><td><code>http.head.etag</code></td><td>string</td><td>true</td></tr>
<tr><td>http</td><td><code>http.head.expires</code></td><td>string</td><td>true</td></tr>
<tr><td>http</td><td><code>http.head.faviconPath</code></td><td>string</td><td>true</td></tr>
<tr><td>http</td><td><code>http.head.lastModified</code></td><td>string</td><td>true</td></tr>
<tr><td>http</td><td><code>http.head.location</code></td><td>string</td><td>true</td></tr>
<tr><td>http</td><td><code>http.head.microsoftsharepointteamservices</code></td><td>string</td><td>true</td></tr>
<tr><td>http</td><td><code>http.head.server</code></td><td>string</td><td>true</td></tr>
<tr><td>http</td><td><code>http.head.setCookie</code></td><td>string</td><td>true</td></tr>
<tr><td>http</td><td><code>http.head.spiislatency</code></td><td>string</td><td>true</td></tr>
<tr><td>http</td><td><code>http.head.vary</code></td><td>string</td><td>true</td></tr>
<tr><td>http</td><td><code>http.head.wwwAuthenticate</code></td><td>string</td><td>true</td></tr>
<tr><td>http</td><td><code>http.head.xConfluenceRequestTime</code></td><td>string</td><td>true</td></tr>
<tr><td>http</td><td><code>http.head.xInfluxdbBuild</code></td><td>string</td><td>true</td></tr>
<tr><td>http</td><td><code>http.head.xInfluxdbVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>http</td><td><code>http.head.xJenkins</code></td><td>string</td><td>true</td></tr>
<tr><td>http</td><td><code>http.head.xNtnxEnv</code></td><td>string</td><td>true</td></tr>
<tr><td>http</td><td><code>http.head.xOracleDmsEcid</code></td><td>string</td><td>true</td></tr>
<tr><td>http</td><td><code>http.head.xOracleDmsRid</code></td><td>string</td><td>true</td></tr>
<tr><td>http</td><td><code>http.head.xPoweredBy</code></td><td>string</td><td>true</td></tr>
<tr><td>http</td><td><code>http.head.xSharepointhealthscore</code></td><td>string</td><td>true</td></tr>
<tr><td>http</td><td><code>http.head.xconfluencerequesttime</code></td><td>string</td><td>true</td></tr>
<tr><td>http</td><td><code>http.head.xframeoptions</code></td><td>string</td><td>true</td></tr>
<tr><td>http</td><td><code>http.location</code></td><td>string</td><td>true</td></tr>
<tr><td>http</td><td><code>http.message</code></td><td>string</td><td>true</td></tr>
<tr><td>http</td><td><code>http.method</code></td><td>string</td><td>true</td></tr>
<tr><td>http</td><td><code>http.ntlm.challenge</code></td><td>string</td><td>true</td></tr>
<tr><td>http</td><td><code>http.ntlm.path</code></td><td>string</td><td>true</td></tr>
<tr><td>http</td><td><code>http.owa.version</code></td><td>string</td><td>true</td></tr>
<tr><td>http</td><td><code>http.owa.version.full</code></td><td>string</td><td>true</td></tr>
<tr><td>http</td><td><code>http.path</code></td><td>string</td><td>true</td></tr>
<tr><td>http</td><td><code>http.port</code></td><td>numeric</td><td>true</td></tr>
<tr><td>http</td><td><code>http.server</code></td><td>string</td><td>true</td></tr>
<tr><td>http</td><td><code>http.setCookie</code></td><td>string</td><td>true</td></tr>
<tr><td>http</td><td><code>http.sonicwall.hardware</code></td><td>string</td><td>true</td></tr>
<tr><td>http</td><td><code>http.sonicwall.softwareVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>http</td><td><code>http.status</code></td><td>string</td><td>true</td></tr>
<tr><td>http</td><td><code>http.statusCode</code></td><td>string</td><td>true</td></tr>
<tr><td>http</td><td><code>http.target</code></td><td>string</td><td>true</td></tr>
<tr><td>http</td><td><code>http.technologies</code></td><td>string</td><td>true</td></tr>
<tr><td>http</td><td><code>http.title</code></td><td>string</td><td>true</td></tr>
<tr><td>http</td><td><code>http.uri</code></td><td>string</td><td>true</td></tr>
<tr><td>http</td><td><code>http.url</code></td><td>string</td><td>true</td></tr>
<tr><td>http</td><td><code>http.version</code></td><td>string</td><td>true</td></tr>
<tr><td>http</td><td><code>http.vmware.thumbprint</code></td><td>string</td><td>true</td></tr>
<tr><td>http</td><td><code>http.vmware.username</code></td><td>string</td><td>true</td></tr>
<tr><td>http</td><td><code>landesk.configPath</code></td><td>string</td><td>true</td></tr>
<tr><td>http</td><td><code>landesk.providerVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>http</td><td><code>landesk.serverVersion</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
</tbody>
<tbody>
</tbody>
<tbody>
<tr><td>iax2</td><td><code>iax2.destCallNumber</code></td><td>string</td><td>true</td></tr>
<tr><td>iax2</td><td><code>iax2.detected</code></td><td>boolean</td><td>true</td></tr>
<tr><td>iax2</td><td><code>iax2.iseqno</code></td><td>string</td><td>true</td></tr>
<tr><td>iax2</td><td><code>iax2.oseqno</code></td><td>string</td><td>true</td></tr>
<tr><td>iax2</td><td><code>iax2.response</code></td><td>string</td><td>true</td></tr>
<tr><td>iax2</td><td><code>iax2.sourceCallNumber</code></td><td>string</td><td>true</td></tr>
<tr><td>iax2</td><td><code>iax2.subclass</code></td><td>string</td><td>true</td></tr>
<tr><td>iax2</td><td><code>iax2.subclassName</code></td><td>string</td><td>true</td></tr>
<tr><td>iax2</td><td><code>iax2.ts</code></td><td>numeric</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>icmp</td><td><code>icmp.addrs</code></td><td>string</td><td>true</td></tr>
<tr><td>icmp</td><td><code>icmp.rtts</code></td><td>string</td><td>true</td></tr>
<tr><td>icmp</td><td><code>icmp.typeCode</code></td><td>string</td><td>true</td></tr>
<tr><td>icmp</td><td><code>icmp.typeCodeN</code></td><td>string</td><td>true</td></tr>
<tr><td>icmp</td><td><code>icmp6.addrs</code></td><td>string</td><td>true</td></tr>
<tr><td>icmp</td><td><code>icmp6.rtts</code></td><td>string</td><td>true</td></tr>
<tr><td>icmp</td><td><code>ip.tos</code></td><td>string</td><td>false</td></tr>
<tr><td>icmp</td><td><code>ip.ttl</code></td><td>string</td><td>false</td></tr>
</tbody>
<tbody>
</tbody>
<tbody>
<tr><td>ident</td><td><code>ident.error</code></td><td>string</td><td>true</td></tr>
<tr><td>ident</td><td><code>ident.opSys</code></td><td>string</td><td>true</td></tr>
<tr><td>ident</td><td><code>ident.osGuess</code></td><td>string</td><td>true</td></tr>
<tr><td>ident</td><td><code>ident.username</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>idrac</td><td><code>idrac.adEnabled</code></td><td>boolean</td><td>true</td></tr>
<tr><td>idrac</td><td><code>idrac.fwVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>idrac</td><td><code>idrac.gui.titleBar</code></td><td>string</td><td>true</td></tr>
<tr><td>idrac</td><td><code>idrac.hostname</code></td><td>string</td><td>true</td></tr>
<tr><td>idrac</td><td><code>idrac.isOEMBranded</code></td><td>boolean</td><td>true</td></tr>
<tr><td>idrac</td><td><code>idrac.license</code></td><td>string</td><td>true</td></tr>
<tr><td>idrac</td><td><code>idrac.name</code></td><td>string</td><td>true</td></tr>
<tr><td>idrac</td><td><code>idrac.oem.hostname</code></td><td>string</td><td>true</td></tr>
<tr><td>idrac</td><td><code>idrac.serverGen</code></td><td>string</td><td>true</td></tr>
<tr><td>idrac</td><td><code>idrac.ssoEnabled</code></td><td>boolean</td><td>true</td></tr>
<tr><td>idrac</td><td><code>idrac.status</code></td><td>string</td><td>true</td></tr>
<tr><td>idrac</td><td><code>idrac.sysDesc</code></td><td>string</td><td>true</td></tr>
<tr><td>idrac</td><td><code>idrac.systemLockdown</code></td><td>string</td><td>true</td></tr>
<tr><td>idrac</td><td><code>idrac.systemModelName</code></td><td>string</td><td>true</td></tr>
<tr><td>idrac</td><td><code>idrac.tfaEnabled</code></td><td>boolean</td><td>true</td></tr>
<tr><td>idrac</td><td><code>idrac.version</code></td><td>string</td><td>true</td></tr>
<tr><td>idrac</td><td><code>service.product</code></td><td>string</td><td>true</td></tr>
<tr><td>idrac</td><td><code>service.vendor</code></td><td>string</td><td>true</td></tr>
<tr><td>idrac</td><td><code>service.version</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>iec104</td><td><code>iec104.asduCOT</code></td><td>string</td><td>true</td></tr>
<tr><td>iec104</td><td><code>iec104.asduCommonAddr</code></td><td>string</td><td>true</td></tr>
<tr><td>iec104</td><td><code>iec104.asduCommonAddrs</code></td><td>string</td><td>true</td></tr>
<tr><td>iec104</td><td><code>iec104.asduInfoObjAddr</code></td><td>string</td><td>true</td></tr>
<tr><td>iec104</td><td><code>iec104.asduNegative</code></td><td>string</td><td>true</td></tr>
<tr><td>iec104</td><td><code>iec104.asduTest</code></td><td>string</td><td>true</td></tr>
<tr><td>iec104</td><td><code>iec104.asduTypes</code></td><td>string</td><td>true</td></tr>
<tr><td>iec104</td><td><code>iec104.command</code></td><td>string</td><td>true</td></tr>
<tr><td>iec104</td><td><code>iec104.commands</code></td><td>string</td><td>true</td></tr>
<tr><td>iec104</td><td><code>iec104.frameCount</code></td><td>numeric</td><td>true</td></tr>
<tr><td>iec104</td><td><code>iec104.frameType</code></td><td>string</td><td>true</td></tr>
<tr><td>iec104</td><td><code>iec104.frameTypes</code></td><td>string</td><td>true</td></tr>
<tr><td>iec104</td><td><code>iec104.initCause</code></td><td>string</td><td>true</td></tr>
<tr><td>iec104</td><td><code>iec104.initLocalFlag</code></td><td>string</td><td>true</td></tr>
<tr><td>iec104</td><td><code>iec104.startDTConfirmed</code></td><td>string</td><td>true</td></tr>
<tr><td>iec104</td><td><code>iec104.testFRConfirmed</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
</tbody>
<tbody>
</tbody>
<tbody>
</tbody>
<tbody>
</tbody>
<tbody>
<tr><td>igel-discovery</td><td><code>igel.firmwareVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>igel-discovery</td><td><code>igel.hostname</code></td><td>string</td><td>true</td></tr>
<tr><td>igel-discovery</td><td><code>igel.ipAddress</code></td><td>string</td><td>true</td></tr>
<tr><td>igel-discovery</td><td><code>igel.macAddress</code></td><td>string</td><td>true</td></tr>
<tr><td>igel-discovery</td><td><code>igel.osType</code></td><td>string</td><td>true</td></tr>
<tr><td>igel-discovery</td><td><code>igel.productID</code></td><td>string</td><td>true</td></tr>
<tr><td>igel-discovery</td><td><code>igel.productName</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>iis</td><td><code>http.owa.version</code></td><td>string</td><td>true</td></tr>
<tr><td>iis</td><td><code>http.owa.version.full</code></td><td>string</td><td>true</td></tr>
<tr><td>iis</td><td><code>rdg.authScheme</code></td><td>string</td><td>true</td></tr>
<tr><td>iis</td><td><code>rdg.transport</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>ike</td><td><code>ike.authMethod</code></td><td>string</td><td>true</td></tr>
<tr><td>ike</td><td><code>ike.dhGroup</code></td><td>string</td><td>true</td></tr>
<tr><td>ike</td><td><code>ike.encryptionAlgo</code></td><td>string</td><td>true</td></tr>
<tr><td>ike</td><td><code>ike.esn</code></td><td>string</td><td>true</td></tr>
<tr><td>ike</td><td><code>ike.exchangeType</code></td><td>string</td><td>true</td></tr>
<tr><td>ike</td><td><code>ike.flags</code></td><td>string</td><td>true</td></tr>
<tr><td>ike</td><td><code>ike.hashAlgo</code></td><td>string</td><td>true</td></tr>
<tr><td>ike</td><td><code>ike.initiatorSPI</code></td><td>string</td><td>true</td></tr>
<tr><td>ike</td><td><code>ike.integrityAlgo</code></td><td>string</td><td>true</td></tr>
<tr><td>ike</td><td><code>ike.keyLength</code></td><td>string</td><td>true</td></tr>
<tr><td>ike</td><td><code>ike.lifeDuration</code></td><td>string</td><td>true</td></tr>
<tr><td>ike</td><td><code>ike.lifeType</code></td><td>string</td><td>true</td></tr>
<tr><td>ike</td><td><code>ike.messageID</code></td><td>string</td><td>true</td></tr>
<tr><td>ike</td><td><code>ike.messageLength</code></td><td>string</td><td>true</td></tr>
<tr><td>ike</td><td><code>ike.nextPayload</code></td><td>string</td><td>true</td></tr>
<tr><td>ike</td><td><code>ike.nonESPMarker</code></td><td>string</td><td>true</td></tr>
<tr><td>ike</td><td><code>ike.notifyTypes</code></td><td>string</td><td>true</td></tr>
<tr><td>ike</td><td><code>ike.payload</code></td><td>string</td><td>true</td></tr>
<tr><td>ike</td><td><code>ike.payloadCount</code></td><td>numeric</td><td>true</td></tr>
<tr><td>ike</td><td><code>ike.prfAlgo</code></td><td>string</td><td>true</td></tr>
<tr><td>ike</td><td><code>ike.reply</code></td><td>string</td><td>true</td></tr>
<tr><td>ike</td><td><code>ike.responderSPI</code></td><td>string</td><td>true</td></tr>
<tr><td>ike</td><td><code>ike.saProtocol</code></td><td>string</td><td>true</td></tr>
<tr><td>ike</td><td><code>ike.sha1</code></td><td>string</td><td>true</td></tr>
<tr><td>ike</td><td><code>ike.vendorID</code></td><td>string</td><td>true</td></tr>
<tr><td>ike</td><td><code>ike.vendorIDCount</code></td><td>numeric</td><td>true</td></tr>
<tr><td>ike</td><td><code>ike.version</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
</tbody>
<tbody>
<tr><td>imap</td><td><code>imap.authMethods</code></td><td>string</td><td>true</td></tr>
<tr><td>imap</td><td><code>imap.authPlain</code></td><td>string</td><td>true</td></tr>
<tr><td>imap</td><td><code>imap.banner</code></td><td>string</td><td>true</td></tr>
<tr><td>imap</td><td><code>imap.capabilities</code></td><td>string</td><td>true</td></tr>
<tr><td>imap</td><td><code>imap.capabilityCount</code></td><td>numeric</td><td>true</td></tr>
<tr><td>imap</td><td><code>imap.capabilityStatus</code></td><td>string</td><td>true</td></tr>
<tr><td>imap</td><td><code>imap.capabilityText</code></td><td>string</td><td>true</td></tr>
<tr><td>imap</td><td><code>imap.greeting</code></td><td>string</td><td>true</td></tr>
<tr><td>imap</td><td><code>imap.greetingText</code></td><td>string</td><td>true</td></tr>
<tr><td>imap</td><td><code>imap.loginDisabled</code></td><td>string</td><td>true</td></tr>
<tr><td>imap</td><td><code>imap.product</code></td><td>string</td><td>true</td></tr>
<tr><td>imap</td><td><code>imap.responseCode</code></td><td>string</td><td>true</td></tr>
<tr><td>imap</td><td><code>imap.revision</code></td><td>string</td><td>true</td></tr>
<tr><td>imap</td><td><code>imap.startTLS</code></td><td>string</td><td>true</td></tr>
<tr><td>imap</td><td><code>imap.vendor</code></td><td>string</td><td>true</td></tr>
<tr><td>imap</td><td><code>imap.version</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
</tbody>
<tbody>
<tr><td>influxdb</td><td><code>influxdb.build</code></td><td>string</td><td>true</td></tr>
<tr><td>influxdb</td><td><code>influxdb.databases</code></td><td>string</td><td>false</td></tr>
<tr><td>influxdb</td><td><code>influxdb.version</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
</tbody>
<tbody>
<tr><td>ipmi</td><td><code>ipmi.additionalSupport</code></td><td>numeric</td><td>true</td></tr>
<tr><td>ipmi</td><td><code>ipmi.additionalSupportRaw</code></td><td>numeric</td><td>true</td></tr>
<tr><td>ipmi</td><td><code>ipmi.authTypes</code></td><td>string</td><td>true</td></tr>
<tr><td>ipmi</td><td><code>ipmi.auxFirmwareRev</code></td><td>string</td><td>true</td></tr>
<tr><td>ipmi</td><td><code>ipmi.channel</code></td><td>string</td><td>true</td></tr>
<tr><td>ipmi</td><td><code>ipmi.cipherSuites</code></td><td>string</td><td>true</td></tr>
<tr><td>ipmi</td><td><code>ipmi.cipherSuitesRaw</code></td><td>string</td><td>true</td></tr>
<tr><td>ipmi</td><td><code>ipmi.cipherSuitesText</code></td><td>string</td><td>true</td></tr>
<tr><td>ipmi</td><td><code>ipmi.cipherZero</code></td><td>string</td><td>true</td></tr>
<tr><td>ipmi</td><td><code>ipmi.ciphers</code></td><td>string</td><td>true</td></tr>
<tr><td>ipmi</td><td><code>ipmi.ciphersPageError</code></td><td>string</td><td>true</td></tr>
<tr><td>ipmi</td><td><code>ipmi.ciphersRaw</code></td><td>string</td><td>true</td></tr>
<tr><td>ipmi</td><td><code>ipmi.command</code></td><td>string</td><td>true</td></tr>
<tr><td>ipmi</td><td><code>ipmi.completionCode</code></td><td>string</td><td>true</td></tr>
<tr><td>ipmi</td><td><code>ipmi.completionCodeDec</code></td><td>string</td><td>true</td></tr>
<tr><td>ipmi</td><td><code>ipmi.connVersions</code></td><td>string</td><td>true</td></tr>
<tr><td>ipmi</td><td><code>ipmi.connVersionsRaw</code></td><td>string</td><td>true</td></tr>
<tr><td>ipmi</td><td><code>ipmi.deviceID</code></td><td>string</td><td>true</td></tr>
<tr><td>ipmi</td><td><code>ipmi.deviceRevision</code></td><td>string</td><td>true</td></tr>
<tr><td>ipmi</td><td><code>ipmi.deviceRevisionRaw</code></td><td>string</td><td>true</td></tr>
<tr><td>ipmi</td><td><code>ipmi.errors</code></td><td>string</td><td>true</td></tr>
<tr><td>ipmi</td><td><code>ipmi.fakeUsername</code></td><td>string</td><td>true</td></tr>
<tr><td>ipmi</td><td><code>ipmi.firmware</code></td><td>string</td><td>true</td></tr>
<tr><td>ipmi</td><td><code>ipmi.firmwareRevision</code></td><td>string</td><td>true</td></tr>
<tr><td>ipmi</td><td><code>ipmi.ipmiVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>ipmi</td><td><code>ipmi.manufacturer</code></td><td>string</td><td>true</td></tr>
<tr><td>ipmi</td><td><code>ipmi.manufacturerID</code></td><td>string</td><td>true</td></tr>
<tr><td>ipmi</td><td><code>ipmi.manufacturerName</code></td><td>string</td><td>true</td></tr>
<tr><td>ipmi</td><td><code>ipmi.oemData</code></td><td>string</td><td>true</td></tr>
<tr><td>ipmi</td><td><code>ipmi.oemID</code></td><td>string</td><td>true</td></tr>
<tr><td>ipmi</td><td><code>ipmi.oemName</code></td><td>string</td><td>true</td></tr>
<tr><td>ipmi</td><td><code>ipmi.passAuth</code></td><td>string</td><td>true</td></tr>
<tr><td>ipmi</td><td><code>ipmi.passAuthRaw</code></td><td>string</td><td>true</td></tr>
<tr><td>ipmi</td><td><code>ipmi.port</code></td><td>numeric</td><td>true</td></tr>
<tr><td>ipmi</td><td><code>ipmi.productID</code></td><td>string</td><td>true</td></tr>
<tr><td>ipmi</td><td><code>ipmi.rakp.authCiphers</code></td><td>string</td><td>true</td></tr>
<tr><td>ipmi</td><td><code>ipmi.rakp.ciphers</code></td><td>string</td><td>true</td></tr>
<tr><td>ipmi</td><td><code>ipmi.rakp.count</code></td><td>numeric</td><td>true</td></tr>
<tr><td>ipmi</td><td><code>ipmi.rakp.cracked</code></td><td>string</td><td>true</td></tr>
<tr><td>ipmi</td><td><code>ipmi.rakp.crackedCount</code></td><td>numeric</td><td>true</td></tr>
<tr><td>ipmi</td><td><code>ipmi.rakp.guids</code></td><td>string</td><td>true</td></tr>
<tr><td>ipmi</td><td><code>ipmi.rakp.hashes</code></td><td>string</td><td>true</td></tr>
<tr><td>ipmi</td><td><code>ipmi.rakp.passwords</code></td><td>string</td><td>true</td></tr>
<tr><td>ipmi</td><td><code>ipmi.rakp.sessionIDs</code></td><td>string</td><td>true</td></tr>
<tr><td>ipmi</td><td><code>ipmi.rakp.usernames</code></td><td>string</td><td>true</td></tr>
<tr><td>ipmi</td><td><code>ipmi.response.commandMismatch</code></td><td>string</td><td>true</td></tr>
<tr><td>ipmi</td><td><code>ipmi.response.data</code></td><td>string</td><td>true</td></tr>
<tr><td>ipmi</td><td><code>ipmi.response.dataLen</code></td><td>string</td><td>true</td></tr>
<tr><td>ipmi</td><td><code>ipmi.response.parseError</code></td><td>string</td><td>true</td></tr>
<tr><td>ipmi</td><td><code>ipmi.response.raw</code></td><td>string</td><td>true</td></tr>
<tr><td>ipmi</td><td><code>ipmi.response.text</code></td><td>string</td><td>true</td></tr>
<tr><td>ipmi</td><td><code>ipmi.rmcpPlus</code></td><td>string</td><td>true</td></tr>
<tr><td>ipmi</td><td><code>ipmi.session.ID</code></td><td>string</td><td>true</td></tr>
<tr><td>ipmi</td><td><code>ipmi.session.activateAuthType</code></td><td>string</td><td>true</td></tr>
<tr><td>ipmi</td><td><code>ipmi.session.activateAuthTypeName</code></td><td>string</td><td>true</td></tr>
<tr><td>ipmi</td><td><code>ipmi.session.activateID</code></td><td>string</td><td>true</td></tr>
<tr><td>ipmi</td><td><code>ipmi.session.activateInboundSeq</code></td><td>string</td><td>true</td></tr>
<tr><td>ipmi</td><td><code>ipmi.session.activateMaxPriv</code></td><td>string</td><td>true</td></tr>
<tr><td>ipmi</td><td><code>ipmi.session.activateMaxPrivName</code></td><td>string</td><td>true</td></tr>
<tr><td>ipmi</td><td><code>ipmi.session.activateStatus</code></td><td>string</td><td>true</td></tr>
<tr><td>ipmi</td><td><code>ipmi.session.challenge</code></td><td>string</td><td>true</td></tr>
<tr><td>ipmi</td><td><code>ipmi.session.challengeAuthType</code></td><td>string</td><td>true</td></tr>
<tr><td>ipmi</td><td><code>ipmi.session.challengeAuthTypeName</code></td><td>string</td><td>true</td></tr>
<tr><td>ipmi</td><td><code>ipmi.session.challengeID</code></td><td>string</td><td>true</td></tr>
<tr><td>ipmi</td><td><code>ipmi.session.challengeStatus</code></td><td>string</td><td>true</td></tr>
<tr><td>ipmi</td><td><code>ipmi.session.consoleID</code></td><td>string</td><td>true</td></tr>
<tr><td>ipmi</td><td><code>ipmi.session.status</code></td><td>string</td><td>true</td></tr>
<tr><td>ipmi</td><td><code>ipmi.session.statusCode</code></td><td>string</td><td>true</td></tr>
<tr><td>ipmi</td><td><code>ipmi.session.username</code></td><td>string</td><td>true</td></tr>
<tr><td>ipmi</td><td><code>ipmi.srcAddr</code></td><td>string</td><td>true</td></tr>
<tr><td>ipmi</td><td><code>ipmi.srcLun</code></td><td>string</td><td>true</td></tr>
<tr><td>ipmi</td><td><code>ipmi.system.guid</code></td><td>string</td><td>true</td></tr>
<tr><td>ipmi</td><td><code>ipmi.system.guidText</code></td><td>string</td><td>true</td></tr>
<tr><td>ipmi</td><td><code>ipmi.systemGUID</code></td><td>string</td><td>true</td></tr>
<tr><td>ipmi</td><td><code>ipmi.target</code></td><td>string</td><td>true</td></tr>
<tr><td>ipmi</td><td><code>ipmi.tgtAddr</code></td><td>string</td><td>true</td></tr>
<tr><td>ipmi</td><td><code>ipmi.tgtLun</code></td><td>string</td><td>true</td></tr>
<tr><td>ipmi</td><td><code>ipmi.userAuth</code></td><td>string</td><td>true</td></tr>
<tr><td>ipmi</td><td><code>ipmi.userAuthRaw</code></td><td>string</td><td>true</td></tr>
<tr><td>ipmi</td><td><code>ipmi.v2.0</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>ipp</td><td><code>ipp.firmwareVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>ipp</td><td><code>ipp.ippVersions</code></td><td>string</td><td>true</td></tr>
<tr><td>ipp</td><td><code>ipp.printerMakeAndModel</code></td><td>string</td><td>true</td></tr>
<tr><td>ipp</td><td><code>ipp.printerName</code></td><td>string</td><td>true</td></tr>
<tr><td>ipp</td><td><code>ipp.printerState</code></td><td>string</td><td>true</td></tr>
<tr><td>ipp</td><td><code>ipp.printerURI</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
</tbody>
<tbody>
<tr><td>ippbrowse</td><td><code>ippbrowse.info</code></td><td>string</td><td>true</td></tr>
<tr><td>ippbrowse</td><td><code>ippbrowse.location</code></td><td>string</td><td>true</td></tr>
<tr><td>ippbrowse</td><td><code>ippbrowse.makeModel</code></td><td>string</td><td>true</td></tr>
<tr><td>ippbrowse</td><td><code>ippbrowse.state</code></td><td>string</td><td>true</td></tr>
<tr><td>ippbrowse</td><td><code>ippbrowse.type</code></td><td>string</td><td>true</td></tr>
<tr><td>ippbrowse</td><td><code>ippbrowse.uri</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>ipsec</td><td><code>ipsec.aggressiveMode</code></td><td>string</td><td>true</td></tr>
<tr><td>ipsec</td><td><code>ipsec.authenticationOnly</code></td><td>string</td><td>true</td></tr>
<tr><td>ipsec</td><td><code>ipsec.commit</code></td><td>string</td><td>true</td></tr>
<tr><td>ipsec</td><td><code>ipsec.encrypted</code></td><td>string</td><td>true</td></tr>
<tr><td>ipsec</td><td><code>ipsec.exchangeType</code></td><td>string</td><td>true</td></tr>
<tr><td>ipsec</td><td><code>ipsec.exchangeTypeID</code></td><td>string</td><td>true</td></tr>
<tr><td>ipsec</td><td><code>ipsec.flags</code></td><td>string</td><td>true</td></tr>
<tr><td>ipsec</td><td><code>ipsec.flagsRaw</code></td><td>string</td><td>true</td></tr>
<tr><td>ipsec</td><td><code>ipsec.initiatorSPI</code></td><td>string</td><td>true</td></tr>
<tr><td>ipsec</td><td><code>ipsec.messageID</code></td><td>string</td><td>true</td></tr>
<tr><td>ipsec</td><td><code>ipsec.messageLength</code></td><td>string</td><td>true</td></tr>
<tr><td>ipsec</td><td><code>ipsec.nextPayload</code></td><td>string</td><td>true</td></tr>
<tr><td>ipsec</td><td><code>ipsec.nextPayloadID</code></td><td>string</td><td>true</td></tr>
<tr><td>ipsec</td><td><code>ipsec.payloadCount</code></td><td>numeric</td><td>true</td></tr>
<tr><td>ipsec</td><td><code>ipsec.payloads</code></td><td>string</td><td>true</td></tr>
<tr><td>ipsec</td><td><code>ipsec.port</code></td><td>numeric</td><td>true</td></tr>
<tr><td>ipsec</td><td><code>ipsec.responderSPI</code></td><td>string</td><td>true</td></tr>
<tr><td>ipsec</td><td><code>ipsec.target</code></td><td>string</td><td>true</td></tr>
<tr><td>ipsec</td><td><code>ipsec.vendorIDCount</code></td><td>numeric</td><td>true</td></tr>
<tr><td>ipsec</td><td><code>ipsec.vendorIDs</code></td><td>string</td><td>true</td></tr>
<tr><td>ipsec</td><td><code>ipsec.version</code></td><td>string</td><td>true</td></tr>
<tr><td>ipsec</td><td><code>ipsec.versionRaw</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>irc</td><td><code>irc.banner</code></td><td>string</td><td>true</td></tr>
<tr><td>irc</td><td><code>irc.channelCount</code></td><td>numeric</td><td>true</td></tr>
<tr><td>irc</td><td><code>irc.channelModes</code></td><td>string</td><td>true</td></tr>
<tr><td>irc</td><td><code>irc.core.sim</code></td><td>string</td><td>true</td></tr>
<tr><td>irc</td><td><code>irc.cpe23</code></td><td>string</td><td>true</td></tr>
<tr><td>irc</td><td><code>irc.createdDate</code></td><td>string</td><td>true</td></tr>
<tr><td>irc</td><td><code>irc.error</code></td><td>string</td><td>true</td></tr>
<tr><td>irc</td><td><code>irc.example.net</code></td><td>string</td><td>true</td></tr>
<tr><td>irc</td><td><code>irc.networkName</code></td><td>string</td><td>true</td></tr>
<tr><td>irc</td><td><code>irc.product</code></td><td>string</td><td>true</td></tr>
<tr><td>irc</td><td><code>irc.serverName</code></td><td>string</td><td>true</td></tr>
<tr><td>irc</td><td><code>irc.serverSoftware</code></td><td>string</td><td>true</td></tr>
<tr><td>irc</td><td><code>irc.userCount</code></td><td>numeric</td><td>true</td></tr>
<tr><td>irc</td><td><code>irc.userModes</code></td><td>string</td><td>true</td></tr>
<tr><td>irc</td><td><code>irc.vendor</code></td><td>string</td><td>true</td></tr>
<tr><td>irc</td><td><code>irc.version</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>iscsi</td><td><code>iscsi.acknowledge</code></td><td>string</td><td>true</td></tr>
<tr><td>iscsi</td><td><code>iscsi.authMethod</code></td><td>string</td><td>true</td></tr>
<tr><td>iscsi</td><td><code>iscsi.bidiReadResidualCount</code></td><td>numeric</td><td>true</td></tr>
<tr><td>iscsi</td><td><code>iscsi.bufferOffset</code></td><td>string</td><td>true</td></tr>
<tr><td>iscsi</td><td><code>iscsi.continue</code></td><td>string</td><td>true</td></tr>
<tr><td>iscsi</td><td><code>iscsi.currentStage</code></td><td>string</td><td>true</td></tr>
<tr><td>iscsi</td><td><code>iscsi.dataDigest</code></td><td>string</td><td>true</td></tr>
<tr><td>iscsi</td><td><code>iscsi.dataSN</code></td><td>string</td><td>true</td></tr>
<tr><td>iscsi</td><td><code>iscsi.expCmdSN</code></td><td>string</td><td>true</td></tr>
<tr><td>iscsi</td><td><code>iscsi.expDataSN</code></td><td>string</td><td>true</td></tr>
<tr><td>iscsi</td><td><code>iscsi.final</code></td><td>string</td><td>true</td></tr>
<tr><td>iscsi</td><td><code>iscsi.flags.readResidualOverflow</code></td><td>string</td><td>true</td></tr>
<tr><td>iscsi</td><td><code>iscsi.flags.readResidualUnderflow</code></td><td>string</td><td>true</td></tr>
<tr><td>iscsi</td><td><code>iscsi.flags.residualOverflow</code></td><td>string</td><td>true</td></tr>
<tr><td>iscsi</td><td><code>iscsi.flags.residualUnderflow</code></td><td>string</td><td>true</td></tr>
<tr><td>iscsi</td><td><code>iscsi.flags.status</code></td><td>string</td><td>true</td></tr>
<tr><td>iscsi</td><td><code>iscsi.headerDigest</code></td><td>string</td><td>true</td></tr>
<tr><td>iscsi</td><td><code>iscsi.immediateDelivery</code></td><td>string</td><td>true</td></tr>
<tr><td>iscsi</td><td><code>iscsi.initiatorTaskTag</code></td><td>string</td><td>true</td></tr>
<tr><td>iscsi</td><td><code>iscsi.isid</code></td><td>string</td><td>true</td></tr>
<tr><td>iscsi</td><td><code>iscsi.keyvalue.MaxRecvDataSegmentLength</code></td><td>string</td><td>true</td></tr>
<tr><td>iscsi</td><td><code>iscsi.keyvalue.authMethod</code></td><td>string</td><td>true</td></tr>
<tr><td>iscsi</td><td><code>iscsi.keyvalue.dataDigest</code></td><td>string</td><td>true</td></tr>
<tr><td>iscsi</td><td><code>iscsi.keyvalue.defaultTime2Retain</code></td><td>string</td><td>true</td></tr>
<tr><td>iscsi</td><td><code>iscsi.keyvalue.defaultTime2Wait</code></td><td>string</td><td>true</td></tr>
<tr><td>iscsi</td><td><code>iscsi.keyvalue.errorRecoveryLevel</code></td><td>string</td><td>true</td></tr>
<tr><td>iscsi</td><td><code>iscsi.keyvalue.headerDigest</code></td><td>string</td><td>true</td></tr>
<tr><td>iscsi</td><td><code>iscsi.keyvalue.ifmarker</code></td><td>string</td><td>true</td></tr>
<tr><td>iscsi</td><td><code>iscsi.keyvalue.maxConnections</code></td><td>numeric</td><td>true</td></tr>
<tr><td>iscsi</td><td><code>iscsi.keyvalue.ofmarker</code></td><td>string</td><td>true</td></tr>
<tr><td>iscsi</td><td><code>iscsi.keyvalue.targetAddress</code></td><td>string</td><td>true</td></tr>
<tr><td>iscsi</td><td><code>iscsi.keyvalue.targetName</code></td><td>string</td><td>true</td></tr>
<tr><td>iscsi</td><td><code>iscsi.keyvalue.xCom.cisco.pingTimeout</code></td><td>string</td><td>true</td></tr>
<tr><td>iscsi</td><td><code>iscsi.keyvalue.xCom.cisco.protocol</code></td><td>string</td><td>true</td></tr>
<tr><td>iscsi</td><td><code>iscsi.keyvalue.xCom.cisco.sendAsyncText</code></td><td>string</td><td>true</td></tr>
<tr><td>iscsi</td><td><code>iscsi.logout.response</code></td><td>string</td><td>true</td></tr>
<tr><td>iscsi</td><td><code>iscsi.lun</code></td><td>string</td><td>true</td></tr>
<tr><td>iscsi</td><td><code>iscsi.lunAddressMode</code></td><td>string</td><td>true</td></tr>
<tr><td>iscsi</td><td><code>iscsi.maxCmdSN</code></td><td>string</td><td>true</td></tr>
<tr><td>iscsi</td><td><code>iscsi.nextStage</code></td><td>string</td><td>true</td></tr>
<tr><td>iscsi</td><td><code>iscsi.opcode</code></td><td>string</td><td>true</td></tr>
<tr><td>iscsi</td><td><code>iscsi.residualCount</code></td><td>numeric</td><td>true</td></tr>
<tr><td>iscsi</td><td><code>iscsi.response</code></td><td>string</td><td>true</td></tr>
<tr><td>iscsi</td><td><code>iscsi.statSN</code></td><td>string</td><td>true</td></tr>
<tr><td>iscsi</td><td><code>iscsi.status</code></td><td>string</td><td>true</td></tr>
<tr><td>iscsi</td><td><code>iscsi.statusClass</code></td><td>string</td><td>true</td></tr>
<tr><td>iscsi</td><td><code>iscsi.statusDetail</code></td><td>string</td><td>true</td></tr>
<tr><td>iscsi</td><td><code>iscsi.targetAddress</code></td><td>string</td><td>true</td></tr>
<tr><td>iscsi</td><td><code>iscsi.targetAddresses</code></td><td>string</td><td>true</td></tr>
<tr><td>iscsi</td><td><code>iscsi.targetCount</code></td><td>string</td><td>true</td></tr>
<tr><td>iscsi</td><td><code>iscsi.targetName</code></td><td>string</td><td>true</td></tr>
<tr><td>iscsi</td><td><code>iscsi.targetNames</code></td><td>string</td><td>true</td></tr>
<tr><td>iscsi</td><td><code>iscsi.time2Retain</code></td><td>string</td><td>true</td></tr>
<tr><td>iscsi</td><td><code>iscsi.time2Wait</code></td><td>string</td><td>true</td></tr>
<tr><td>iscsi</td><td><code>iscsi.transferTaskTag</code></td><td>string</td><td>true</td></tr>
<tr><td>iscsi</td><td><code>iscsi.transit</code></td><td>string</td><td>true</td></tr>
<tr><td>iscsi</td><td><code>iscsi.tsih</code></td><td>string</td><td>true</td></tr>
<tr><td>iscsi</td><td><code>iscsi.unknownData</code></td><td>string</td><td>true</td></tr>
<tr><td>iscsi</td><td><code>iscsi.versionActive</code></td><td>string</td><td>true</td></tr>
<tr><td>iscsi</td><td><code>iscsi.versionMax</code></td><td>string</td><td>true</td></tr>
<tr><td>iscsi</td><td><code>iscsi.versionMin</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>iua</td><td><code>iua.errorCode</code></td><td>string</td><td>true</td></tr>
<tr><td>iua</td><td><code>iua.infoString</code></td><td>string</td><td>true</td></tr>
<tr><td>iua</td><td><code>iua.messageClass</code></td><td>string</td><td>true</td></tr>
<tr><td>iua</td><td><code>iua.messageType</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
</tbody>
<tbody>
</tbody>
<tbody>
</tbody>
<tbody>
</tbody>
<tbody>
<tr><td>jdwp</td><td><code>jdwp.banner</code></td><td>string</td><td>true</td></tr>
<tr><td>jdwp</td><td><code>jdwp.description</code></td><td>string</td><td>true</td></tr>
<tr><td>jdwp</td><td><code>jdwp.major</code></td><td>string</td><td>true</td></tr>
<tr><td>jdwp</td><td><code>jdwp.minor</code></td><td>string</td><td>true</td></tr>
<tr><td>jdwp</td><td><code>jdwp.packetID</code></td><td>string</td><td>true</td></tr>
<tr><td>jdwp</td><td><code>jdwp.version</code></td><td>string</td><td>true</td></tr>
<tr><td>jdwp</td><td><code>jdwp.vmName</code></td><td>string</td><td>true</td></tr>
<tr><td>jdwp</td><td><code>jdwp.vmVersion</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>jetdirect</td><td><code>jetdirect.banner</code></td><td>string</td><td>true</td></tr>
<tr><td>jetdirect</td><td><code>jetdirect.cpe23</code></td><td>string</td><td>true</td></tr>
<tr><td>jetdirect</td><td><code>jetdirect.filesystemAccess</code></td><td>string</td><td>true</td></tr>
<tr><td>jetdirect</td><td><code>jetdirect.firmware</code></td><td>string</td><td>true</td></tr>
<tr><td>jetdirect</td><td><code>jetdirect.id</code></td><td>string</td><td>true</td></tr>
<tr><td>jetdirect</td><td><code>jetdirect.model</code></td><td>string</td><td>true</td></tr>
<tr><td>jetdirect</td><td><code>jetdirect.status</code></td><td>string</td><td>true</td></tr>
<tr><td>jetdirect</td><td><code>jetdirect.vendor</code></td><td>string</td><td>true</td></tr>
<tr><td>jetdirect</td><td><code>pjl.id</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>jira</td><td><code>jira.baseURL</code></td><td>string</td><td>true</td></tr>
<tr><td>jira</td><td><code>jira.build</code></td><td>string</td><td>true</td></tr>
<tr><td>jira</td><td><code>jira.version</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>jms</td><td><code>jms.admin</code></td><td>string</td><td>true</td></tr>
<tr><td>jms</td><td><code>jms.cluster</code></td><td>string</td><td>true</td></tr>
<tr><td>jms</td><td><code>jms.jms</code></td><td>string</td><td>true</td></tr>
<tr><td>jms</td><td><code>jms.jmsdirect</code></td><td>string</td><td>true</td></tr>
<tr><td>jms</td><td><code>jms.jmxrmi</code></td><td>string</td><td>true</td></tr>
<tr><td>jms</td><td><code>jms.jmxrmi.env.url</code></td><td>string</td><td>true</td></tr>
<tr><td>jms</td><td><code>jms.jmxrmi.env.version</code></td><td>string</td><td>true</td></tr>
<tr><td>jms</td><td><code>jms.mqdirect2</code></td><td>string</td><td>true</td></tr>
<tr><td>jms</td><td><code>jms.portmapper</code></td><td>numeric</td><td>true</td></tr>
<tr><td>jms</td><td><code>jms.portmapper.env.imqhome</code></td><td>numeric</td><td>true</td></tr>
<tr><td>jms</td><td><code>jms.portmapper.env.imqvarhome</code></td><td>numeric</td><td>true</td></tr>
<tr><td>jms</td><td><code>jms.portmapper.env.sessionid</code></td><td>numeric</td><td>true</td></tr>
<tr><td>jms</td><td><code>jms.services</code></td><td>string</td><td>false</td></tr>
<tr><td>jms</td><td><code>jms.tcp.ports</code></td><td>numeric</td><td>false</td></tr>
<tr><td>jms</td><td><code>jms.version</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>kafka</td><td><code>kafka.correlationID</code></td><td>string</td><td>true</td></tr>
<tr><td>kafka</td><td><code>kafka.version</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>kasa</td><td><code>kasa.deviceAlias</code></td><td>string</td><td>true</td></tr>
<tr><td>kasa</td><td><code>kasa.deviceId</code></td><td>string</td><td>true</td></tr>
<tr><td>kasa</td><td><code>kasa.deviceType</code></td><td>string</td><td>true</td></tr>
<tr><td>kasa</td><td><code>kasa.hardwareAddress</code></td><td>string</td><td>true</td></tr>
<tr><td>kasa</td><td><code>kasa.hardwareId</code></td><td>string</td><td>true</td></tr>
<tr><td>kasa</td><td><code>kasa.hardwareVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>kasa</td><td><code>kasa.model</code></td><td>string</td><td>true</td></tr>
<tr><td>kasa</td><td><code>kasa.obdSource</code></td><td>string</td><td>true</td></tr>
<tr><td>kasa</td><td><code>kasa.oemId</code></td><td>string</td><td>true</td></tr>
<tr><td>kasa</td><td><code>kasa.softwareVersion</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>kerberos</td><td><code>kerberos.error</code></td><td>string</td><td>true</td></tr>
<tr><td>kerberos</td><td><code>kerberos.errorCode</code></td><td>string</td><td>true</td></tr>
<tr><td>kerberos</td><td><code>kerberos.errorCodeName</code></td><td>string</td><td>true</td></tr>
<tr><td>kerberos</td><td><code>kerberos.messageType</code></td><td>string</td><td>true</td></tr>
<tr><td>kerberos</td><td><code>kerberos.messageTypeCode</code></td><td>string</td><td>true</td></tr>
<tr><td>kerberos</td><td><code>kerberos.microseconds</code></td><td>string</td><td>true</td></tr>
<tr><td>kerberos</td><td><code>kerberos.port</code></td><td>numeric</td><td>true</td></tr>
<tr><td>kerberos</td><td><code>kerberos.realm</code></td><td>string</td><td>true</td></tr>
<tr><td>kerberos</td><td><code>kerberos.serverTS</code></td><td>numeric</td><td>true</td></tr>
<tr><td>kerberos</td><td><code>kerberos.servicePrincipal</code></td><td>string</td><td>true</td></tr>
<tr><td>kerberos</td><td><code>kerberos.target</code></td><td>string</td><td>true</td></tr>
<tr><td>kerberos</td><td><code>kerberos.ticket.realm</code></td><td>string</td><td>true</td></tr>
<tr><td>kerberos</td><td><code>kerberos.version</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>knxnet</td><td><code>knxnet.address</code></td><td>string</td><td>true</td></tr>
<tr><td>knxnet</td><td><code>knxnet.bus.address</code></td><td>string</td><td>true</td></tr>
<tr><td>knxnet</td><td><code>knxnet.bus.applicationID</code></td><td>string</td><td>true</td></tr>
<tr><td>knxnet</td><td><code>knxnet.bus.descriptor</code></td><td>string</td><td>true</td></tr>
<tr><td>knxnet</td><td><code>knxnet.bus.firmwareRevision</code></td><td>string</td><td>true</td></tr>
<tr><td>knxnet</td><td><code>knxnet.bus.hardwareType</code></td><td>string</td><td>true</td></tr>
<tr><td>knxnet</td><td><code>knxnet.bus.manufacturerID</code></td><td>string</td><td>true</td></tr>
<tr><td>knxnet</td><td><code>knxnet.bus.name</code></td><td>string</td><td>true</td></tr>
<tr><td>knxnet</td><td><code>knxnet.bus.orderInfo</code></td><td>string</td><td>true</td></tr>
<tr><td>knxnet</td><td><code>knxnet.bus.programVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>knxnet</td><td><code>knxnet.bus.serialNumber</code></td><td>string</td><td>true</td></tr>
<tr><td>knxnet</td><td><code>knxnet.busDevice</code></td><td>string</td><td>false</td></tr>
<tr><td>knxnet</td><td><code>knxnet.busDeviceCount</code></td><td>numeric</td><td>true</td></tr>
<tr><td>knxnet</td><td><code>knxnet.channel</code></td><td>string</td><td>true</td></tr>
<tr><td>knxnet</td><td><code>knxnet.decodeErrors</code></td><td>string</td><td>true</td></tr>
<tr><td>knxnet</td><td><code>knxnet.decodeWarning</code></td><td>string</td><td>false</td></tr>
<tr><td>knxnet</td><td><code>knxnet.descriptor</code></td><td>string</td><td>true</td></tr>
<tr><td>knxnet</td><td><code>knxnet.firmwareRevision</code></td><td>string</td><td>true</td></tr>
<tr><td>knxnet</td><td><code>knxnet.hardwareType</code></td><td>string</td><td>true</td></tr>
<tr><td>knxnet</td><td><code>knxnet.hpaiDataEP</code></td><td>string</td><td>false</td></tr>
<tr><td>knxnet</td><td><code>knxnet.mac</code></td><td>string</td><td>true</td></tr>
<tr><td>knxnet</td><td><code>knxnet.manufacturerData</code></td><td>string</td><td>true</td></tr>
<tr><td>knxnet</td><td><code>knxnet.manufacturerID</code></td><td>string</td><td>true</td></tr>
<tr><td>knxnet</td><td><code>knxnet.medium</code></td><td>string</td><td>true</td></tr>
<tr><td>knxnet</td><td><code>knxnet.multicast</code></td><td>string</td><td>true</td></tr>
<tr><td>knxnet</td><td><code>knxnet.multicastAddress</code></td><td>string</td><td>true</td></tr>
<tr><td>knxnet</td><td><code>knxnet.name</code></td><td>string</td><td>true</td></tr>
<tr><td>knxnet</td><td><code>knxnet.orderInfo</code></td><td>string</td><td>true</td></tr>
<tr><td>knxnet</td><td><code>knxnet.remoteDevice</code></td><td>string</td><td>false</td></tr>
<tr><td>knxnet</td><td><code>knxnet.remoteDeviceCount</code></td><td>numeric</td><td>true</td></tr>
<tr><td>knxnet</td><td><code>knxnet.serial</code></td><td>string</td><td>true</td></tr>
<tr><td>knxnet</td><td><code>knxnet.serialNumber</code></td><td>string</td><td>true</td></tr>
<tr><td>knxnet</td><td><code>knxnet.service.Core</code></td><td>string</td><td>true</td></tr>
<tr><td>knxnet</td><td><code>knxnet.service.Tunnelling</code></td><td>string</td><td>true</td></tr>
<tr><td>knxnet</td><td><code>knxnet.serviceFamilies</code></td><td>string</td><td>true</td></tr>
<tr><td>knxnet</td><td><code>knxnet.status</code></td><td>string</td><td>true</td></tr>
<tr><td>knxnet</td><td><code>knxnet.tunnelData</code></td><td>string</td><td>true</td></tr>
<tr><td>knxnet</td><td><code>knxnet.tunnelEP</code></td><td>string</td><td>false</td></tr>
<tr><td>knxnet</td><td><code>knxnet.type</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>l2t</td><td><code>l2t.assignedTunnelID</code></td><td>string</td><td>true</td></tr>
<tr><td>l2t</td><td><code>l2t.bearerCaps</code></td><td>string</td><td>true</td></tr>
<tr><td>l2t</td><td><code>l2t.firmwareRevision</code></td><td>string</td><td>true</td></tr>
<tr><td>l2t</td><td><code>l2t.framingCaps</code></td><td>string</td><td>true</td></tr>
<tr><td>l2t</td><td><code>l2t.hostName</code></td><td>string</td><td>true</td></tr>
<tr><td>l2t</td><td><code>l2t.messageType</code></td><td>string</td><td>true</td></tr>
<tr><td>l2t</td><td><code>l2t.protocolVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>l2t</td><td><code>l2t.vendorName</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>l2tp</td><td><code>l2tp.assignedTunnelID</code></td><td>string</td><td>true</td></tr>
<tr><td>l2tp</td><td><code>l2tp.bearerCaps</code></td><td>string</td><td>true</td></tr>
<tr><td>l2tp</td><td><code>l2tp.controlCode</code></td><td>string</td><td>true</td></tr>
<tr><td>l2tp</td><td><code>l2tp.errorCode</code></td><td>string</td><td>true</td></tr>
<tr><td>l2tp</td><td><code>l2tp.errorMsg</code></td><td>string</td><td>true</td></tr>
<tr><td>l2tp</td><td><code>l2tp.firmwareRevision</code></td><td>string</td><td>true</td></tr>
<tr><td>l2tp</td><td><code>l2tp.framingCaps</code></td><td>string</td><td>true</td></tr>
<tr><td>l2tp</td><td><code>l2tp.hostName</code></td><td>string</td><td>true</td></tr>
<tr><td>l2tp</td><td><code>l2tp.nr</code></td><td>string</td><td>true</td></tr>
<tr><td>l2tp</td><td><code>l2tp.ns</code></td><td>string</td><td>true</td></tr>
<tr><td>l2tp</td><td><code>l2tp.protoVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>l2tp</td><td><code>l2tp.recvWindowSize</code></td><td>string</td><td>true</td></tr>
<tr><td>l2tp</td><td><code>l2tp.resultCode</code></td><td>string</td><td>true</td></tr>
<tr><td>l2tp</td><td><code>l2tp.sessionID</code></td><td>string</td><td>true</td></tr>
<tr><td>l2tp</td><td><code>l2tp.tunnelID</code></td><td>string</td><td>true</td></tr>
<tr><td>l2tp</td><td><code>l2tp.unknownType</code></td><td>string</td><td>true</td></tr>
<tr><td>l2tp</td><td><code>l2tp.vendorName</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>landesk</td><td><code>landesk.configPath</code></td><td>string</td><td>true</td></tr>
<tr><td>landesk</td><td><code>landesk.providerVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>landesk</td><td><code>landesk.serverVersion</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>langflow</td><td><code>service.product</code></td><td>string</td><td>true</td></tr>
<tr><td>langflow</td><td><code>service.version</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>lantronix</td><td><code>lantronix.fwinfo</code></td><td>string</td><td>true</td></tr>
<tr><td>lantronix</td><td><code>lantronix.mac</code></td><td>string</td><td>true</td></tr>
<tr><td>lantronix</td><td><code>lantronix.macVendor</code></td><td>string</td><td>true</td></tr>
<tr><td>lantronix</td><td><code>lantronix.serial</code></td><td>string</td><td>true</td></tr>
<tr><td>lantronix</td><td><code>lantronix.type</code></td><td>string</td><td>true</td></tr>
<tr><td>lantronix</td><td><code>lantronix.version</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>ldap</td><td><code>ldap.auth</code></td><td>string</td><td>true</td></tr>
<tr><td>ldap</td><td><code>ldap.configurationNamingContext</code></td><td>string</td><td>true</td></tr>
<tr><td>ldap</td><td><code>ldap.currentTime</code></td><td>string</td><td>true</td></tr>
<tr><td>ldap</td><td><code>ldap.defaultNamingContext</code></td><td>string</td><td>true</td></tr>
<tr><td>ldap</td><td><code>ldap.diagMessage</code></td><td>string</td><td>true</td></tr>
<tr><td>ldap</td><td><code>ldap.dnsHostName</code></td><td>string</td><td>true</td></tr>
<tr><td>ldap</td><td><code>ldap.domainControllerFunctionality</code></td><td>string</td><td>true</td></tr>
<tr><td>ldap</td><td><code>ldap.domainFunctionality</code></td><td>string</td><td>true</td></tr>
<tr><td>ldap</td><td><code>ldap.dsServiceName</code></td><td>string</td><td>true</td></tr>
<tr><td>ldap</td><td><code>ldap.error</code></td><td>string</td><td>true</td></tr>
<tr><td>ldap</td><td><code>ldap.example.com</code></td><td>string</td><td>true</td></tr>
<tr><td>ldap</td><td><code>ldap.forestFunctionality</code></td><td>string</td><td>true</td></tr>
<tr><td>ldap</td><td><code>ldap.isGlobalCatalogReady</code></td><td>string</td><td>true</td></tr>
<tr><td>ldap</td><td><code>ldap.isSynchronized</code></td><td>string</td><td>true</td></tr>
<tr><td>ldap</td><td><code>ldap.matchedDN</code></td><td>string</td><td>true</td></tr>
<tr><td>ldap</td><td><code>ldap.namingContexts</code></td><td>numeric</td><td>true</td></tr>
<tr><td>ldap</td><td><code>ldap.notes</code></td><td>string</td><td>false</td></tr>
<tr><td>ldap</td><td><code>ldap.resultCode</code></td><td>string</td><td>true</td></tr>
<tr><td>ldap</td><td><code>ldap.resultCodeName</code></td><td>string</td><td>true</td></tr>
<tr><td>ldap</td><td><code>ldap.rootDomainNamingContext</code></td><td>string</td><td>true</td></tr>
<tr><td>ldap</td><td><code>ldap.schemaNamingContext</code></td><td>string</td><td>true</td></tr>
<tr><td>ldap</td><td><code>ldap.searchresult</code></td><td>string</td><td>true</td></tr>
<tr><td>ldap</td><td><code>ldap.serverName</code></td><td>string</td><td>true</td></tr>
<tr><td>ldap</td><td><code>ldap.serverType</code></td><td>string</td><td>true</td></tr>
<tr><td>ldap</td><td><code>ldap.startTLS</code></td><td>string</td><td>true</td></tr>
<tr><td>ldap</td><td><code>ldap.subschemaSubentry</code></td><td>string</td><td>true</td></tr>
<tr><td>ldap</td><td><code>ldap.supportedControl</code></td><td>string</td><td>true</td></tr>
<tr><td>ldap</td><td><code>ldap.supportedControls</code></td><td>numeric</td><td>true</td></tr>
<tr><td>ldap</td><td><code>ldap.supportedExtension</code></td><td>string</td><td>true</td></tr>
<tr><td>ldap</td><td><code>ldap.supportedExtensions</code></td><td>numeric</td><td>true</td></tr>
<tr><td>ldap</td><td><code>ldap.supportedLDAPVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>ldap</td><td><code>ldap.supportedSASLMechanisms</code></td><td>numeric</td><td>true</td></tr>
<tr><td>ldap</td><td><code>ldap.supportsStartTLS</code></td><td>numeric</td><td>true</td></tr>
<tr><td>ldap</td><td><code>ldap.vendorName</code></td><td>string</td><td>true</td></tr>
<tr><td>ldap</td><td><code>ldap.vendorVersion</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
</tbody>
<tbody>
</tbody>
<tbody>
</tbody>
<tbody>
<tr><td>llmnr</td><td><code>llmnr.ipv4</code></td><td>string</td><td>true</td></tr>
<tr><td>llmnr</td><td><code>llmnr.ipv6</code></td><td>string</td><td>true</td></tr>
<tr><td>llmnr</td><td><code>llmnr.name</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>lockdownd</td><td><code>lockdownd.cpuArchitecture</code></td><td>string</td><td>true</td></tr>
<tr><td>lockdownd</td><td><code>lockdownd.deviceName</code></td><td>string</td><td>true</td></tr>
<tr><td>lockdownd</td><td><code>lockdownd.hardwareModel</code></td><td>string</td><td>true</td></tr>
<tr><td>lockdownd</td><td><code>lockdownd.productName</code></td><td>string</td><td>true</td></tr>
<tr><td>lockdownd</td><td><code>lockdownd.productType</code></td><td>string</td><td>true</td></tr>
<tr><td>lockdownd</td><td><code>lockdownd.productVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>lockdownd</td><td><code>lockdownd.supportedDeviceFamilies</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>lpd</td><td><code>lpd.banner</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
</tbody>
<tbody>
<tr><td>lwm2m</td><td><code>lwm2m.bootstrapServer</code></td><td>string</td><td>true</td></tr>
<tr><td>lwm2m</td><td><code>lwm2m.payload</code></td><td>string</td><td>true</td></tr>
<tr><td>lwm2m</td><td><code>lwm2m.registrationDirectory</code></td><td>string</td><td>true</td></tr>
<tr><td>lwm2m</td><td><code>lwm2m.serverImpl</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>m2pa</td><td><code>m2pa.errorCode</code></td><td>string</td><td>true</td></tr>
<tr><td>m2pa</td><td><code>m2pa.infoString</code></td><td>string</td><td>true</td></tr>
<tr><td>m2pa</td><td><code>m2pa.linkState</code></td><td>string</td><td>true</td></tr>
<tr><td>m2pa</td><td><code>m2pa.linkStateName</code></td><td>string</td><td>true</td></tr>
<tr><td>m2pa</td><td><code>m2pa.messageClass</code></td><td>string</td><td>true</td></tr>
<tr><td>m2pa</td><td><code>m2pa.messageType</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>m2ua</td><td><code>m2ua.errorCode</code></td><td>string</td><td>true</td></tr>
<tr><td>m2ua</td><td><code>m2ua.infoString</code></td><td>string</td><td>true</td></tr>
<tr><td>m2ua</td><td><code>m2ua.messageClass</code></td><td>string</td><td>true</td></tr>
<tr><td>m2ua</td><td><code>m2ua.messageType</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>m3ua</td><td><code>m3ua.errorCode</code></td><td>string</td><td>true</td></tr>
<tr><td>m3ua</td><td><code>m3ua.infoString</code></td><td>string</td><td>true</td></tr>
<tr><td>m3ua</td><td><code>m3ua.messageClass</code></td><td>string</td><td>true</td></tr>
<tr><td>m3ua</td><td><code>m3ua.messageType</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>managesieve</td><td><code>managesieve.banner</code></td><td>string</td><td>true</td></tr>
<tr><td>managesieve</td><td><code>managesieve.extensions</code></td><td>string</td><td>true</td></tr>
<tr><td>managesieve</td><td><code>managesieve.implementation</code></td><td>string</td><td>true</td></tr>
<tr><td>managesieve</td><td><code>managesieve.language</code></td><td>string</td><td>true</td></tr>
<tr><td>managesieve</td><td><code>managesieve.sasl</code></td><td>string</td><td>true</td></tr>
<tr><td>managesieve</td><td><code>managesieve.startTLS</code></td><td>string</td><td>true</td></tr>
<tr><td>managesieve</td><td><code>managesieve.version</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
</tbody>
<tbody>
</tbody>
<tbody>
</tbody>
<tbody>
</tbody>
<tbody>
<tr><td>megaco</td><td><code>megaco.banner</code></td><td>string</td><td>true</td></tr>
<tr><td>megaco</td><td><code>megaco.error</code></td><td>string</td><td>true</td></tr>
<tr><td>megaco</td><td><code>megaco.errorCode</code></td><td>string</td><td>true</td></tr>
<tr><td>megaco</td><td><code>megaco.format</code></td><td>string</td><td>true</td></tr>
<tr><td>megaco</td><td><code>megaco.mid</code></td><td>string</td><td>true</td></tr>
<tr><td>megaco</td><td><code>megaco.port</code></td><td>numeric</td><td>true</td></tr>
<tr><td>megaco</td><td><code>megaco.profile</code></td><td>string</td><td>true</td></tr>
<tr><td>megaco</td><td><code>megaco.replyID</code></td><td>string</td><td>true</td></tr>
<tr><td>megaco</td><td><code>megaco.serviceChange</code></td><td>string</td><td>true</td></tr>
<tr><td>megaco</td><td><code>megaco.target</code></td><td>string</td><td>true</td></tr>
<tr><td>megaco</td><td><code>megaco.transactionID</code></td><td>string</td><td>true</td></tr>
<tr><td>megaco</td><td><code>megaco.version</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>melsecq</td><td><code>melsecq.cpe</code></td><td>string</td><td>true</td></tr>
<tr><td>melsecq</td><td><code>melsecq.cpuModel</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
</tbody>
<tbody>
<tr><td>memcached</td><td><code>memcached.binaryProtocol</code></td><td>string</td><td>true</td></tr>
<tr><td>memcached</td><td><code>memcached.bytes</code></td><td>string</td><td>true</td></tr>
<tr><td>memcached</td><td><code>memcached.connections</code></td><td>numeric</td><td>true</td></tr>
<tr><td>memcached</td><td><code>memcached.error</code></td><td>string</td><td>true</td></tr>
<tr><td>memcached</td><td><code>memcached.items</code></td><td>string</td><td>true</td></tr>
<tr><td>memcached</td><td><code>memcached.libevent</code></td><td>string</td><td>true</td></tr>
<tr><td>memcached</td><td><code>memcached.maxBytes</code></td><td>string</td><td>true</td></tr>
<tr><td>memcached</td><td><code>memcached.maxConnections</code></td><td>numeric</td><td>true</td></tr>
<tr><td>memcached</td><td><code>memcached.pid</code></td><td>string</td><td>true</td></tr>
<tr><td>memcached</td><td><code>memcached.pointerSize</code></td><td>string</td><td>true</td></tr>
<tr><td>memcached</td><td><code>memcached.threads</code></td><td>string</td><td>true</td></tr>
<tr><td>memcached</td><td><code>memcached.totalConnections</code></td><td>string</td><td>true</td></tr>
<tr><td>memcached</td><td><code>memcached.totalItems</code></td><td>string</td><td>true</td></tr>
<tr><td>memcached</td><td><code>memcached.uptime</code></td><td>numeric</td><td>true</td></tr>
<tr><td>memcached</td><td><code>memcached.version</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
</tbody>
<tbody>
<tr><td>mgcp</td><td><code>mgcp.endpoint</code></td><td>string</td><td>true</td></tr>
<tr><td>mgcp</td><td><code>mgcp.endpoints</code></td><td>numeric</td><td>true</td></tr>
<tr><td>mgcp</td><td><code>mgcp.localOptions</code></td><td>string</td><td>true</td></tr>
<tr><td>mgcp</td><td><code>mgcp.mode</code></td><td>string</td><td>true</td></tr>
<tr><td>mgcp</td><td><code>mgcp.packages</code></td><td>string</td><td>true</td></tr>
<tr><td>mgcp</td><td><code>mgcp.responseCode</code></td><td>string</td><td>true</td></tr>
<tr><td>mgcp</td><td><code>mgcp.signals</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
</tbody>
<tbody>
<tr><td>mikrotikwinbox</td><td><code>mikrotikwinbox.banner</code></td><td>string</td><td>true</td></tr>
<tr><td>mikrotikwinbox</td><td><code>mikrotikwinbox.subProtocol</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
</tbody>
<tbody>
<tr><td>minecraft</td><td><code>minecraft.currentplayers</code></td><td>numeric</td><td>true</td></tr>
<tr><td>minecraft</td><td><code>minecraft.maxplayers</code></td><td>numeric</td><td>true</td></tr>
<tr><td>minecraft</td><td><code>minecraft.motd</code></td><td>string</td><td>true</td></tr>
<tr><td>minecraft</td><td><code>minecraft.version</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
</tbody>
<tbody>
<tr><td>modbus</td><td><code>modbus.applicationName</code></td><td>string</td><td>true</td></tr>
<tr><td>modbus</td><td><code>modbus.deviceCount</code></td><td>numeric</td><td>true</td></tr>
<tr><td>modbus</td><td><code>modbus.exception</code></td><td>string</td><td>true</td></tr>
<tr><td>modbus</td><td><code>modbus.function</code></td><td>string</td><td>true</td></tr>
<tr><td>modbus</td><td><code>modbus.gateway</code></td><td>string</td><td>true</td></tr>
<tr><td>modbus</td><td><code>modbus.gatewayPort</code></td><td>numeric</td><td>true</td></tr>
<tr><td>modbus</td><td><code>modbus.identifier</code></td><td>string</td><td>true</td></tr>
<tr><td>modbus</td><td><code>modbus.modelName</code></td><td>string</td><td>true</td></tr>
<tr><td>modbus</td><td><code>modbus.port</code></td><td>numeric</td><td>true</td></tr>
<tr><td>modbus</td><td><code>modbus.productCode</code></td><td>string</td><td>true</td></tr>
<tr><td>modbus</td><td><code>modbus.productName</code></td><td>string</td><td>true</td></tr>
<tr><td>modbus</td><td><code>modbus.registers</code></td><td>string</td><td>true</td></tr>
<tr><td>modbus</td><td><code>modbus.remote</code></td><td>string</td><td>true</td></tr>
<tr><td>modbus</td><td><code>modbus.revision</code></td><td>string</td><td>true</td></tr>
<tr><td>modbus</td><td><code>modbus.subDeviceCount</code></td><td>numeric</td><td>true</td></tr>
<tr><td>modbus</td><td><code>modbus.target</code></td><td>string</td><td>true</td></tr>
<tr><td>modbus</td><td><code>modbus.unitID</code></td><td>string</td><td>true</td></tr>
<tr><td>modbus</td><td><code>modbus.vendor</code></td><td>string</td><td>true</td></tr>
<tr><td>modbus</td><td><code>modbus.vendorURL</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>mongodb</td><td><code>mongodb.allocator</code></td><td>string</td><td>true</td></tr>
<tr><td>mongodb</td><td><code>mongodb.auth</code></td><td>string</td><td>true</td></tr>
<tr><td>mongodb</td><td><code>mongodb.bits</code></td><td>numeric</td><td>true</td></tr>
<tr><td>mongodb</td><td><code>mongodb.buildEnvironment.cc</code></td><td>string</td><td>true</td></tr>
<tr><td>mongodb</td><td><code>mongodb.buildEnvironment.ccflags</code></td><td>string</td><td>true</td></tr>
<tr><td>mongodb</td><td><code>mongodb.buildEnvironment.cxx</code></td><td>string</td><td>true</td></tr>
<tr><td>mongodb</td><td><code>mongodb.buildEnvironment.cxxflags</code></td><td>string</td><td>true</td></tr>
<tr><td>mongodb</td><td><code>mongodb.buildEnvironment.distarch</code></td><td>string</td><td>true</td></tr>
<tr><td>mongodb</td><td><code>mongodb.buildEnvironment.distmod</code></td><td>string</td><td>true</td></tr>
<tr><td>mongodb</td><td><code>mongodb.buildEnvironment.linkflags</code></td><td>string</td><td>true</td></tr>
<tr><td>mongodb</td><td><code>mongodb.buildEnvironment.target_arch</code></td><td>string</td><td>true</td></tr>
<tr><td>mongodb</td><td><code>mongodb.buildEnvironment.target_os</code></td><td>string</td><td>true</td></tr>
<tr><td>mongodb</td><td><code>mongodb.cpuArch</code></td><td>string</td><td>true</td></tr>
<tr><td>mongodb</td><td><code>mongodb.debug</code></td><td>bool</td><td>true</td></tr>
<tr><td>mongodb</td><td><code>mongodb.error</code></td><td>string</td><td>true</td></tr>
<tr><td>mongodb</td><td><code>mongodb.gitVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>mongodb</td><td><code>mongodb.hostname</code></td><td>string</td><td>true</td></tr>
<tr><td>mongodb</td><td><code>mongodb.isMaster</code></td><td>string</td><td>true</td></tr>
<tr><td>mongodb</td><td><code>mongodb.javascriptEngine</code></td><td>string</td><td>true</td></tr>
<tr><td>mongodb</td><td><code>mongodb.jsEngine</code></td><td>string</td><td>true</td></tr>
<tr><td>mongodb</td><td><code>mongodb.legacyWireVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>mongodb</td><td><code>mongodb.maxBsonObjectSize</code></td><td>numeric</td><td>true</td></tr>
<tr><td>mongodb</td><td><code>mongodb.maxWireVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>mongodb</td><td><code>mongodb.memSizeMB</code></td><td>string</td><td>true</td></tr>
<tr><td>mongodb</td><td><code>mongodb.minWireVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>mongodb</td><td><code>mongodb.modules</code></td><td>string</td><td>false</td></tr>
<tr><td>mongodb</td><td><code>mongodb.mongos</code></td><td>string</td><td>true</td></tr>
<tr><td>mongodb</td><td><code>mongodb.numCores</code></td><td>string</td><td>true</td></tr>
<tr><td>mongodb</td><td><code>mongodb.ok</code></td><td>string</td><td>true</td></tr>
<tr><td>mongodb</td><td><code>mongodb.opcode</code></td><td>string</td><td>true</td></tr>
<tr><td>mongodb</td><td><code>mongodb.openssl.compiled</code></td><td>string</td><td>true</td></tr>
<tr><td>mongodb</td><td><code>mongodb.openssl.running</code></td><td>string</td><td>true</td></tr>
<tr><td>mongodb</td><td><code>mongodb.os</code></td><td>string</td><td>true</td></tr>
<tr><td>mongodb</td><td><code>mongodb.osVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>mongodb</td><td><code>mongodb.readOnly</code></td><td>string</td><td>true</td></tr>
<tr><td>mongodb</td><td><code>mongodb.setParameter.md5</code></td><td>string</td><td>true</td></tr>
<tr><td>mongodb</td><td><code>mongodb.storageEngines</code></td><td>string</td><td>false</td></tr>
<tr><td>mongodb</td><td><code>mongodb.sysInfo</code></td><td>string</td><td>true</td></tr>
<tr><td>mongodb</td><td><code>mongodb.version</code></td><td>string</td><td>true</td></tr>
<tr><td>mongodb</td><td><code>mongodb.versionArray</code></td><td>string</td><td>false</td></tr>
</tbody>
<tbody>
</tbody>
<tbody>
<tr><td>mqtt</td><td><code>mqtt.broker.authRequired</code></td><td>boolean</td><td>true</td></tr>
<tr><td>mqtt</td><td><code>mqtt.broker.supportedProtocols</code></td><td>numeric</td><td>true</td></tr>
<tr><td>mqtt</td><td><code>mqtt.broker.sys.buildTime</code></td><td>string</td><td>true</td></tr>
<tr><td>mqtt</td><td><code>mqtt.broker.sys.clients.connected</code></td><td>string</td><td>true</td></tr>
<tr><td>mqtt</td><td><code>mqtt.broker.sys.clients.maximum</code></td><td>string</td><td>true</td></tr>
<tr><td>mqtt</td><td><code>mqtt.broker.sys.clients.total</code></td><td>string</td><td>true</td></tr>
<tr><td>mqtt</td><td><code>mqtt.broker.sys.messages.retained.count</code></td><td>numeric</td><td>true</td></tr>
<tr><td>mqtt</td><td><code>mqtt.broker.sys.messages.stored</code></td><td>string</td><td>true</td></tr>
<tr><td>mqtt</td><td><code>mqtt.broker.sys.subscriptions.count</code></td><td>numeric</td><td>true</td></tr>
<tr><td>mqtt</td><td><code>mqtt.broker.sys.time</code></td><td>string</td><td>true</td></tr>
<tr><td>mqtt</td><td><code>mqtt.broker.sys.uptime</code></td><td>numeric</td><td>true</td></tr>
<tr><td>mqtt</td><td><code>mqtt.broker.sys.version</code></td><td>string</td><td>true</td></tr>
<tr><td>mqtt</td><td><code>mqtt.connAckCode</code></td><td>string</td><td>true</td></tr>
<tr><td>mqtt</td><td><code>mqtt.connAckMessage</code></td><td>string</td><td>true</td></tr>
<tr><td>mqtt</td><td><code>mqtt.isV5</code></td><td>string</td><td>true</td></tr>
<tr><td>mqtt</td><td><code>mqtt.port</code></td><td>numeric</td><td>true</td></tr>
<tr><td>mqtt</td><td><code>mqtt.protocolVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>mqtt</td><td><code>mqtt.sessionPresent</code></td><td>string</td><td>true</td></tr>
<tr><td>mqtt</td><td><code>mqtt.target</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>mssql</td><td><code>mssql.browser.response</code></td><td>string</td><td>false</td></tr>
<tr><td>mssql</td><td><code>mssql.encryption</code></td><td>string</td><td>true</td></tr>
<tr><td>mssql</td><td><code>mssql.encryptionCode</code></td><td>string</td><td>true</td></tr>
<tr><td>mssql</td><td><code>mssql.instanceName</code></td><td>string</td><td>true</td></tr>
<tr><td>mssql</td><td><code>mssql.instanceNames</code></td><td>string</td><td>true</td></tr>
<tr><td>mssql</td><td><code>mssql.isClustered</code></td><td>string</td><td>true</td></tr>
<tr><td>mssql</td><td><code>mssql.mars</code></td><td>string</td><td>true</td></tr>
<tr><td>mssql</td><td><code>mssql.nps</code></td><td>string</td><td>true</td></tr>
<tr><td>mssql</td><td><code>mssql.ntlm.dnsComputer</code></td><td>string</td><td>true</td></tr>
<tr><td>mssql</td><td><code>mssql.ntlm.dnsDomain</code></td><td>string</td><td>true</td></tr>
<tr><td>mssql</td><td><code>mssql.ntlm.dnsTree</code></td><td>string</td><td>true</td></tr>
<tr><td>mssql</td><td><code>mssql.ntlm.negotiateFlags</code></td><td>string</td><td>true</td></tr>
<tr><td>mssql</td><td><code>mssql.ntlm.netbiosComputer</code></td><td>string</td><td>true</td></tr>
<tr><td>mssql</td><td><code>mssql.ntlm.netbiosDomain</code></td><td>string</td><td>true</td></tr>
<tr><td>mssql</td><td><code>mssql.ntlm.osBuild</code></td><td>string</td><td>true</td></tr>
<tr><td>mssql</td><td><code>mssql.ntlm.osVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>mssql</td><td><code>mssql.ntlm.targetName</code></td><td>string</td><td>true</td></tr>
<tr><td>mssql</td><td><code>mssql.ntlm.timestamp</code></td><td>numeric</td><td>true</td></tr>
<tr><td>mssql</td><td><code>mssql.packetType</code></td><td>string</td><td>true</td></tr>
<tr><td>mssql</td><td><code>mssql.packetTypeCode</code></td><td>string</td><td>true</td></tr>
<tr><td>mssql</td><td><code>mssql.port</code></td><td>numeric</td><td>true</td></tr>
<tr><td>mssql</td><td><code>mssql.product</code></td><td>string</td><td>true</td></tr>
<tr><td>mssql</td><td><code>mssql.requiresEncryption</code></td><td>string</td><td>true</td></tr>
<tr><td>mssql</td><td><code>mssql.requiresTDS8Strict</code></td><td>string</td><td>true</td></tr>
<tr><td>mssql</td><td><code>mssql.serverName</code></td><td>string</td><td>true</td></tr>
<tr><td>mssql</td><td><code>mssql.serverNames</code></td><td>string</td><td>true</td></tr>
<tr><td>mssql</td><td><code>mssql.sessionEncryption</code></td><td>string</td><td>true</td></tr>
<tr><td>mssql</td><td><code>mssql.target</code></td><td>string</td><td>true</td></tr>
<tr><td>mssql</td><td><code>mssql.tcp</code></td><td>string</td><td>true</td></tr>
<tr><td>mssql</td><td><code>mssql.tcp.ports</code></td><td>numeric</td><td>false</td></tr>
<tr><td>mssql</td><td><code>mssql.version</code></td><td>string</td><td>true</td></tr>
<tr><td>mssql</td><td><code>mssql.versionBuild</code></td><td>string</td><td>true</td></tr>
<tr><td>mssql</td><td><code>mssql.versionMajor</code></td><td>string</td><td>true</td></tr>
<tr><td>mssql</td><td><code>mssql.versionMinor</code></td><td>string</td><td>true</td></tr>
<tr><td>mssql</td><td><code>mssql.versionName</code></td><td>string</td><td>true</td></tr>
<tr><td>mssql</td><td><code>mssql.versionSubBuild</code></td><td>string</td><td>true</td></tr>
<tr><td>mssql</td><td><code>mssql.versions</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
</tbody>
<tbody>
</tbody>
<tbody>
<tr><td>munin</td><td><code>munin.capabilities</code></td><td>string</td><td>false</td></tr>
<tr><td>munin</td><td><code>munin.hostname</code></td><td>string</td><td>true</td></tr>
<tr><td>munin</td><td><code>munin.metrics</code></td><td>string</td><td>false</td></tr>
<tr><td>munin</td><td><code>munin.nodes</code></td><td>string</td><td>false</td></tr>
<tr><td>munin</td><td><code>munin.rawBanner</code></td><td>string</td><td>true</td></tr>
<tr><td>munin</td><td><code>munin.tlsRequired</code></td><td>boolean</td><td>true</td></tr>
<tr><td>munin</td><td><code>munin.version</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>mysql</td><td><code>mysql.authPluginDataLength</code></td><td>string</td><td>true</td></tr>
<tr><td>mysql</td><td><code>mysql.authPluginName</code></td><td>string</td><td>true</td></tr>
<tr><td>mysql</td><td><code>mysql.capabilities</code></td><td>string</td><td>true</td></tr>
<tr><td>mysql</td><td><code>mysql.capabilityFlags</code></td><td>string</td><td>true</td></tr>
<tr><td>mysql</td><td><code>mysql.characterSet</code></td><td>string</td><td>true</td></tr>
<tr><td>mysql</td><td><code>mysql.characterSetName</code></td><td>string</td><td>true</td></tr>
<tr><td>mysql</td><td><code>mysql.connectionID</code></td><td>string</td><td>true</td></tr>
<tr><td>mysql</td><td><code>mysql.error</code></td><td>string</td><td>true</td></tr>
<tr><td>mysql</td><td><code>mysql.errorCode</code></td><td>string</td><td>true</td></tr>
<tr><td>mysql</td><td><code>mysql.errorMessage</code></td><td>string</td><td>true</td></tr>
<tr><td>mysql</td><td><code>mysql.errorSQLState</code></td><td>string</td><td>true</td></tr>
<tr><td>mysql</td><td><code>mysql.family</code></td><td>string</td><td>true</td></tr>
<tr><td>mysql</td><td><code>mysql.normalizedVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>mysql</td><td><code>mysql.packetType</code></td><td>string</td><td>true</td></tr>
<tr><td>mysql</td><td><code>mysql.product</code></td><td>string</td><td>true</td></tr>
<tr><td>mysql</td><td><code>mysql.protocolVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>mysql</td><td><code>mysql.ssl</code></td><td>string</td><td>true</td></tr>
<tr><td>mysql</td><td><code>mysql.sslSupported</code></td><td>numeric</td><td>true</td></tr>
<tr><td>mysql</td><td><code>mysql.status</code></td><td>string</td><td>true</td></tr>
<tr><td>mysql</td><td><code>mysql.statusFlags</code></td><td>string</td><td>true</td></tr>
<tr><td>mysql</td><td><code>mysql.version</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>mysqlx</td><td><code>mysqlx.authentication.mechanisms</code></td><td>string</td><td>true</td></tr>
<tr><td>mysqlx</td><td><code>mysqlx.client.interactive</code></td><td>string</td><td>true</td></tr>
<tr><td>mysqlx</td><td><code>mysqlx.client.pwdExpireOk</code></td><td>string</td><td>true</td></tr>
<tr><td>mysqlx</td><td><code>mysqlx.compression.algorithm</code></td><td>string</td><td>true</td></tr>
<tr><td>mysqlx</td><td><code>mysqlx.doc.formats</code></td><td>numeric</td><td>true</td></tr>
<tr><td>mysqlx</td><td><code>mysqlx.error</code></td><td>string</td><td>true</td></tr>
<tr><td>mysqlx</td><td><code>mysqlx.errorCode</code></td><td>string</td><td>true</td></tr>
<tr><td>mysqlx</td><td><code>mysqlx.errorSeverity</code></td><td>string</td><td>true</td></tr>
<tr><td>mysqlx</td><td><code>mysqlx.messageType</code></td><td>string</td><td>true</td></tr>
<tr><td>mysqlx</td><td><code>mysqlx.nodeType</code></td><td>string</td><td>true</td></tr>
<tr><td>mysqlx</td><td><code>mysqlx.tls</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>natpmp</td><td><code>natpmp.externalIP</code></td><td>string</td><td>true</td></tr>
<tr><td>natpmp</td><td><code>natpmp.lastChange</code></td><td>string</td><td>true</td></tr>
<tr><td>natpmp</td><td><code>natpmp.responseCode</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>nats</td><td><code>nats.authRequired</code></td><td>boolean</td><td>true</td></tr>
<tr><td>nats</td><td><code>nats.banner</code></td><td>string</td><td>true</td></tr>
<tr><td>nats</td><td><code>nats.clientID</code></td><td>string</td><td>true</td></tr>
<tr><td>nats</td><td><code>nats.clientIP</code></td><td>string</td><td>true</td></tr>
<tr><td>nats</td><td><code>nats.cluster</code></td><td>string</td><td>true</td></tr>
<tr><td>nats</td><td><code>nats.connectURLs</code></td><td>string</td><td>true</td></tr>
<tr><td>nats</td><td><code>nats.domain</code></td><td>string</td><td>true</td></tr>
<tr><td>nats</td><td><code>nats.gitCommit</code></td><td>string</td><td>true</td></tr>
<tr><td>nats</td><td><code>nats.goVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>nats</td><td><code>nats.headers</code></td><td>string</td><td>true</td></tr>
<tr><td>nats</td><td><code>nats.host</code></td><td>string</td><td>true</td></tr>
<tr><td>nats</td><td><code>nats.info</code></td><td>string</td><td>true</td></tr>
<tr><td>nats</td><td><code>nats.jetStream</code></td><td>string</td><td>true</td></tr>
<tr><td>nats</td><td><code>nats.ldm</code></td><td>string</td><td>true</td></tr>
<tr><td>nats</td><td><code>nats.maxPayload</code></td><td>string</td><td>true</td></tr>
<tr><td>nats</td><td><code>nats.nonce</code></td><td>string</td><td>true</td></tr>
<tr><td>nats</td><td><code>nats.ok</code></td><td>string</td><td>true</td></tr>
<tr><td>nats</td><td><code>nats.pong</code></td><td>string</td><td>true</td></tr>
<tr><td>nats</td><td><code>nats.port</code></td><td>numeric</td><td>true</td></tr>
<tr><td>nats</td><td><code>nats.proto</code></td><td>string</td><td>true</td></tr>
<tr><td>nats</td><td><code>nats.serverID</code></td><td>string</td><td>true</td></tr>
<tr><td>nats</td><td><code>nats.serverName</code></td><td>string</td><td>true</td></tr>
<tr><td>nats</td><td><code>nats.tlsAvailable</code></td><td>string</td><td>true</td></tr>
<tr><td>nats</td><td><code>nats.tlsRequired</code></td><td>boolean</td><td>true</td></tr>
<tr><td>nats</td><td><code>nats.tlsVerify</code></td><td>string</td><td>true</td></tr>
<tr><td>nats</td><td><code>nats.version</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>ndmp</td><td><code>ndmp.reason</code></td><td>string</td><td>true</td></tr>
<tr><td>ndmp</td><td><code>ndmp.status</code></td><td>string</td><td>true</td></tr>
<tr><td>ndmp</td><td><code>ndmp.statusName</code></td><td>string</td><td>true</td></tr>
<tr><td>ndmp</td><td><code>ndmp.timestampTS</code></td><td>numeric</td><td>true</td></tr>
<tr><td>ndmp</td><td><code>ndmp.version</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>neo4j</td><td><code>neo4j.boltVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>neo4j</td><td><code>neo4j.neo4jVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>neo4j</td><td><code>neo4j.server</code></td><td>string</td><td>true</td></tr>
<tr><td>neo4j</td><td><code>neo4j.serverVersion</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>netbios</td><td><code>netbios.addrs</code></td><td>string</td><td>true</td></tr>
<tr><td>netbios</td><td><code>netbios.domain</code></td><td>string</td><td>true</td></tr>
<tr><td>netbios</td><td><code>netbios.domainController</code></td><td>string</td><td>true</td></tr>
<tr><td>netbios</td><td><code>netbios.mac</code></td><td>string</td><td>true</td></tr>
<tr><td>netbios</td><td><code>netbios.macDateAdded</code></td><td>string</td><td>true</td></tr>
<tr><td>netbios</td><td><code>netbios.macVendor</code></td><td>string</td><td>true</td></tr>
<tr><td>netbios</td><td><code>netbios.name</code></td><td>string</td><td>true</td></tr>
<tr><td>netbios</td><td><code>netbios.names</code></td><td>string</td><td>true</td></tr>
<tr><td>netbios</td><td><code>netbios.nodeType</code></td><td>string</td><td>true</td></tr>
<tr><td>netbios</td><td><code>netbios.primarydomainController</code></td><td>string</td><td>true</td></tr>
<tr><td>netbios</td><td><code>netbios.responseType</code></td><td>string</td><td>true</td></tr>
<tr><td>netbios</td><td><code>netbios.username</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
</tbody>
<tbody>
</tbody>
<tbody>
</tbody>
<tbody>
</tbody>
<tbody>
<tr><td>nfs</td><td><code>nfs.allowed</code></td><td>string</td><td>false</td></tr>
<tr><td>nfs</td><td><code>nfs.detected</code></td><td>boolean</td><td>true</td></tr>
<tr><td>nfs</td><td><code>nfs.exports</code></td><td>string</td><td>true</td></tr>
<tr><td>nfs</td><td><code>nfs.maxVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>nfs</td><td><code>nfs.minVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>nfs</td><td><code>nfs.unknownReply</code></td><td>string</td><td>true</td></tr>
<tr><td>nfs</td><td><code>nfs.verifierFlavor</code></td><td>string</td><td>true</td></tr>
<tr><td>nfs</td><td><code>nfs.versions</code></td><td>string</td><td>true</td></tr>
<tr><td>nfs</td><td><code>nfs.xid</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>nrpe</td><td><code>nrpe.commandArgsEnabled</code></td><td>boolean</td><td>true</td></tr>
<tr><td>nrpe</td><td><code>nrpe.output</code></td><td>string</td><td>true</td></tr>
<tr><td>nrpe</td><td><code>nrpe.resultCode</code></td><td>string</td><td>true</td></tr>
<tr><td>nrpe</td><td><code>nrpe.version</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>ntp</td><td><code>ntp.controlAssociationID</code></td><td>string</td><td>true</td></tr>
<tr><td>ntp</td><td><code>ntp.controlOpcode</code></td><td>string</td><td>true</td></tr>
<tr><td>ntp</td><td><code>ntp.controlSequence</code></td><td>string</td><td>true</td></tr>
<tr><td>ntp</td><td><code>ntp.controlStatus</code></td><td>string</td><td>true</td></tr>
<tr><td>ntp</td><td><code>ntp.controlVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>ntp</td><td><code>ntp.interval</code></td><td>string</td><td>true</td></tr>
<tr><td>ntp</td><td><code>ntp.leapIndicator</code></td><td>string</td><td>true</td></tr>
<tr><td>ntp</td><td><code>ntp.leapIndicatorCode</code></td><td>string</td><td>true</td></tr>
<tr><td>ntp</td><td><code>ntp.mode</code></td><td>string</td><td>true</td></tr>
<tr><td>ntp</td><td><code>ntp.modeCode</code></td><td>string</td><td>true</td></tr>
<tr><td>ntp</td><td><code>ntp.monlistItemSize</code></td><td>string</td><td>true</td></tr>
<tr><td>ntp</td><td><code>ntp.monlistNumItems</code></td><td>string</td><td>true</td></tr>
<tr><td>ntp</td><td><code>ntp.monlistSupported</code></td><td>numeric</td><td>true</td></tr>
<tr><td>ntp</td><td><code>ntp.originTimestamp</code></td><td>numeric</td><td>true</td></tr>
<tr><td>ntp</td><td><code>ntp.poll</code></td><td>string</td><td>true</td></tr>
<tr><td>ntp</td><td><code>ntp.pollSeconds</code></td><td>string</td><td>true</td></tr>
<tr><td>ntp</td><td><code>ntp.precision</code></td><td>string</td><td>true</td></tr>
<tr><td>ntp</td><td><code>ntp.precisionSeconds</code></td><td>string</td><td>true</td></tr>
<tr><td>ntp</td><td><code>ntp.processor</code></td><td>string</td><td>true</td></tr>
<tr><td>ntp</td><td><code>ntp.readVar</code></td><td>string</td><td>true</td></tr>
<tr><td>ntp</td><td><code>ntp.receiveTimestamp</code></td><td>numeric</td><td>true</td></tr>
<tr><td>ntp</td><td><code>ntp.referenceID</code></td><td>string</td><td>true</td></tr>
<tr><td>ntp</td><td><code>ntp.referenceIDDescription</code></td><td>string</td><td>true</td></tr>
<tr><td>ntp</td><td><code>ntp.referenceTimestamp</code></td><td>numeric</td><td>true</td></tr>
<tr><td>ntp</td><td><code>ntp.rootDelay</code></td><td>string</td><td>true</td></tr>
<tr><td>ntp</td><td><code>ntp.rootDispersion</code></td><td>string</td><td>true</td></tr>
<tr><td>ntp</td><td><code>ntp.serverTime</code></td><td>string</td><td>true</td></tr>
<tr><td>ntp</td><td><code>ntp.skew</code></td><td>string</td><td>true</td></tr>
<tr><td>ntp</td><td><code>ntp.skewMS</code></td><td>string</td><td>true</td></tr>
<tr><td>ntp</td><td><code>ntp.stratum</code></td><td>string</td><td>true</td></tr>
<tr><td>ntp</td><td><code>ntp.stratumDescription</code></td><td>string</td><td>true</td></tr>
<tr><td>ntp</td><td><code>ntp.swVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>ntp</td><td><code>ntp.system</code></td><td>string</td><td>true</td></tr>
<tr><td>ntp</td><td><code>ntp.timestamp</code></td><td>string</td><td>true</td></tr>
<tr><td>ntp</td><td><code>ntp.transmitTimestamp</code></td><td>numeric</td><td>true</td></tr>
<tr><td>ntp</td><td><code>ntp.version</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>omronfins</td><td><code>omronfins.banner</code></td><td>string</td><td>true</td></tr>
<tr><td>omronfins</td><td><code>omronfins.model</code></td><td>string</td><td>true</td></tr>
<tr><td>omronfins</td><td><code>omronfins.transport</code></td><td>numeric</td><td>true</td></tr>
<tr><td>omronfins</td><td><code>omronfins.version</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
</tbody>
<tbody>
<tr><td>opcua</td><td><code>opcua.applications</code></td><td>string</td><td>false</td></tr>
<tr><td>opcua</td><td><code>opcua.channelCertSHA256</code></td><td>string</td><td>true</td></tr>
<tr><td>opcua</td><td><code>opcua.clientThumbprint</code></td><td>string</td><td>true</td></tr>
<tr><td>opcua</td><td><code>opcua.endpointCerts</code></td><td>numeric</td><td>true</td></tr>
<tr><td>opcua</td><td><code>opcua.endpointCertsSuppressed</code></td><td>string</td><td>true</td></tr>
<tr><td>opcua</td><td><code>opcua.endpointCount</code></td><td>numeric</td><td>true</td></tr>
<tr><td>opcua</td><td><code>opcua.endpointUniqueCerts</code></td><td>numeric</td><td>true</td></tr>
<tr><td>opcua</td><td><code>opcua.endpoints</code></td><td>numeric</td><td>true</td></tr>
<tr><td>opcua</td><td><code>opcua.error</code></td><td>string</td><td>true</td></tr>
<tr><td>opcua</td><td><code>opcua.errorReason</code></td><td>string</td><td>true</td></tr>
<tr><td>opcua</td><td><code>opcua.errorText</code></td><td>string</td><td>true</td></tr>
<tr><td>opcua</td><td><code>opcua.maxChunkCount</code></td><td>numeric</td><td>true</td></tr>
<tr><td>opcua</td><td><code>opcua.maxMessageSize</code></td><td>string</td><td>true</td></tr>
<tr><td>opcua</td><td><code>opcua.messageType</code></td><td>string</td><td>true</td></tr>
<tr><td>opcua</td><td><code>opcua.port</code></td><td>numeric</td><td>true</td></tr>
<tr><td>opcua</td><td><code>opcua.protocol</code></td><td>string</td><td>true</td></tr>
<tr><td>opcua</td><td><code>opcua.receiveBufferSize</code></td><td>string</td><td>true</td></tr>
<tr><td>opcua</td><td><code>opcua.revisedLifetime</code></td><td>string</td><td>true</td></tr>
<tr><td>opcua</td><td><code>opcua.secureChannelID</code></td><td>string</td><td>true</td></tr>
<tr><td>opcua</td><td><code>opcua.securityPolicy</code></td><td>string</td><td>true</td></tr>
<tr><td>opcua</td><td><code>opcua.sendBufferSize</code></td><td>string</td><td>true</td></tr>
<tr><td>opcua</td><td><code>opcua.supportedMessageSecurityModes</code></td><td>numeric</td><td>true</td></tr>
<tr><td>opcua</td><td><code>opcua.supportedSecurityPolicies</code></td><td>numeric</td><td>true</td></tr>
<tr><td>opcua</td><td><code>opcua.supportedUserTokenTypes</code></td><td>numeric</td><td>true</td></tr>
<tr><td>opcua</td><td><code>opcua.target</code></td><td>string</td><td>true</td></tr>
<tr><td>opcua</td><td><code>opcua.tokenID</code></td><td>string</td><td>true</td></tr>
<tr><td>opcua</td><td><code>opcua.unknownNodeId</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>openvpn</td><td><code>openvpn.detected</code></td><td>boolean</td><td>true</td></tr>
<tr><td>openvpn</td><td><code>openvpn.keyID</code></td><td>string</td><td>true</td></tr>
<tr><td>openvpn</td><td><code>openvpn.messagePacketID</code></td><td>string</td><td>true</td></tr>
<tr><td>openvpn</td><td><code>openvpn.opcode</code></td><td>string</td><td>true</td></tr>
<tr><td>openvpn</td><td><code>openvpn.packetID</code></td><td>string</td><td>true</td></tr>
<tr><td>openvpn</td><td><code>openvpn.packetIDArrayLength</code></td><td>string</td><td>true</td></tr>
<tr><td>openvpn</td><td><code>openvpn.remoteSessionID</code></td><td>string</td><td>true</td></tr>
<tr><td>openvpn</td><td><code>openvpn.reply</code></td><td>string</td><td>true</td></tr>
<tr><td>openvpn</td><td><code>openvpn.service</code></td><td>string</td><td>true</td></tr>
<tr><td>openvpn</td><td><code>openvpn.sessionID</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>oracle</td><td><code>oracle.connectFlags0</code></td><td>string</td><td>true</td></tr>
<tr><td>oracle</td><td><code>oracle.connectFlags1</code></td><td>string</td><td>true</td></tr>
<tr><td>oracle</td><td><code>oracle.didResend</code></td><td>string</td><td>true</td></tr>
<tr><td>oracle</td><td><code>oracle.globalServiceOptions</code></td><td>string</td><td>true</td></tr>
<tr><td>oracle</td><td><code>oracle.nsn.Authentication</code></td><td>string</td><td>true</td></tr>
<tr><td>oracle</td><td><code>oracle.nsn.Encryption</code></td><td>string</td><td>true</td></tr>
<tr><td>oracle</td><td><code>oracle.nsnVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>oracle</td><td><code>oracle.packetType</code></td><td>string</td><td>true</td></tr>
<tr><td>oracle</td><td><code>oracle.packetTypeCode</code></td><td>string</td><td>true</td></tr>
<tr><td>oracle</td><td><code>oracle.redirectData</code></td><td>string</td><td>true</td></tr>
<tr><td>oracle</td><td><code>oracle.redirectDescriptor</code></td><td>string</td><td>true</td></tr>
<tr><td>oracle</td><td><code>oracle.refuseData</code></td><td>string</td><td>true</td></tr>
<tr><td>oracle</td><td><code>oracle.refuseDescriptor</code></td><td>string</td><td>true</td></tr>
<tr><td>oracle</td><td><code>oracle.refuseReason</code></td><td>string</td><td>true</td></tr>
<tr><td>oracle</td><td><code>oracle.tnsVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>oracle</td><td><code>oracle.version</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>oracledb</td><td><code>oracledb.errCode</code></td><td>string</td><td>true</td></tr>
<tr><td>oracledb</td><td><code>oracledb.packetType</code></td><td>string</td><td>true</td></tr>
<tr><td>oracledb</td><td><code>oracledb.tns.error</code></td><td>string</td><td>true</td></tr>
<tr><td>oracledb</td><td><code>oracledb.tns.version</code></td><td>string</td><td>true</td></tr>
<tr><td>oracledb</td><td><code>oracledb.tns.vsn</code></td><td>string</td><td>true</td></tr>
<tr><td>oracledb</td><td><code>oracledb.version</code></td><td>string</td><td>true</td></tr>
<tr><td>oracledb</td><td><code>oracledb.vsnnum</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>orion</td><td><code>orion.components</code></td><td>string</td><td>true</td></tr>
<tr><td>orion</td><td><code>orion.version</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
</tbody>
<tbody>
<tr><td>panxmlapi</td><td><code>host.mac</code></td><td>string</td><td>false</td></tr>
<tr><td>panxmlapi</td><td><code>host.name</code></td><td>string</td><td>false</td></tr>
<tr><td>panxmlapi</td><td><code>pan.api.advancedRouting</code></td><td>string</td><td>true</td></tr>
<tr><td>panxmlapi</td><td><code>pan.api.appVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>panxmlapi</td><td><code>pan.api.arpcache.ports</code></td><td>string</td><td>true</td></tr>
<tr><td>panxmlapi</td><td><code>pan.api.avDatabaseVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>panxmlapi</td><td><code>pan.api.deviceCertificateStatus</code></td><td>string</td><td>true</td></tr>
<tr><td>panxmlapi</td><td><code>pan.api.globalProtectVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>panxmlapi</td><td><code>pan.api.logdbVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>panxmlapi</td><td><code>pan.api.model</code></td><td>string</td><td>true</td></tr>
<tr><td>panxmlapi</td><td><code>pan.api.multiVsys</code></td><td>string</td><td>true</td></tr>
<tr><td>panxmlapi</td><td><code>pan.api.operationalMode</code></td><td>string</td><td>true</td></tr>
<tr><td>panxmlapi</td><td><code>pan.api.osVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>panxmlapi</td><td><code>pan.api.plugins</code></td><td>string</td><td>true</td></tr>
<tr><td>panxmlapi</td><td><code>pan.api.serialNumber</code></td><td>string</td><td>true</td></tr>
<tr><td>panxmlapi</td><td><code>pan.api.threatDatabaseVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>panxmlapi</td><td><code>pan.api.urlDatabaseVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>panxmlapi</td><td><code>pan.api.vmMode</code></td><td>string</td><td>true</td></tr>
<tr><td>panxmlapi</td><td><code>pan.api.vpnDisableMode</code></td><td>string</td><td>true</td></tr>
<tr><td>panxmlapi</td><td><code>pan.api.wildfireDatabaseVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>panxmlapi</td><td><code>pan.api.wildfireRt</code></td><td>string</td><td>true</td></tr>
<tr><td>panxmlapi</td><td><code>snmp.arpcache</code></td><td>string</td><td>false</td></tr>
</tbody>
<tbody>
<tr><td>pca</td><td><code>pca.caps</code></td><td>string</td><td>true</td></tr>
<tr><td>pca</td><td><code>pca.isRequest</code></td><td>string</td><td>true</td></tr>
<tr><td>pca</td><td><code>pca.name</code></td><td>string</td><td>true</td></tr>
<tr><td>pca</td><td><code>pca.status</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>pcworx</td><td><code>pcworx.firmwareDate</code></td><td>string</td><td>true</td></tr>
<tr><td>pcworx</td><td><code>pcworx.firmwareTime</code></td><td>string</td><td>true</td></tr>
<tr><td>pcworx</td><td><code>pcworx.firmwareVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>pcworx</td><td><code>pcworx.modelNumber</code></td><td>string</td><td>true</td></tr>
<tr><td>pcworx</td><td><code>pcworx.plcType</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>pega</td><td><code>pega.version</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>pfcp</td><td><code>pfcp.nodeID</code></td><td>string</td><td>true</td></tr>
<tr><td>pfcp</td><td><code>pfcp.nodeIDType</code></td><td>string</td><td>true</td></tr>
<tr><td>pfcp</td><td><code>pfcp.recoveryTimestamp</code></td><td>numeric</td><td>true</td></tr>
<tr><td>pfcp</td><td><code>pfcp.seidPresent</code></td><td>string</td><td>true</td></tr>
<tr><td>pfcp</td><td><code>pfcp.sequenceNumber</code></td><td>string</td><td>true</td></tr>
<tr><td>pfcp</td><td><code>pfcp.version</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>pop3</td><td><code>pop3.apop</code></td><td>string</td><td>true</td></tr>
<tr><td>pop3</td><td><code>pop3.apopBanner</code></td><td>string</td><td>true</td></tr>
<tr><td>pop3</td><td><code>pop3.authMethods</code></td><td>string</td><td>true</td></tr>
<tr><td>pop3</td><td><code>pop3.banner</code></td><td>string</td><td>true</td></tr>
<tr><td>pop3</td><td><code>pop3.capa.message</code></td><td>string</td><td>true</td></tr>
<tr><td>pop3</td><td><code>pop3.capa.status</code></td><td>string</td><td>true</td></tr>
<tr><td>pop3</td><td><code>pop3.capabilities</code></td><td>string</td><td>true</td></tr>
<tr><td>pop3</td><td><code>pop3.capabilityCount</code></td><td>numeric</td><td>true</td></tr>
<tr><td>pop3</td><td><code>pop3.expire</code></td><td>string</td><td>true</td></tr>
<tr><td>pop3</td><td><code>pop3.implementation</code></td><td>string</td><td>true</td></tr>
<tr><td>pop3</td><td><code>pop3.loginDelay</code></td><td>string</td><td>true</td></tr>
<tr><td>pop3</td><td><code>pop3.message</code></td><td>string</td><td>true</td></tr>
<tr><td>pop3</td><td><code>pop3.pipelining</code></td><td>string</td><td>true</td></tr>
<tr><td>pop3</td><td><code>pop3.responseCodes</code></td><td>string</td><td>true</td></tr>
<tr><td>pop3</td><td><code>pop3.startTLS</code></td><td>string</td><td>true</td></tr>
<tr><td>pop3</td><td><code>pop3.status</code></td><td>string</td><td>true</td></tr>
<tr><td>pop3</td><td><code>pop3.top</code></td><td>string</td><td>true</td></tr>
<tr><td>pop3</td><td><code>pop3.uidl</code></td><td>string</td><td>true</td></tr>
<tr><td>pop3</td><td><code>pop3.userAuth</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>postgres</td><td><code>postgres.TimeZone</code></td><td>string</td><td>true</td></tr>
<tr><td>postgres</td><td><code>postgres.authType</code></td><td>string</td><td>true</td></tr>
<tr><td>postgres</td><td><code>postgres.backendPID</code></td><td>string</td><td>true</td></tr>
<tr><td>postgres</td><td><code>postgres.errorCode</code></td><td>string</td><td>true</td></tr>
<tr><td>postgres</td><td><code>postgres.errorMessage</code></td><td>string</td><td>true</td></tr>
<tr><td>postgres</td><td><code>postgres.noticeMessage</code></td><td>string</td><td>true</td></tr>
<tr><td>postgres</td><td><code>postgres.noticeSeverity</code></td><td>string</td><td>true</td></tr>
<tr><td>postgres</td><td><code>postgres.packetType</code></td><td>string</td><td>true</td></tr>
<tr><td>postgres</td><td><code>postgres.routine</code></td><td>string</td><td>true</td></tr>
<tr><td>postgres</td><td><code>postgres.serverVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>postgres</td><td><code>postgres.severity</code></td><td>string</td><td>true</td></tr>
<tr><td>postgres</td><td><code>postgres.sslSupported</code></td><td>numeric</td><td>true</td></tr>
<tr><td>postgres</td><td><code>postgres.txStatus</code></td><td>string</td><td>true</td></tr>
<tr><td>postgres</td><td><code>postgresql.auth.details</code></td><td>string</td><td>true</td></tr>
<tr><td>postgres</td><td><code>postgresql.auth.method</code></td><td>string</td><td>true</td></tr>
<tr><td>postgres</td><td><code>postgresql.error.code</code></td><td>numeric</td><td>true</td></tr>
<tr><td>postgres</td><td><code>postgresql.error.file</code></td><td>string</td><td>true</td></tr>
<tr><td>postgres</td><td><code>postgresql.error.line</code></td><td>string</td><td>true</td></tr>
<tr><td>postgres</td><td><code>postgresql.error.message</code></td><td>string</td><td>true</td></tr>
<tr><td>postgres</td><td><code>postgresql.error.routine</code></td><td>string</td><td>true</td></tr>
<tr><td>postgres</td><td><code>postgresql.error.severity</code></td><td>string</td><td>true</td></tr>
<tr><td>postgres</td><td><code>postgresql.error.text</code></td><td>string</td><td>true</td></tr>
<tr><td>postgres</td><td><code>postgresql.error.unknown</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>postgresql</td><td><code>postgresql.auth.details</code></td><td>string</td><td>true</td></tr>
<tr><td>postgresql</td><td><code>postgresql.auth.method</code></td><td>string</td><td>true</td></tr>
<tr><td>postgresql</td><td><code>postgresql.error.code</code></td><td>string</td><td>true</td></tr>
<tr><td>postgresql</td><td><code>postgresql.error.file</code></td><td>string</td><td>true</td></tr>
<tr><td>postgresql</td><td><code>postgresql.error.line</code></td><td>string</td><td>true</td></tr>
<tr><td>postgresql</td><td><code>postgresql.error.message</code></td><td>string</td><td>true</td></tr>
<tr><td>postgresql</td><td><code>postgresql.error.routine</code></td><td>string</td><td>true</td></tr>
<tr><td>postgresql</td><td><code>postgresql.error.severity</code></td><td>string</td><td>true</td></tr>
<tr><td>postgresql</td><td><code>postgresql.error.text</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
</tbody>
<tbody>
<tr><td>pptp</td><td><code>pptp.bearerCapabilities</code></td><td>string</td><td>true</td></tr>
<tr><td>pptp</td><td><code>pptp.errorCode</code></td><td>string</td><td>true</td></tr>
<tr><td>pptp</td><td><code>pptp.errorText</code></td><td>string</td><td>true</td></tr>
<tr><td>pptp</td><td><code>pptp.firmwareRevision</code></td><td>string</td><td>true</td></tr>
<tr><td>pptp</td><td><code>pptp.framingCapabilities</code></td><td>string</td><td>true</td></tr>
<tr><td>pptp</td><td><code>pptp.fwRevision</code></td><td>string</td><td>true</td></tr>
<tr><td>pptp</td><td><code>pptp.hostname</code></td><td>string</td><td>true</td></tr>
<tr><td>pptp</td><td><code>pptp.maxChannels</code></td><td>string</td><td>true</td></tr>
<tr><td>pptp</td><td><code>pptp.port</code></td><td>numeric</td><td>true</td></tr>
<tr><td>pptp</td><td><code>pptp.protocolVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>pptp</td><td><code>pptp.protocolVersionRaw</code></td><td>string</td><td>true</td></tr>
<tr><td>pptp</td><td><code>pptp.resultCode</code></td><td>string</td><td>true</td></tr>
<tr><td>pptp</td><td><code>pptp.resultText</code></td><td>string</td><td>true</td></tr>
<tr><td>pptp</td><td><code>pptp.target</code></td><td>string</td><td>true</td></tr>
<tr><td>pptp</td><td><code>pptp.vendor</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
</tbody>
<tbody>
<tr><td>proconos</td><td><code>proconos.bootProject</code></td><td>string</td><td>true</td></tr>
<tr><td>proconos</td><td><code>proconos.ladderLogicRuntime</code></td><td>string</td><td>true</td></tr>
<tr><td>proconos</td><td><code>proconos.plcType</code></td><td>string</td><td>true</td></tr>
<tr><td>proconos</td><td><code>proconos.projectName</code></td><td>string</td><td>true</td></tr>
<tr><td>proconos</td><td><code>proconos.projectSourceCode</code></td><td>string</td><td>true</td></tr>
<tr><td>proconos</td><td><code>prosoft.moduleName</code></td><td>string</td><td>true</td></tr>
<tr><td>proconos</td><td><code>prosoft.operatingSystemRevision</code></td><td>string</td><td>true</td></tr>
<tr><td>proconos</td><td><code>prosoft.softwareRevision</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>profinet</td><td><code>profinet.annotation</code></td><td>string</td><td>true</td></tr>
<tr><td>profinet</td><td><code>profinet.cpe</code></td><td>string</td><td>true</td></tr>
<tr><td>profinet</td><td><code>profinet.deviceName</code></td><td>string</td><td>true</td></tr>
<tr><td>profinet</td><td><code>profinet.deviceType</code></td><td>string</td><td>true</td></tr>
<tr><td>profinet</td><td><code>profinet.vendor</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
</tbody>
<tbody>
<tr><td>prosoft</td><td><code>firmwareDate</code></td><td>string</td><td>true</td></tr>
<tr><td>prosoft</td><td><code>moduleName</code></td><td>string</td><td>true</td></tr>
<tr><td>prosoft</td><td><code>moduleRevision</code></td><td>string</td><td>true</td></tr>
<tr><td>prosoft</td><td><code>moduleSerial</code></td><td>string</td><td>true</td></tr>
<tr><td>prosoft</td><td><code>moduleStatus</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>psdisco</td><td><code>psdisco.appName</code></td><td>string</td><td>true</td></tr>
<tr><td>psdisco</td><td><code>psdisco.appTitleID</code></td><td>string</td><td>true</td></tr>
<tr><td>psdisco</td><td><code>psdisco.code</code></td><td>string</td><td>true</td></tr>
<tr><td>psdisco</td><td><code>psdisco.id</code></td><td>string</td><td>true</td></tr>
<tr><td>psdisco</td><td><code>psdisco.name</code></td><td>string</td><td>true</td></tr>
<tr><td>psdisco</td><td><code>psdisco.protoVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>psdisco</td><td><code>psdisco.requestPort</code></td><td>string</td><td>true</td></tr>
<tr><td>psdisco</td><td><code>psdisco.status</code></td><td>string</td><td>true</td></tr>
<tr><td>psdisco</td><td><code>psdisco.sysVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>psdisco</td><td><code>psdisco.type</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>pulsar</td><td><code>pulsar.protocolVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>pulsar</td><td><code>pulsar.serverVersion</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
</tbody>
<tbody>
<tr><td>qotd</td><td><code>qotd.quote</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>qualys</td><td><code>qualys.correlationID</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
</tbody>
<tbody>
<tr><td>radius</td><td><code>radius.attributes</code></td><td>string</td><td>true</td></tr>
<tr><td>radius</td><td><code>radius.calledStationId</code></td><td>string</td><td>true</td></tr>
<tr><td>radius</td><td><code>radius.code</code></td><td>numeric</td><td>true</td></tr>
<tr><td>radius</td><td><code>radius.codeID</code></td><td>string</td><td>true</td></tr>
<tr><td>radius</td><td><code>radius.identifier</code></td><td>string</td><td>true</td></tr>
<tr><td>radius</td><td><code>radius.nasIdentifier</code></td><td>string</td><td>true</td></tr>
<tr><td>radius</td><td><code>radius.replyMessage</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
</tbody>
<tbody>
<tr><td>rdp</td><td><code>rdp.auth.nla</code></td><td>string</td><td>true</td></tr>
<tr><td>rdp</td><td><code>rdp.auth.sspeua</code></td><td>string</td><td>true</td></tr>
<tr><td>rdp</td><td><code>rdp.auth.supportsNegotiation</code></td><td>numeric</td><td>true</td></tr>
<tr><td>rdp</td><td><code>rdp.auth.tls</code></td><td>string</td><td>true</td></tr>
<tr><td>rdp</td><td><code>rdp.failureCode</code></td><td>string</td><td>true</td></tr>
<tr><td>rdp</td><td><code>rdp.failureCodeName</code></td><td>string</td><td>true</td></tr>
<tr><td>rdp</td><td><code>rdp.features</code></td><td>string</td><td>true</td></tr>
<tr><td>rdp</td><td><code>rdp.flags</code></td><td>string</td><td>true</td></tr>
<tr><td>rdp</td><td><code>rdp.negotiation</code></td><td>string</td><td>true</td></tr>
<tr><td>rdp</td><td><code>rdp.ntlm.dnsComputer</code></td><td>string</td><td>true</td></tr>
<tr><td>rdp</td><td><code>rdp.ntlm.dnsDomain</code></td><td>string</td><td>true</td></tr>
<tr><td>rdp</td><td><code>rdp.ntlm.dnsTree</code></td><td>string</td><td>true</td></tr>
<tr><td>rdp</td><td><code>rdp.ntlm.netbiosComputer</code></td><td>string</td><td>true</td></tr>
<tr><td>rdp</td><td><code>rdp.ntlm.netbiosDomain</code></td><td>string</td><td>true</td></tr>
<tr><td>rdp</td><td><code>rdp.ntlm.osBuild</code></td><td>string</td><td>true</td></tr>
<tr><td>rdp</td><td><code>rdp.ntlm.osMajor</code></td><td>string</td><td>true</td></tr>
<tr><td>rdp</td><td><code>rdp.ntlm.osMinor</code></td><td>string</td><td>true</td></tr>
<tr><td>rdp</td><td><code>rdp.ntlm.osVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>rdp</td><td><code>rdp.ntlm.serverChallenge</code></td><td>string</td><td>true</td></tr>
<tr><td>rdp</td><td><code>rdp.ntlm.targetName</code></td><td>string</td><td>true</td></tr>
<tr><td>rdp</td><td><code>rdp.securityLevel</code></td><td>string</td><td>true</td></tr>
<tr><td>rdp</td><td><code>rdp.selectedProtocol</code></td><td>string</td><td>true</td></tr>
<tr><td>rdp</td><td><code>rdp.selectedProtocolName</code></td><td>string</td><td>true</td></tr>
<tr><td>rdp</td><td><code>rdp.tls.fingerprintSHA256</code></td><td>string</td><td>true</td></tr>
<tr><td>rdp</td><td><code>rdp.tls.issuer</code></td><td>string</td><td>true</td></tr>
<tr><td>rdp</td><td><code>rdp.tls.notAfter</code></td><td>string</td><td>true</td></tr>
<tr><td>rdp</td><td><code>rdp.tls.notBefore</code></td><td>string</td><td>true</td></tr>
<tr><td>rdp</td><td><code>rdp.tls.subject</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>redis</td><td><code>redis.archBits</code></td><td>numeric</td><td>true</td></tr>
<tr><td>redis</td><td><code>redis.authRequired</code></td><td>boolean</td><td>true</td></tr>
<tr><td>redis</td><td><code>redis.buildID</code></td><td>string</td><td>true</td></tr>
<tr><td>redis</td><td><code>redis.clusterEnabled</code></td><td>boolean</td><td>true</td></tr>
<tr><td>redis</td><td><code>redis.connectedClients</code></td><td>numeric</td><td>true</td></tr>
<tr><td>redis</td><td><code>redis.error</code></td><td>string</td><td>true</td></tr>
<tr><td>redis</td><td><code>redis.gccVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>redis</td><td><code>redis.gitSHA1</code></td><td>string</td><td>true</td></tr>
<tr><td>redis</td><td><code>redis.maxMemory</code></td><td>string</td><td>true</td></tr>
<tr><td>redis</td><td><code>redis.memAllocator</code></td><td>string</td><td>true</td></tr>
<tr><td>redis</td><td><code>redis.mode</code></td><td>string</td><td>true</td></tr>
<tr><td>redis</td><td><code>redis.os</code></td><td>string</td><td>true</td></tr>
<tr><td>redis</td><td><code>redis.ping</code></td><td>string</td><td>true</td></tr>
<tr><td>redis</td><td><code>redis.port</code></td><td>numeric</td><td>true</td></tr>
<tr><td>redis</td><td><code>redis.protectedMode</code></td><td>string</td><td>true</td></tr>
<tr><td>redis</td><td><code>redis.redisVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>redis</td><td><code>redis.role</code></td><td>string</td><td>true</td></tr>
<tr><td>redis</td><td><code>redis.runID</code></td><td>string</td><td>true</td></tr>
<tr><td>redis</td><td><code>redis.totalCommands</code></td><td>string</td><td>true</td></tr>
<tr><td>redis</td><td><code>redis.totalConnections</code></td><td>string</td><td>true</td></tr>
<tr><td>redis</td><td><code>redis.uptime</code></td><td>numeric</td><td>true</td></tr>
<tr><td>redis</td><td><code>redis.usedMemory</code></td><td>string</td><td>true</td></tr>
<tr><td>redis</td><td><code>redis.valkeyVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>redis</td><td><code>redis.version</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
</tbody>
<tbody>
<tr><td>riak</td><td><code>riak.nodename</code></td><td>string</td><td>true</td></tr>
<tr><td>riak</td><td><code>riak.version</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>riak-http</td><td><code>riak-http.version</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>rip</td><td><code>rip.auth</code></td><td>string</td><td>true</td></tr>
<tr><td>rip</td><td><code>rip.nextHop</code></td><td>string</td><td>false</td></tr>
<tr><td>rip</td><td><code>rip.route</code></td><td>string</td><td>false</td></tr>
<tr><td>rip</td><td><code>rip.routeCidr</code></td><td>string</td><td>false</td></tr>
<tr><td>rip</td><td><code>rip.routeCount</code></td><td>string</td><td>true</td></tr>
<tr><td>rip</td><td><code>rip.routingDomain</code></td><td>string</td><td>true</td></tr>
<tr><td>rip</td><td><code>rip.version</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
</tbody>
<tbody>
<tr><td>roomalert</td><td><code>roomalert.ipAddress</code></td><td>string</td><td>false</td></tr>
<tr><td>roomalert</td><td><code>roomalert.macAddress</code></td><td>string</td><td>false</td></tr>
<tr><td>roomalert</td><td><code>roomalert.model</code></td><td>string</td><td>false</td></tr>
<tr><td>roomalert</td><td><code>roomalert.osVersion</code></td><td>string</td><td>false</td></tr>
<tr><td>roomalert</td><td><code>roomalert.serialNumber</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>rpcbind</td><td><code>rpcbind.acceptState</code></td><td>string</td><td>true</td></tr>
<tr><td>rpcbind</td><td><code>rpcbind.acceptStatus</code></td><td>string</td><td>true</td></tr>
<tr><td>rpcbind</td><td><code>rpcbind.addrs</code></td><td>string</td><td>true</td></tr>
<tr><td>rpcbind</td><td><code>rpcbind.authStatus</code></td><td>string</td><td>true</td></tr>
<tr><td>rpcbind</td><td><code>rpcbind.error</code></td><td>string</td><td>true</td></tr>
<tr><td>rpcbind</td><td><code>rpcbind.mappingCount</code></td><td>numeric</td><td>true</td></tr>
<tr><td>rpcbind</td><td><code>rpcbind.mountd</code></td><td>string</td><td>true</td></tr>
<tr><td>rpcbind</td><td><code>rpcbind.nfs</code></td><td>string</td><td>true</td></tr>
<tr><td>rpcbind</td><td><code>rpcbind.nlockmgr</code></td><td>string</td><td>true</td></tr>
<tr><td>rpcbind</td><td><code>rpcbind.programEntries</code></td><td>string</td><td>true</td></tr>
<tr><td>rpcbind</td><td><code>rpcbind.programs</code></td><td>string</td><td>true</td></tr>
<tr><td>rpcbind</td><td><code>rpcbind.rejectStatus</code></td><td>string</td><td>true</td></tr>
<tr><td>rpcbind</td><td><code>rpcbind.replyStatus</code></td><td>string</td><td>true</td></tr>
<tr><td>rpcbind</td><td><code>rpcbind.transport</code></td><td>numeric</td><td>true</td></tr>
<tr><td>rpcbind</td><td><code>rpcbind.versionRange</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>rsync</td><td><code>rsync.banner</code></td><td>string</td><td>true</td></tr>
<tr><td>rsync</td><td><code>rsync.modules</code></td><td>string</td><td>true</td></tr>
<tr><td>rsync</td><td><code>rsync.service</code></td><td>string</td><td>true</td></tr>
<tr><td>rsync</td><td><code>rsync.version</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
</tbody>
<tbody>
<tr><td>rtmp</td><td><code>rtmp.version</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
</tbody>
<tbody>
<tr><td>rtsp</td><td><code>rtsp.banner</code></td><td>string</td><td>true</td></tr>
<tr><td>rtsp</td><td><code>rtsp.contentType</code></td><td>string</td><td>true</td></tr>
<tr><td>rtsp</td><td><code>rtsp.cseq</code></td><td>string</td><td>true</td></tr>
<tr><td>rtsp</td><td><code>rtsp.head.*</code></td><td>string</td><td>true</td></tr>
<tr><td>rtsp</td><td><code>rtsp.methodCount</code></td><td>numeric</td><td>true</td></tr>
<tr><td>rtsp</td><td><code>rtsp.methods</code></td><td>string</td><td>true</td></tr>
<tr><td>rtsp</td><td><code>rtsp.port</code></td><td>numeric</td><td>true</td></tr>
<tr><td>rtsp</td><td><code>rtsp.public</code></td><td>string</td><td>true</td></tr>
<tr><td>rtsp</td><td><code>rtsp.reasonPhrase</code></td><td>string</td><td>true</td></tr>
<tr><td>rtsp</td><td><code>rtsp.request.cseq</code></td><td>string</td><td>true</td></tr>
<tr><td>rtsp</td><td><code>rtsp.request.method</code></td><td>string</td><td>true</td></tr>
<tr><td>rtsp</td><td><code>rtsp.request.uri</code></td><td>string</td><td>true</td></tr>
<tr><td>rtsp</td><td><code>rtsp.server</code></td><td>string</td><td>true</td></tr>
<tr><td>rtsp</td><td><code>rtsp.session</code></td><td>string</td><td>true</td></tr>
<tr><td>rtsp</td><td><code>rtsp.statusClass</code></td><td>string</td><td>true</td></tr>
<tr><td>rtsp</td><td><code>rtsp.statusCode</code></td><td>string</td><td>true</td></tr>
<tr><td>rtsp</td><td><code>rtsp.statusName</code></td><td>string</td><td>true</td></tr>
<tr><td>rtsp</td><td><code>rtsp.target</code></td><td>string</td><td>true</td></tr>
<tr><td>rtsp</td><td><code>rtsp.transport</code></td><td>numeric</td><td>true</td></tr>
<tr><td>rtsp</td><td><code>rtsp.version</code></td><td>string</td><td>true</td></tr>
<tr><td>rtsp</td><td><code>rtsp.wwwAuthenticate</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>s7comm</td><td><code>s7comm.componentCount</code></td><td>numeric</td><td>true</td></tr>
<tr><td>s7comm</td><td><code>s7comm.components</code></td><td>string</td><td>true</td></tr>
<tr><td>s7comm</td><td><code>s7comm.copyright</code></td><td>string</td><td>true</td></tr>
<tr><td>s7comm</td><td><code>s7comm.cpuType</code></td><td>string</td><td>true</td></tr>
<tr><td>s7comm</td><td><code>s7comm.firmwareExtension</code></td><td>string</td><td>true</td></tr>
<tr><td>s7comm</td><td><code>s7comm.firmwareExtensionVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>s7comm</td><td><code>s7comm.firmwareName</code></td><td>string</td><td>true</td></tr>
<tr><td>s7comm</td><td><code>s7comm.firmwareVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>s7comm</td><td><code>s7comm.hardwareName</code></td><td>string</td><td>true</td></tr>
<tr><td>s7comm</td><td><code>s7comm.hardwareVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>s7comm</td><td><code>s7comm.locationDesignation</code></td><td>string</td><td>true</td></tr>
<tr><td>s7comm</td><td><code>s7comm.memoryCardSerial</code></td><td>string</td><td>true</td></tr>
<tr><td>s7comm</td><td><code>s7comm.moduleName</code></td><td>string</td><td>true</td></tr>
<tr><td>s7comm</td><td><code>s7comm.moduleType</code></td><td>string</td><td>true</td></tr>
<tr><td>s7comm</td><td><code>s7comm.moduleTypeName</code></td><td>string</td><td>true</td></tr>
<tr><td>s7comm</td><td><code>s7comm.moduleVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>s7comm</td><td><code>s7comm.plantDesignation</code></td><td>string</td><td>true</td></tr>
<tr><td>s7comm</td><td><code>s7comm.protocolVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>s7comm</td><td><code>s7comm.serialNumber</code></td><td>string</td><td>true</td></tr>
<tr><td>s7comm</td><td><code>s7comm.systemName</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>sadp</td><td><code>sadp.activated</code></td><td>string</td><td>true</td></tr>
<tr><td>sadp</td><td><code>sadp.analogChannelNum</code></td><td>string</td><td>true</td></tr>
<tr><td>sadp</td><td><code>sadp.bootTime</code></td><td>string</td><td>true</td></tr>
<tr><td>sadp</td><td><code>sadp.cmdPort</code></td><td>string</td><td>true</td></tr>
<tr><td>sadp</td><td><code>sadp.deviceDesc</code></td><td>string</td><td>true</td></tr>
<tr><td>sadp</td><td><code>sadp.deviceSerial</code></td><td>string</td><td>true</td></tr>
<tr><td>sadp</td><td><code>sadp.deviceType</code></td><td>string</td><td>true</td></tr>
<tr><td>sadp</td><td><code>sadp.dhcp</code></td><td>string</td><td>true</td></tr>
<tr><td>sadp</td><td><code>sadp.digitalChannelNum</code></td><td>string</td><td>true</td></tr>
<tr><td>sadp</td><td><code>sadp.dspVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>sadp</td><td><code>sadp.httpPort</code></td><td>string</td><td>true</td></tr>
<tr><td>sadp</td><td><code>sadp.ipv4.address</code></td><td>string</td><td>true</td></tr>
<tr><td>sadp</td><td><code>sadp.ipv4.gateway</code></td><td>string</td><td>true</td></tr>
<tr><td>sadp</td><td><code>sadp.ipv4.subnet</code></td><td>string</td><td>true</td></tr>
<tr><td>sadp</td><td><code>sadp.ipv6.address</code></td><td>string</td><td>true</td></tr>
<tr><td>sadp</td><td><code>sadp.ipv6.gateway</code></td><td>string</td><td>true</td></tr>
<tr><td>sadp</td><td><code>sadp.ipv6.maskLen</code></td><td>string</td><td>true</td></tr>
<tr><td>sadp</td><td><code>sadp.mac</code></td><td>string</td><td>true</td></tr>
<tr><td>sadp</td><td><code>sadp.oemInfo</code></td><td>string</td><td>true</td></tr>
<tr><td>sadp</td><td><code>sadp.passwordResetAbility</code></td><td>string</td><td>true</td></tr>
<tr><td>sadp</td><td><code>sadp.softwareVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>sadp</td><td><code>sadp.uuid</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>sccp</td><td><code>sccp.deviceType</code></td><td>string</td><td>true</td></tr>
<tr><td>sccp</td><td><code>sccp.protocolVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>sccp</td><td><code>sccp.rejected</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
</tbody>
<tbody>
<tr><td>securemote</td><td><code>securemote.hostname</code></td><td>string</td><td>true</td></tr>
<tr><td>securemote</td><td><code>securemote.server</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
</tbody>
<tbody>
</tbody>
<tbody>
<tr><td>servicetag</td><td><code>serviceTag.agentURN</code></td><td>string</td><td>true</td></tr>
<tr><td>servicetag</td><td><code>serviceTag.agentVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>servicetag</td><td><code>serviceTag.registryVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>servicetag</td><td><code>serviceTag.servicePort</code></td><td>string</td><td>true</td></tr>
<tr><td>servicetag</td><td><code>serviceTag.sysinfo.cpuInfo.name</code></td><td>string</td><td>true</td></tr>
<tr><td>servicetag</td><td><code>serviceTag.sysinfo.cpuMfg</code></td><td>string</td><td>true</td></tr>
<tr><td>servicetag</td><td><code>serviceTag.sysinfo.hostID</code></td><td>string</td><td>true</td></tr>
<tr><td>servicetag</td><td><code>serviceTag.sysinfo.hostname</code></td><td>string</td><td>true</td></tr>
<tr><td>servicetag</td><td><code>serviceTag.sysinfo.mfg</code></td><td>string</td><td>true</td></tr>
<tr><td>servicetag</td><td><code>serviceTag.sysinfo.platform</code></td><td>string</td><td>true</td></tr>
<tr><td>servicetag</td><td><code>serviceTag.sysinfo.release</code></td><td>string</td><td>true</td></tr>
<tr><td>servicetag</td><td><code>serviceTag.sysinfo.serialNumber</code></td><td>string</td><td>true</td></tr>
<tr><td>servicetag</td><td><code>serviceTag.sysinfo.system</code></td><td>string</td><td>true</td></tr>
<tr><td>servicetag</td><td><code>servicetag.cpuMfg</code></td><td>string</td><td>true</td></tr>
<tr><td>servicetag</td><td><code>servicetag.cpuName</code></td><td>string</td><td>true</td></tr>
<tr><td>servicetag</td><td><code>servicetag.hostid</code></td><td>string</td><td>true</td></tr>
<tr><td>servicetag</td><td><code>servicetag.hostname</code></td><td>string</td><td>true</td></tr>
<tr><td>servicetag</td><td><code>servicetag.manufacturer</code></td><td>string</td><td>true</td></tr>
<tr><td>servicetag</td><td><code>servicetag.platform</code></td><td>string</td><td>true</td></tr>
<tr><td>servicetag</td><td><code>servicetag.port</code></td><td>numeric</td><td>true</td></tr>
<tr><td>servicetag</td><td><code>servicetag.registryVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>servicetag</td><td><code>servicetag.release</code></td><td>string</td><td>true</td></tr>
<tr><td>servicetag</td><td><code>servicetag.serial</code></td><td>string</td><td>true</td></tr>
<tr><td>servicetag</td><td><code>servicetag.system</code></td><td>string</td><td>true</td></tr>
<tr><td>servicetag</td><td><code>servicetag.urn</code></td><td>string</td><td>true</td></tr>
<tr><td>servicetag</td><td><code>servicetag.version</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>sgsap</td><td><code>sgsap.messageType</code></td><td>string</td><td>true</td></tr>
<tr><td>sgsap</td><td><code>sgsap.sgsCause</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>sip</td><td><code>sip.accept</code></td><td>string</td><td>true</td></tr>
<tr><td>sip</td><td><code>sip.allow</code></td><td>string</td><td>true</td></tr>
<tr><td>sip</td><td><code>sip.contact</code></td><td>string</td><td>true</td></tr>
<tr><td>sip</td><td><code>sip.head.*</code></td><td>string</td><td>true</td></tr>
<tr><td>sip</td><td><code>sip.local</code></td><td>string</td><td>true</td></tr>
<tr><td>sip</td><td><code>sip.port</code></td><td>numeric</td><td>true</td></tr>
<tr><td>sip</td><td><code>sip.reasonPhrase</code></td><td>string</td><td>true</td></tr>
<tr><td>sip</td><td><code>sip.server</code></td><td>string</td><td>true</td></tr>
<tr><td>sip</td><td><code>sip.statusCode</code></td><td>string</td><td>true</td></tr>
<tr><td>sip</td><td><code>sip.supported</code></td><td>numeric</td><td>true</td></tr>
<tr><td>sip</td><td><code>sip.target</code></td><td>string</td><td>true</td></tr>
<tr><td>sip</td><td><code>sip.userAgent</code></td><td>string</td><td>true</td></tr>
<tr><td>sip</td><td><code>sip.via</code></td><td>string</td><td>true</td></tr>
<tr><td>sip</td><td><code>sip.wwwAuthenticate</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>slp</td><td><code>slp.attributes</code></td><td>string</td><td>true</td></tr>
<tr><td>slp</td><td><code>slp.da.attributes</code></td><td>string</td><td>true</td></tr>
<tr><td>slp</td><td><code>slp.da.bootTimestamp</code></td><td>numeric</td><td>true</td></tr>
<tr><td>slp</td><td><code>slp.da.scopes</code></td><td>string</td><td>true</td></tr>
<tr><td>slp</td><td><code>slp.da.spi</code></td><td>string</td><td>true</td></tr>
<tr><td>slp</td><td><code>slp.da.url</code></td><td>string</td><td>true</td></tr>
<tr><td>slp</td><td><code>slp.error</code></td><td>string</td><td>true</td></tr>
<tr><td>slp</td><td><code>slp.errorCode</code></td><td>string</td><td>true</td></tr>
<tr><td>slp</td><td><code>slp.flags</code></td><td>string</td><td>true</td></tr>
<tr><td>slp</td><td><code>slp.function</code></td><td>string</td><td>true</td></tr>
<tr><td>slp</td><td><code>slp.functionID</code></td><td>string</td><td>true</td></tr>
<tr><td>slp</td><td><code>slp.language</code></td><td>string</td><td>true</td></tr>
<tr><td>slp</td><td><code>slp.length</code></td><td>numeric</td><td>true</td></tr>
<tr><td>slp</td><td><code>slp.nextExtensionOffset</code></td><td>string</td><td>true</td></tr>
<tr><td>slp</td><td><code>slp.port</code></td><td>numeric</td><td>true</td></tr>
<tr><td>slp</td><td><code>slp.sa.attributes</code></td><td>string</td><td>true</td></tr>
<tr><td>slp</td><td><code>slp.sa.scopes</code></td><td>string</td><td>true</td></tr>
<tr><td>slp</td><td><code>slp.sa.url</code></td><td>string</td><td>true</td></tr>
<tr><td>slp</td><td><code>slp.serviceAgentURL</code></td><td>string</td><td>true</td></tr>
<tr><td>slp</td><td><code>slp.serviceTypeCount</code></td><td>numeric</td><td>true</td></tr>
<tr><td>slp</td><td><code>slp.serviceTypes</code></td><td>string</td><td>true</td></tr>
<tr><td>slp</td><td><code>slp.serviceTypesRaw</code></td><td>string</td><td>true</td></tr>
<tr><td>slp</td><td><code>slp.target</code></td><td>string</td><td>true</td></tr>
<tr><td>slp</td><td><code>slp.urlCount</code></td><td>numeric</td><td>true</td></tr>
<tr><td>slp</td><td><code>slp.urls</code></td><td>string</td><td>true</td></tr>
<tr><td>slp</td><td><code>slp.version</code></td><td>string</td><td>true</td></tr>
<tr><td>slp</td><td><code>slp.xid</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>smb</td><td><code>smb.accessControl</code></td><td>string</td><td>true</td></tr>
<tr><td>smb</td><td><code>smb.bootTime</code></td><td>string</td><td>true</td></tr>
<tr><td>smb</td><td><code>smb.bootTimeTS</code></td><td>string</td><td>true</td></tr>
<tr><td>smb</td><td><code>smb.capabilities</code></td><td>string</td><td>true</td></tr>
<tr><td>smb</td><td><code>smb.cipherAlg</code></td><td>string</td><td>false</td></tr>
<tr><td>smb</td><td><code>smb.cipherAlgCnt</code></td><td>numeric</td><td>true</td></tr>
<tr><td>smb</td><td><code>smb.compAlg</code></td><td>string</td><td>false</td></tr>
<tr><td>smb</td><td><code>smb.compAlgCnt</code></td><td>numeric</td><td>true</td></tr>
<tr><td>smb</td><td><code>smb.compFlags</code></td><td>string</td><td>true</td></tr>
<tr><td>smb</td><td><code>smb.dialect</code></td><td>string</td><td>true</td></tr>
<tr><td>smb</td><td><code>smb.dialectIndex</code></td><td>string</td><td>true</td></tr>
<tr><td>smb</td><td><code>smb.dialectName</code></td><td>string</td><td>true</td></tr>
<tr><td>smb</td><td><code>smb.dialectRevision</code></td><td>string</td><td>true</td></tr>
<tr><td>smb</td><td><code>smb.dnsComputer</code></td><td>string</td><td>true</td></tr>
<tr><td>smb</td><td><code>smb.dnsDomain</code></td><td>string</td><td>true</td></tr>
<tr><td>smb</td><td><code>smb.dnsTree</code></td><td>string</td><td>true</td></tr>
<tr><td>smb</td><td><code>smb.guid</code></td><td>string</td><td>true</td></tr>
<tr><td>smb</td><td><code>smb.hashAlg</code></td><td>string</td><td>false</td></tr>
<tr><td>smb</td><td><code>smb.hashAlgCnt</code></td><td>numeric</td><td>true</td></tr>
<tr><td>smb</td><td><code>smb.hashSaltLen</code></td><td>string</td><td>true</td></tr>
<tr><td>smb</td><td><code>smb.maxReadSize</code></td><td>string</td><td>true</td></tr>
<tr><td>smb</td><td><code>smb.maxTransactSize</code></td><td>string</td><td>true</td></tr>
<tr><td>smb</td><td><code>smb.maxWriteSize</code></td><td>string</td><td>true</td></tr>
<tr><td>smb</td><td><code>smb.nativeLM</code></td><td>string</td><td>true</td></tr>
<tr><td>smb</td><td><code>smb.nativeOS</code></td><td>string</td><td>true</td></tr>
<tr><td>smb</td><td><code>smb.negCtxCnt</code></td><td>numeric</td><td>true</td></tr>
<tr><td>smb</td><td><code>smb.netName</code></td><td>string</td><td>true</td></tr>
<tr><td>smb</td><td><code>smb.netbiosComputer</code></td><td>string</td><td>true</td></tr>
<tr><td>smb</td><td><code>smb.netbiosDomain</code></td><td>string</td><td>true</td></tr>
<tr><td>smb</td><td><code>smb.ntStatus</code></td><td>string</td><td>true</td></tr>
<tr><td>smb</td><td><code>smb.ntlm.serverChallenge</code></td><td>string</td><td>true</td></tr>
<tr><td>smb</td><td><code>smb.ntlmssp</code></td><td>string</td><td>true</td></tr>
<tr><td>smb</td><td><code>smb.ntlmsspNegFlags</code></td><td>string</td><td>true</td></tr>
<tr><td>smb</td><td><code>smb.ntlmsspVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>smb</td><td><code>smb.posixExtensions</code></td><td>string</td><td>true</td></tr>
<tr><td>smb</td><td><code>smb.rdmaTransformCnt</code></td><td>numeric</td><td>true</td></tr>
<tr><td>smb</td><td><code>smb.rdmaTransforms</code></td><td>string</td><td>false</td></tr>
<tr><td>smb</td><td><code>smb.securityMode</code></td><td>string</td><td>true</td></tr>
<tr><td>smb</td><td><code>smb.serverGUID</code></td><td>string</td><td>true</td></tr>
<tr><td>smb</td><td><code>smb.sessionID</code></td><td>string</td><td>true</td></tr>
<tr><td>smb</td><td><code>smb.signing</code></td><td>string</td><td>true</td></tr>
<tr><td>smb</td><td><code>smb.signingAlg</code></td><td>string</td><td>false</td></tr>
<tr><td>smb</td><td><code>smb.signingAlgCnt</code></td><td>numeric</td><td>true</td></tr>
<tr><td>smb</td><td><code>smb.signingEnabled</code></td><td>boolean</td><td>true</td></tr>
<tr><td>smb</td><td><code>smb.signingRequired</code></td><td>boolean</td><td>true</td></tr>
<tr><td>smb</td><td><code>smb.supportsEncryptedPasswords</code></td><td>numeric</td><td>true</td></tr>
<tr><td>smb</td><td><code>smb.timestamp</code></td><td>numeric</td><td>true</td></tr>
<tr><td>smb</td><td><code>smb.timestampTS</code></td><td>numeric</td><td>true</td></tr>
<tr><td>smb</td><td><code>smb.transportSecurity</code></td><td>numeric</td><td>true</td></tr>
<tr><td>smb</td><td><code>smb.version</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
</tbody>
<tbody>
</tbody>
<tbody>
<tr><td>smb3</td><td><code>ntlmssp.dnsComputer</code></td><td>string</td><td>true</td></tr>
<tr><td>smb3</td><td><code>ntlmssp.dnsDomain</code></td><td>string</td><td>true</td></tr>
<tr><td>smb3</td><td><code>ntlmssp.negFlags</code></td><td>string</td><td>true</td></tr>
<tr><td>smb3</td><td><code>ntlmssp.netbiosComputer</code></td><td>string</td><td>true</td></tr>
<tr><td>smb3</td><td><code>ntlmssp.netbiosDomain</code></td><td>string</td><td>true</td></tr>
<tr><td>smb3</td><td><code>ntlmssp.ntlmRevision</code></td><td>numeric</td><td>true</td></tr>
<tr><td>smb3</td><td><code>ntlmssp.targetName</code></td><td>string</td><td>true</td></tr>
<tr><td>smb3</td><td><code>ntlmssp.version</code></td><td>string</td><td>true</td></tr>
<tr><td>smb3</td><td><code>ntlmssp.versionInvalid</code></td><td>string</td><td>true</td></tr>
<tr><td>smb3</td><td><code>smb.accessControl</code></td><td>string</td><td>true</td></tr>
<tr><td>smb3</td><td><code>smb.capabilities</code></td><td>string</td><td>true</td></tr>
<tr><td>smb3</td><td><code>smb.cipherAlg</code></td><td>string</td><td>false</td></tr>
<tr><td>smb3</td><td><code>smb.cipherAlgCnt</code></td><td>string</td><td>true</td></tr>
<tr><td>smb3</td><td><code>smb.compAlg</code></td><td>string</td><td>false</td></tr>
<tr><td>smb3</td><td><code>smb.compAlgCnt</code></td><td>string</td><td>true</td></tr>
<tr><td>smb3</td><td><code>smb.compFlags</code></td><td>numeric</td><td>true</td></tr>
<tr><td>smb3</td><td><code>smb.dialect</code></td><td>string</td><td>true</td></tr>
<tr><td>smb3</td><td><code>smb.guid</code></td><td>string</td><td>true</td></tr>
<tr><td>smb3</td><td><code>smb.hashAlg</code></td><td>string</td><td>false</td></tr>
<tr><td>smb3</td><td><code>smb.hashAlgCnt</code></td><td>string</td><td>true</td></tr>
<tr><td>smb3</td><td><code>smb.hashSaltLen</code></td><td>string</td><td>true</td></tr>
<tr><td>smb3</td><td><code>smb.nativeLM</code></td><td>string</td><td>true</td></tr>
<tr><td>smb3</td><td><code>smb.nativeOS</code></td><td>string</td><td>true</td></tr>
<tr><td>smb3</td><td><code>smb.netName</code></td><td>string</td><td>true</td></tr>
<tr><td>smb3</td><td><code>smb.netbiosComputer</code></td><td>string</td><td>true</td></tr>
<tr><td>smb3</td><td><code>smb.netbiosDomain</code></td><td>string</td><td>true</td></tr>
<tr><td>smb3</td><td><code>smb.posixExtensions</code></td><td>string</td><td>true</td></tr>
<tr><td>smb3</td><td><code>smb.rdmaTransformCnt</code></td><td>string</td><td>true</td></tr>
<tr><td>smb3</td><td><code>smb.rdmaTransforms</code></td><td>string</td><td>false</td></tr>
<tr><td>smb3</td><td><code>smb.sessionID</code></td><td>string</td><td>true</td></tr>
<tr><td>smb3</td><td><code>smb.signing</code></td><td>string</td><td>true</td></tr>
<tr><td>smb3</td><td><code>smb.signingAlg</code></td><td>string</td><td>false</td></tr>
<tr><td>smb3</td><td><code>smb.signingAlgCnt</code></td><td>string</td><td>true</td></tr>
<tr><td>smb3</td><td><code>smb.supportsEncryptedPasswords</code></td><td>string</td><td>true</td></tr>
<tr><td>smb3</td><td><code>smb.transportSecurity</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>smpp</td><td><code>smpp.commandID</code></td><td>string</td><td>true</td></tr>
<tr><td>smpp</td><td><code>smpp.commandStatus</code></td><td>string</td><td>true</td></tr>
<tr><td>smpp</td><td><code>smpp.interfaceVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>smpp</td><td><code>smpp.product</code></td><td>string</td><td>true</td></tr>
<tr><td>smpp</td><td><code>smpp.systemID</code></td><td>string</td><td>true</td></tr>
<tr><td>smpp</td><td><code>smpp.vendor</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>smtp</td><td><code>smtp.authMethods</code></td><td>string</td><td>true</td></tr>
<tr><td>smtp</td><td><code>smtp.banner</code></td><td>string</td><td>true</td></tr>
<tr><td>smtp</td><td><code>smtp.eightBitMime</code></td><td>string</td><td>true</td></tr>
<tr><td>smtp</td><td><code>smtp.enhancedStatusCodes</code></td><td>string</td><td>true</td></tr>
<tr><td>smtp</td><td><code>smtp.esmtp</code></td><td>string</td><td>true</td></tr>
<tr><td>smtp</td><td><code>smtp.extensions</code></td><td>string</td><td>true</td></tr>
<tr><td>smtp</td><td><code>smtp.hostname</code></td><td>string</td><td>true</td></tr>
<tr><td>smtp</td><td><code>smtp.maxSize</code></td><td>string</td><td>true</td></tr>
<tr><td>smtp</td><td><code>smtp.pipelining</code></td><td>string</td><td>true</td></tr>
<tr><td>smtp</td><td><code>smtp.startTLS</code></td><td>string</td><td>true</td></tr>
<tr><td>smtp</td><td><code>smtp.statusCode</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>snmp</td><td><code>snmp._secrets</code></td><td>string</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.a10.softwareVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.arpCount</code></td><td>numeric</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.arpcache</code></td><td>string</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.arpcache.oids</code></td><td>string</td><td>false</td></tr>
<tr><td>snmp</td><td><code>snmp.arpcache.ports</code></td><td>numeric</td><td>false</td></tr>
<tr><td>snmp</td><td><code>snmp.cdpCapabilities</code></td><td>string</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.cdpDeviceIDs</code></td><td>string</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.cdpIPs</code></td><td>string</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.cdpNeighborCount</code></td><td>numeric</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.cdpPlatforms</code></td><td>string</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.cdpPortIDs</code></td><td>string</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.cisco.hardware</code></td><td>string</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.cisco.hardwareRev</code></td><td>string</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.cisco.softwareVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.community</code></td><td>string</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.credentials</code></td><td>string</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.defaultCommunities</code></td><td>string</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.engineBoots</code></td><td>numeric</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.engineID.enterpriseID</code></td><td>string</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.engineID.raw</code></td><td>string</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.engineID.vendor</code></td><td>string</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.engineTime</code></td><td>string</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.errorIndex</code></td><td>string</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.errorStatus</code></td><td>string</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.errorStatusName</code></td><td>string</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.extendOsReleaseFull</code></td><td>string</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.f5.hardware</code></td><td>string</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.f5.softwareBuild</code></td><td>string</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.f5.softwareVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.failedAuth</code></td><td>string</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.fortinet.fgSysVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.fortinet.fnSysSerial</code></td><td>string</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.fortinet.fnSysVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.hostname</code></td><td>string</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.ifCount</code></td><td>numeric</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.inauthentic</code></td><td>string</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.installedSWErr</code></td><td>string</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.installedSWHWHint</code></td><td>string</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.installedSWOSHint</code></td><td>string</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.installedSWProtoVer</code></td><td>string</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.installedSoftware</code></td><td>string</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.installedSoftwareCount</code></td><td>numeric</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.interfaceAddrs</code></td><td>string</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.interfaceAddrsMap</code></td><td>string</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.interfaceAliases</code></td><td>string</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.interfaceAliasesMap</code></td><td>string</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.interfaceCount</code></td><td>numeric</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.interfaceMacs</code></td><td>string</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.interfaceMacsMap</code></td><td>string</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.interfaceNames</code></td><td>string</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.interfaceNamesMap</code></td><td>string</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.interfaces</code></td><td>string</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.ivanti.esapVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.ivanti.productName</code></td><td>string</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.ivanti.productVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.juniper.serialNumbers</code></td><td>string</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.juniper.softwareVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.juniperModel</code></td><td>string</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.lldp.neighbor</code></td><td>string</td><td>false</td></tr>
<tr><td>snmp</td><td><code>snmp.lldpChassisIDTypes</code></td><td>string</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.lldpChassisIDs</code></td><td>string</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.lldpNeighborCount</code></td><td>numeric</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.lldpPortDescs</code></td><td>numeric</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.lldpPortIDs</code></td><td>numeric</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.lldpPortNums</code></td><td>numeric</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.lldpSysDescrs</code></td><td>string</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.lldpSysNames</code></td><td>string</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.macs.ports</code></td><td>numeric</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.macs.vlans</code></td><td>string</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.modelNames</code></td><td>string</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.msgMaxSize</code></td><td>string</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.pan.appDatabaseVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.pan.avDatabaseVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.pan.hardwareVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.pan.serialNumber</code></td><td>string</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.pan.softwareVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.pan.threatDatabaseVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.pan.urlDatabaseVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.pan.vpnClientVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.port</code></td><td>numeric</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.routeCount</code></td><td>numeric</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.routes</code></td><td>string</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.secretCommunities</code></td><td>string</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.serialNumbers</code></td><td>string</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.sonicwall.hardware</code></td><td>string</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.sonicwall.serialNumber</code></td><td>string</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.sonicwall.softwareVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.sophos.ha.peer</code></td><td>string</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.sophos.ha.status</code></td><td>string</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.sophos.hardware</code></td><td>string</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.sophos.softwareVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.sysContact</code></td><td>string</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.sysDesc</code></td><td>string</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.sysDescr</code></td><td>string</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.sysLocation</code></td><td>string</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.sysName</code></td><td>string</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.sysObjectID</code></td><td>string</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.sysServices</code></td><td>string</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.sysUpTimeFormatted</code></td><td>string</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.sysUptime</code></td><td>string</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.sysUptimeFormatted</code></td><td>string</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.target</code></td><td>string</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.username</code></td><td>string</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.usmStatsDecryptionErrors</code></td><td>string</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.usmStatsNotInTimeWindows</code></td><td>string</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.usmStatsUnknownEngineIDs</code></td><td>string</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.usmStatsUnknownUserNames</code></td><td>string</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.usmStatsUnsupportedSecLevels</code></td><td>numeric</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.usmStatsWrongDigests</code></td><td>numeric</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.varbindCount</code></td><td>numeric</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.version</code></td><td>string</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.versionCode</code></td><td>string</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.vlanCount</code></td><td>numeric</td><td>true</td></tr>
<tr><td>snmp</td><td><code>snmp.vlans</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>snpp</td><td><code>snpp.banner</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
</tbody>
<tbody>
<tr><td>socks4</td><td><code>socks4.anonymousAccess</code></td><td>string</td><td>true</td></tr>
<tr><td>socks4</td><td><code>socks4.status</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>socks5</td><td><code>socks5.authMethod</code></td><td>string</td><td>true</td></tr>
<tr><td>socks5</td><td><code>socks5.authRequired</code></td><td>boolean</td><td>true</td></tr>
<tr><td>socks5</td><td><code>socks5.noAcceptable</code></td><td>string</td><td>true</td></tr>
<tr><td>socks5</td><td><code>socks5.open</code></td><td>string</td><td>true</td></tr>
<tr><td>socks5</td><td><code>socks5.socks4</code></td><td>string</td><td>true</td></tr>
<tr><td>socks5</td><td><code>socks5.version</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>solr</td><td><code>service.product</code></td><td>string</td><td>true</td></tr>
<tr><td>solr</td><td><code>service.version</code></td><td>string</td><td>true</td></tr>
<tr><td>solr</td><td><code>solr.jvm.name</code></td><td>string</td><td>true</td></tr>
<tr><td>solr</td><td><code>solr.jvm.version</code></td><td>string</td><td>true</td></tr>
<tr><td>solr</td><td><code>solr.lucene.version</code></td><td>string</td><td>true</td></tr>
<tr><td>solr</td><td><code>solr.system.arch</code></td><td>string</td><td>true</td></tr>
<tr><td>solr</td><td><code>solr.system.name</code></td><td>string</td><td>true</td></tr>
<tr><td>solr</td><td><code>solr.system.version</code></td><td>string</td><td>true</td></tr>
<tr><td>solr</td><td><code>solr.version</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
</tbody>
<tbody>
</tbody>
<tbody>
</tbody>
<tbody>
</tbody>
<tbody>
<tr><td>splunk</td><td><code>splunk.build</code></td><td>string</td><td>true</td></tr>
<tr><td>splunk</td><td><code>splunk.version</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>spotify-connect</td><td><code>brandDisplayName</code></td><td>string</td><td>true</td></tr>
<tr><td>spotify-connect</td><td><code>clientID</code></td><td>string</td><td>true</td></tr>
<tr><td>spotify-connect</td><td><code>deviceID</code></td><td>string</td><td>true</td></tr>
<tr><td>spotify-connect</td><td><code>deviceType</code></td><td>string</td><td>true</td></tr>
<tr><td>spotify-connect</td><td><code>modelDisplayName</code></td><td>string</td><td>true</td></tr>
<tr><td>spotify-connect</td><td><code>remoteName</code></td><td>string</td><td>true</td></tr>
<tr><td>spotify-connect</td><td><code>scope</code></td><td>string</td><td>true</td></tr>
<tr><td>spotify-connect</td><td><code>status</code></td><td>string</td><td>true</td></tr>
<tr><td>spotify-connect</td><td><code>statusString</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
</tbody>
<tbody>
<tr><td>ssh</td><td><code>ssh.authMethods</code></td><td>string</td><td>false</td></tr>
<tr><td>ssh</td><td><code>ssh.banner</code></td><td>string</td><td>true</td></tr>
<tr><td>ssh</td><td><code>ssh.comments</code></td><td>numeric</td><td>true</td></tr>
<tr><td>ssh</td><td><code>ssh.error</code></td><td>string</td><td>true</td></tr>
<tr><td>ssh</td><td><code>ssh.exitStatus</code></td><td>string</td><td>true</td></tr>
<tr><td>ssh</td><td><code>ssh.extensionNames</code></td><td>string</td><td>true</td></tr>
<tr><td>ssh</td><td><code>ssh.extensions</code></td><td>string</td><td>false</td></tr>
<tr><td>ssh</td><td><code>ssh.firstKexFollows</code></td><td>string</td><td>true</td></tr>
<tr><td>ssh</td><td><code>ssh.hostKey</code></td><td>string</td><td>true</td></tr>
<tr><td>ssh</td><td><code>ssh.hostKey.bkhash</code></td><td>string</td><td>true</td></tr>
<tr><td>ssh</td><td><code>ssh.hostKey.data</code></td><td>string</td><td>true</td></tr>
<tr><td>ssh</td><td><code>ssh.hostKey.md5</code></td><td>string</td><td>true</td></tr>
<tr><td>ssh</td><td><code>ssh.hostKey.sha256</code></td><td>string</td><td>true</td></tr>
<tr><td>ssh</td><td><code>ssh.hostKeyAlgs</code></td><td>string</td><td>true</td></tr>
<tr><td>ssh</td><td><code>ssh.hostKeyCount</code></td><td>numeric</td><td>true</td></tr>
<tr><td>ssh</td><td><code>ssh.hostKeyTypes</code></td><td>string</td><td>false</td></tr>
<tr><td>ssh</td><td><code>ssh.kbdInstructions</code></td><td>string</td><td>true</td></tr>
<tr><td>ssh</td><td><code>ssh.kbdName</code></td><td>string</td><td>true</td></tr>
<tr><td>ssh</td><td><code>ssh.kbdQuestion</code></td><td>string</td><td>true</td></tr>
<tr><td>ssh</td><td><code>ssh.kexAlgs</code></td><td>string</td><td>true</td></tr>
<tr><td>ssh</td><td><code>ssh.kexCookie</code></td><td>string</td><td>true</td></tr>
<tr><td>ssh</td><td><code>ssh.kexPadding</code></td><td>string</td><td>true</td></tr>
<tr><td>ssh</td><td><code>ssh.preAuthBanner</code></td><td>string</td><td>true</td></tr>
<tr><td>ssh</td><td><code>ssh.protoVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>ssh</td><td><code>ssh.service</code></td><td>string</td><td>true</td></tr>
<tr><td>ssh</td><td><code>ssh.sessionMethod</code></td><td>string</td><td>true</td></tr>
<tr><td>ssh</td><td><code>ssh.sessionOutput</code></td><td>string</td><td>true</td></tr>
<tr><td>ssh</td><td><code>ssh.softwareVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>ssh</td><td><code>ssh.stage</code></td><td>string</td><td>true</td></tr>
<tr><td>ssh</td><td><code>ssh.toClientCiphers</code></td><td>string</td><td>true</td></tr>
<tr><td>ssh</td><td><code>ssh.toClientCompression</code></td><td>string</td><td>true</td></tr>
<tr><td>ssh</td><td><code>ssh.toClientComps</code></td><td>string</td><td>true</td></tr>
<tr><td>ssh</td><td><code>ssh.toClientLangs</code></td><td>string</td><td>true</td></tr>
<tr><td>ssh</td><td><code>ssh.toClientMACs</code></td><td>string</td><td>true</td></tr>
<tr><td>ssh</td><td><code>ssh.toServerCiphers</code></td><td>string</td><td>true</td></tr>
<tr><td>ssh</td><td><code>ssh.toServerCompression</code></td><td>string</td><td>true</td></tr>
<tr><td>ssh</td><td><code>ssh.toServerComps</code></td><td>string</td><td>true</td></tr>
<tr><td>ssh</td><td><code>ssh.toServerLangs</code></td><td>string</td><td>true</td></tr>
<tr><td>ssh</td><td><code>ssh.toServerMACs</code></td><td>string</td><td>true</td></tr>
<tr><td>ssh</td><td><code>ssh.version</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>sstp</td><td><code>sstp.server</code></td><td>string</td><td>true</td></tr>
<tr><td>sstp</td><td><code>sstp.vendor</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>steam</td><td><code>steam.authKeyIDs</code></td><td>string</td><td>true</td></tr>
<tr><td>steam</td><td><code>steam.broadcastingActive</code></td><td>string</td><td>true</td></tr>
<tr><td>steam</td><td><code>steam.clientID</code></td><td>string</td><td>true</td></tr>
<tr><td>steam</td><td><code>steam.connectPort</code></td><td>string</td><td>true</td></tr>
<tr><td>steam</td><td><code>steam.contentCachePort</code></td><td>string</td><td>true</td></tr>
<tr><td>steam</td><td><code>steam.deviceID</code></td><td>string</td><td>true</td></tr>
<tr><td>steam</td><td><code>steam.downloadLANPeerGroup</code></td><td>string</td><td>true</td></tr>
<tr><td>steam</td><td><code>steam.eUniverse</code></td><td>string</td><td>true</td></tr>
<tr><td>steam</td><td><code>steam.enabledServices</code></td><td>string</td><td>true</td></tr>
<tr><td>steam</td><td><code>steam.gamesRunning</code></td><td>string</td><td>true</td></tr>
<tr><td>steam</td><td><code>steam.hostname</code></td><td>string</td><td>true</td></tr>
<tr><td>steam</td><td><code>steam.instanceID</code></td><td>string</td><td>true</td></tr>
<tr><td>steam</td><td><code>steam.ipAddresses</code></td><td>string</td><td>true</td></tr>
<tr><td>steam</td><td><code>steam.is64Bit</code></td><td>string</td><td>true</td></tr>
<tr><td>steam</td><td><code>steam.isSteamDeck</code></td><td>string</td><td>true</td></tr>
<tr><td>steam</td><td><code>steam.macAddresses</code></td><td>string</td><td>true</td></tr>
<tr><td>steam</td><td><code>steam.minVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>steam</td><td><code>steam.osType</code></td><td>string</td><td>true</td></tr>
<tr><td>steam</td><td><code>steam.publicIPAddress</code></td><td>string</td><td>true</td></tr>
<tr><td>steam</td><td><code>steam.remotePlayActive</code></td><td>string</td><td>true</td></tr>
<tr><td>steam</td><td><code>steam.screenLocked</code></td><td>string</td><td>true</td></tr>
<tr><td>steam</td><td><code>steam.steamIDs</code></td><td>string</td><td>true</td></tr>
<tr><td>steam</td><td><code>steam.steamVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>steam</td><td><code>steam.supportedServices</code></td><td>string</td><td>true</td></tr>
<tr><td>steam</td><td><code>steam.timestamp</code></td><td>string</td><td>true</td></tr>
<tr><td>steam</td><td><code>steam.version</code></td><td>string</td><td>true</td></tr>
<tr><td>steam</td><td><code>steam.vrActive</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>stun</td><td><code>stun.attributeCount</code></td><td>numeric</td><td>true</td></tr>
<tr><td>stun</td><td><code>stun.attributes</code></td><td>string</td><td>true</td></tr>
<tr><td>stun</td><td><code>stun.errorCode</code></td><td>string</td><td>true</td></tr>
<tr><td>stun</td><td><code>stun.errorReason</code></td><td>string</td><td>true</td></tr>
<tr><td>stun</td><td><code>stun.fingerprint</code></td><td>string</td><td>true</td></tr>
<tr><td>stun</td><td><code>stun.mappedAddress</code></td><td>string</td><td>true</td></tr>
<tr><td>stun</td><td><code>stun.mappedIP</code></td><td>string</td><td>true</td></tr>
<tr><td>stun</td><td><code>stun.mappedPort</code></td><td>numeric</td><td>true</td></tr>
<tr><td>stun</td><td><code>stun.messageClass</code></td><td>string</td><td>true</td></tr>
<tr><td>stun</td><td><code>stun.messageLength</code></td><td>string</td><td>true</td></tr>
<tr><td>stun</td><td><code>stun.messageMethod</code></td><td>string</td><td>true</td></tr>
<tr><td>stun</td><td><code>stun.otherAddress</code></td><td>string</td><td>true</td></tr>
<tr><td>stun</td><td><code>stun.responseOrigin</code></td><td>string</td><td>true</td></tr>
<tr><td>stun</td><td><code>stun.software</code></td><td>string</td><td>true</td></tr>
<tr><td>stun</td><td><code>stun.transactionID</code></td><td>string</td><td>true</td></tr>
<tr><td>stun</td><td><code>stun.type</code></td><td>string</td><td>true</td></tr>
<tr><td>stun</td><td><code>stun.xorMappedAddress</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>sua</td><td><code>sua.errorCode</code></td><td>string</td><td>true</td></tr>
<tr><td>sua</td><td><code>sua.infoString</code></td><td>string</td><td>true</td></tr>
<tr><td>sua</td><td><code>sua.messageClass</code></td><td>string</td><td>true</td></tr>
<tr><td>sua</td><td><code>sua.messageType</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
</tbody>
<tbody>
<tr><td>sunrpc</td><td><code>rpcbind.mappingCount</code></td><td>string</td><td>true</td></tr>
<tr><td>sunrpc</td><td><code>rpcbind.mountd</code></td><td>string</td><td>true</td></tr>
<tr><td>sunrpc</td><td><code>rpcbind.nfs</code></td><td>string</td><td>true</td></tr>
<tr><td>sunrpc</td><td><code>rpcbind.programs</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>svn</td><td><code>svn.authMechanisms</code></td><td>string</td><td>true</td></tr>
<tr><td>svn</td><td><code>svn.banner</code></td><td>string</td><td>true</td></tr>
<tr><td>svn</td><td><code>svn.capabilities</code></td><td>string</td><td>true</td></tr>
<tr><td>svn</td><td><code>svn.maxVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>svn</td><td><code>svn.minVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>svn</td><td><code>svn.repoURL</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>sybase</td><td><code>sybase.target</code></td><td>string</td><td>true</td></tr>
<tr><td>sybase</td><td><code>sybase.version</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>syslog</td><td><code>syslog.appName</code></td><td>string</td><td>true</td></tr>
<tr><td>syslog</td><td><code>syslog.facility</code></td><td>string</td><td>true</td></tr>
<tr><td>syslog</td><td><code>syslog.facilityName</code></td><td>string</td><td>true</td></tr>
<tr><td>syslog</td><td><code>syslog.hostname</code></td><td>string</td><td>true</td></tr>
<tr><td>syslog</td><td><code>syslog.priority</code></td><td>string</td><td>true</td></tr>
<tr><td>syslog</td><td><code>syslog.rfc</code></td><td>string</td><td>true</td></tr>
<tr><td>syslog</td><td><code>syslog.severity</code></td><td>string</td><td>true</td></tr>
<tr><td>syslog</td><td><code>syslog.severityName</code></td><td>string</td><td>true</td></tr>
<tr><td>syslog</td><td><code>syslog.version</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
</tbody>
<tbody>
<tr><td>teamviewer</td><td><code>teamviewer.command</code></td><td>string</td><td>true</td></tr>
<tr><td>teamviewer</td><td><code>teamviewer.magic</code></td><td>string</td><td>true</td></tr>
<tr><td>teamviewer</td><td><code>teamviewer.response</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>telnet</td><td><code>telnet.banner</code></td><td>string</td><td>true</td></tr>
<tr><td>telnet</td><td><code>telnet.do</code></td><td>string</td><td>true</td></tr>
<tr><td>telnet</td><td><code>telnet.doText</code></td><td>string</td><td>true</td></tr>
<tr><td>telnet</td><td><code>telnet.dont</code></td><td>string</td><td>true</td></tr>
<tr><td>telnet</td><td><code>telnet.dontText</code></td><td>string</td><td>true</td></tr>
<tr><td>telnet</td><td><code>telnet.hasIAC</code></td><td>string</td><td>true</td></tr>
<tr><td>telnet</td><td><code>telnet.hasLogin</code></td><td>string</td><td>true</td></tr>
<tr><td>telnet</td><td><code>telnet.hasPassword</code></td><td>string</td><td>true</td></tr>
<tr><td>telnet</td><td><code>telnet.will</code></td><td>string</td><td>true</td></tr>
<tr><td>telnet</td><td><code>telnet.willText</code></td><td>string</td><td>true</td></tr>
<tr><td>telnet</td><td><code>telnet.wont</code></td><td>string</td><td>true</td></tr>
<tr><td>telnet</td><td><code>telnet.wontText</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
</tbody>
<tbody>
<tr><td>tftp</td><td><code>tftp.banner</code></td><td>string</td><td>true</td></tr>
<tr><td>tftp</td><td><code>tftp.error</code></td><td>string</td><td>true</td></tr>
<tr><td>tftp</td><td><code>tftp.example.test</code></td><td>string</td><td>true</td></tr>
<tr><td>tftp</td><td><code>tftp.message</code></td><td>string</td><td>true</td></tr>
<tr><td>tftp</td><td><code>tftp.mode</code></td><td>string</td><td>true</td></tr>
<tr><td>tftp</td><td><code>tftp.opcode</code></td><td>string</td><td>true</td></tr>
<tr><td>tftp</td><td><code>tftp.rrq.filename</code></td><td>string</td><td>true</td></tr>
<tr><td>tftp</td><td><code>tftp.wrq.filename</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
</tbody>
<tbody>
<tr><td>time</td><td><code>time.skew</code></td><td>string</td><td>true</td></tr>
<tr><td>time</td><td><code>time.skewMS</code></td><td>string</td><td>true</td></tr>
<tr><td>time</td><td><code>time.timestamp</code></td><td>numeric</td><td>true</td></tr>
<tr><td>time</td><td><code>time.value</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>tls</td><td><code>tls.alert</code></td><td>string</td><td>true</td></tr>
<tr><td>tls</td><td><code>tls.alertDescription</code></td><td>string</td><td>true</td></tr>
<tr><td>tls</td><td><code>tls.alertLevel</code></td><td>string</td><td>true</td></tr>
<tr><td>tls</td><td><code>tls.alpn</code></td><td>string</td><td>true</td></tr>
<tr><td>tls</td><td><code>tls.authorityKeyID</code></td><td>string</td><td>true</td></tr>
<tr><td>tls</td><td><code>tls.caUnknown</code></td><td>string</td><td>true</td></tr>
<tr><td>tls</td><td><code>tls.certificate</code></td><td>string</td><td>true</td></tr>
<tr><td>tls</td><td><code>tls.certificateCount</code></td><td>numeric</td><td>true</td></tr>
<tr><td>tls</td><td><code>tls.certificateParseError</code></td><td>string</td><td>true</td></tr>
<tr><td>tls</td><td><code>tls.certificates</code></td><td>string</td><td>true</td></tr>
<tr><td>tls</td><td><code>tls.chainFingerprints</code></td><td>numeric</td><td>true</td></tr>
<tr><td>tls</td><td><code>tls.cipher</code></td><td>string</td><td>true</td></tr>
<tr><td>tls</td><td><code>tls.cipherName</code></td><td>string</td><td>true</td></tr>
<tr><td>tls</td><td><code>tls.cipherSuiteNames</code></td><td>string</td><td>true</td></tr>
<tr><td>tls</td><td><code>tls.cipherSuites</code></td><td>string</td><td>true</td></tr>
<tr><td>tls</td><td><code>tls.cn</code></td><td>string</td><td>true</td></tr>
<tr><td>tls</td><td><code>tls.compression</code></td><td>string</td><td>true</td></tr>
<tr><td>tls</td><td><code>tls.crl</code></td><td>string</td><td>false</td></tr>
<tr><td>tls</td><td><code>tls.emails</code></td><td>string</td><td>false</td></tr>
<tr><td>tls</td><td><code>tls.errors</code></td><td>string</td><td>true</td></tr>
<tr><td>tls</td><td><code>tls.expired</code></td><td>string</td><td>true</td></tr>
<tr><td>tls</td><td><code>tls.extensionNames</code></td><td>string</td><td>true</td></tr>
<tr><td>tls</td><td><code>tls.extensions</code></td><td>string</td><td>true</td></tr>
<tr><td>tls</td><td><code>tls.fp.bkhash</code></td><td>string</td><td>true</td></tr>
<tr><td>tls</td><td><code>tls.fp.caSha1</code></td><td>string</td><td>false</td></tr>
<tr><td>tls</td><td><code>tls.fp.sha1</code></td><td>string</td><td>true</td></tr>
<tr><td>tls</td><td><code>tls.fp.sha1Hex</code></td><td>string</td><td>true</td></tr>
<tr><td>tls</td><td><code>tls.fp.sha256</code></td><td>string</td><td>true</td></tr>
<tr><td>tls</td><td><code>tls.helloVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>tls</td><td><code>tls.hostTime</code></td><td>string</td><td>true</td></tr>
<tr><td>tls</td><td><code>tls.hostTimeTS</code></td><td>numeric</td><td>true</td></tr>
<tr><td>tls</td><td><code>tls.issuer</code></td><td>string</td><td>true</td></tr>
<tr><td>tls</td><td><code>tls.issuingURL</code></td><td>string</td><td>false</td></tr>
<tr><td>tls</td><td><code>tls.names</code></td><td>string</td><td>false</td></tr>
<tr><td>tls</td><td><code>tls.negotiationError</code></td><td>string</td><td>true</td></tr>
<tr><td>tls</td><td><code>tls.notAfter</code></td><td>string</td><td>true</td></tr>
<tr><td>tls</td><td><code>tls.notAfterTS</code></td><td>numeric</td><td>true</td></tr>
<tr><td>tls</td><td><code>tls.notBefore</code></td><td>string</td><td>true</td></tr>
<tr><td>tls</td><td><code>tls.notBeforeTS</code></td><td>numeric</td><td>true</td></tr>
<tr><td>tls</td><td><code>tls.ocsp</code></td><td>string</td><td>false</td></tr>
<tr><td>tls</td><td><code>tls.ocspResponse</code></td><td>string</td><td>true</td></tr>
<tr><td>tls</td><td><code>tls.port</code></td><td>numeric</td><td>true</td></tr>
<tr><td>tls</td><td><code>tls.pqHybridKeyExchangeCodes</code></td><td>string</td><td>false</td></tr>
<tr><td>tls</td><td><code>tls.pqHybridKeyExchangeNames</code></td><td>string</td><td>false</td></tr>
<tr><td>tls</td><td><code>tls.pqc</code></td><td>string</td><td>false</td></tr>
<tr><td>tls</td><td><code>tls.publicKeyAlgorithm</code></td><td>string</td><td>true</td></tr>
<tr><td>tls</td><td><code>tls.random</code></td><td>string</td><td>true</td></tr>
<tr><td>tls</td><td><code>tls.requiresClientCertificate</code></td><td>string</td><td>true</td></tr>
<tr><td>tls</td><td><code>tls.rzfp</code></td><td>string</td><td>true</td></tr>
<tr><td>tls</td><td><code>tls.rzfp0</code></td><td>string</td><td>true</td></tr>
<tr><td>tls</td><td><code>tls.sans</code></td><td>string</td><td>true</td></tr>
<tr><td>tls</td><td><code>tls.selfSigned</code></td><td>string</td><td>true</td></tr>
<tr><td>tls</td><td><code>tls.serial</code></td><td>string</td><td>true</td></tr>
<tr><td>tls</td><td><code>tls.sessionID</code></td><td>string</td><td>true</td></tr>
<tr><td>tls</td><td><code>tls.signatureAlgorithm</code></td><td>string</td><td>true</td></tr>
<tr><td>tls</td><td><code>tls.stack</code></td><td>string</td><td>true</td></tr>
<tr><td>tls</td><td><code>tls.subject</code></td><td>string</td><td>true</td></tr>
<tr><td>tls</td><td><code>tls.subjectKeyID</code></td><td>string</td><td>true</td></tr>
<tr><td>tls</td><td><code>tls.supportedVersionCodes</code></td><td>string</td><td>true</td></tr>
<tr><td>tls</td><td><code>tls.supportedVersionNames</code></td><td>string</td><td>false</td></tr>
<tr><td>tls</td><td><code>tls.supportedVersions</code></td><td>string</td><td>false</td></tr>
<tr><td>tls</td><td><code>tls.target</code></td><td>string</td><td>true</td></tr>
<tr><td>tls</td><td><code>tls.uri</code></td><td>string</td><td>false</td></tr>
<tr><td>tls</td><td><code>tls.version</code></td><td>string</td><td>true</td></tr>
<tr><td>tls</td><td><code>tls.versionName</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
</tbody>
<tbody>
<tr><td>turn</td><td><code>turn.attributeCount</code></td><td>numeric</td><td>true</td></tr>
<tr><td>turn</td><td><code>turn.attributes</code></td><td>string</td><td>true</td></tr>
<tr><td>turn</td><td><code>turn.errorCode</code></td><td>string</td><td>true</td></tr>
<tr><td>turn</td><td><code>turn.errorReason</code></td><td>string</td><td>true</td></tr>
<tr><td>turn</td><td><code>turn.fingerprint</code></td><td>string</td><td>true</td></tr>
<tr><td>turn</td><td><code>turn.lifetime</code></td><td>string</td><td>true</td></tr>
<tr><td>turn</td><td><code>turn.mappedAddress</code></td><td>string</td><td>true</td></tr>
<tr><td>turn</td><td><code>turn.mappedIP</code></td><td>string</td><td>true</td></tr>
<tr><td>turn</td><td><code>turn.mappedPort</code></td><td>numeric</td><td>true</td></tr>
<tr><td>turn</td><td><code>turn.messageClass</code></td><td>string</td><td>true</td></tr>
<tr><td>turn</td><td><code>turn.messageMethod</code></td><td>string</td><td>true</td></tr>
<tr><td>turn</td><td><code>turn.nonce</code></td><td>string</td><td>true</td></tr>
<tr><td>turn</td><td><code>turn.realm</code></td><td>string</td><td>true</td></tr>
<tr><td>turn</td><td><code>turn.relayedIP</code></td><td>string</td><td>true</td></tr>
<tr><td>turn</td><td><code>turn.relayedPort</code></td><td>numeric</td><td>true</td></tr>
<tr><td>turn</td><td><code>turn.requestedTransport</code></td><td>numeric</td><td>true</td></tr>
<tr><td>turn</td><td><code>turn.software</code></td><td>string</td><td>true</td></tr>
<tr><td>turn</td><td><code>turn.type</code></td><td>string</td><td>true</td></tr>
<tr><td>turn</td><td><code>turn.xorMappedAddress</code></td><td>string</td><td>true</td></tr>
<tr><td>turn</td><td><code>turn.xorRelayedAddress</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>ubnt</td><td><code>ubnt.addrs</code></td><td>string</td><td>false</td></tr>
<tr><td>ubnt</td><td><code>ubnt.configStatus</code></td><td>string</td><td>true</td></tr>
<tr><td>ubnt</td><td><code>ubnt.directConnectDomain</code></td><td>string</td><td>true</td></tr>
<tr><td>ubnt</td><td><code>ubnt.essid</code></td><td>string</td><td>true</td></tr>
<tr><td>ubnt</td><td><code>ubnt.firmware</code></td><td>string</td><td>true</td></tr>
<tr><td>ubnt</td><td><code>ubnt.hostName</code></td><td>string</td><td>true</td></tr>
<tr><td>ubnt</td><td><code>ubnt.interfaceMap</code></td><td>string</td><td>false</td></tr>
<tr><td>ubnt</td><td><code>ubnt.macs</code></td><td>string</td><td>false</td></tr>
<tr><td>ubnt</td><td><code>ubnt.modelFull</code></td><td>string</td><td>true</td></tr>
<tr><td>ubnt</td><td><code>ubnt.modelShort</code></td><td>string</td><td>true</td></tr>
<tr><td>ubnt</td><td><code>ubnt.protoVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>ubnt</td><td><code>ubnt.sourceMAC</code></td><td>string</td><td>false</td></tr>
<tr><td>ubnt</td><td><code>ubnt.unifiVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>ubnt</td><td><code>ubnt.uptime</code></td><td>string</td><td>true</td></tr>
<tr><td>ubnt</td><td><code>ubnt.webMgmtPort</code></td><td>string</td><td>true</td></tr>
<tr><td>ubnt</td><td><code>ubnt.webMgmtTLS</code></td><td>string</td><td>true</td></tr>
<tr><td>ubnt</td><td><code>ubnt.wmode</code></td><td>string</td><td>false</td></tr>
</tbody>
<tbody>
<tr><td>unitronics</td><td><code>unitronics.cpe</code></td><td>string</td><td>true</td></tr>
<tr><td>unitronics</td><td><code>unitronics.hwVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>unitronics</td><td><code>unitronics.model</code></td><td>string</td><td>true</td></tr>
<tr><td>unitronics</td><td><code>unitronics.osVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>unitronics</td><td><code>unitronics.unitID</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>upnp</td><td><code>upnp.controlURL</code></td><td>string</td><td>true</td></tr>
<tr><td>upnp</td><td><code>upnp.deviceType</code></td><td>string</td><td>true</td></tr>
<tr><td>upnp</td><td><code>upnp.eventSubURL</code></td><td>string</td><td>true</td></tr>
<tr><td>upnp</td><td><code>upnp.friendlyName</code></td><td>string</td><td>true</td></tr>
<tr><td>upnp</td><td><code>upnp.manufacturer</code></td><td>string</td><td>true</td></tr>
<tr><td>upnp</td><td><code>upnp.manufacturerURL</code></td><td>string</td><td>true</td></tr>
<tr><td>upnp</td><td><code>upnp.modelDescription</code></td><td>string</td><td>true</td></tr>
<tr><td>upnp</td><td><code>upnp.modelName</code></td><td>string</td><td>true</td></tr>
<tr><td>upnp</td><td><code>upnp.modelNumber</code></td><td>string</td><td>true</td></tr>
<tr><td>upnp</td><td><code>upnp.modelURL</code></td><td>string</td><td>true</td></tr>
<tr><td>upnp</td><td><code>upnp.presentationURL</code></td><td>string</td><td>true</td></tr>
<tr><td>upnp</td><td><code>upnp.scpdURL</code></td><td>string</td><td>true</td></tr>
<tr><td>upnp</td><td><code>upnp.serialNumber</code></td><td>string</td><td>true</td></tr>
<tr><td>upnp</td><td><code>upnp.udn</code></td><td>string</td><td>true</td></tr>
<tr><td>upnp</td><td><code>upnp.upc</code></td><td>string</td><td>true</td></tr>
<tr><td>upnp</td><td><code>upnp.url</code></td><td>string</td><td>true</td></tr>
<tr><td>upnp</td><td><code>upnp.urlBase</code></td><td>string</td><td>true</td></tr>
<tr><td>upnp</td><td><code>upnp.wifiMac</code></td><td>string</td><td>true</td></tr>
<tr><td>upnp</td><td><code>upnp.wiredMac</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>uscan</td><td><code>uscan.makeAndModel</code></td><td>string</td><td>true</td></tr>
<tr><td>uscan</td><td><code>uscan.manufacturer</code></td><td>string</td><td>true</td></tr>
<tr><td>uscan</td><td><code>uscan.serialNumber</code></td><td>string</td><td>true</td></tr>
<tr><td>uscan</td><td><code>uscan.version</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
</tbody>
<tbody>
<tr><td>vault</td><td><code>vault.version</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
</tbody>
<tbody>
<tr><td>vmware</td><td><code>http.vmware.thumbprint</code></td><td>string</td><td>true</td></tr>
<tr><td>vmware</td><td><code>service.product</code></td><td>string</td><td>true</td></tr>
<tr><td>vmware</td><td><code>service.vendor</code></td><td>string</td><td>true</td></tr>
<tr><td>vmware</td><td><code>service.version</code></td><td>string</td><td>true</td></tr>
<tr><td>vmware</td><td><code>vmware.apiType</code></td><td>string</td><td>true</td></tr>
<tr><td>vmware</td><td><code>vmware.apiVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>vmware</td><td><code>vmware.build</code></td><td>string</td><td>true</td></tr>
<tr><td>vmware</td><td><code>vmware.fullName</code></td><td>string</td><td>true</td></tr>
<tr><td>vmware</td><td><code>vmware.name</code></td><td>string</td><td>true</td></tr>
<tr><td>vmware</td><td><code>vmware.osType</code></td><td>string</td><td>true</td></tr>
<tr><td>vmware</td><td><code>vmware.productLineID</code></td><td>string</td><td>true</td></tr>
<tr><td>vmware</td><td><code>vmware.version</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>vnc</td><td><code>vnc.banner</code></td><td>string</td><td>true</td></tr>
<tr><td>vnc</td><td><code>vnc.desktopName</code></td><td>string</td><td>true</td></tr>
<tr><td>vnc</td><td><code>vnc.error</code></td><td>string</td><td>true</td></tr>
<tr><td>vnc</td><td><code>vnc.framebufferHeight</code></td><td>string</td><td>true</td></tr>
<tr><td>vnc</td><td><code>vnc.framebufferWidth</code></td><td>string</td><td>true</td></tr>
<tr><td>vnc</td><td><code>vnc.majorVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>vnc</td><td><code>vnc.minorVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>vnc</td><td><code>vnc.noAuth</code></td><td>string</td><td>true</td></tr>
<tr><td>vnc</td><td><code>vnc.securityTypeCount</code></td><td>numeric</td><td>true</td></tr>
<tr><td>vnc</td><td><code>vnc.securityTypes</code></td><td>string</td><td>true</td></tr>
<tr><td>vnc</td><td><code>vnc.version</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
</tbody>
<tbody>
</tbody>
<tbody>
</tbody>
<tbody>
<tr><td>wbsm</td><td><code>wbsm.active</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
</tbody>
<tbody>
<tr><td>webmin</td><td><code>webmin.port</code></td><td>string</td><td>true</td></tr>
<tr><td>webmin</td><td><code>webmin.scheme</code></td><td>string</td><td>true</td></tr>
<tr><td>webmin</td><td><code>webmin.server</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>wireguard</td><td><code>wireguard.confidence</code></td><td>string</td><td>true</td></tr>
<tr><td>wireguard</td><td><code>wireguard.detection</code></td><td>string</td><td>true</td></tr>
<tr><td>wireguard</td><td><code>wireguard.payloadLength</code></td><td>string</td><td>true</td></tr>
<tr><td>wireguard</td><td><code>wireguard.receiverIndex</code></td><td>string</td><td>true</td></tr>
<tr><td>wireguard</td><td><code>wireguard.receiverIndexHex</code></td><td>string</td><td>true</td></tr>
<tr><td>wireguard</td><td><code>wireguard.receiverIndexMatches</code></td><td>string</td><td>true</td></tr>
<tr><td>wireguard</td><td><code>wireguard.responseType</code></td><td>string</td><td>true</td></tr>
<tr><td>wireguard</td><td><code>wireguard.responseTypeName</code></td><td>string</td><td>true</td></tr>
<tr><td>wireguard</td><td><code>wireguard.senderIndex</code></td><td>string</td><td>true</td></tr>
<tr><td>wireguard</td><td><code>wireguard.senderIndexHex</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>wiznet</td><td><code>wiznet.fields</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>wsd</td><td><code>wsd.addrs</code></td><td>string</td><td>false</td></tr>
<tr><td>wsd</td><td><code>wsd.types</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>wsman</td><td><code>wsman.body</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>x11</td><td><code>x11.accessGranted</code></td><td>string</td><td>true</td></tr>
<tr><td>x11</td><td><code>x11.anonymousAccess</code></td><td>string</td><td>true</td></tr>
<tr><td>x11</td><td><code>x11.displayNumber</code></td><td>string</td><td>true</td></tr>
<tr><td>x11</td><td><code>x11.failureReason</code></td><td>string</td><td>true</td></tr>
<tr><td>x11</td><td><code>x11.status</code></td><td>string</td><td>true</td></tr>
<tr><td>x11</td><td><code>x11.vendor</code></td><td>string</td><td>true</td></tr>
<tr><td>x11</td><td><code>x11.version</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>x2ap</td><td><code>x2ap.criticality</code></td><td>string</td><td>true</td></tr>
<tr><td>x2ap</td><td><code>x2ap.messageType</code></td><td>string</td><td>true</td></tr>
<tr><td>x2ap</td><td><code>x2ap.procedureCode</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>xdmcp</td><td><code>xdmcp.authName</code></td><td>string</td><td>true</td></tr>
<tr><td>xdmcp</td><td><code>xdmcp.hostname</code></td><td>string</td><td>true</td></tr>
<tr><td>xdmcp</td><td><code>xdmcp.opcode</code></td><td>string</td><td>true</td></tr>
<tr><td>xdmcp</td><td><code>xdmcp.status</code></td><td>string</td><td>true</td></tr>
<tr><td>xdmcp</td><td><code>xdmcp.version</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>xmpp</td><td><code>xmpp.authMechanisms</code></td><td>string</td><td>true</td></tr>
<tr><td>xmpp</td><td><code>xmpp.banner</code></td><td>string</td><td>true</td></tr>
<tr><td>xmpp</td><td><code>xmpp.capsHash</code></td><td>string</td><td>true</td></tr>
<tr><td>xmpp</td><td><code>xmpp.capsNode</code></td><td>string</td><td>true</td></tr>
<tr><td>xmpp</td><td><code>xmpp.capsVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>xmpp</td><td><code>xmpp.compression</code></td><td>string</td><td>true</td></tr>
<tr><td>xmpp</td><td><code>xmpp.cpe</code></td><td>string</td><td>true</td></tr>
<tr><td>xmpp</td><td><code>xmpp.port</code></td><td>numeric</td><td>true</td></tr>
<tr><td>xmpp</td><td><code>xmpp.serverFrom</code></td><td>string</td><td>true</td></tr>
<tr><td>xmpp</td><td><code>xmpp.serverSoftware</code></td><td>string</td><td>true</td></tr>
<tr><td>xmpp</td><td><code>xmpp.streamID</code></td><td>string</td><td>true</td></tr>
<tr><td>xmpp</td><td><code>xmpp.target</code></td><td>string</td><td>true</td></tr>
<tr><td>xmpp</td><td><code>xmpp.tlsSupport</code></td><td>numeric</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>zabbix</td><td><code>zabbix.agentData</code></td><td>string</td><td>true</td></tr>
<tr><td>zabbix</td><td><code>zabbix.agentVersion</code></td><td>string</td><td>true</td></tr>
<tr><td>zabbix</td><td><code>zabbix.cpe23</code></td><td>string</td><td>true</td></tr>
<tr><td>zabbix</td><td><code>zabbix.remoteCommandsEnabled</code></td><td>boolean</td><td>true</td></tr>
<tr><td>zabbix</td><td><code>zabbix.version</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>zabbix-agent</td><td><code>zabbix.agentVersion</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>zebra</td><td><code>host.name</code></td><td>string</td><td>true</td></tr>
<tr><td>zebra</td><td><code>zebra.deviceName</code></td><td>string</td><td>false</td></tr>
<tr><td>zebra</td><td><code>zebra.firmware</code></td><td>string</td><td>false</td></tr>
<tr><td>zebra</td><td><code>zebra.ip</code></td><td>string</td><td>false</td></tr>
<tr><td>zebra</td><td><code>zebra.model</code></td><td>string</td><td>false</td></tr>
<tr><td>zebra</td><td><code>zebra.response</code></td><td>string</td><td>false</td></tr>
<tr><td>zebra</td><td><code>zebra.serial</code></td><td>string</td><td>false</td></tr>
</tbody>
<tbody>
<tr><td>zookeeper</td><td><code>zk.access</code></td><td>string</td><td>true</td></tr>
<tr><td>zookeeper</td><td><code>zookeeper.access</code></td><td>string</td><td>true</td></tr>
<tr><td>zookeeper</td><td><code>zookeeper.banner</code></td><td>string</td><td>true</td></tr>
<tr><td>zookeeper</td><td><code>zookeeper.connections</code></td><td>numeric</td><td>true</td></tr>
<tr><td>zookeeper</td><td><code>zookeeper.imok</code></td><td>string</td><td>true</td></tr>
<tr><td>zookeeper</td><td><code>zookeeper.mode</code></td><td>string</td><td>true</td></tr>
<tr><td>zookeeper</td><td><code>zookeeper.nodeCount</code></td><td>numeric</td><td>true</td></tr>
<tr><td>zookeeper</td><td><code>zookeeper.port</code></td><td>numeric</td><td>true</td></tr>
<tr><td>zookeeper</td><td><code>zookeeper.restricted</code></td><td>string</td><td>true</td></tr>
<tr><td>zookeeper</td><td><code>zookeeper.restrictionReason</code></td><td>string</td><td>true</td></tr>
<tr><td>zookeeper</td><td><code>zookeeper.ruok</code></td><td>string</td><td>true</td></tr>
<tr><td>zookeeper</td><td><code>zookeeper.srvr</code></td><td>string</td><td>true</td></tr>
<tr><td>zookeeper</td><td><code>zookeeper.target</code></td><td>string</td><td>true</td></tr>
<tr><td>zookeeper</td><td><code>zookeeper.version</code></td><td>string</td><td>true</td></tr>
<tr><td>zookeeper</td><td><code>zookeeper.versionRaw</code></td><td>string</td><td>true</td></tr>
</tbody>
<tbody>
<tr><td>zyxel</td><td><code>zyxel.builddate</code></td><td>string</td><td>true</td></tr>
<tr><td>zyxel</td><td><code>zyxel.dhcpstate</code></td><td>string</td><td>true</td></tr>
<tr><td>zyxel</td><td><code>zyxel.firmware</code></td><td>string</td><td>true</td></tr>
<tr><td>zyxel</td><td><code>zyxel.firstlogin</code></td><td>string</td><td>true</td></tr>
<tr><td>zyxel</td><td><code>zyxel.gateway</code></td><td>string</td><td>true</td></tr>
<tr><td>zyxel</td><td><code>zyxel.hostname</code></td><td>string</td><td>true</td></tr>
<tr><td>zyxel</td><td><code>zyxel.ip</code></td><td>string</td><td>true</td></tr>
<tr><td>zyxel</td><td><code>zyxel.mac</code></td><td>string</td><td>true</td></tr>
<tr><td>zyxel</td><td><code>zyxel.maxport</code></td><td>string</td><td>true</td></tr>
<tr><td>zyxel</td><td><code>zyxel.model</code></td><td>string</td><td>true</td></tr>
<tr><td>zyxel</td><td><code>zyxel.subnetmask</code></td><td>string</td><td>true</td></tr>
<tr><td>zyxel</td><td><code>zyxel.uptime</code></td><td>string</td><td>true</td></tr>
</tbody>
</table>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[runZero data formats]]></title>
    <link href="https://www.runzero.com/docs/data-formats/"/>
    <id>https://www.runzero.com/docs/data-formats/</id>
      
      <published>2025-01-14T23:37:36+00:00</published>
      <updated>2025-01-14T23:37:36+00:00</updated>
      <summary type="html"><![CDATA[<p>runZero consumes and produces a handful of <span class="book-index" data-book-index="data formats">data formats</span>. This page provides examples of these formats and describes the fields and use cases for each.</p>
<h2 id="formats">Formats</h2>
<ul>
<li><a href="/docs/data-formats/#scan-data">Scan data</a>   (<a href="/data/scan-data.json">sample</a>)</li>
<li><a href="/docs/data-formats/#asset-data">Asset data</a> (<a href="/data/asset-data.json">sample</a>)</li>
<li><a href="/docs/data-formats/#change-reports">Change reports</a> (<a href="/data/change-report.json">sample</a>)</li>
</ul>
<h2 id="scan-data"><span class="book-index" data-book-index="Scan data">Scan data</span></h2>
<p>The raw output produced by the runZero Explorer and the runZero CLI is the <strong>scan data</strong>. This is newline-delimited JSON – <span class="book-index" data-book-index="JSONL">JSONL</span> – that represents the unprocessed output of the scan engine. This format is returned when downloading the task data for an Explorer-run scan and correlates to the <code>scan.runzero.gz</code> file created by the CLI. The runZero Inventory view is built by processing scan data in chronological order to create the current state at a given point in time.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Common sign-in issues]]></title>
    <link href="https://www.runzero.com/docs/troubleshooting-sign-in-issues/"/>
    <id>https://www.runzero.com/docs/troubleshooting-sign-in-issues/</id>
      
      <published>2025-06-13T14:37:42+00:00</published>
      <updated>2025-06-13T14:37:42+00:00</updated>
      <summary type="html"><![CDATA[<h2 id="user-account-has-been-locked-from-too-many-failed-sign-in-attempts">User account has been locked from too many failed sign-in attempts.</h2>
<p><strong>Cause</strong>: The account you are signing into is configured for password authentication and has been locked due to repeated incorrect sign-in attempts.</p>
<p><strong>Remediation</strong>: Contact your runZero administrator and have them follow these steps:</p>
<ol>
<li>In the runZero console, visit the Team page</li>
<li>Select the locked account</li>
<li>Use the “Unlock user accounts” option in the “Reset” dropdown menu.</li>
</ol>
<p>If contacting an administrator is not an option, please reach out to <a href="mailto:support@runzero.com">support@runzero.com</a>.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Browsers supported by the runZero Console]]></title>
    <link href="https://www.runzero.com/docs/troubleshooting-supported-browsers/"/>
    <id>https://www.runzero.com/docs/troubleshooting-supported-browsers/</id>
      
      <published>2026-03-17T06:49:47+00:00</published>
      <updated>2026-03-17T06:49:47+00:00</updated>
      <summary type="html"><![CDATA[<h2 id="which-browsers-are-supported-when-accessing-the-runzero-console">Which browsers are supported when accessing the runZero Console?</h2>
<p>We maintain compatibility with the following <span class="book-index" data-book-index="browser versions">browser versions</span> or newer:</p>
<ul>
<li><em>Chrome 123</em> (released March 18, 2024)</li>
<li><em>Edge 123</em> (released March 22, 2024)</li>
<li><em>Safari 17.5</em> (released May 12, 2024)</li>
<li><em>Firefox 120</em> (released November 20, 2023)</li>
<li><em>Opera 109</em> (released March 26, 2024)</li>
</ul>
<p>Internet Explorer is <em>not</em> supported.</p>
<p>Mobile browser support is experimental and is not guaranteed to work.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Explorer security model]]></title>
    <link href="https://www.runzero.com/docs/explorer-security-model/"/>
    <id>https://www.runzero.com/docs/explorer-security-model/</id>
      
      <published>2025-05-30T15:55:54+00:00</published>
      <updated>2025-05-30T15:55:54+00:00</updated>
      <summary type="html"><![CDATA[<p>runZero Explorers are responsible for running network scans, sampling traffic for passive discovery, and implementing integrations within their deployed environment.
This document describes the security model of runZero Explorers.</p>
<h2 id="development">Development</h2>
<p>runZero Explorers are built using the Go programming language. This language provides cross-platform compatibility and memory safety by default. The runZero engineering team updates the Explorer code and it’s dependencies on a continuous basis to ensure that any dependency-level vulnerabilities are resolved quickly. All engineers are required to use MFA to access our Git repository. All code changes go through manual review before being merged to our development branch, deployed to a test environment, reviewed again before being merged to our staging branch, and deployed to a staging environment. During the build process, Explorer binaries are signed with a private Ed25519 key and the signature is stamped into the end of the binary. For Windows binaries, an Authenticode signature is also applied, using an extended-validation certificate stored in a cloud-based HSM. Once all automated tests pass and any changes to behavior are confirmed, the staging environment binaries are tagged for release, and moved to the production deployment location in AWS S3.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Explorer not capturing screenshots]]></title>
    <link href="https://www.runzero.com/docs/troubleshooting-no-screenshots/"/>
    <id>https://www.runzero.com/docs/troubleshooting-no-screenshots/</id>
      
      <published>2026-05-04T10:03:43+00:00</published>
      <updated>2026-05-04T10:03:43+00:00</updated>
      <summary type="html"><![CDATA[<h2 id="why-didnt-the-runzero-explorer-capture-screenshots">Why didn’t the runZero Explorer capture screenshots?</h2>
<p>The runZero Explorer needs a working install of <span class="book-index" data-book-index="Google Chrome">Google Chrome</span> to obtain screenshots. To check for Google Chrome, the Explorer looks in the following locations on each OS.</p>
<h3 id="screenshots-windows">Windows</h3>
<p>The runZero Explorer looks for Chrome on Windows in:</p>
<pre><code>c:\Program Files (x86)\Google\Chrome\Application\chrome.exe
</code></pre>
<p>The Explorer also checks the following environment variables:</p>
<ul>
<li><code>ProgramFiles(x86)</code></li>
<li><code>ProgramFiles</code></li>
<li><code>ProgramW6432</code></li>
</ul>
<p>Each may list another directory, in which case the Explorer looks in <code>\Google\Chrome\Application\chrome.exe</code> under each of those directories as well.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Scanning VMWare virtual machines]]></title>
    <link href="https://www.runzero.com/docs/troubleshooting-scanning-vms/"/>
    <id>https://www.runzero.com/docs/troubleshooting-scanning-vms/</id>
      
      <published>2024-02-22T16:30:44+00:00</published>
      <updated>2024-02-22T16:30:44+00:00</updated>
      <summary type="html"><![CDATA[<h2 id="how-do-i-scan-vmware-virtual-machines-without-crashing-the-host">How do I scan VMware virtual machines without crashing the host?</h2>
<p>runZero can be used to scan <span class="book-index" data-book-index="VMware">VMware</span> <span class="book-index" data-book-index="virtual machines">virtual machines</span>. However, there are some precautions you should take.</p>
<p>VMnet interfaces normally use Network Address Translation (NAT) to route traffic between the host system and the virtual machines. The VMware software effectively operates as a stateful router. As explained above, this can cause problems when runZero tries to open thousands of connections.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Scanning routers]]></title>
    <link href="https://www.runzero.com/docs/troubleshooting-scanning-routers/"/>
    <id>https://www.runzero.com/docs/troubleshooting-scanning-routers/</id>
      
      <published>2022-08-17T11:44:57+00:00</published>
      <updated>2022-08-17T11:44:57+00:00</updated>
      <summary type="html"><![CDATA[<h2 id="how-do-i-run-runzero-without-crashing-my-router">How do I run runZero without crashing my router?</h2>
<p>If your router is crashing while being scanned, the likely issue is that your router is stateful and it is keeping track of every connection going through it. Since our scanning process involves thousands of attempted connections, your router likely ran out of available stateful sessions. This usually occurs when a router is using Network Address Translation (<span class="book-index" data-book-index="NAT">NAT</span>) or is acting as a stateful security firewall.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Identical assets in inventory]]></title>
    <link href="https://www.runzero.com/docs/troubleshooting-identical-assets/"/>
    <id>https://www.runzero.com/docs/troubleshooting-identical-assets/</id>
      
      <published>2024-10-17T13:42:14+00:00</published>
      <updated>2024-10-17T13:42:14+00:00</updated>
      <summary type="html"><![CDATA[<h2 id="why-are-there-so-many-identical-assets-in-my-inventory">Why are there so many identical assets in my inventory?</h2>
<p>Some enterprise routers and firewalls, like <span class="book-index" data-book-index="Cisco ASA">Cisco ASA</span> devices, are designed to reply to all unexpected attempts on a particular port with a TCP reset (RST). On top of that, some routers listen to <span class="book-index" data-book-index="SIP">SIP</span> traffic on all addresses and automatically respond to it. runZero tries to automatically detect and avoid most of the SIP helper implementations, but can’t always do so without possibly losing real results.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Frequently asked questions]]></title>
    <link href="https://www.runzero.com/docs/troubleshooting/"/>
    <id>https://www.runzero.com/docs/troubleshooting/</id>
      
      <published>2026-05-01T22:14:59+00:00</published>
      <updated>2026-05-01T22:14:59+00:00</updated>
      <summary type="html"><![CDATA[<p>Here you can browse the solutions to some common runZero issues and the answers to some frequently asked questions (FAQs).</p>
<p>For more solutions and FAQs, check out the <span class="book-index" data-book-index="knowledgebase">knowledgebase</span> on <a href="https://runzero.freshdesk.com/support/home">the runZero support portal</a>.</p>
<h2 id="issues-and-faqs">Issues and FAQs</h2>
<ul>
<li><a href="/docs/troubleshooting-identical-assets/">Why are there so many identical assets in my inventory?</a></li>
<li><a href="/docs/troubleshooting-scanning-routers/">How do I run runZero without crashing my router?</a></li>
<li><a href="/docs/troubleshooting-scanning-vms/">How do I scan VMware virtual machines without crashing the host?</a></li>
<li><a href="/docs/troubleshooting-no-screenshots/">Why didn’t the runZero Explorer capture screenshots?</a></li>
<li><a href="/docs/troubleshooting-protocols-supported/">What protocols does runZero support?</a></li>
<li><a href="/docs/troubleshooting-ports-scanned/">What ports does runZero scan?</a></li>
<li><a href="/docs/troubleshooting-iot-and-ot/">Can I safely scan my IoT or OT environments?</a></li>
<li><a href="/docs/troubleshooting-supported-browsers/">Which browsers are supported when accessing the runZero Console?</a></li>
</ul>
<p>Still can’t find your answer? <a href="mailto:support@runzero.com">Let us know</a>.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[PCI Data Security Standard (DSS)]]></title>
    <link href="https://www.runzero.com/docs/compliance/pci-dss/"/>
    <id>https://www.runzero.com/docs/compliance/pci-dss/</id>
      
      <published>2025-02-21T12:20:13+00:00</published>
      <updated>2025-02-21T12:20:13+00:00</updated>
      <summary type="html"><![CDATA[<h2 id="pcidss-what">What are the Payment Card Industry Data Security Standard?</h2>
<p>The Payment Card Industry Data Security Standard (<span class="book-index" data-book-index="PCI DSS">PCI DSS</span>) is an evolving global framework for safeguarding payment card data, such as primary account number (i.e. credit card number), expiration date, card verification code, and other associated data. It is published and maintained by the Payment Card Industry Security Standards Council (PCI SSC) along with other standards and supplemental resources. PCI DSS is enforced contractually by payment brands such as Visa, MasterCard, Discover, and American Express, as well as financial institutions that process payment transactions on behalf of merchants. PCI DSS defines 12 high-level requirements for protecting payment card data, each of which includes multiple sections, requirements, testing procedures, and supporting guidance.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[NIST Cybersecurity Framework (CSF)]]></title>
    <link href="https://www.runzero.com/docs/compliance/nist-csf/"/>
    <id>https://www.runzero.com/docs/compliance/nist-csf/</id>
      
      <published>2025-02-21T12:17:09+00:00</published>
      <updated>2025-02-21T12:17:09+00:00</updated>
      <summary type="html"><![CDATA[<h2 id="csf-what">What is the NIST Cybersecurity Framework?</h2>
<p>The <strong>Framework for Improving Critical Infrastructure Cybersecurity</strong>, more commonly referred to as simply the <strong>Cybersecurity Framework</strong> (<span class="book-index" data-book-index="CSF">CSF</span>), was originally published by the National Institute for Standards and Technology (NIST) in February 2014. This framework was published in response to Executive Order 13636, <a href="https://obamawhitehouse.archives.gov/the-press-office/2013/02/12/executive-order-improving-critical-infrastructure-cybersecurity">Improving Critical Infrastructure Cybersecurity</a>. The <span class="book-index" data-book-index="NIST CSF">NIST CSF</span> is an evolving framework developed to improve cybersecurity risk management in critical infrastructure. While the framework itself is not mandatory, there is increasing pressure from regulating agencies for critical infrastructure operators to improve cybersecurity and NIST CSF acts as a guide for doing so.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[NERC Critical Infrastructure Protection]]></title>
    <link href="https://www.runzero.com/docs/compliance/nerc-cip/"/>
    <id>https://www.runzero.com/docs/compliance/nerc-cip/</id>
      
      <published>2025-01-14T22:41:28+00:00</published>
      <updated>2025-01-14T22:41:28+00:00</updated>
      <summary type="html"><![CDATA[<h2 id="nerc-cip-what">What is NERC-CIP?</h2>
<p>The North American Electric Reliability Corporation Critical Infrastructure Protection (<span class="book-index" data-book-index="NERC-CIP">NERC-CIP</span>) plan is a set of cybersecurity standards developed to protect the reliability of the North American bulk power system. It is part of the broader NERC Reliability Standards. In 2007, under the authority of the Federal Energy Regulatory Commission (FERC), compliance with NERC Reliability Standards became a legal requirement for bulk power system owners and operators.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[ISO/IEC 27001:2022]]></title>
    <link href="https://www.runzero.com/docs/compliance/iso-27001/"/>
    <id>https://www.runzero.com/docs/compliance/iso-27001/</id>
      
      <published>2025-07-03T10:10:07+00:00</published>
      <updated>2025-07-03T10:10:07+00:00</updated>
      <summary type="html"><![CDATA[<h2 id="iso27001-what">What is ISO 27001?</h2>
<p><span class="book-index" data-book-index="ISO/IEC 27001:2022">ISO/IEC 27001:2022</span> is an globally recognized standard, published by the International Organization for Standardization and the International Electrotechnical Commission, that provides requirements for establishing, implementing, maintaining and continually improving an information security management system. In the 2022 revision of the ISO 27001 standard, controls are organized into four categories - Organizational, People, Physical and Technical controls.</p>
<h2 id="iso27001-who">Who is the intended audience?</h2>
<p>ISO/IEC 27001:2022 is intended for organizations of all sizes, and in any industry, seeking a framework for measuring and improving their information security program. Achieving a formal ISO/IEC 27001 certification is an industry recognized method of demonstrating your organization’s commitment to implementing information security best practices.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Cybersecurity Maturity Model Certification (CMMC)]]></title>
    <link href="https://www.runzero.com/docs/compliance/cmmc/"/>
    <id>https://www.runzero.com/docs/compliance/cmmc/</id>
      
      <published>2024-02-22T16:30:44+00:00</published>
      <updated>2024-02-22T16:30:44+00:00</updated>
      <summary type="html"><![CDATA[<h2 id="cmmc-what">What is the Cybersecurity Maturity Model Certification?</h2>
<p>The Cybersecurity Maturity Model Certification (<span class="book-index" data-book-index="CMMC">CMMC</span>) program was developed by the United States Department of Defense to enforce protection of sensitive unclassified information that is shared by the Department with its contractors and subcontractors. Contracts are required to implement progressively advanced levels of controls depending on the type and sensitivity of information that is shared. In November 2021, the Department of Defense announced CMMC 2.0 with an updated structure and requirements. CMMC 2.0 has 3 tiers of certification that are outlined in the following table.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Cybersecurity Capability Maturity Model (C2M2)]]></title>
    <link href="https://www.runzero.com/docs/compliance/c2m2/"/>
    <id>https://www.runzero.com/docs/compliance/c2m2/</id>
      
      <published>2024-02-22T16:30:44+00:00</published>
      <updated>2024-02-22T16:30:44+00:00</updated>
      <summary type="html"><![CDATA[<h2 id="c2m2-what">What is the Cybersecurity Capability Maturity Model?</h2>
<p>The Cybersecurity Capability Maturity Model (<span class="book-index" data-book-index="C2M2">C2M2</span>) is a framework developed by the United States Department of Energy. It was initially published in 2012 and most recently updated in 2022. It is a voluntary framework designed to help organizations evaluate their cybersecurity capabilities and optimize security investments. C2M2 defines practices across 10 cybersecurity domains and measures progression within each domain using maturity level indicators.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[CISA Binding Operational Directive (BOD) 23-01]]></title>
    <link href="https://www.runzero.com/docs/compliance/cisa-bod-23-01/"/>
    <id>https://www.runzero.com/docs/compliance/cisa-bod-23-01/</id>
      
      <published>2024-02-22T16:30:44+00:00</published>
      <updated>2024-02-22T16:30:44+00:00</updated>
      <summary type="html"><![CDATA[<h2 id="cisa-bod-23-01-what">What is CISA Binding Operational Directive 23-01?</h2>
<p>Binding Operational Directive (<span class="book-index" data-book-index="BOD 23-01">BOD</span>) 23-01 was issued in October 2022 by the Cybersecurity and Infrastructure Security Agency in the United States Department of Homeland Security. The purpose of <span class="book-index" data-book-index="CISA BOD">BOD</span> 23-01 is to “make measurable progress toward enhancing visibility into agency assets and associated vulnerabilities.” It focuses on two primary objectives: <strong>asset discovery</strong> and <strong>vulnerability enumeration</strong>.</p>
<h2 id="cisa-bod-23-01-who">Who is the intended audience?</h2>
<p>This Directive applies to all Federal Civilian Executive Branch (<span class="book-index" data-book-index="FCEB">FCEB</span>) departments and agencies of the United States government and any FCEB unclassified federal information systems.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[CIS Critical Security Controls (CSC)]]></title>
    <link href="https://www.runzero.com/docs/compliance/cis-csc/"/>
    <id>https://www.runzero.com/docs/compliance/cis-csc/</id>
      
      <published>2024-02-22T16:30:44+00:00</published>
      <updated>2024-02-22T16:30:44+00:00</updated>
      <summary type="html"><![CDATA[<h2 id="csc-what">What are the Critical Security Controls?</h2>
<p>The CIS Critical Security Controls (<span class="book-index" data-book-index="CIS Controls">CIS Controls</span>) is a collection of prioritized cybersecurity best practices, originally developed by the SANS Institute in 2008 and now maintained by the Center for Internet Security. The CIS Controls are updated through an informal community process to ensure that it continues to align with the most effective security controls and the most relevant cyber attacks.</p>
<h2 id="csc-who">Who is the intended audience?</h2>
<p>The CIS Critical Security Controls are intended for organizations of all sizes that are looking for a prioritized approach to defending their organization against cyber attacks. It is a voluntary framework and is not a replacement for any industry standards, regulatory frameworks, or other legal obligations.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Compliance alignment]]></title>
    <link href="https://www.runzero.com/docs/compliance/overview/"/>
    <id>https://www.runzero.com/docs/compliance/overview/</id>
      
      <published>2025-07-03T10:10:07+00:00</published>
      <updated>2025-07-03T10:10:07+00:00</updated>
      <summary type="html"><![CDATA[<p>runZero customers face a variety of <span class="book-index" data-book-index="compliance">compliance</span> obligations from industry standards to state, federal, and international laws and regulations. While each has its own unique attributes, there are common themes across most IT and <span class="book-index" data-book-index="cybersecurity frameworks">cybersecurity frameworks</span>. The following sections summarize several of these themes and how runZero can help organizations achieve and maintain compliance.</p>
<h2 id="compliance-asset-inventory">Establish and maintain an asset inventory</h2>
<p>A common adage in cybersecurity is that <strong>you can’t protect what you can’t see</strong>. As such, establishing an inventory of assets is foundational to building an effective cybersecurity program. Most cybersecurity standards and frameworks include provisions for establishing an asset inventory. Examples of asset inventory controls include:</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[MSSP guidance]]></title>
    <link href="https://www.runzero.com/docs/playbooks/mssp-guide/"/>
    <id>https://www.runzero.com/docs/playbooks/mssp-guide/</id>
      
      <published>2025-11-13T10:35:40+00:00</published>
      <updated>2025-11-13T10:35:40+00:00</updated>
      <summary type="html"><![CDATA[<p>As an <span class="book-index" data-book-index="MSSP">MSSP</span>, you can use runZero to enhance current offerings and create new offerings for your customers related to asset management and asset risk management.</p>
<h2 id="mssp-audience">Who is this playbook for and why?</h2>
<p>This playbook is meant to guide MSSPs along their path to creating and delivering an offering using the runZero platform. It is highly simplified by design and should serve as a starting point rather than a complete offering. We are laying the basic groundwork for you to take it to adapt to your needs.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Tracking Security and IT Initiatives with Goals]]></title>
    <link href="https://www.runzero.com/docs/playbooks/tracking-security-and-it-initiatives-with-goals/"/>
    <id>https://www.runzero.com/docs/playbooks/tracking-security-and-it-initiatives-with-goals/</id>
      
      <published>2025-07-09T12:34:51+00:00</published>
      <updated>2025-07-09T12:34:51+00:00</updated>
      <summary type="html"><![CDATA[<p>Many organizations have ongoing initiatives to improve their security posture, ensure compliance, or maintain IT hygiene. The runZero Goals feature allows you to track, measure, and report on the progress of these initiatives over time, turning any inventory query into a measurable objective.</p>
<h2 id="goals-audience">Who is this playbook for and why?</h2>
<p>This playbook is for <strong>IT, Security, and Compliance teams</strong> who need to:</p>
<ul>
<li>Measure progress against specific objectives, like eliminating end-of-life software or ensuring all assets have an owner.</li>
<li>Create trackable Key Performance Indicators (KPIs) from their asset inventory data.</li>
<li>Report on the status of security and IT initiatives to management and stakeholders.</li>
</ul>
<h2 id="goals-solution">How will runZero help?</h2>
<p>runZero’s Goals feature provides a clear, visual way to track your progress against any objective that can be defined by an inventory query. By comparing the current number of assets matching a query to a defined target, you can easily see how your initiatives are progressing and where more attention is needed. This transforms your asset inventory from a simple list into a dynamic tool for driving improvement.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Scanning with SNMP]]></title>
    <link href="https://www.runzero.com/docs/playbooks/scanning-with-snmp/"/>
    <id>https://www.runzero.com/docs/playbooks/scanning-with-snmp/</id>
      
      <published>2026-05-01T22:14:59+00:00</published>
      <updated>2026-05-01T22:14:59+00:00</updated>
      <summary type="html"><![CDATA[<p>The Simple Network Management Protocol (SNMP) is an open standard network protocol for collecting information about devices on a network. runZero supports the three main versions of the protocol: SNMPv1, the SNMPv2c variant of SNMPv2, and SNMPv3.</p>
<p>runZero scans can be performed with the following SNMP configurations:</p>
<ul>
<li>SNMPv1 and SNMPv2 enabled</li>
<li>Only SNMPv3 enabled</li>
<li>SNMPv1, SNMPv2, and SNMPv3 enabled</li>
</ul>
<p>SNMP scanning provides additional visibility, enhances network context, and <a href="/docs/identify-gaps-in-scanning/#identifying-gaps-switch-topology">improves reporting</a>.</p>
<h2 id="snmp-scanning-audience">Who is this playbook for and why?</h2>
<p>This playbook is intended for runZero users that are interested in configuring SNMP scanning to gather additional detail and context about their network and improve reporting.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Scanning OT networks]]></title>
    <link href="https://www.runzero.com/docs/playbooks/scanning-ot-networks/"/>
    <id>https://www.runzero.com/docs/playbooks/scanning-ot-networks/</id>
      
      <published>2026-05-13T14:38:20+00:00</published>
      <updated>2026-05-13T14:38:20+00:00</updated>
      <summary type="html"><![CDATA[<p><span class="book-index" data-book-index="Operational technology">Operational technology</span> (<span class="book-index" data-book-index="OT">OT</span>) is <a href="https://csrc.nist.gov/News/2022/guide-to-operational-technology-ot-security">defined by the <span class="book-index" data-book-index="National Institute of Standards and Technology">National Institute of Standards and Technology</span> (<span class="book-index" data-book-index="NIST">NIST</span>)</a> as programmable systems or devices that interact with the physical environment or manage devices that interact with the physical environment. Examples include <span class="book-index" data-book-index="industrial control systems">industrial control systems</span> (<span class="book-index" data-book-index="ICS">ICS</span>), computer numerical control systems (CNC), building control systems, transportation systems, and many others. While OT systems and devices were once isolated independent systems running on specialized hardware and software, they have become increasingly interconnected, adopting industry standard operating systems and network protocols. As a result, it has become increasingly important for organizations to maintain an accurate inventory of network-connected <span class="book-index" data-book-index="OT assets">OT assets</span>.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Personal Customer Health Review]]></title>
    <link href="https://www.runzero.com/docs/playbooks/customer-health-review/"/>
    <id>https://www.runzero.com/docs/playbooks/customer-health-review/</id>
      
      <published>2025-11-14T20:21:20+00:00</published>
      <updated>2025-11-14T20:21:20+00:00</updated>
      <summary type="html"><![CDATA[<p>This guide helps you evaluate and improve your use of runZero by focusing on three core areas:</p>
<ul>
<li><strong>Total Visibility</strong></li>
<li><strong>Exposure Detection</strong></li>
<li><strong>Reporting &amp; Ownership</strong>.</li>
</ul>
<p>Each section includes recommended actions and direct links to the <a href="https://help.runzero.com/docs/use-case-library/">Use Case Library</a> and your <a href="https://console.runzero.com">runZero console</a>.</p>
<hr>
<h2 id="1-total-visibility">1) Total Visibility</h2>
<p>Achieving full asset visibility is foundational with runZero. Total visibility begins with scanning internal and external environments, automating scan tasks, and integrating existing systems.</p>
<h3 id="1a-integrations">1A. Integrations</h3>
<p>runZero evaluates inbound integration activity to measure platform adoption.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Finding gaps in vulnerability scanning]]></title>
    <link href="https://www.runzero.com/docs/playbooks/finding-gaps-in-vuln-scanning/"/>
    <id>https://www.runzero.com/docs/playbooks/finding-gaps-in-vuln-scanning/</id>
      
      <published>2024-02-08T09:09:54+00:00</published>
      <updated>2024-02-08T09:09:54+00:00</updated>
      <summary type="html"><![CDATA[<p>Your vulnerability scanning is only as <a href="https://www.runzero.com/blog/strengthen-vm/">good as the coverage</a>. As devices get added and taken off the network, it is important to monitor for gaps in scanning.</p>
<h2 id="vuln-scan-gaps-audience">Who is this playbook for and why?</h2>
<p>This playbook will be useful for <strong>security teams</strong> who want to close gaps in their vulnerability management program to ensure effective and efficient remediation of vulnerabilities.</p>
<h2 id="vuln-scan-gaps-solution">How will runZero help?</h2>
<p>runZero is able to discover assets on your network without an agent and import asset information from your vulnerability management platform. This allows you to easily identify assets that are not currently being scanned by your vulnerability management platform.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Finding gaps in endpoint protection]]></title>
    <link href="https://www.runzero.com/docs/playbooks/finding-gaps-in-endpoint-protection/"/>
    <id>https://www.runzero.com/docs/playbooks/finding-gaps-in-endpoint-protection/</id>
      
      <published>2025-07-03T10:10:07+00:00</published>
      <updated>2025-07-03T10:10:07+00:00</updated>
      <summary type="html"><![CDATA[<p>Many customers use runZero to get a consolidated view into their assets. Once you’ve integrated your endpoint protection platform with runZero, there are a variety of ways you can monitor the state of your deployment from within runZero.</p>
<h2 id="edr-gaps-audience">Who is this playbook for and why?</h2>
<p>This playbook will be useful for <strong>security</strong> and <strong>IT</strong> personnel who are responsible for managing their organization’s endpoint protection platform. It can help find gaps in your endpoint protection coverage and ensure that you’re getting full value out of your investment.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Creating queries and dashboard for NYDFS compliance]]></title>
    <link href="https://www.runzero.com/docs/playbooks/nydfs-compliance/"/>
    <id>https://www.runzero.com/docs/playbooks/nydfs-compliance/</id>
      
      <published>2025-07-03T10:10:07+00:00</published>
      <updated>2025-07-03T10:10:07+00:00</updated>
      <summary type="html"><![CDATA[<h2 id="NYDFS-audience">Who is this playbook for and why?</h2>
<ul>
<li><strong>Security teams</strong></li>
<li><strong>Compliance teams</strong></li>
</ul>
<h2 id="NYDFS-solution">How will runZero help?</h2>
<p>runZero is able to gather the necessary data for a large portion of the NYDFS compliance, especially in the 500.09 section. By utilizing different queries and widgets in a custom dashboard, you can track and display the information needed.</p>
<h2 id="NYDFS-overview">What will I need to do?</h2>
<ol>
<li>Identify and save queries for the different requirements of the compliance.</li>
<li>Create a new custom dashboard for easily accessible information regarding the different requirements.</li>
<li>Configure the dashboard utilizing the different queries defined in step 1.</li>
</ol>
<h2 id="NYDFS-prereqs">Prerequisites</h2>
<ul>
<li>(Optional) Go through the <a href="https://help.runzero.com/docs/playbooks/finding-gaps-in-endpoint-protection/">Finding gaps in endpoint protection</a> and <a href="https://help.runzero.com/docs/playbooks/finding-gaps-in-vuln-scanning/">Finding gaps in vulnerability scanning</a> playbooks to create and save queries on finding gaps in your EDR and Vulnerability Management tools (if applicable).</li>
</ul>
<h2 id="NYDFS-steps">Steps to implement</h2>
<h3 id="NYDFS-queries">1. Identify queries of interest</h3>
<p>For all of these queries, you first will want to run the query in the <a href="https://console.runzero.com/inventory">Asset Inventory</a> first, click the top right button with the three dots, and then click “Save Query”. This is important so we can reference them later for the dashboard.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Building your complete asset inventory]]></title>
    <link href="https://www.runzero.com/docs/playbooks/building-complete-asset-inventory/"/>
    <id>https://www.runzero.com/docs/playbooks/building-complete-asset-inventory/</id>
      
      <published>2024-02-08T09:09:54+00:00</published>
      <updated>2024-02-08T09:09:54+00:00</updated>
      <summary type="html"><![CDATA[<p>A complete asset inventory is a list of all assets owned by your organization, including managed, unmanaged, on-premises, and cloud infrastructure.</p>
<h2 id="complete-inventory-audience">Who is this playbook for and why?</h2>
<ul>
<li><strong>IT teams</strong> who want to use the asset inventory to understand the infrastructure they are supporting, find legacy operating systems, and track initiatives across the organization.</li>
<li><strong>OT teams</strong> who want to use the asset inventory to understand how assets are connected and to verify their network segmentation.</li>
<li><strong>Security teams</strong> who want to use the asset inventory during investigations and to monitor for potential vulnerabilities.</li>
</ul>
<h2 id="complete-inventory-solution">How will runZero help?</h2>
<p>runZero is able to safely scan all networks in an efficient manner with benign traffic. Using the data from the scans, you will get full visibility into everything on your network.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Alerting on runZero system events]]></title>
    <link href="https://www.runzero.com/docs/playbooks/alerting-on-system-events/"/>
    <id>https://www.runzero.com/docs/playbooks/alerting-on-system-events/</id>
      
      <published>2025-07-16T10:59:26+00:00</published>
      <updated>2025-07-16T10:59:26+00:00</updated>
      <summary type="html"><![CDATA[<p>runZero logs system events on a wide range of administrative actions related to assets, agents, tasks, users, and other components of the platform. Creating alerts on system events will allow you to more effectively monitor your runZero environment. The <code>agent-offline</code> system event specifically targets scenarios where an Explorer goes offline.</p>
<h2 id="system-events-audience">Who is this playbook for and why?</h2>
<p>System events can be useful for a broad range of personnel depending on roles and responsibilities associated with your runZero implementation. However, <strong>IT operations</strong> and <strong>cybersecurity</strong> personnel are most common. Sending alerts via email or webhook allows you to standardize monitoring of runZero with other platforms in your technology stack, which will increase overall efficiency.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Alerting on asset and service changes]]></title>
    <link href="https://www.runzero.com/docs/playbooks/alerting-on-queries/"/>
    <id>https://www.runzero.com/docs/playbooks/alerting-on-queries/</id>
      
      <published>2026-05-22T14:50:01+00:00</published>
      <updated>2026-05-22T14:50:01+00:00</updated>
      <summary type="html"><![CDATA[<p>runZero scans capture a rich dataset of information about all of the assets in your environment and the services running on them. Once gathered, you can run queries on this data to identify points of interest.</p>
<p>A few common use cases include:</p>
<ul>
<li>Identifying network misconfigurations</li>
<li>Identifying potential vulnerabilities</li>
<li>Finding new open services</li>
</ul>
<h2 id="alerting-queries-audience">Who is this playbook for and why?</h2>
<ul>
<li><strong>Security teams</strong> who want to reduce the number of misconfigurations and potential vulnerabilities in their environment, or are interested in identifying new services that could be malicious.</li>
<li><strong>IT teams</strong> who want to ensure their teams are following standard procedures when making updates in their environment.</li>
</ul>
<h2 id="alerting-queries-solution">How will runZero help?</h2>
<p>runZero is able to safely scan your entire network with benign traffic, so it has complete visibility into assets and services running in your network. This allows you to find misconfigurations, potential vulnerabilities, and new services that you would not see in other tools.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Achieving RFC 1918 coverage]]></title>
    <link href="https://www.runzero.com/docs/playbooks/achieving-rfc1918-coverage/"/>
    <id>https://www.runzero.com/docs/playbooks/achieving-rfc1918-coverage/</id>
      
      <published>2025-12-17T18:17:03+00:00</published>
      <updated>2025-12-17T18:17:03+00:00</updated>
      <summary type="html"><![CDATA[<p>RFC 1918 is an internet standard published by the Internet Engineering Task Force (IETF) that defines best practices for private networking. RFC 1918 defines three address ranges that are reserved for private networking.</p>
<ul>
<li><strong>10.0.0.0/8</strong> or <strong>10.0.0.0 – 10.255.255.255</strong></li>
<li><strong>172.16.0.0/12</strong> or <strong>172.16.0.0 – 172.31.255.255</strong></li>
<li><strong>192.168.0.0/16</strong> or <strong>192.168.0.0 – 192.168.255.255</strong></li>
</ul>
<p>Scanning the entire RFC 1918 space can allow you to identify subnets or assets that you were previously unaware of within your internal network.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Playbooks]]></title>
    <link href="https://www.runzero.com/docs/playbooks/playbooks/"/>
    <id>https://www.runzero.com/docs/playbooks/playbooks/</id>
      
      <published>2025-10-27T11:14:30+00:00</published>
      <updated>2025-10-27T11:14:30+00:00</updated>
      <summary type="html"><![CDATA[<p>Playbooks help you accomplish specific tasks in runZero. Each playbook includes the following sections and information:</p>
<ul>
<li><strong>Who is this playbook for and why</strong> - Identifies the teams who will ideally benefit from the playbook and why it’s helpful.</li>
<li><strong>How will runZero help</strong> - Explains how runZero can help address the problem you’re looking to solve.</li>
<li><strong>What will I need to do</strong> - Gives a quick summary of what you will be doing to achieve the objective.</li>
<li><strong>Prerequisites</strong> - Covers the license requirements and other tasks expected to be completed ahead of the steps to implement.</li>
<li><strong>Implementation steps</strong> - Provides the steps you need to take in order to accomplish the outcomes.</li>
</ul>
<h2 id="available-playbooks">Available playbooks</h2>
<p>The following playbooks are available:</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Glossary]]></title>
    <link href="https://www.runzero.com/docs/glossary/"/>
    <id>https://www.runzero.com/docs/glossary/</id>
      
      <published>2025-05-27T13:27:14+00:00</published>
      <updated>2025-05-27T13:27:14+00:00</updated>
      <summary type="html"><![CDATA[<p>As you read through the documentation, you will see <span class="book-index" data-book-index="glossary">commonly used terms</span>. These are the definitions for those terms, so you can familiarize yourself with them ahead of time.</p>
<h2 id="terms">Terms</h2>
<dl>
<dt>Alerts</dt>
<dd><a href="/docs/managing-alerts/">Alerts</a> are triggered when a certain events occurs based on <a href="/docs/rules-engine/">rules</a> defined in the Rules Engine.</dd>
<dt>Analysis reports</dt>
<dd><a href="/docs/reviewing-results/#analysis-reports">Analysis reports</a> are reports which run as tasks, rather than being generated on-the-fly. These reports are static, so any changes to your <a href="/docs/using-the-inventory/">inventory</a> may result in assets no longer being accessible from the report.</dd>
<dt>Asset</dt>
<dd>An <a href="/docs/understanding-assets/">asset</a> is a unique network entity from the perspective of the system running the <a href="/docs/managing-explorers/">Explorer</a>.</dd>
<dt>Automatic queries</dt>
<dd><a href="/docs/automating-queries/">Automatic queries</a> are certain queries you always want to run after a scan. After the query runs, you will be able to view its results in the <a href="https://console.runzero.com/queries">queries table</a>.</dd>
<dt>Dashboard</dt>
<dd>The <a href="/docs/reviewing-results/#dashboard--inventory-views">dashboard</a> provides trend data and insights that will help you assess how your inventory is changing over time.</dd>
<dt>Discovery scan</dt>
<dd>A <a href="/docs/discovering-assets/">discovery scan</a> finds, identifies, and builds an <a href="/docs/using-the-inventory/">inventory</a> of all the connected devices and assets on your internal network.</dd>
<dt>Explorer</dt>
<dd>The <a href="/docs/managing-explorers/">Explorer</a> is a lightweight scan engine that enables network and asset discovery.</dd>
<dt>Insights</dt>
<dd><a href="/docs/reviewing-results/#insights-from-queries">Insights</a> are queries that run automatically after each scan. They will populate on your <a href="/docs/reviewing-results/#dashboard--inventory-views">dashboard</a>.</dd>
<dt>Inventory</dt>
<dd>The <a href="/docs/using-the-inventory/">inventory</a> displays all assets within the Organization and can be sorted, filtered,</dd>
<dt>Organization</dt>
<dd>An <a href="/docs/organizations/">organization</a> represents a distinct entity; this can be your business, a specific department within your business, or one of your customers.</dd>
<dt>Outliers</dt>
<dd><a href="/docs/reviewing-results/#outliers">Outliers</a> show how often different values occur in specific attributes of assets and services.</dd>
<dt>Queries</dt>
<dd><a href="/docs/reviewing-results/#sample-queries">Queries</a> are filters that can be applied to your Inventory to find assets of interest.</dd>
<dt>Rules</dt>
<dd>A <a href="/docs/rules-engine/">rule</a> defines the action that is taken based on a set of conditions. You can create rules to proactively alert your team when there are changes to things like Explorers, assets, scans, organizations, and sites.</dd>
<dt>Scheduled scans</dt>
<dd><a href="/docs/discovering-assets/#schedulescheduled-scans">Scheduled scans</a> allow you to set a date and frequency for your scan task.</dd>
<dt>Self-hosted</dt>
<dd>The <a href="/docs/self-hosting/">self-hosted</a> version runZero allows you to run the entire platform on-premises or within your own cloud environment.</dd>
<dt>Site</dt>
<dd>A <a href="/docs/sites/">site</a> represents a distinct network segment, usually defined by addressing or accessibility.</dd>
</dl>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Model Context Protocol]]></title>
    <link href="https://www.runzero.com/docs/mcp/"/>
    <id>https://www.runzero.com/docs/mcp/</id>
      
      <published>2026-06-05T11:14:32+00:00</published>
      <updated>2026-06-05T11:14:32+00:00</updated>
      <summary type="html"><![CDATA[<p class="licenses"><a href="https://www.runzero.com/product/pricing/"><span class="com">Community</span></a>&nbsp;<a href="https://www.runzero.com/product/pricing/"><span class="pla">Platform</span></a></p>
<p>runZero supports the Model Context Protocol (MCP) at the <code>/mcp</code> endpoint and utilizes streaming-HTTP for communication. This integration allows clients to directly access runZero’s comprehensive security inventory data, enabling advanced, AI-driven queries and insights into network assets and vulnerabilities.</p>
<p>Some models are not designed with “tool use” or “function calling” in mind and will struggle. They might lack the internal mechanisms or sufficient training to reliably interpret tool schemas, decide when to call a tool, or correctly parse its output. Trying to force MCP onto such models would likely lead to frequent errors, hallucinations, or simply an inability to use the tools effectively.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Using the CLI]]></title>
    <link href="https://www.runzero.com/docs/using-the-cli/"/>
    <id>https://www.runzero.com/docs/using-the-cli/</id>
      
      <published>2026-04-11T03:07:33+00:00</published>
      <updated>2026-04-11T03:07:33+00:00</updated>
      <summary type="html"><![CDATA[<p class="licenses"><a href="https://www.runzero.com/product/pricing/"><span class="pla">Platform</span></a></p>
<p>The runZero Command Line Interface (CLI) provides various utility functions. For licensed users, it also allows standalone network scanning.</p>
<h2 id="scanner">Scanner</h2>
<p>The <code>scan</code> command has the same options as the runZero Explorer, and similar performance characteristics. The output file named <code>scan.runzero.gz</code> can be uploaded to the runZero Console through the Inventory <em>Import</em> menu. This</p>
<p>The CLI scanner works best with root privileges on Linux/macOS and Administrator privileges on Windows. Although the CLI will function without privileged access, many probe types will be unavailable. The <code>sudo</code> command can be used to run the CLI as root on Linux and macOS, while the tool is best run from an elevated command shell on Windows. On the Windows platform, the runZero CLI will look for an existing <code>npcap</code> installation and try to install it if the software is not found. This behavior can be disabled with the <code>--nopcap</code> flag.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Leveraging the API]]></title>
    <link href="https://www.runzero.com/docs/leveraging-the-api/"/>
    <id>https://www.runzero.com/docs/leveraging-the-api/</id>
      
      <published>2026-03-26T13:48:51+00:00</published>
      <updated>2026-03-26T13:48:51+00:00</updated>
      <summary type="html"><![CDATA[<p>runZero provides three primary APIs as well as integration-specific endpoints:</p>
<ul>
<li>The <span class="book-index" data-book-index="Export API">Export API</span> provides read-only access to a specific organizations.</li>
<li>The <span class="book-index" data-book-index="Organization API">Organization API</span> provides read-write access to a specific organizations (Professional and Platform licenses).</li>
<li>The <span class="book-index" data-book-index="Account API">Account API</span> provides read-write access to all account settings and organizations (Platform license).</li>
</ul>
<p>To get started, you will need an <span class="book-index" data-book-index="API key">API key</span> / <span class="book-index" data-book-index="token">token</span> or <span class="book-index" data-book-index="API client credentials">API client credentials</span>.</p>
<iframe src="https://demo.arcade.software/SHgu7YOmaQMJXbhkxWFT?embed" loading="lazy" allowfullscreen="" title="Walkthrough - Creating API Keys"></iframe>
<h2 id="api-keys-and-tokens">API keys and tokens</h2>
<p>The console supports five types of runZero API key, with different levels of access to runZero APIs. As an additional security option around API access, runZero allows users to create an IP address allowlist to restrict API access based on IP addresses and network ranges (in CIDR notation).</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Asset Route Pathing]]></title>
    <link href="https://www.runzero.com/docs/asset-route-pathing-report/"/>
    <id>https://www.runzero.com/docs/asset-route-pathing-report/</id>
      
      <published>2026-05-10T18:17:22+00:00</published>
      <updated>2026-05-10T18:17:22+00:00</updated>
      <summary type="html"><![CDATA[<p class="licenses"><a href="https://www.runzero.com/product/pricing/"><span class="pla">Platform</span></a></p>
<div class="alert alert-info">
<svg class="alert-icon" xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewbox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><circle cx="12" cy="12" r="10"></circle><line x1="12" y1="16" x2="12" y2="12"></line><line x1="12" y1="8" x2="12.01" y2="8"></line></svg>
<div class="alert-body">
<p>Most users should start with the <a href="/docs/network-map/">Network Map</a>, which lets you set sources and targets, trace inbound or outbound paths, apply per-hop include/exclude filters, and rank choke points — all in one interactive view.</p>
</div>
</div>
<p>The <span class="book-index" data-book-index="asset route pathing report">asset route pathing report</span> generates a visualization of the potential <span class="book-index" data-book-index="network paths">network paths</span> between a source asset and destination asset in an organization. Following the paths, you can see assets connected between the target and source destinations. These assets represent opportunities an attacker could potentially leverage to break into your target asset.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Network Bridge Report]]></title>
    <link href="https://www.runzero.com/docs/network-bridge-report/"/>
    <id>https://www.runzero.com/docs/network-bridge-report/</id>
      
      <published>2026-05-10T20:05:10+00:00</published>
      <updated>2026-05-10T20:05:10+00:00</updated>
      <summary type="html"><![CDATA[<p class="licenses"><a href="https://www.runzero.com/product/pricing/"><span class="pla">Platform</span></a></p>
<div class="alert alert-info">
<svg class="alert-icon" xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewbox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><circle cx="12" cy="12" r="10"></circle><line x1="12" y1="16" x2="12" y2="12"></line><line x1="12" y1="8" x2="12.01" y2="8"></line></svg>
<div class="alert-body">
<p>Most users should start with the <a href="/docs/network-map/">Network Map</a>. It surfaces the same multi-homed bridge assets — and goes further with subnet clustering, choke-point ranking, hop-filter tracing, and exports to Gephi, Cytoscape, and Visio.</p>
</div>
</div>
<p>The <span class="book-index" data-book-index="network bridge report">network bridge report</span> finds assets that bridge two or more network segments. These <span class="book-index" data-book-index="multi-homed">multi-homed</span> assets are the pivots an attacker uses to move between zones — between guest Wi-Fi and corporate LAN, between IT and OT, or between an internal segment and the public internet.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Switch Topology]]></title>
    <link href="https://www.runzero.com/docs/switch-topology-report/"/>
    <id>https://www.runzero.com/docs/switch-topology-report/</id>
      
      <published>2026-05-10T18:17:22+00:00</published>
      <updated>2026-05-10T18:17:22+00:00</updated>
      <summary type="html"><![CDATA[<p class="licenses"><a href="https://www.runzero.com/product/pricing/"><span class="pla">Platform</span></a></p>
<div class="alert alert-info">
<svg class="alert-icon" xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewbox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><circle cx="12" cy="12" r="10"></circle><line x1="12" y1="16" x2="12" y2="12"></line><line x1="12" y1="8" x2="12.01" y2="8"></line></svg>
<div class="alert-body">
<p>Most users should start with the <a href="/docs/network-map/">Network Map</a>, which combines switch topology, network bridges, and route pathing into a single interactive view with search, hop-filter tracing, and choke-point analysis.</p>
</div>
</div>
<p>The runZero <span class="book-index" data-book-index="switch topology">switch topology</span> report allows you to view a graph of the switches and routers on your network, and see
how they are interconnected. It will also show which assets are connected to each switch.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Site Comparison]]></title>
    <link href="https://www.runzero.com/docs/site-comparison-report/"/>
    <id>https://www.runzero.com/docs/site-comparison-report/</id>
      
      <published>2026-05-10T18:17:22+00:00</published>
      <updated>2026-05-10T18:17:22+00:00</updated>
      <summary type="html"><![CDATA[<p class="licenses"><a href="https://www.runzero.com/product/pricing/"><span class="pla">Platform</span></a></p>
<p>The <a href="https://console.runzero.com/reports/analysis/compare">Site and organization comparison feature</a> lets you generate a <span class="book-index" data-book-index="side-by-side">side-by-side</span> analysis of two sites, so you can understand:</p>
<ul>
<li><a href="/docs/site-comparison-report/#view-how-assets-change-over-time">How assets change over time</a> such as their TCP/UDP services, TCP/UDP ports, and service protocols. You can leverage this data to evaluate <span class="book-index" data-book-index="historical changes">historical changes</span> for assets for a specific point in time.</li>
<li><a href="/docs/site-comparison-report/#view-how-exposure-differs-between-networks">How exposure changes</a> based on scanning your network from different locations. For example, if you use public IP addresses internally and externally, you may want to scan those addresses from inside and outside your network to understand your potential exposure.</li>
</ul>
<p>The <span class="book-index" data-book-index="report">report</span> provides a summary view of <span class="book-index" data-book-index="differences">differences</span>. It only captures certain attributes that were added or removed from an asset, such as IP addresses, TCP ports, TCP service counts, UDP ports, UDP service counts, service protocols, and service counts. It does not track every modification to an asset, such as fingerprint or service banner changes.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[External Assets]]></title>
    <link href="https://www.runzero.com/docs/external-asset-report/"/>
    <id>https://www.runzero.com/docs/external-asset-report/</id>
      
      <published>2026-05-10T18:17:22+00:00</published>
      <updated>2026-05-10T18:17:22+00:00</updated>
      <summary type="html"><![CDATA[<p class="licenses"><a href="https://www.runzero.com/product/pricing/"><span class="pla">Platform</span></a></p>
<p>The <span class="book-index" data-book-index="External Asset Report">External Asset Report</span> captures a point-in-time snapshot of the external asset data within your organization and sites. The report organizes data from your asset inventory into relevant sections and summarizes the major findings. The External Asset Report is useful for sharing with teams and leaders who may not have access to runZero and need an at-a-glance look into their public-facing assets.</p>
<p>The report helps you quickly assess high-level metrics across multiple categories for external assets in your organization and sites, such as asset types, operating systems, hardware, protocols, and products. The report also includes a summary of top Certificate Authorities and GeoIP countries. For organizations with less than 50,000 assets, you can include additional information from your inventory via asset details and screenshots.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[RFC 1918 Report]]></title>
    <link href="https://www.runzero.com/docs/coverage-reports/"/>
    <id>https://www.runzero.com/docs/coverage-reports/</id>
      
      <published>2026-05-10T18:17:22+00:00</published>
      <updated>2026-05-10T18:17:22+00:00</updated>
      <summary type="html"><![CDATA[<p><span class="book-index" data-book-index="Coverage reports">Coverage reports</span> help you understand potential blind spots on your network by identifying which IP spaces have been scanned, which ones contain assets, and which ones still are unknown. With this information, you can find things like <span class="book-index" data-book-index="missing subnets">missing subnets</span>, rogue devices, and misconfigurations.</p>
<p>To access the <a href="https://console.runzero.com/reports/coverage">coverage reports</a>, go to <strong>Reports</strong> on the main menu and scroll down to <strong>RFC 1918 coverage</strong>.</p>
<iframe src="https://demo.arcade.software/hG1TeyEa7oywQBl8FIez?embed" loading="lazy" allowfullscreen="" title="Walkthroughs - RFC1918 Report"></iframe>
<h2 id="rfc1918-coverage-report">RFC1918 coverage report</h2>
<p>The <span class="book-index" data-book-index="RFC1918">RFC1918</span> coverage report helps you better track and identify the <span class="book-index" data-book-index="subnets">subnets</span> that are in use on your internal network, the ones that have been scanned, and the ones that haven’t been scanned.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Organization Overview]]></title>
    <link href="https://www.runzero.com/docs/organization-overview-report/"/>
    <id>https://www.runzero.com/docs/organization-overview-report/</id>
      
      <published>2026-05-10T18:17:22+00:00</published>
      <updated>2026-05-10T18:17:22+00:00</updated>
      <summary type="html"><![CDATA[<p class="licenses"><a href="https://www.runzero.com/product/pricing/"><span class="com">Community</span></a>&nbsp;<a href="https://www.runzero.com/product/pricing/"><span class="pla">Platform</span></a></p>
<p>The <span class="book-index" data-book-index="Organization Overview Report">Organization Overview Report</span> captures a point-in-time snapshot of the asset data within your organization and sites. The report organizes data from your asset inventory into relevant sections and summarizes the major findings. The Organization Overview Report is useful for sharing with teams and leaders who may not have access to runZero and need an at-a-glance look into their network.</p>
<p>The report helps you quickly assess high-level metrics across multiple categories for your organization and sites, such as your asset types, operating systems, hardware, protocols, and products. The report also includes a summary of your RFC 1918 coverage, subnet utilization, and switches. For organizations with less than 50,000 assets, you can include additional information from your inventory via asset details and screenshots.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[World Map]]></title>
    <link href="https://www.runzero.com/docs/world-map/"/>
    <id>https://www.runzero.com/docs/world-map/</id>
      
      <published>2026-05-10T18:17:22+00:00</published>
      <updated>2026-05-10T18:17:22+00:00</updated>
      <summary type="html"><![CDATA[<p class="licenses"><a href="https://www.runzero.com/product/pricing/"><span class="pla">Platform</span></a></p>
<p>The <span class="book-index" data-book-index="World Map">World Map</span> plots every asset that has a known geographic location on an interactive globe. It is the geographic counterpart to the <a href="/docs/network-map/">Network Map</a>: where the Network Map shows logical relationships between assets, the World Map shows where in the world each asset is.</p>
<h2 id="world-map-prerequisites">Prerequisites</h2>
<p>The World Map only shows assets that have at least one resolved location. runZero produces locations from MaxMind GeoIP lookups, cloud region centroids, integration attributes, and user-supplied <code>geo*</code> tags. See <a href="/docs/asset-geolocation/">Geolocation</a> for the full list of sources and how to manually pin an asset’s location.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Network Map]]></title>
    <link href="https://www.runzero.com/docs/network-map/"/>
    <id>https://www.runzero.com/docs/network-map/</id>
      
      <published>2026-05-13T14:38:20+00:00</published>
      <updated>2026-05-13T14:38:20+00:00</updated>
      <summary type="html"><![CDATA[<p class="licenses"><a href="https://www.runzero.com/product/pricing/"><span class="pla">Platform</span></a></p>
<p>The <span class="book-index" data-book-index="Network Map">Network Map</span> is an interactive Layer-2 / Layer-3 topology of every asset in the current scope. Where the <a href="/docs/world-map/">World Map</a> shows assets by physical location, the Network Map shows logical relationships: which subnets contain which assets, which gateways and switches connect them, and which assets pivot between subnets.</p>
<p>The map ships in two modes — a 2D Canvas view and a 3D rotating globe — that share the same data, search syntax, and trace engine.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Exporting HP iLO data]]></title>
    <link href="https://www.runzero.com/docs/exporting-hp-ilo/"/>
    <id>https://www.runzero.com/docs/exporting-hp-ilo/</id>
      
      <published>2025-01-19T12:09:42+00:00</published>
      <updated>2025-01-19T12:09:42+00:00</updated>
      <summary type="html"><![CDATA[<p class="licenses"><a href="https://www.runzero.com/product/pricing/"><span class="com">Community</span></a>&nbsp;<a href="https://www.runzero.com/product/pricing/"><span class="pla">Platform</span></a></p>
<p>HP Integrated Lights-Out (iLO) provides remote management, configuration, and monitoring capabilities for HP servers. These capabilities centralize operations for your server environments and streamline tasks like rebooting servers, booting into single user mode, and bypassing authentication.</p>
<p>Being able to identify and find the serial number for <span class="book-index" data-book-index="HP iLO">HP iLO</span> devices is useful for tracking warranties for support and contract management. If you have runZero Platform, you can export the runZero data as a CSV to feed into warranty tracking tools.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Exporting asset data]]></title>
    <link href="https://www.runzero.com/docs/exporting-asset-data/"/>
    <id>https://www.runzero.com/docs/exporting-asset-data/</id>
      
      <published>2024-08-29T12:20:50+00:00</published>
      <updated>2024-08-29T12:20:50+00:00</updated>
      <summary type="html"><![CDATA[<p>The <a href="https://console.runzero.com/inventory">inventory</a> view provides a few ways to <span class="book-index" data-book-index="export asset data">export asset data</span>. The <code>Export</code> menu offers Export All options in both <span class="book-index" data-book-index="CSV">CSV</span> and <span class="book-index" data-book-index="JSON">JSON</span> format, and when a <a href="/docs/search-query-syntax/">search query</a> has been provided, options to export just the search results as both CSV and JSON.</p>
<p>The CSV format can be opened with tools like Microsoft Excel and easily imported into other applications but does not contain the full details of certain fields, such as Services. The JSON format contains a complete export but may take additional processing to use with other tools.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Automating queries]]></title>
    <link href="https://www.runzero.com/docs/automating-queries/"/>
    <id>https://www.runzero.com/docs/automating-queries/</id>
      
      <published>2025-06-16T18:02:52+00:00</published>
      <updated>2025-06-16T18:02:52+00:00</updated>
      <summary type="html"><![CDATA[<p class="licenses"><a href="https://www.runzero.com/product/pricing/"><span class="com">Community</span></a>&nbsp;<a href="https://www.runzero.com/product/pricing/"><span class="pla">Platform</span></a></p>
<p>runZero’s <span class="book-index" data-book-index="query language">query language</span> allows you to search and filter your asset inventory, based on asset fields and values. runZero includes a <span class="book-index" data-book-index="query library">query library</span> of <span class="book-index" data-book-index="prebuilt searches">prebuilt searches</span> which can be browsed from the <span class="book-index" data-book-index="Queries">Queries</span> page. You can apply these queries after a scan to investigate discovery findings.</p>
<p>In addition to a flexible query language, the same search syntax can be used to track and monitor events across your network, based on any combination of fields. You can save your custom queries to reuse over and over again. Review the <a href="/docs/search-query-syntax/">query syntax</a> documentation for a refresher on how to build a query.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Events]]></title>
    <link href="https://www.runzero.com/docs/search-query-events/"/>
    <id>https://www.runzero.com/docs/search-query-events/</id>
      
      <published>2023-10-07T11:59:23+00:00</published>
      <updated>2023-10-07T11:59:23+00:00</updated>
      <summary type="html"><![CDATA[<p>When viewing <span class="book-index" data-book-index="system events">system events</span> under <span class="book-index" data-book-index="alerts">alerts</span>, you can use the keywords in this section to search and filter.</p>
<p>Note that event records are retained for one year.</p>
<h2 id="events-action">Action</h2>
<p>Use the syntax <code>action:&lt;text&gt;</code> to search by the action which caused the event.</p>
<pre><code class="language-plaintext">action:agent-reconnected
</code></pre>
<h2 id="events-timestamps">Created timestamp</h2>
<p>The timestamp fields <code>created_at</code> can be searched using the syntax <code>created_at:&lt;term&gt;</code>. The term supports the standard runZero <a href="/docs/search-query-syntax/#time-and-date-values">time comparison syntax</a>.</p>
<pre><code class="language-plaintext">created_at:&gt;2weeks
</code></pre>
<pre><code class="language-plaintext">created_at:&lt;30minutes
</code></pre>
<pre><code class="language-plaintext">updated_at:&gt;1month
</code></pre>
<pre><code class="language-plaintext">updated_at:2hours
</code></pre>
<h2 id="events-details">Details</h2>
<p>The details in the event record can be searched using the syntax <code>details:&lt;text&gt;</code>. This can be useful for searching for IP addresses.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Queries]]></title>
    <link href="https://www.runzero.com/docs/search-query-queries/"/>
    <id>https://www.runzero.com/docs/search-query-queries/</id>
      
      <published>2024-02-22T16:30:44+00:00</published>
      <updated>2024-02-22T16:30:44+00:00</updated>
      <summary type="html"><![CDATA[<p>When viewing saved queries, you can use the keywords in this section to <span class="book-index" data-book-index="search queries">search</span> and filter.</p>
<h2 id="queries-name">Name</h2>
<p>The <code>Name</code> field can be searched using the syntax <code>name:&lt;text&gt;</code>.</p>
<pre><code class="language-plaintext">name:&#34;smb2&#34;
</code></pre>
<h2 id="queries-description">Description</h2>
<p>The <code>Description</code> field can be searched using the syntax <code>description:&lt;text&gt;</code>.</p>
<pre><code class="language-plaintext">description:&#34;smb version 1&#34;
</code></pre>
<pre><code class="language-plaintext">description:&#34;wep&#34;
</code></pre>
<h2 id="queries-type">Type</h2>
<p>The <code>Type</code> field can be searched using the syntax <code>type:&lt;term&gt;</code> .</p>
<pre><code class="language-plaintext">type:&#34;services&#34;
</code></pre>
<h2 id="queries-category">Category</h2>
<p>The <code>Category</code> field can be searched using the syntax <code>category:&lt;term&gt;</code>.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Credentials]]></title>
    <link href="https://www.runzero.com/docs/search-query-credentials/"/>
    <id>https://www.runzero.com/docs/search-query-credentials/</id>
      
      <published>2024-02-22T16:30:44+00:00</published>
      <updated>2024-02-22T16:30:44+00:00</updated>
      <summary type="html"><![CDATA[<p>When viewing saved credentials, you can use the keywords in this section to <span class="book-index" data-book-index="search credentials">search</span> and filter.</p>
<h2 id="credential-fields">Credential fields</h2>
<h3 id="credentials-ID">Credential ID</h3>
<p>The ID field is the unique identifier for a given credential, written as a UUID. This field is searched using the syntax <code>id:&lt;uuid&gt;</code>.</p>
<pre><code class="language-plaintext">id:cdb084f9-4811-445c-8ea1-3ea9cf88d536
</code></pre>
<h3 id="credentials-name">Credential name</h3>
<p>The credential name can be searched using the syntax <code>name:&lt;text&gt;</code>.</p>
<pre><code class="language-plaintext">name:&#34;AWS read-only account&#34;
</code></pre>
<pre><code class="language-plaintext">name:&#34;Miradore API key&#34;
</code></pre>
<h3 id="credentials-type">Credential type</h3>
<p>The credential type can be searched using the syntax <code>name:&lt;text&gt;</code>.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Sites and organizations]]></title>
    <link href="https://www.runzero.com/docs/search-query-sitesorganizations/"/>
    <id>https://www.runzero.com/docs/search-query-sitesorganizations/</id>
      
      <published>2023-05-09T16:59:37+00:00</published>
      <updated>2023-05-09T16:59:37+00:00</updated>
      <summary type="html"><![CDATA[<h2 id="site-search-keywords"><span class="book-index" data-book-index="Site search">Site search</span> keywords</h2>
<p>When viewing sites, you can use the keywords in this section to search and filter.</p>
<h3 id="sites-name">Name</h3>
<p>The Name field can be searched using the syntax <code>name:&lt;text&gt;</code>.</p>
<pre><code class="language-plaintext">name:&#34;Primary&#34;
</code></pre>
<h3 id="sites-description">Description</h3>
<p>The Description field can be searched using the syntax <code>description:&lt;text&gt;</code>.</p>
<pre><code class="language-plaintext">description:&#34;wireless&#34;
</code></pre>
<pre><code class="language-plaintext">description:&#34;vlan 50&#34;
</code></pre>
<h3 id="sites-scope">Scope</h3>
<p>The Scope field can be searched using the syntax <code>scope:&lt;term&gt;</code> .</p>
<pre><code class="language-plaintext">scope:&#34;10.10.10.&#34;
</code></pre>
<h3 id="sites-excludes">Excludes</h3>
<p>The Excludes field can be searched using the syntax <code>excludes:&lt;term&gt;</code> .</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[runZero users and groups]]></title>
    <link href="https://www.runzero.com/docs/search-query-usersgroups/"/>
    <id>https://www.runzero.com/docs/search-query-usersgroups/</id>
      
      <published>2024-11-05T09:40:30+00:00</published>
      <updated>2024-11-05T09:40:30+00:00</updated>
      <summary type="html"><![CDATA[<h2 id="user-search-keywords"><span class="book-index" data-book-index="User search">User search</span> keywords</h2>
<p>When viewing users, you can use the keywords in this section to search and filter.</p>
<h3 id="users-email">Email</h3>
<p>Use the syntax <code>email:&lt;address&gt;</code> to search for someone by email address.</p>
<pre><code class="language-plaintext">email:john@example.com
</code></pre>
<h3 id="users-name">Name</h3>
<p>Use the syntax <code>name:&lt;text&gt;</code> to search for someone by name.</p>
<pre><code class="language-plaintext">name:john
</code></pre>
<pre><code class="language-plaintext">name:&#34;John Smith&#34;
</code></pre>
<h3 id="users-superuser">Superuser</h3>
<p>To search for people based on whether they have superuser access, use the term <code>superuser:&lt;boolean&gt;</code>.</p>
<pre><code class="language-plaintext">superuser:true
</code></pre>
<pre><code class="language-plaintext">superuser:f
</code></pre>
<h3 id="users-access">Access</h3>
<p>Use the syntax <code>access:&lt;term&gt;</code> to search for users with a specific access level. Possible access levels are <code>admin</code>, <code>user</code>, <code>annotator</code>, <code>viewer</code>, <code>billing</code> and <code>none</code>.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Explorers]]></title>
    <link href="https://www.runzero.com/docs/search-query-explorers/"/>
    <id>https://www.runzero.com/docs/search-query-explorers/</id>
      
      <published>2024-02-22T16:30:44+00:00</published>
      <updated>2024-02-22T16:30:44+00:00</updated>
      <summary type="html"><![CDATA[<p>When viewing deployed Explorers, you can use the keywords in this section to <span class="book-index" data-book-index="search explorers">search</span> and filter.</p>
<h2 id="explorers-name">Name</h2>
<p>The Name field can be searched using the syntax <code>name:&lt;text&gt;</code>.</p>
<pre><code class="language-plaintext">name:&#34;main&#34;
</code></pre>
<h2 id="explorers-site">Site</h2>
<p>The site can be searched using the syntax <code>site:&lt;text&gt;</code>.</p>
<pre><code class="language-plaintext">site:Primary
</code></pre>
<h2 id="explorers-up">Up</h2>
<p>Whether the Explorer is up can be searched using the syntax <code>up:&lt;boolean&gt;</code>.</p>
<pre><code class="language-plaintext">up:true
</code></pre>
<h2 id="explorers-address">Address</h2>
<p>The IP address(es) the Explorer is deployed on can be searched using the syntax <code>address:&lt;IP address&gt;</code>.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Analysis reports]]></title>
    <link href="https://www.runzero.com/docs/search-query-reports/"/>
    <id>https://www.runzero.com/docs/search-query-reports/</id>
      
      <published>2024-02-22T16:30:44+00:00</published>
      <updated>2024-02-22T16:30:44+00:00</updated>
      <summary type="html"><![CDATA[<p>When viewing generated analysis reports, you can use the keywords in this section to <span class="book-index" data-book-index="search reports">search</span> and filter.</p>
<h2 id="reports-name">Name</h2>
<p>The Name field can be searched using the syntax <code>name:&lt;text&gt;</code>.</p>
<pre><code class="language-plaintext">name:&#34;main&#34;
</code></pre>
<h2 id="reports-description">Description</h2>
<p>The Description field can be searched using the syntax <code>description:&lt;text&gt;</code></p>
<pre><code class="language-plaintext">description:&#34;compare secondary&#34;
</code></pre>
<h2 id="reports-type">Type</h2>
<p>The report type can be searched using the syntax <code>type:&lt;text&gt;</code></p>
<pre><code class="language-plaintext">type:outliers
</code></pre>
<h2 id="reports-ID">Report ID</h2>
<p>The ID field is the unique identifier for a given analysis report, written as a UUID. This field is searched using the syntax <code>id:&lt;uuid&gt;</code>.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Tasks]]></title>
    <link href="https://www.runzero.com/docs/search-query-tasks/"/>
    <id>https://www.runzero.com/docs/search-query-tasks/</id>
      
      <published>2024-02-22T16:30:44+00:00</published>
      <updated>2024-02-22T16:30:44+00:00</updated>
      <summary type="html"><![CDATA[<p>When viewing all tasks, you can use the keywords in this section to <span class="book-index" data-book-index="searching tasks">search</span> and filter them.</p>
<h2 id="task-name">Name</h2>
<p>The Name field can be searched using the syntax <code>name:&lt;text&gt;</code>.</p>
<pre><code class="language-plaintext">name:&#34;test scan&#34;
</code></pre>
<h2 id="task-description">Description</h2>
<p>The Description field can be searched using the syntax <code>description:&lt;text&gt;</code></p>
<pre><code class="language-plaintext">description:&#34;full scan&#34;
</code></pre>
<h2 id="task-createdBy">Created by</h2>
<p>The <code>Created By</code> field can be searched using the syntax <code>created_by:&lt;term&gt;</code>.</p>
<pre><code class="language-plaintext">created_by:&#34;admin&#34;
</code></pre>
<h2 id="task-type">Type</h2>
<p>The task type can be searched using <code>type:&lt;text&gt;</code>.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Findings]]></title>
    <link href="https://www.runzero.com/docs/search-query-findings/"/>
    <id>https://www.runzero.com/docs/search-query-findings/</id>
      
      <published>2025-12-10T12:22:32+00:00</published>
      <updated>2025-12-10T12:22:32+00:00</updated>
      <summary type="html"><![CDATA[<p>When viewing <span class="book-index" data-book-index="findings">findings</span>, you can use the keywords in this section to search and filter.</p>
<h2 id="finding-code">Finding code</h2>
<p>The <span class="book-index" data-book-index="finding code">finding code</span> field is the unique identifier for a given finding. Use the syntax <code>finding_code:&lt;uuid&gt;</code> to filter by the code field.</p>
<pre><code class="language-plaintext">finding_code:rz-finding-internet-exposed-database
</code></pre>
<h2 id="finding-name">Name</h2>
<p>Use the syntax <code>name:&lt;text&gt;</code> to search by finding name.</p>
<pre><code class="language-plaintext">name:&#34;Internet Exposed Database&#34;
</code></pre>
<h2 id="finding-description">Description</h2>
<p>The <code>Description</code> field can be searched using the syntax <code>description:&lt;text&gt;</code>.</p>
<pre><code class="language-plaintext">description:&#34;indicated databases&#34;
</code></pre>
<h2 id="finding-solution">Solution</h2>
<p>The <code>Solution</code> field can be searched using the syntax <code>solution:&lt;text&gt;</code>.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Scan templates]]></title>
    <link href="https://www.runzero.com/docs/search-query-scantemplates/"/>
    <id>https://www.runzero.com/docs/search-query-scantemplates/</id>
      
      <published>2024-02-22T16:30:44+00:00</published>
      <updated>2024-02-22T16:30:44+00:00</updated>
      <summary type="html"><![CDATA[<p>When viewing scan templates, you can use the keywords in this section to <span class="book-index" data-book-index="search scan templates">search</span> and filter.</p>
<h2 id="scantemplate-ID">ID</h2>
<p>The ID field is the unique identifier for a given template, written as a UUID. Use the syntax <code>id:&lt;uuid&gt;</code> to filter by ID field.</p>
<pre><code class="language-plaintext">id:cdb084f9-4811-445c-8ea1-3ea9cf88d536
</code></pre>
<h2 id="scantemplate-name">Name</h2>
<p>Use the syntax <code>name:&lt;text&gt;</code> to search by scan template name.</p>
<pre><code class="language-plaintext">name:WiFi
</code></pre>
<pre><code class="language-plaintext">name:&#34;Data Center&#34;
</code></pre>
<h2 id="scantemplate-timestamps">Timestamps</h2>
<p>Use the following syntaxes to search the scan template timestamp fields (<code>created_at</code>, <code>updated_at</code>):</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Interface keywords]]></title>
    <link href="https://www.runzero.com/docs/search-query-components/"/>
    <id>https://www.runzero.com/docs/search-query-components/</id>
      
      <published>2025-05-27T13:27:12+00:00</published>
      <updated>2025-05-27T13:27:12+00:00</updated>
      <summary type="html"><![CDATA[<p>The data across your runZero account can be queried and filtered using the <a href="/docs/search-query-syntax/">search syntax</a> in conjunction with the available interface-specific keywords. Keywords and example values are documented for the following sections of the runZero Console:</p>
<ul>
<li><a href="/docs/search-query-scantemplates/">Scan templates</a></li>
<li><a href="/docs/search-query-findings/">Findings</a></li>
<li><a href="/docs/search-query-tasks/">Tasks</a></li>
<li><a href="/docs/search-query-reports/">Analysis reports</a></li>
<li><a href="/docs/search-query-explorers/">Explorers</a></li>
<li><a href="/docs/search-query-usersgroups/">runZero users and groups</a></li>
<li><a href="/docs/search-query-sitesorganizations/">Sites and organizations</a></li>
<li><a href="/docs/search-query-credentials/">Credentials</a></li>
<li><a href="/docs/search-query-queries/">Queries</a></li>
<li><a href="/docs/search-query-events/">Events</a></li>
</ul>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Groups inventory]]></title>
    <link href="https://www.runzero.com/docs/search-query-groups/"/>
    <id>https://www.runzero.com/docs/search-query-groups/</id>
      
      <published>2024-02-22T16:30:44+00:00</published>
      <updated>2024-02-22T16:30:44+00:00</updated>
      <summary type="html"><![CDATA[<p>When viewing the Groups inventory, you can use the following keywords to <span class="book-index" data-book-index="search groups">search</span> and filter groups.</p>
<h2 id="groups-source">Source</h2>
<p>The source reporting the groups can be searched or filtered by name using the syntax <code>source:&lt;name&gt;</code>.</p>
<pre><code class="language-plaintext">source:ldap
</code></pre>
<h2 id="groups-names">Name fields</h2>
<p>There are two name fields found in the group attributes that can be searched or filtered using the same syntax. Use the syntax <code>&lt;name_field&gt;:&lt;text&gt;</code> to search a field for matches.</p>
<p>The following name fields can be searched this way:</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Users inventory]]></title>
    <link href="https://www.runzero.com/docs/search-query-users/"/>
    <id>https://www.runzero.com/docs/search-query-users/</id>
      
      <published>2024-02-22T16:30:44+00:00</published>
      <updated>2024-02-22T16:30:44+00:00</updated>
      <summary type="html"><![CDATA[<p>When viewing the Users inventory, you can use the following keywords to <span class="book-index" data-book-index="search users">search</span> and filter users.</p>
<h2 id="users-source">Source</h2>
<p>The source reporting the users can be searched or filtered by name using the syntax <code>source:&lt;name&gt;</code>.</p>
<pre><code class="language-plaintext">source:ldap
</code></pre>
<h2 id="users-names">Name fields</h2>
<p>There are multiple name fields found in the user attributes that can be searched or filtered using the same syntax. Use the syntax <code>&lt;name_field&gt;:&lt;text&gt;</code> to search a field for matches.</p>
<p>The following name fields can be searched this way:</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Wireless inventory]]></title>
    <link href="https://www.runzero.com/docs/search-query-wireless/"/>
    <id>https://www.runzero.com/docs/search-query-wireless/</id>
      
      <published>2024-02-22T16:30:44+00:00</published>
      <updated>2024-02-22T16:30:44+00:00</updated>
      <summary type="html"><![CDATA[<p>When viewing WiFi networks, you can use the keywords in this section to <span class="book-index" data-book-index="search WiFi networks">search</span> and filter.</p>
<h2 id="wireless-SSID">SSID and ESSID</h2>
<p>The <span class="book-index" data-book-index="SSID">SSID</span>/<span class="book-index" data-book-index="ESSID">ESSID</span> field can be searched using the syntax <code>ssid:&lt;text&gt;</code>.</p>
<pre><code class="language-plaintext">ssid:&#34;Guest Network&#34;
</code></pre>
<pre><code class="language-plaintext">ssid:&#34;Corporate&#34;
</code></pre>
<h2 id="wireless-BSSID">BSSID (MAC)</h2>
<p>The BSSID field can be searched using the syntax <code>bssid:&lt;text&gt;</code> or <code>mac:&lt;text&gt;</code>.</p>
<pre><code class="language-plaintext">bssid:&#34;00:01:02:03:04:05&#34;
</code></pre>
<pre><code class="language-plaintext">mac:&#34;00:01:%&#34;
</code></pre>
<h2 id="wireless-vendor">Vendor</h2>
<p>The vendor field can be searched using the syntax <code>mac_vendor:&lt;text&gt;</code>.</p>
<pre><code class="language-plaintext">mac_vendor:&#34;Google&#34;
</code></pre>
<pre><code class="language-plaintext">mac_vendor:&#34;Netgear&#34;
</code></pre>
<pre><code class="language-plaintext">mac_vendor:&#34;Cisco&#34;
</code></pre>
<h2 id="wireless-family">Family</h2>
<p>The family field can be searched using the syntax <code>family:&lt;term&gt;</code>.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Certificate inventory]]></title>
    <link href="https://www.runzero.com/docs/search-query-certificates/"/>
    <id>https://www.runzero.com/docs/search-query-certificates/</id>
      
      <published>2025-11-05T10:06:01+00:00</published>
      <updated>2025-11-05T10:06:01+00:00</updated>
      <summary type="html"><![CDATA[<p>When viewing certificates, you can use the following keywords to <span class="book-index" data-book-index="search certificates">search</span> and filter.</p>
<h2 id="general-certificate-fields">General certificate fields</h2>
<h3 id="certificates-ID">Certificate ID</h3>
<p>The ID field is the unique identifier for a given certificate, written as a UUID. Use the syntax <code>id:&lt;uuid&gt;</code> to filter by ID field.</p>
<pre><code class="language-plaintext">id:21e5252d-a6a5-467e-83ed-683657412dff
</code></pre>
<h3 id="certificates-type">Certificate type</h3>
<p>Use the syntax <code>type:&lt;text&gt;</code> to search for certificates by type.</p>
<pre><code class="language-plaintext">type:x509
</code></pre>
<h3 id="certificates-name">Name</h3>
<p>Use the syntax <code>name:&lt;text&gt;</code> to search for certificates by name.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Vulnerability instance inventory]]></title>
    <link href="https://www.runzero.com/docs/search-query-vulnerabilities/"/>
    <id>https://www.runzero.com/docs/search-query-vulnerabilities/</id>
      
      <published>2026-03-10T13:09:54+00:00</published>
      <updated>2026-03-10T13:09:54+00:00</updated>
      <summary type="html"><![CDATA[<p>When viewing <span class="book-index" data-book-index="vulnerability instances">vulnerability instances</span> on assets, you can use the following keywords to <span class="book-index" data-book-index="search vulnerabilities">search</span> and filter information.</p>
<h2 id="vulnerability-ID">Vulnerability ID</h2>
<p>The ID field is the unique identifier for a given vulnerability, written as a UUID. Use the syntax <code>id:&lt;uuid&gt;</code> to filter by the ID field.</p>
<pre><code class="language-plaintext">id:a124a141-e518-4735-9878-8e89c575b1d2
</code></pre>
<h2 id="vulnerability-source">Source</h2>
<p>The source reporting the vulnerability detected can be searched or filtered by name using the syntax <code>source:&lt;name&gt;</code>.</p>
<pre><code class="language-plaintext">source:tenable
</code></pre>
<h2 id="vulnerability-severity">Severity</h2>
<p>The severity field can be searched using the syntax <code>severity:&lt;term&gt;</code>.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Vulnerabilities inventory]]></title>
    <link href="https://www.runzero.com/docs/search-query-vulnerability-groups/"/>
    <id>https://www.runzero.com/docs/search-query-vulnerability-groups/</id>
      
      <published>2026-03-10T13:09:54+00:00</published>
      <updated>2026-03-10T13:09:54+00:00</updated>
      <summary type="html"><![CDATA[<p>When viewing <span class="book-index" data-book-index="vulnerability groups">vulnerability groups</span>, you can use the keywords in this section to search and filter.</p>
<h2 id="vulnerabilities-name">Name</h2>
<p>The name field can be searched using the syntax <code>name:&lt;term&gt;</code>.</p>
<pre><code class="language-plaintext">name:&#34;Cisco IOS Software DHCP Remote Code Execution Vulnerability&#34;
</code></pre>
<pre><code class="language-plaintext">name:&#34;PHP &lt; 5.3.12 / 5.4.2 CGI Query String Code Execution&#34;
</code></pre>
<h2 id="vulnerabilities-CVE">CVE</h2>
<p>The CVE field can be searched using the syntax <code>cve:&lt;term&gt;</code>.</p>
<pre><code class="language-plaintext">cve:CVE-2021-44228
</code></pre>
<pre><code class="language-plaintext">cve:CVE-2016-2183
</code></pre>
<h2 id="vulnerabilities-KEV">KEV</h2>
<p>Membership in a Known Exploited Vulnerability (KEV) list can be searched using the syntax <code>kev:&lt;term&gt;</code>.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Software instance inventory]]></title>
    <link href="https://www.runzero.com/docs/search-query-software/"/>
    <id>https://www.runzero.com/docs/search-query-software/</id>
      
      <published>2024-02-22T16:30:44+00:00</published>
      <updated>2024-02-22T16:30:44+00:00</updated>
      <summary type="html"><![CDATA[<p>When viewing software instances on assets, you can use the keywords in this section to <span class="book-index" data-book-index="search software">search</span> and filter.</p>
<h2 id="source">Source</h2>
<p>The source reporting the software installed can be searched or filtered by name using the syntax <code>source:&lt;name&gt;</code>.</p>
<pre><code class="language-plaintext">source:runzero
</code></pre>
<h2 id="vendor">Vendor</h2>
<p>The vendor associated with a software can be searched by name using the syntax <code>vendor:&lt;name&gt;</code>.</p>
<pre><code class="language-plaintext">vendor:oracle
</code></pre>
<h2 id="product">Product</h2>
<p>The product associated with a software can be searched by name using the syntax <code>product:&lt;name&gt;</code>.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Software inventory]]></title>
    <link href="https://www.runzero.com/docs/search-query-software-groups/"/>
    <id>https://www.runzero.com/docs/search-query-software-groups/</id>
      
      <published>2024-02-22T16:30:44+00:00</published>
      <updated>2024-02-22T16:30:44+00:00</updated>
      <summary type="html"><![CDATA[<p>When viewing <span class="book-index" data-book-index="software groups">software groups</span>, you can use the keywords in this section to search and filter.</p>
<h2 id="sgvendor">Vendor</h2>
<p>The vendor associated with a software can be searched by name using the syntax <code>vendor:&lt;name&gt;</code>.</p>
<pre><code class="language-plaintext">vendor:oracle
</code></pre>
<h2 id="sgproduct">Product</h2>
<p>The product associated with a software can be searched by name using the syntax <code>product:&lt;name&gt;</code>.</p>
<pre><code class="language-plaintext">product:java
</code></pre>
<h2 id="sgversion">Version</h2>
<p>The version associated with a software can be searched by name using the syntax <code>version:&lt;name&gt;</code>.</p>
<pre><code class="language-plaintext">version:1.2.3
</code></pre>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Service inventory]]></title>
    <link href="https://www.runzero.com/docs/search-query-services/"/>
    <id>https://www.runzero.com/docs/search-query-services/</id>
      
      <published>2025-12-15T10:35:10+00:00</published>
      <updated>2025-12-15T10:35:10+00:00</updated>
      <summary type="html"><![CDATA[<p>When viewing services, you can use the keywords in this section to <span class="book-index" data-book-index="search services">search</span> and filter.</p>
<h2 id="services-ports">Ports</h2>
<p>The TCP and UDP services associated with a service can be searched by port number using the syntax <code>port:&lt;number&gt;</code>.
This search term supports numerical comparison operators (<code>&gt;</code>, <code>&gt;=</code>, <code>&lt;</code>, <code>&lt;=</code>, <code>=</code>).</p>
<pre><code class="language-plaintext">port:&lt;=25
</code></pre>
<h2 id="services-TCP">TCP ports</h2>
<p>Use the syntax <code>tcp:&lt;number&gt;</code> to search TCP service associated with a service by port number.</p>
<pre><code class="language-plaintext">tcp:53
</code></pre>
<p>To search for all services on assets with a specific list of TCP ports open, you can use the syntax <code>service_ports_tcp:=&lt;list&gt;</code>. Values should be in ascending numerical order, and separated by commas.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Asset inventory]]></title>
    <link href="https://www.runzero.com/docs/search-query-assets/"/>
    <id>https://www.runzero.com/docs/search-query-assets/</id>
      
      <published>2026-05-13T14:38:20+00:00</published>
      <updated>2026-05-13T14:38:20+00:00</updated>
      <summary type="html"><![CDATA[<p>When viewing assets, you can use the following keywords to <span class="book-index" data-book-index="search assets">search</span> and filter.</p>
<h2 id="user-specified-fields">User-specified fields</h2>
<h3 id="assets-comments">Comments</h3>
<p>Use the syntax <code>comment:&lt;text&gt;</code> to search comments on an asset.</p>
<pre><code class="language-plaintext">comment:&#34;contractor laptop&#34;
</code></pre>
<pre><code class="language-plaintext">comment:&#34;imaging server&#34;
</code></pre>
<h3 id="assets-tags">Tags</h3>
<p>Use the syntax <code>tag:&lt;term&gt;</code> to search tags added to an asset. The term can be the tag name, or the tag name followed by an equal sign and the tag value. Tag value matches must be exact.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Inventory keywords]]></title>
    <link href="https://www.runzero.com/docs/search-query-inventory/"/>
    <id>https://www.runzero.com/docs/search-query-inventory/</id>
      
      <published>2025-05-27T13:27:12+00:00</published>
      <updated>2025-05-27T13:27:12+00:00</updated>
      <summary type="html"><![CDATA[<p>The data across your runZero inventories can be queried and filtered using the <a href="/docs/search-query-syntax/">search syntax</a> in conjunction with the available inventory keywords. Keywords and example values are documented for the following inventories:</p>
<ul>
<li><a href="/docs/search-query-assets/">Assets</a></li>
<li><a href="/docs/search-query-services/">Services</a></li>
<li><a href="/docs/search-query-software-groups/">Software</a></li>
<li><a href="/docs/search-query-vulnerabilities/">Vulnerabilities</a></li>
<li><a href="/docs/search-query-certificates/">Certificates</a></li>
<li><a href="/docs/search-query-wireless/">Wireless networks</a></li>
<li><a href="/docs/search-query-users/">Users</a></li>
<li><a href="/docs/search-query-groups/">Groups</a></li>
</ul>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Query examples]]></title>
    <link href="https://www.runzero.com/docs/search-query-examples/"/>
    <id>https://www.runzero.com/docs/search-query-examples/</id>
      
      <published>2025-05-01T15:16:04+00:00</published>
      <updated>2025-05-01T15:16:04+00:00</updated>
      <summary type="html"><![CDATA[<p>There are endless ways to combine terms and operators into effective queries, and the <span class="book-index" data-book-index="example queries">examples</span> below can be used as-is or adjusted to meet your needs.</p>
<h2 id="network-configurations-and-access">Network configurations and access</h2>
<ul>
<li>Multihomed assets with public and private IP addresses:</li>
</ul>
<pre><code class="language-plaintext">alive:t AND has_public:t AND has_private:t
</code></pre>
<ul>
<li>Multihomed assets connected only to private networks</li>
</ul>
<pre><code class="language-plaintext">multi_home:t AND has_public:f
</code></pre>
<ul>
<li>Default SSH configuration using passwords for authentication:</li>
</ul>
<pre><code class="language-plaintext">alive:t AND protocol:&#34;ssh&#34; AND ssh.authMethods:&#34;=password&#34;
</code></pre>
<ul>
<li>Microsoft FTP servers:</li>
</ul>
<pre><code class="language-plaintext">alive:t AND protocol:&#34;ftp&#34; AND banner:&#34;=%Microsoft FTP%&#34;
</code></pre>
<ul>
<li>Remote access services/protocols:</li>
</ul>
<pre><code class="language-plaintext">protocol:rdp OR protocol:vnc OR protocol:teamviewer
</code></pre>
<ul>
<li>Assets with public IPs running remote access services:</li>
</ul>
<pre><code class="language-plaintext">has_public:t OR has_public:t AND alive:t AND (protocol:rdp OR protocol:vnc OR protocol:teamviewer)
</code></pre>
<ul>
<li>Open ports associated with cleartext protocols:</li>
</ul>
<pre><code class="language-plaintext">port:21 OR port:23 OR port:80 OR port:443 OR port:139 OR port:445 OR port:3306 OR port:1433 OR port:161 OR 
port:8080 OR port:3389 OR port:5900
</code></pre>
<ul>
<li>Telnet on nondefault ports:</li>
</ul>
<pre><code class="language-plaintext">protocol:telnet AND NOT port:23
</code></pre>
<ul>
<li>Windows assets offering SMB services:</li>
</ul>
<pre><code class="language-plaintext">os:windows AND protocol:smb1 OR protocol:smb2
</code></pre>
<ul>
<li>Switch assets accepting Username and Password authentication:</li>
</ul>
<pre><code class="language-plaintext">type:switch AND (_asset.protocol:http AND NOT _asset.protocol:tls) AND ( html.inputs:&#34;password:&#34; OR 
last.html.inputs:&#34;password:&#34; OR has:http.head.wwwAuthenticate OR has:last.http.head.wwwAuthenticate )
</code></pre>
<ul>
<li>Assets more than 8 hops away:</li>
</ul>
<pre><code class="language-plaintext">attribute:&#34;ip.ttl.hops&#34; AND ip.ttl.hops:&gt;&#34;8
</code></pre>
<h2 id="asset-lifecycle-and-hardware">Asset lifecycle and hardware</h2>
<ul>
<li>Assets created as a result of arbitrary responses:</li>
</ul>
<pre><code class="language-plaintext">has_mac:f AND has_name:f AND os:= AND hardware:= AND detected_by:icmp AND service_count:&lt;2
</code></pre>
<ul>
<li>End of Life assets:</li>
</ul>
<pre><code class="language-plaintext">os_eol:&lt;now
</code></pre>
<ul>
<li>Assets where both OS support and extended support are expired:</li>
</ul>
<pre><code class="language-plaintext">os_eol:&lt;now AND os_eol_extended:&lt;now
</code></pre>
<ul>
<li>Assets where OS support is EOL but still covered by extended support:</li>
</ul>
<pre><code class="language-plaintext">os_eol:&lt;now AND os_eol_extended:&gt;now
</code></pre>
<ul>
<li>EOL Linux operating systems:</li>
</ul>
<pre><code class="language-plaintext">os:linux AND os_eol:&lt;now
</code></pre>
<ul>
<li>EOL Windows operating systems:</li>
</ul>
<pre><code class="language-plaintext">os:windows AND os_eol:&lt;now
</code></pre>
<ul>
<li>Assets discovered within the past two weeks:</li>
</ul>
<pre><code class="language-plaintext">first_seen:&#34;&lt;2weeks&#34;
</code></pre>
<ul>
<li>All available serial number sources</li>
</ul>
<pre><code class="language-plaintext">protocol:snmp has:snmp.serialNumbers OR hw.serialNumber:t OR ilo.serialNumber:t
</code></pre>
<ul>
<li>Asset serial numbers from SNMP:</li>
</ul>
<pre><code class="language-plaintext">protocol:snmp has:snmp.serialNumbers
</code></pre>
<ul>
<li>Older Windows OSes:</li>
</ul>
<pre><code class="language-plaintext">os:&#34;Windows Server 2012&#34; OR os:&#34;Windows 7&#34;
</code></pre>
<ul>
<li>Older Linux OSes:</li>
</ul>
<pre><code class="language-plaintext">OS:linux AND os_eol:&lt;now
</code></pre>
<ul>
<li>BACnet devices:</li>
</ul>
<pre><code class="language-plaintext">type:bacnet
</code></pre>
<ul>
<li>Hikvision DVRs:</li>
</ul>
<pre><code class="language-plaintext">type:dvr AND os:hikvision
</code></pre>
<ul>
<li>IoT Devices:</li>
</ul>
<pre><code class="language-plaintext">type:&#34;IP Camera&#34; OR type:&#34;thermostat&#34; OR type:&#34;Amazon Device&#34; OR hw:&#34;Google Chromecast&#34; OR 
type:&#34;Game Console&#34; OR type:&#34;Robotic Cleaner&#34; OR type:&#34;Nest Device&#34; OR type:&#34;Network Audio&#34; OR 
type:&#34;Smart TV&#34; OR type:&#34;VR Headset&#34; OR type:&#34;Voice Assistant&#34;&#34;
</code></pre>
<ul>
<li>Video-related assets:</li>
</ul>
<pre><code class="language-plaintext">type:&#34;IP Camera&#34; OR type:&#34;DVR&#34; OR type:&#34;Video Encoder&#34;
</code></pre>
<h2 id="misconfigurations">Misconfigurations</h2>
<ul>
<li>SMBv1:</li>
</ul>
<pre><code class="language-plaintext">protocol:&#34;smb1&#34;
</code></pre>
<ul>
<li>Remote access with common services:</li>
</ul>
<pre><code class="language-plaintext">protocol:rdp OR protocol:vnc OR protocol:teamviewer OR protocol:spice OR protocol:pca
</code></pre>
<ul>
<li>Switches with default configurations for web access:</li>
</ul>
<pre><code class="language-plaintext">type:switch AND (_asset.protocol:http AND NOT _asset.protocol:tls) AND ( html.inputs:&#34;password:&#34; OR 
last.html.inputs:&#34;password:&#34; OR has:http.head.wwwAuthenticate OR has:last.http.head.wwwAuthenticate )
</code></pre>
<ul>
<li>Default SSH configurations using passwords for authentication:</li>
</ul>
<pre><code class="language-plaintext">alive:t AND protocol:&#34;ssh&#34; AND ssh.authMethods:&#34;=password&#34;
</code></pre>
<ul>
<li>Switches using Telnet or HTTP for remote access:</li>
</ul>
<pre><code class="language-plaintext">type:switch AND protocol:telnet OR protocol:http
</code></pre>
<ul>
<li>Microsoft FTP servers:</li>
</ul>
<pre><code class="language-plaintext">alive:t AND protocol:&#34;ftp&#34; AND banner:&#34;=%Microsoft FTP%&#34;
</code></pre>
<ul>
<li>Virtual machines that are not syncing time with the host:</li>
</ul>
<pre><code class="language-plaintext">@vmware.vm.config.tools.syncTimeWithHost:&#34;False&#34;
</code></pre>
<h2 id="weak-configurations">Weak configurations</h2>
<ul>
<li>Telnet (vs. SSH):</li>
</ul>
<pre><code class="language-plaintext">protocol:telnet
</code></pre>
<ul>
<li>FTP on ports 10-21 (vs. FTPS on port 990):</li>
</ul>
<pre><code class="language-plaintext">protocol:ftp
</code></pre>
<ul>
<li>FTP on ports 20-21 (vs. SCP on port 22):</li>
</ul>
<pre><code class="language-plaintext">protocol:ftp
</code></pre>
<ul>
<li>HTTP on port 80 (vs. HTTPS on port 443):</li>
</ul>
<pre><code class="language-plaintext">protocol:http
</code></pre>
<ul>
<li>SSH versions &lt; 2.0:</li>
</ul>
<pre><code class="language-plaintext">protocol:ssh AND NOT banner:&#34;SSH-2.0&#34;
</code></pre>
<ul>
<li>TLS:</li>
</ul>
<pre><code class="language-plaintext">tls.versionName:&#34;=TLSv1.3&#34; OR tls.versionName:&#34;=TLSv1.2&#34; OR tls.versionName:&#34;=TLSv1.1&#34; OR 
tls.versionName:&#34;=TLSv1.0&#34;
</code></pre>
<ul>
<li>LDAP on port 389 (vs. LDAPS on port 636):</li>
</ul>
<pre><code class="language-plaintext">protocol:ldap OR port:389
</code></pre>
<ul>
<li>Wireless access points without WPA authentication:</li>
</ul>
<pre><code class="language-plaintext">not authentication:WPA
</code></pre>
<ul>
<li>Online assets with SSH accepting password authentication:</li>
</ul>
<pre><code class="language-plaintext">alive:t AND has:&#34;ssh.authMethods&#34; AND protocol:&#34;ssh&#34; AND (ssh.authMethods:&#34;=password&#34; OR 
ssh.authMethods:&#34;=password%publickey&#34;)
</code></pre>
<ul>
<li>Detect OpenSSL version 3.0 - 3.0.6:</li>
</ul>
<pre><code class="language-plaintext">product:openssl AND version:3.0
</code></pre>
<h2 id="edr--mdm">EDR / MDM</h2>
<ul>
<li>CrowdStrike coverage gaps:</li>
</ul>
<pre><code class="language-plaintext">not edr.name:crowdstrike AND (type:server OR type:desktop OR type:laptop)
</code></pre>
<ul>
<li>Assets with CrowdStrike Agent status “Not Provisioned”:</li>
</ul>
<pre><code class="language-plaintext">@crowdstrike.dev.provisionStatus:&#34;NotProvisioned&#34;
</code></pre>
<ul>
<li>Assets with CrowdStrike Agent mode “Reduced Functionality”:</li>
</ul>
<pre><code class="language-plaintext">@crowdstrike.dev.reducedFunctionalityMode:&#34;yes&#34;
</code></pre>
<ul>
<li>Assets with CrowdStrike Agent status “Normal”:</li>
</ul>
<pre><code class="language-plaintext">@crowdstrike.dev.status:&#34;normal&#34;
</code></pre>
<ul>
<li>SentinelOne coverage gaps:</li>
</ul>
<pre><code class="language-plaintext">not edr.name:Sentinelone AND (type:server OR type:desktop OR type:laptop)
</code></pre>
<ul>
<li>Assets with SentinelOne Agent requiring patch:</li>
</ul>
<pre><code class="language-plaintext">(alive:t OR scanned:f) AND has:&#34;@sentinelone.dev.appsVulnerabilityStatus&#34; AND 
@sentinelone.dev.appsVulnerabilityStatus:&#34;=patch_required&#34;
</code></pre>
<ul>
<li>Assets missing either CrowdStrike or SentinelOne EDR agents:</li>
</ul>
<pre><code class="language-plaintext">NOT edr.name:crowdstrike AND (type:server OR type:desktop OR type:laptop) OR NOT edr.name:sentinelone AND
(type:server OR type:desktop OR type:laptop)
</code></pre>
<ul>
<li>Miradore coverage gaps:</li>
</ul>
<pre><code class="language-plaintext">not source:Miradore AND (os:google android OR os:apple ios) AND type:mobile
</code></pre>
<ul>
<li>Microsoft Defender coverage gaps:</li>
</ul>
<pre><code class="language-plaintext">not edr.name:&#34;Defender&#34; AND os:Windows
</code></pre>
<ul>
<li>Assets not managed by a Microsoft product:</li>
</ul>
<pre><code class="language-plaintext">source:runzero AND NOT (source:ms365defender OR source:intune OR source:azuread)
</code></pre>
<ul>
<li>Find mobile devices on the network:</li>
</ul>
<pre><code class="language-plaintext">(os:google ANDroid OR os:apple ios) AND type:mobile
</code></pre>
<ul>
<li>Known FCC security threats, like Kaspersky:</li>
</ul>
<pre><code class="language-plaintext">alive:t AND edr.name:Kaspersky
</code></pre>
<h2 id="virtual-machine-configurations">Virtual machine configurations</h2>
<ul>
<li>Virtual machines with less than 8 GB of memory:</li>
</ul>
<pre><code class="language-plaintext">@vmware.vm.config.hardware.memoryMB:&lt;&#34;8192&#34;
</code></pre>
<ul>
<li>VMs with less than 16GB of memory:</li>
</ul>
<pre><code class="language-plaintext">@vmware.vm.runtime.maxMemoryUsage:&#34;16384&#34;
</code></pre>
<ul>
<li>Virtual machines that are not syncing time with the host:</li>
</ul>
<pre><code class="language-plaintext">@vmware.vm.config.tools.syncTimeWithHost:&#34;False&#34;
</code></pre>
<ul>
<li>Virtual machines that are configured with floppy drives:</li>
</ul>
<pre><code class="language-plaintext">@vmware.vm.config.extra.floppy0.autodetect:&#34;true&#34;
</code></pre>
<ul>
<li>Virtual machines running VMware tools:</li>
</ul>
<pre><code class="language-plaintext">@vmware.vm.config.extra.guestinfo.vmtools.versionString:&#34;_&#34;
</code></pre>
<ul>
<li>Virtual machines running Windows:</li>
</ul>
<pre><code class="language-plaintext">source:VMware AND os:Windows
</code></pre>
<ul>
<li>Virtual machines running Linux:</li>
</ul>
<pre><code class="language-plaintext">source:VMware AND os:Linux
</code></pre>
<h2 id="vulnerability-concerns">Vulnerability concerns</h2>
<ul>
<li>Rapid7 - fails PCI compliance:</li>
</ul>
<pre><code class="language-plaintext">test.pciComplianceStatus:&#34;fail&#34;
</code></pre>
<ul>
<li>Tenable - High and Critical severity vulnerabilities that are on CISA’s Known Exploited list:</li>
</ul>
<pre><code class="language-plaintext">plugin.xrefs.type:&#34;CISA-KNOWN-EXPLOITED&#34; AND (severity:high OR severity:critical)
</code></pre>
<ul>
<li>Tenable - Critical severity vulnerabilities where exploits are available:</li>
</ul>
<pre><code class="language-plaintext">plugin.exploitabilityEase:&#34;Exploits are available&#34; AND severity:critical
</code></pre>
<ul>
<li>Tenable - High and Critical severity vulnerabilities where exploits are not required</li>
</ul>
<pre><code class="language-plaintext">plugin.exploitabilityEase:&#34;No exploit is required&#34; AND (severity:critical OR severity:high)
</code></pre>
<h2 id="wireless-results">Wireless results</h2>
<ul>
<li>Search ESSID for authentication exceptions:</li>
</ul>
<pre><code class="language-plaintext">essid:&#34;&lt;ESSID&gt;&#34; AND NOT authentication:&#34;wpa2-enterprise&#34;
</code></pre>
<ul>
<li>Find unknown BSSIDs broadcasting known ESSID (exclude known BSSIDs in query for gap analysis)</li>
</ul>
<pre><code class="language-plaintext">essid:=&#34;&lt;ESSID&gt;&#34; AND NOT bssid:&#34;&lt;MAC address&gt;&#34;
</code></pre>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Search query syntax]]></title>
    <link href="https://www.runzero.com/docs/search-query-syntax/"/>
    <id>https://www.runzero.com/docs/search-query-syntax/</id>
      
      <published>2025-11-04T17:50:44+00:00</published>
      <updated>2025-11-04T17:50:44+00:00</updated>
      <summary type="html"><![CDATA[<p>runZero supports deep searching across the Asset, Service, and Wireless Inventory, across organizations and sites, and through the Query Library. The runZero Export API uses the same inventory <span class="book-index" data-book-index="search syntax">search syntax</span> to <span class="book-index" data-book-index="filter">filter</span> results.</p>
<h2 id="query-syntax">Query syntax</h2>
<h3 id="boolean-operators">Boolean operators</h3>
<p>Search queries can be combined through <code>AND</code> and <code>OR</code> operators and be grouped using parenthesis.</p>
<h4 id="and">AND</h4>
<p>For example, a Asset Inventory query of <code>os:&#34;Windows 10&#34; AND protocols:http AND protocols:smb2</code> will show only those assets where Windows 10 was identified and both SMB and a web server were discovered. Search values that contain spaces must be placed in double quotes.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Querying your data]]></title>
    <link href="https://www.runzero.com/docs/querying-your-data/"/>
    <id>https://www.runzero.com/docs/querying-your-data/</id>
      
      <published>2025-06-16T18:02:52+00:00</published>
      <updated>2025-06-16T18:02:52+00:00</updated>
      <summary type="html"><![CDATA[<p>runZero provides many ways to query your data. Generally, <span class="book-index" data-book-index="queries">queries</span> can be broken into two concepts:</p>
<ul>
<li>Filters or parameters used in the search bars on pages across the console, or</li>
<li>System and custom queries for which match metrics are calculated as tasks complete.</li>
</ul>
<p>Both allow you to leverage the extensive query language to quickly find the information you’re looking for.</p>
<h2 id="filtering-and-searching-data">Filtering and searching data</h2>
<p>The various inventory pages are likely the main place you’d look to use these queries, but many other pages include the same type of search bar that can be used to filter results. The following documentation pages will help you craft a query that meets your needs:</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Creating alert templates]]></title>
    <link href="https://www.runzero.com/docs/creating-alert-templates/"/>
    <id>https://www.runzero.com/docs/creating-alert-templates/</id>
      
      <published>2026-05-22T14:50:01+00:00</published>
      <updated>2026-05-22T14:50:01+00:00</updated>
      <summary type="html"><![CDATA[<p class="licenses"><a href="https://www.runzero.com/product/pricing/"><span class="com">Community</span></a>&nbsp;<a href="https://www.runzero.com/product/pricing/"><span class="pla">Platform</span></a></p>
<p>With the <a href="/docs/rules-engine/">Rules Engine</a>, you can define <span class="book-index" data-book-index="rules">rules</span> that alert you on specific events, such as changes to scans, assets, and Explorers. To customize the <span class="book-index" data-book-index="alert messages">alert messages</span>, you can create custom <span class="book-index" data-book-index="templates">templates</span> to standardize and format alerts triggered from rules. With custom templates, you can include more context and data for your alerts.</p>
<p>Templates can output as raw HTML, a runZero HTML template, JSON, and text for use in emails, internal notifications, or <span class="book-index" data-book-index="webhooks">webhooks</span>. You can customize the contents of these templates as needed.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Using the rules engine]]></title>
    <link href="https://www.runzero.com/docs/rules-engine/"/>
    <id>https://www.runzero.com/docs/rules-engine/</id>
      
      <published>2024-11-26T17:13:36+00:00</published>
      <updated>2024-11-26T17:13:36+00:00</updated>
      <summary type="html"><![CDATA[<p class="licenses"><a href="https://www.runzero.com/product/pricing/"><span class="com">Community</span></a>&nbsp;<a href="https://www.runzero.com/product/pricing/"><span class="pla">Platform</span></a></p>
<p>The <span class="book-index" data-book-index="Rules">Rules</span> Engine is an automation framework for monitoring, alerts, and workflow management. You can use the Rules Engine to customize <span class="book-index" data-book-index="alerts">alerts</span> for the <span class="book-index" data-book-index="events">events</span> that matter most to your organization and automate repetitive tasks. At the heart of the Rule Engine are rules. A rule defines the action that is taken based on a set of conditions. You can create rules to proactively alert your team when there are changes to things like Explorers, assets, scans, organizations, and sites. You can also automate tagging and modification of asset fields based on the results of a query.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Managing alerts]]></title>
    <link href="https://www.runzero.com/docs/managing-alerts/"/>
    <id>https://www.runzero.com/docs/managing-alerts/</id>
      
      <published>2026-05-22T14:50:01+00:00</published>
      <updated>2026-05-22T14:50:01+00:00</updated>
      <summary type="html"><![CDATA[<p class="licenses"><a href="https://www.runzero.com/product/pricing/"><span class="com">Community</span></a>&nbsp;<a href="https://www.runzero.com/product/pricing/"><span class="pla">Platform</span></a></p>
<p>runZero can trigger automatic <span class="book-index" data-book-index="alerts">alerts</span> when certain events occur through a combination of <span class="book-index" data-book-index="Channels">Channels</span> and <span class="book-index" data-book-index="Rules">Rules</span>.</p>
<p>runZero currently supports
Internal, <span class="book-index" data-book-index="Email">Email</span>, <span class="book-index" data-book-index="Email runZero Users">Email runZero Users</span>, and <span class="book-index" data-book-index="Webhook">Webhook</span> channel types.</p>
<p>Internal channels store events within the <a href="https://console.runzero.com/alerts">Alerts</a> list within the runZero Console. Internal alerts support explicit acknowledgement. Internal alerts can be
bulk acknowledged and cleared from within the runZero Console.</p>
<p>Email channels can be configured to deliver mail to one or more recipients. These email messages contain a summary of the alert and a link to the specifics within the runZero Console. Email is sent from the runZero infrastructure using the <span class="book-index" data-book-index="Sendgrid">Sendgrid</span> service.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Understanding fingerprints]]></title>
    <link href="https://www.runzero.com/docs/fingerprinting/"/>
    <id>https://www.runzero.com/docs/fingerprinting/</id>
      
      <published>2026-05-10T19:03:44+00:00</published>
      <updated>2026-05-10T19:03:44+00:00</updated>
      <summary type="html"><![CDATA[<p>runZero automatically builds <strong>fingerprints</strong> for every asset it discovers. Fingerprints describe how runZero identified a device, service, or operating system based on collected evidence. Each fingerprint includes a set of attributes that show <em>what was matched</em> and <em>where it came from</em>.</p>
<p>Fingerprints are a core part of how runZero normalizes your inventory, enabling accurate correlation and deduplication across multiple discovery sources.</p>
<h2 id="understanding-fingerprints">How fingerprints work</h2>
<p>During discovery, runZero gathers a variety of clues—such as TCP banners, mDNS names, SMB negotiation data, TLS certificates, and more.
Each clue is analyzed and classified into one or more fingerprint categories.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Protocol gateways]]></title>
    <link href="https://www.runzero.com/docs/protocol-gateways/"/>
    <id>https://www.runzero.com/docs/protocol-gateways/</id>
      
      <published>2026-05-13T14:38:20+00:00</published>
      <updated>2026-05-13T14:38:20+00:00</updated>
      <summary type="html"><![CDATA[<p class="licenses"><a href="https://www.runzero.com/product/pricing/"><span class="pla">Platform</span></a></p>
<p>A <span class="book-index" data-book-index="protocol gateway">protocol gateway</span> is a device that bridges an IP network to a separate, sometimes non-IP fieldbus, backplane, or serial bus — for example, a Modbus/TCP-to-Modbus-RTU gateway, an EtherNet/IP CIP rack with backplane modules, a BACnet/IP router fronting an MS/TP segment, or a HART-IP multiplexer in front of a loop of HART field instruments. From the IP side, only the gateway is reachable. The PLCs, RTUs, IEDs, meters, sensors, and CNC modules behind it are invisible to a typical port scanner.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Understanding network segmentation]]></title>
    <link href="https://www.runzero.com/docs/understanding-network-segmentation/"/>
    <id>https://www.runzero.com/docs/understanding-network-segmentation/</id>
      
      <published>2024-02-22T16:30:44+00:00</published>
      <updated>2024-02-22T16:30:44+00:00</updated>
      <summary type="html"><![CDATA[<h2 id="runzero-multi-homed-asset-detection">runZero multi-homed asset detection</h2>
<p><span class="book-index" data-book-index="network segmentation">Network segmentation</span> is a critical security control for many businesses, but verifying that <span class="book-index" data-book-index="segmentation">segmentation</span> is working correctly can be challenging, especially across large and complex environments. Common techniques to validate segmentation, such as reviewing firewall rules and spot testing from individual systems can only go so far, and comprehensive testing, such as running full network scans from every segment to every segment, can be time intensive and are hard to justify on a regular basis.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Understanding suppression]]></title>
    <link href="https://www.runzero.com/docs/understanding-suppression/"/>
    <id>https://www.runzero.com/docs/understanding-suppression/</id>
      
      <published>2025-12-15T17:20:35+00:00</published>
      <updated>2025-12-15T17:20:35+00:00</updated>
      <summary type="html"><![CDATA[<p>runZero supports <span class="book-index" data-book-index="suppressing">suppressing</span> records for findings, vulnerabilities and vulnerability groups so that they are not shown in the platform
if desired. This can be useful for filtering out false positives for example, or hiding any vulnerabilities that are not relevant to
your environment for some reason. Suppressed objects are not deleted, but remain stored within the platform with metadata about when
and why they were suppressed, and by whom.</p>
<h2 id="understanding-suppression">How suppression works</h2>
<p><span class="book-index" data-book-index="Suppression">Suppression</span> works differently depending on the type of object being suppressed. When a vulnerability instance is suppressed, it becomes
hidden from view on the vulnerabilities by asset inventory. When a finding is suppressed, it becomes hidden from view
on the findings list, and any vulnerabilities associated with the finding will also be suppressed. Similarly, when a vulnerability group
is suppressed, it becomes hidden from view on the vulnerability groups inventory, and any vulnerabilities associated with the group will
also be suppressed.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Tracking goal progress]]></title>
    <link href="https://www.runzero.com/docs/goal-tracking/"/>
    <id>https://www.runzero.com/docs/goal-tracking/</id>
      
      <published>2025-07-09T13:51:28+00:00</published>
      <updated>2025-07-09T13:51:28+00:00</updated>
      <summary type="html"><![CDATA[<p class="licenses"><a href="https://www.runzero.com/product/pricing/"><span class="com">Community</span></a>&nbsp;<a href="https://www.runzero.com/product/pricing/"><span class="pla">Platform</span></a></p>
<p>With runZero goals, users are able to create and monitor progress toward achieving security initiatives. All goal types are supported by the robust query language on the backend. <a href="/docs/search-query-syntax/">All types of inventory queries</a> are supported by the <span class="book-index" data-book-index="goal tracking">goal tracking</span> feature.</p>
<p>There are two types of <span class="book-index" data-book-index="goals">goals</span>:</p>
<ul>
<li><strong>Saved query</strong> - a goal based on the results of a user-defined or runZero system query against all inventory.</li>
<li><strong>Baseline</strong> - a goal based on the results of a user-defined query against a subset of inventory, specified by another user-defined query.</li>
</ul>
<iframe src="https://demo.arcade.software/cqKBd5J4zidJdRuojSfc?embed" loading="lazy" allowfullscreen="" title="Walkthrough - Goals"></iframe>
<h2 id="goal-creation">Goal creation</h2>
<p>New goals can be created by users whose <a href="/docs/managing-your-team/">default role</a> is user or greater from the <a href="https://console.runzero.com/goals/">Goals</a> page in the console. Users with viewer-level or greater access will be able to view the goals page and see the goals that apply to organizations they have access to.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Managing tasks]]></title>
    <link href="https://www.runzero.com/docs/managing-tasks/"/>
    <id>https://www.runzero.com/docs/managing-tasks/</id>
      
      <published>2024-11-08T10:25:56+00:00</published>
      <updated>2024-11-08T10:25:56+00:00</updated>
      <summary type="html"><![CDATA[<p>You can view and manage discovery <span class="book-index" data-book-index="scans">scans</span> and other background actions from the <a href="https://console.runzero.com/tasks"><span class="book-index" data-book-index="Tasks overview page">Tasks overview page</span></a>. The <em>Active</em> and <em>Completed</em> task sections will show standard <span class="book-index" data-book-index="tasks">tasks</span>, such as scans and imports, along with their current progress and summarized results. You can <a href="/docs/search-query-tasks/">search or filter</a> the tasks using different attributes.</p>
<h2 id="task-status-values">Task status values</h2>
<p>Tasks can have the following status values:</p>
<ul>
<li><strong>New</strong>: The task has been created and is waiting to be picked up by a scanner or connector.</li>
<li><strong>Active</strong>: A scan task is in progress and the Explorer is scanning the network.</li>
<li><strong>Scanned</strong>: The network scan part of a scan task has completed.</li>
<li><strong>Connecting</strong>: A connector task is connecting to the remote system and downloading data.</li>
<li><strong>Connected</strong>: A connector task has finished downloading and the data is waiting to be processed.</li>
<li><strong>Processing, queued</strong>: Task data has been collected from a scan or a connector task, and is queued for processing.</li>
<li><strong>Processing</strong>: Task data is being processed.</li>
<li><strong>Processed</strong>: Task data has been processed and runZero data updated.</li>
<li><strong>Stopping</strong>: The task was requested to stop and is in the process of doing so.</li>
<li><strong>Stopped</strong>: The task successfully stopped.</li>
<li><strong>Canceled</strong>: An error occurred which meant that the task could not continue.</li>
<li><strong>Paused</strong>: A repeating task has been paused.</li>
</ul>
<h2 id="tabs">Tabs</h2>
<p>Tabs on the Tasks overview page allow you to view a filtered subset of active, processing, scheduled, failed, completed, or recurring tasks. Each tab includes a search bar so that you can <a href="/docs/search-query-tasks/">search your complete task history</a>.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Managing ownership]]></title>
    <link href="https://www.runzero.com/docs/managing-ownership/"/>
    <id>https://www.runzero.com/docs/managing-ownership/</id>
      
      <published>2026-05-22T14:50:01+00:00</published>
      <updated>2026-05-22T14:50:01+00:00</updated>
      <summary type="html"><![CDATA[<p class="licenses"><a href="https://www.runzero.com/product/pricing/"><span class="pla">Platform</span></a></p>
<p>runZero is able to help users track <span class="book-index" data-book-index="ownership">ownership</span> with the ability to configure different types of owners and assign owners to runZero assets and vulnerability records. Ownership coverage can also be tracked as a <a href="/docs/goal-tracking/">goal</a>.</p>
<iframe src="https://demo.arcade.software/V7pjRI8KY5VVr5dbbriG?embed" loading="lazy" allowfullscreen="" title="Managing ownership demo"></iframe>
<h2 id="ownership-types">Ownership types</h2>
<p>Superusers can manage the available types of ownership on the <a href="https://console.runzero.com/account/ownership-types"><strong>Account</strong> &gt; <strong>Ownership types</strong></a> page. Custom ownership types can be configured to meet your needs. Some common ownership types may include <strong>Security owner</strong>, <strong>IT owner</strong>, or <strong>Compliance owner</strong>.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Geolocation]]></title>
    <link href="https://www.runzero.com/docs/asset-geolocation/"/>
    <id>https://www.runzero.com/docs/asset-geolocation/</id>
      
      <published>2026-05-11T17:47:42+00:00</published>
      <updated>2026-05-11T17:47:42+00:00</updated>
      <summary type="html"><![CDATA[<p class="licenses"><a href="https://www.runzero.com/product/pricing/"><span class="pla">Platform</span></a></p>
<p>runZero resolves a geographic location for every asset where it has enough information to do so, and uses those locations to power the <a href="/docs/world-map/">World Map</a>, inventory search, and exports. This page describes the different sources runZero uses for <span class="book-index" data-book-index="asset geolocation">asset geolocation</span>, how user-supplied location tags are interpreted, and the order in which sources are applied.</p>
<h2 id="where-locations-come-from">Where locations come from</h2>
<p>runZero builds asset locations from five independent sources during each analysis pass. Every location is recorded with provenance, so each pin on the World Map can be traced back to the specific attribute, integration, or tag that produced it.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Certificates]]></title>
    <link href="https://www.runzero.com/docs/certificates-inventory/"/>
    <id>https://www.runzero.com/docs/certificates-inventory/</id>
      
      <published>2025-08-20T22:56:17+00:00</published>
      <updated>2025-08-20T22:56:17+00:00</updated>
      <summary type="html"><![CDATA[<p>runZero automatically collects TLS certificates as part active scans and passive network monitoring. These are stored in the Certificates Inventory, which you can access from the <em>Inventory</em> menu, <em>Certificates</em> sub-menu. Although the most sources of <span class="book-index" data-book-index="TLS certificates">TLS certificates</span> are web servers, certificates are also acquired from SMTP, RDP, and other TLS-aware services.</p>
<p>Certificates have a validity period. In the inventory view, the <em>Valid from</em> and <em>Valid until</em> values are color coded to show if the certificate is not valid yet, has expired, or is soon to expire.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Asset risk and criticality]]></title>
    <link href="https://www.runzero.com/docs/asset-risk-and-criticality/"/>
    <id>https://www.runzero.com/docs/asset-risk-and-criticality/</id>
      
      <published>2026-05-22T14:50:01+00:00</published>
      <updated>2026-05-22T14:50:01+00:00</updated>
      <summary type="html"><![CDATA[<p class="licenses"><a href="https://www.runzero.com/product/pricing/"><span class="com">Community</span></a>&nbsp;<a href="https://www.runzero.com/product/pricing/"><span class="pla">Platform</span></a></p>
<p>runZero is able to help users assign and evaluate risk and criticality levels to the assets in their inventory. This can help prioritize risk mitigation or vulnerability remediation efforts by allowing users to quickly identify the assets in their organization with the highest levels of risk or criticality.</p>
<iframe src="https://demo.arcade.software/5vFbrNShs6eNOG0nYjTz?embed" loading="lazy" allowfullscreen="" title="Walkthrough - Risk and Criticality"></iframe>
<h2 id="defining-risk-and-criticality">Defining risk and criticality</h2>
<p>The <strong><span class="book-index" data-book-index="risk">risk</span></strong> level assigned automatically to assets in your inventory is inferred from the risk associated with vulnerabilities or risky configurations on that asset and defaults to the value <code>none</code>. Vulnerability risk level may be defined by the vulnerability management solution the vulnerability records are ingested from, or by the risk level assigned to a query vulnerability. The risk level can be overridden, in which case the override is retained until the asset or vulnerability is deleted. For vulnerabilities ingested from integrations, this may occur when the source no longer reports the vulnerability on that asset.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Understanding findings]]></title>
    <link href="https://www.runzero.com/docs/understanding-findings/"/>
    <id>https://www.runzero.com/docs/understanding-findings/</id>
      
      <published>2025-05-27T13:27:12+00:00</published>
      <updated>2025-05-27T13:27:12+00:00</updated>
      <summary type="html"><![CDATA[<p><a href="https://console.runzero.com/findings"><span class="book-index" data-book-index="Findings">Findings</span></a> simplify <span class="book-index" data-book-index="vulnerabilities">vulnerabilities</span>, misconfigurations and best practices into a prioritized, curated and aggregated list that helps you identify and remediate the most critical risk in your environment.  runZero Findings are available from the <em>Findings</em> menu, and from the <span class="book-index" data-book-index="Risk Management">Risk Management</span> dashboard.</p>
<h2 id="what-are-findings">What are findings?</h2>
<p>Findings highlight the risks attackers are most likely to target.  This enables security teams to focus remediation efforts on risks with real operational impact.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Understanding assets]]></title>
    <link href="https://www.runzero.com/docs/understanding-assets/"/>
    <id>https://www.runzero.com/docs/understanding-assets/</id>
      
      <published>2026-05-10T20:05:10+00:00</published>
      <updated>2026-05-10T20:05:10+00:00</updated>
      <summary type="html"><![CDATA[<p>runZero treats <span class="book-index" data-book-index="assets">assets</span> as unique network entities from the perspective of the system running the Explorer. An asset may have multiple <span class="book-index" data-book-index="IP addresses">IP addresses</span>, <span class="book-index" data-book-index="MAC addresses">MAC addresses</span>, and <span class="book-index" data-book-index="hostnames">hostnames</span> and it may move around the network as these attributes are updated. runZero tries hard to follow assets by correlating new scan data with the existing inventory, using multiple attributes.</p>
<p>An asset is always associated with a single <span class="book-index" data-book-index="site">site</span>. If the same system happens to be covered by multiple sites, these will be treated as
different assets, and will only be correlated against assets within their respective site. This separation by site allows the same network
to be scanned from multiple perspectives and compared in a single view within the organization.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Using the inventory]]></title>
    <link href="https://www.runzero.com/docs/using-the-inventory/"/>
    <id>https://www.runzero.com/docs/using-the-inventory/</id>
      
      <published>2026-05-04T13:27:21+00:00</published>
      <updated>2026-05-04T13:27:21+00:00</updated>
      <summary type="html"><![CDATA[<p>The <a href="https://console.runzero.com/inventory">inventory</a> page is the heart of runZero Network Discovery and the key to understanding what is on your network. The <span class="book-index" data-book-index="inventory">inventory</span> displays all <span class="book-index" data-book-index="assets">assets</span> within the Organization and can be sorted, filtered, and exported to obtain specific views of the environment.</p>
<h2 id="understanding-assets">Understanding assets</h2>
<p>An <a href="/docs/understanding-assets/">asset</a> within runZero is defined as a unique network entity. Assets may have multiple <span class="book-index" data-book-index="IP addresses">IP addresses</span> and <span class="book-index" data-book-index="MAC addresses">MAC addresses</span> and these addresses may change as the environment is updated. runZero tracks assets based on several heuristics, including MAC address, IP address, <span class="book-index" data-book-index="hostnames">hostnames</span>, and <span class="book-index" data-book-index="fingerprint results">fingerprint results</span> for the <span class="book-index" data-book-index="operating system">operating system</span> and running <span class="book-index" data-book-index="services">services</span>.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Using dashboards]]></title>
    <link href="https://www.runzero.com/docs/dashboard/"/>
    <id>https://www.runzero.com/docs/dashboard/</id>
      
      <published>2026-05-10T19:03:44+00:00</published>
      <updated>2026-05-10T19:03:44+00:00</updated>
      <summary type="html"><![CDATA[<p><span class="book-index" data-book-index="Dashboards">Dashboards</span> provide customizable, visual views into your asset inventory and can be <a href="/docs/dashboard/#creating-dashboards">created</a> to serve different use cases such as compliance, vulnerability remediation, or asset visibility.</p>
<p>A variety of visualization <a href="/docs/dashboard/#widget-types">widgets</a> are available that show operational information, trends, insights, goals, sources, and most and least seen graphs.
You can also create your own <a href="/docs/dashboard/#custom-widgets">custom widget</a> based on queries to get the exact data you are looking to surface, displayed either as a trend line or latest count.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Reviewing results]]></title>
    <link href="https://www.runzero.com/docs/reviewing-results/"/>
    <id>https://www.runzero.com/docs/reviewing-results/</id>
      
      <published>2025-12-24T14:46:11+00:00</published>
      <updated>2025-12-24T14:46:11+00:00</updated>
      <summary type="html"><![CDATA[<h2 id="task-details">Task details</h2>
<p>After each discovery task completes, the <span class="book-index" data-book-index="task details">task details</span> page will list a summary of how many assets were updated. To understand the numbers, it’s important to remember that runZero will correlate assets across IPs and data sources, which can result in different results than IP-based matching alone.</p>
<p>The change summary on the task details page includes the following statistics:</p>
<ul>
<li>Asset changes:
<ul>
<li><strong><span class="book-index" data-book-index="Newly discovered assets">Newly discovered assets</span></strong> are devices that were found during the task for which no device with matching fingerprints was previously seen.</li>
<li><strong><span class="book-index" data-book-index="Assets marked offline">Assets marked offline</span></strong> are assets that runZero has previously seen on the scanned network, but that didn’t respond on any of the IP addresses during this scan. When this happens, the asset is marked offline. The offline status is a flag on the asset, and doesn’t count as a change to the asset. Assets may be marked offline because the device was powered down or disconnected, or because of network problems.</li>
<li><strong><span class="book-index" data-book-index="Assets back online">Assets back online</span></strong> are assets that were marked offline at some point in the past, but the runZero Explorer got a response from them during this scan. The online status is a flag on the asset, and doesn’t count as a change to the asset.</li>
<li><strong><span class="book-index" data-book-index="Assets changed">Assets changed</span></strong> is the number of assets where some property of the asset was modified, other than its online status. Examples include changes to the device’s IP addresses or hostname, or responses from new ports or protocols.</li>
<li><strong><span class="book-index" data-book-index="Assets unchanged">Assets unchanged</span></strong> is the number of assets that were seen exactly where runZero found them in the last scan, with no changes to their responses.</li>
<li><strong><span class="book-index" data-book-index="Assets ignored">Assets ignored</span></strong> is the number of occasions where the Explorer got a response from probing an IP address, but it turned out to be bogus in some way. This typically happens when a web proxy, stateful firewall, or SIP gateway responds as if it is the asset at every address on a subnet.</li>
<li><strong><span class="book-index" data-book-index="Total assets seen by task">Total assets seen by task</span></strong> is the total of <strong>Assets changed</strong> plus <strong>Assets unchanged</strong>. It indicates the number of asset records that are now up-to-date.</li>
</ul>
</li>
<li>User changes:
<ul>
<li><strong><span class="book-index" data-book-index="Newly discovered users">Newly discovered users</span></strong> are users that were seen for the first time during the integration sync.</li>
<li><strong><span class="book-index" data-book-index="Users changed">Users changed</span></strong> are users that had attributes change during the integration sync.</li>
<li><strong><span class="book-index" data-book-index="Users unchanged">Users unchanged</span></strong> are users that did not change during the integration sync.</li>
<li><strong><span class="book-index" data-book-index="Users updated by task">Users updated by task</span></strong> is the total number of <strong>Users changed</strong> and <strong>Users unchanged</strong>, indicating how many user records are now up-to-date.</li>
</ul>
</li>
<li>Group changes:
<ul>
<li><strong><span class="book-index" data-book-index="Newly discovered groups">Newly discovered groups</span></strong> are groups that were seen for the first time during the integration sync.</li>
<li><strong><span class="book-index" data-book-index="Groups changed">Groups changed</span></strong> are groups that had attributes change during the integration sync.</li>
<li><strong><span class="book-index" data-book-index="Groups unchanged">Groups unchanged</span></strong> are groups that did not change during the integration sync.</li>
<li><strong><span class="book-index" data-book-index="Groups updated by task">Groups updated by task</span></strong> is the total number of <strong>Groups changed</strong> and <strong>Groups unchanged</strong>, indicating how many group records are now up-to-date.</li>
</ul>
</li>
</ul>
<h2 id="dashboard--inventory-views"><span class="book-index" data-book-index="Dashboard">Dashboard</span> &amp; <span class="book-index" data-book-index="inventory views">inventory views</span></h2>
<p>The dashboard will be populated with results after the first scan completes. The dashboard provides trend data and insights that will help you assess how your inventory is changing over time. You can select a time period and site for the trend data using the selectors at the top right of the dashboard page.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Findings]]></title>
    <link href="https://www.runzero.com/docs/em-findings/"/>
    <id>https://www.runzero.com/docs/em-findings/</id>
      
      <published>2026-04-11T04:16:08+00:00</published>
      <updated>2026-04-11T04:16:08+00:00</updated>
      <summary type="html"><![CDATA[<p>Findings are groups of significant exposures with the same root cause.</p>
<div class="summary-chart"><div class="summary-stats"><div class="summary-stat summary-stat-hero"><div class="summary-stat-value">30</div><div class="summary-stat-label">Findings</div></div><div class="summary-stat summary-stat-hero"><div class="summary-stat-value">205</div><div class="summary-stat-label">Queries</div></div></div><div class="summary-bar-section"><div class="summary-bar-label">Risk distribution</div><div class="summary-bar"><div class="summary-bar-seg" style="width:26.7%;background:#dc2626" title="Critical: 8 (27%)">&nbsp;</div><div class="summary-bar-seg" style="width:13.3%;background:#ea580c" title="High: 4 (13%)">&nbsp;</div><div class="summary-bar-seg" style="width:13.3%;background:#ca8a04" title="Medium: 4 (13%)">&nbsp;</div><div class="summary-bar-seg" style="width:16.7%;background:#008099" title="Low: 5 (17%)">&nbsp;</div><div class="summary-bar-seg" style="width:30.0%;background:#6b7280" title="Info: 9 (30%)">&nbsp;</div></div><div class="summary-legend"><span class="summary-legend-item"><span class="summary-legend-dot" style="background:#dc2626"></span>Critical <strong>8</strong></span><span class="summary-legend-item"><span class="summary-legend-dot" style="background:#ea580c"></span>High <strong>4</strong></span><span class="summary-legend-item"><span class="summary-legend-dot" style="background:#ca8a04"></span>Medium <strong>4</strong></span><span class="summary-legend-item"><span class="summary-legend-dot" style="background:#008099"></span>Low <strong>5</strong></span><span class="summary-legend-item"><span class="summary-legend-dot" style="background:#6b7280"></span>Info <strong>9</strong></span></div></div></div><div class="fd-toolbar"><input type="text" class="fd-search" placeholder="Filter by finding code, query name, or query..." oninput="fdFilter()"><div class="fd-risk-filters"><button class="fd-risk-btn fd-risk-critical active" data-risk="critical" onclick="fdToggleRisk(this)">Critical</button><button class="fd-risk-btn fd-risk-high active" data-risk="high" onclick="fdToggleRisk(this)">High</button><button class="fd-risk-btn fd-risk-medium active" data-risk="medium" onclick="fdToggleRisk(this)">Medium</button><button class="fd-risk-btn fd-risk-low active" data-risk="low" onclick="fdToggleRisk(this)">Low</button><button class="fd-risk-btn fd-risk-info active" data-risk="info" onclick="fdToggleRisk(this)">Info</button></div></div><div class="fd-count"><span id="fd-match-count">30</span> of 30 findings (205 queries)</div><div id="fd-grid-host" class="fd-grid"><div class="deferred-loading">Loading findings…</div></div>
<template id="fd-grid-content">
<div class="fd-card" id="rz-finding-best-practice" data-fd-search="best practice rz-finding-best-practice http directory indexing enabled _asset.protocol:=http and protocol:=http and has:html.title and (html.title:=&#34;index of /%&#34; or html.title:=&#34;hfs /%&#34; or html.title:=&#34;directory listing%&#34;)" data-fd-risk="low">
  <div class="fd-card-header">
    <div class="fd-title">Best Practice</div>
    <div class="fd-meta"><span class="fd-badge fd-risk-low">Low</span><span class="fd-query-count">1 query</span></div>
  </div>
  <div class="ql-code-section">
    <div class="ql-query-wrap">
      <pre><code>finding:rz-finding-best-practice</code></pre>
      <button class="fd-copy-btn" onclick="fdCopy(this)" data-query="finding:rz-finding-best-practice" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
    </div>
    <div class="ql-action-bar">
      <a href="https://console.runzero.com/inventory/?search=finding%3Arz-finding-best-practice" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="13" height="13" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/?search=finding%3Arz-finding-best-practice" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="13" height="13" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="fdCopy(this)" data-query="finding:rz-finding-best-practice"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
    </div>
  </div>
  <div class="fd-source-header">Source queries (1)</div>
  <div class="fd-queries-section">
    <div class="fd-queries-list">
      <div class="fd-query-item">
        <div class="fd-query-header"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span> <span class="fd-query-name">HTTP Directory Indexing Enabled</span></div>
        <div class="fd-query-desc"><p>The web server is configured to show directory listings when no default web page is present.
This can expose sensitive information about the server&rsquo;s content to attackers.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Templates]]></title>
    <link href="https://www.runzero.com/docs/em-templates/"/>
    <id>https://www.runzero.com/docs/em-templates/</id>
      
      <published>2026-04-11T16:31:16+00:00</published>
      <updated>2026-04-11T16:31:16+00:00</updated>
      <summary type="html"><![CDATA[<p>The table below lists the <a href="https://github.com/projectdiscovery/nuclei">Nuclei</a>  vulnerability templates available for scans. The full set of tuned templates can be found in our <a href="https://github.com/runZeroInc/nuclei-templates">nuclei-templates</a> repository.</p>
<div class="summary-chart"><div class="summary-stats"><div class="summary-stat summary-stat-hero"><div class="summary-stat-value">2,665</div><div class="summary-stat-label">Templates</div></div><div class="summary-stat summary-stat-hero"><div class="summary-stat-value">1,089</div><div class="summary-stat-label">CVEs Covered</div></div><div class="summary-stat summary-stat-hero"><div class="summary-stat-value">3</div><div class="summary-stat-label">Scan Categories</div></div></div><div class="summary-bar-section"><div class="summary-bar-label">Severity distribution</div><div class="summary-bar"><div class="summary-bar-seg" style="width:21.3%;background:#dc2626" title="Critical: 567 (21%)">&nbsp;</div><div class="summary-bar-seg" style="width:23.3%;background:#ea580c" title="High: 622 (23%)">&nbsp;</div><div class="summary-bar-seg" style="width:10.3%;background:#ca8a04" title="Medium: 274 (10%)">&nbsp;</div><div class="summary-bar-seg" style="width:2.7%;background:#008099" title="Low: 71 (3%)">&nbsp;</div><div class="summary-bar-seg" style="width:42.4%;background:#6b7280" title="Info: 1129 (42%)">&nbsp;</div></div><div class="summary-legend"><span class="summary-legend-item"><span class="summary-legend-dot" style="background:#dc2626"></span>Critical <strong>567</strong></span><span class="summary-legend-item"><span class="summary-legend-dot" style="background:#ea580c"></span>High <strong>622</strong></span><span class="summary-legend-item"><span class="summary-legend-dot" style="background:#ca8a04"></span>Medium <strong>274</strong></span><span class="summary-legend-item"><span class="summary-legend-dot" style="background:#008099"></span>Low <strong>71</strong></span><span class="summary-legend-item"><span class="summary-legend-dot" style="background:#6b7280"></span>Info <strong>1129</strong></span></div></div><div class="summary-bar-section"><div class="summary-bar-label">Enabled by scan option</div><div class="summary-tags"><span class="summary-tag">Identify critical remote vulnerabilities <strong>1291</strong></span><span class="summary-tag">Identify web-based control panels <strong>1140</strong></span><span class="summary-tag">Identify default logins in web-based control panels <strong>232</strong></span></div></div></div><div class="nt-toolbar"><input type="text" class="nt-search" placeholder="Filter by name, CVE, severity, or scan option..." oninput="ntFilter()"><div class="nt-sev-filters"><button class="fd-risk-btn fd-risk-critical active" data-sev="critical" onclick="ntToggleSev(this)">Critical</button><button class="fd-risk-btn fd-risk-high active" data-sev="high" onclick="ntToggleSev(this)">High</button><button class="fd-risk-btn fd-risk-medium active" data-sev="medium" onclick="ntToggleSev(this)">Medium</button><button class="fd-risk-btn fd-risk-low active" data-sev="low" onclick="ntToggleSev(this)">Low</button><button class="fd-risk-btn fd-risk-info active" data-sev="info" onclick="ntToggleSev(this)">Info</button></div></div><div class="nt-count"><span id="nt-match-count">2665</span> of 2665 templates</div><div id="nt-grid-host" class="nt-grid"><div class="deferred-loading">Loading templates…</div></div>
<template id="nt-grid-content">
<div class="nt-card" data-nt-search=".net framework - leaking objrefs via http .net remoting high identify critical remote vulnerabilities .net framework information disclosure vulnerability cve-2024-29059 iamnoooob,rootxharsh,dhiyaneshdk,pdresearch cve cve2024 deserialization dotnet kev microsoft remoting vkev vuln cwe-209" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">.NET Framework - Leaking ObjRefs via HTTP .NET Remoting</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-29059.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-29059.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> iamnoooob,rootxharsh,DhiyaneshDk,pdresearch</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 28, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/209.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-209</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-29059" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-29059</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.head.server&#34;] matches &#34;(?i)ms .net remoting&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">.NET Framework Information Disclosure Vulnerability</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can exploit leaked ObjRefs to access remote objects via .NET Remoting, potentially gaining unauthorized access to application data.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply security patches for .NET Framework addressing CVE-2024-29059.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">deserialization</span><span class="nt-tag">dotnet</span><span class="nt-tag">kev</span><span class="nt-tag">microsoft</span><span class="nt-tag">remoting</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-29059" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://code-white.com/blog/leaking-objrefs-to-exploit-http-dotnet-remoting/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/codewhitesec/HttpRemotingObjRefLeak" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/NaInSec/CVE-LIST" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/fkie-cad/nvd-json-data-feeds" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="1 click wordpress migration &lt;= 2.2 - unauthenticated information disclsoure medium identify critical remote vulnerabilities 1 click wordpress migration &lt;= 2.2 contains an information disclosure caused by uncleared debug information, letting attackers retrieve embedded sensitive data, exploit requires no specific privileges. pussycat0x 1clickmigration cve cve2025 vkev wordpress wp-plugin wpscan" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">1 Click WordPress Migration &lt;= 2.2 - Unauthenticated Information Disclsoure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-32257.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-32257.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 7, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/1-click-migration/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">1 Click WordPress Migration &lt;= 2.2 contains an information disclosure caused by uncleared debug information, letting attackers retrieve embedded sensitive data, exploit requires no specific privileges.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can access sensitive embedded data, potentially leading to information disclosure and further exploitation.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Remove debug information and update to the latest version of 1 Click WordPress Migration.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">1clickmigration</span><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">vkev</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">wpscan</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wpscan.com/vulnerability/03211216-8cc9-49f9-83da-9fbc57554816/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="1password scim bridge - panel info identify web-based control panels 1password scim bridge login was detected. splint3r7 panel 1password login detect discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">1Password SCIM Bridge - Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/1password-scim-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">1password-scim-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Splint3r7</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 28, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)1Password SCIM Bridge Login&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">1Password SCIM Bridge Login was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">1password</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="3com nj2000 - default login high identify default logins in web-based control panels 3com nj2000 contains a default login vulnerability. default admin login password of &#39;password&#39; was found. an attacker can obtain access to user accounts and access sensitive information, modify data, and/or execute unauthorized operations. daffainfo 3com default-login nj2000 vuln cwe-522" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">3COM NJ2000 - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/3com/3com-nj2000-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">3com-nj2000-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> daffainfo</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/522.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-522</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;ManageEngine Password&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">3COM NJ2000 contains a default login vulnerability. Default admin login password of &#39;password&#39; was found. An attacker can obtain access to user accounts and access sensitive information, modify data, and/or execute unauthorized operations.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">3com</span><span class="nt-tag">default-login</span><span class="nt-tag">nj2000</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.manualslib.com/manual/204158/3com-Intellijack-Nj2000.html?page=12" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="3cx phone system management console - panel detect info identify web-based control panels 3cx phone system management console panel was detected. idealphase 3cx discovery panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">3CX Phone System Management Console - Panel Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/3cx-phone-management-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">3cx-phone-management-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> idealphase</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)3cx webclient&#34;}) || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)3cx phone system management console&#34;}) || service[&#34;favicon.ico.image.mmh3&#34;] == &#34;970132176&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">3CX Phone System Management Console panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">3cx</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.3cx.com/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.3cx.com/phone-system/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://medium.com/@frycos/pwning-3cx-phone-management-backends-from-the-internet-d0096339dd88" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="3cx phone system web client management console - panel detect info identify web-based control panels 3cx phone system web client management console panel was detected. idealphase 3cx discovery panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">3CX Phone System Web Client Management Console - Panel Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/3cx-phone-webclient-management-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">3cx-phone-webclient-management-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> idealphase</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)3cx webclient&#34;}) || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)3cx phone system management console&#34;}) || service[&#34;favicon.ico.image.mmh3&#34;] == &#34;970132176&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">3CX Phone System Web Client Management Console panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">3cx</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.3cx.com/phone-system/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.3cx.com/blog/unified-communications/client-apps/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://medium.com/@frycos/pwning-3cx-phone-management-backends-from-the-internet-d0096339dd88" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="3com wireless 8760 dual radio - default login high identify default logins in web-based control panels 3com wireless 8760 dual radio contains a default login vulnerability. default admin login password &#39;password&#39; was found. ritikchaddha 3com default-login vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">3Com Wireless 8760 Dual Radio - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/3com/3Com-wireless-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">3Com-wireless-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 4, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)3COM&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">3COM Wireless 8760 Dual Radio contains a default login vulnerability. Default admin login password &#39;password&#39; was found.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">3com</span><span class="nt-tag">default-login</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.speedguide.net/routers/3com-wl-546-3com-wireless-8760-dual-radio-11abg-1256" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="3ware controller 3dm2 - default login high identify default logins in web-based control panels the default password for logging in to the 3dm2 web interface of a 3ware controller is &#34;3ware&#34; for both the administrator and user accounts. ritikchaddha 3dm2 3ware default-login vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">3ware Controller 3DM2 - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/3ware-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">3ware-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 4, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)3ware&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The default password for logging in to the 3DM2 web interface of a 3ware controller is &#34;3ware&#34; for both the Administrator and User accounts.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">3dm2</span><span class="nt-tag">3ware</span><span class="nt-tag">default-login</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.thomas-krenn.com/en/wiki/3ware_Controller_3DM2_Password" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="74cms - ajax_common.php sql injection critical identify critical remote vulnerabilities sql injection in 74cms 3.2.0 via the query parameter to plus/ajax_common.php. cve-2020-22209 ritikchaddha 74cms cve cve2020 sqli vuln cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">74cms - ajax_common.php SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2020/CVE-2020-22209.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2020-22209.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2020-22209" target="_blank" rel="noopener" class="nt-cve-link">CVE-2020-22209</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)74cms&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">SQL Injection in 74cms 3.2.0 via the query parameter to plus/ajax_common.php.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability can lead to unauthorized access, data leakage, and potential compromise of the underlying database.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest patch or update provided by the vendor to fix the SQL Injection vulnerability in the 74cms - ajax_common.php file.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">74cms</span><span class="nt-tag">cve</span><span class="nt-tag">cve2020</span><span class="nt-tag">sqli</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/blindkey/cve_like/issues/12" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2020-22209" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/20142995/sectool" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/ARPSyndicate/cvemon" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/ARPSyndicate/kenzer-templates" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="74cms - ajax_officebuilding.php sql injection critical identify critical remote vulnerabilities a sql injection vulnerability exists in 74cms 3.2.0 via the x parameter to ajax_officebuilding.php. cve-2020-22210 ritikchaddha 74cms cve cve2020 sqli vuln cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">74cms - ajax_officebuilding.php SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2020/CVE-2020-22210.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2020-22210.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2020-22210" target="_blank" rel="noopener" class="nt-cve-link">CVE-2020-22210</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)74cms&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A SQL injection vulnerability exists in 74cms 3.2.0 via the x parameter to ajax_officebuilding.php.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized access, data leakage, or data manipulation.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest patch or update provided by the vendor to fix the SQL Injection vulnerability in the 74cms - ajax_officebuilding.php file.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">74cms</span><span class="nt-tag">cve</span><span class="nt-tag">cve2020</span><span class="nt-tag">sqli</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/blindkey/cve_like/issues/11" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2020-22210" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/ARPSyndicate/kenzer-templates" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="74cms - ajax_street.php &#39;key&#39; sql injection critical identify critical remote vulnerabilities sql injection in 74cms 3.2.0 via the key parameter to plus/ajax_street.php. cve-2020-22211 ritikchaddha 74cms cve cve2020 sqli vkev vuln cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">74cms - ajax_street.php &#39;key&#39; SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2020/CVE-2020-22211.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2020-22211.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2020-22211" target="_blank" rel="noopener" class="nt-cve-link">CVE-2020-22211</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)74cms&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">SQL Injection in 74cms 3.2.0 via the key parameter to plus/ajax_street.php.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized access, data leakage, or data manipulation.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest patch or update provided by the vendor to fix the SQL Injection vulnerability in the &#39;key&#39; parameter of ajax_street.php in 74cms.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">74cms</span><span class="nt-tag">cve</span><span class="nt-tag">cve2020</span><span class="nt-tag">sqli</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/blindkey/cve_like/issues/13" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2020-22211" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/ARPSyndicate/kenzer-templates" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="74cms - ajax_street.php &#39;x&#39; sql injection critical identify critical remote vulnerabilities sql injection in 74cms 3.2.0 via the x parameter to plus/ajax_street.php. cve-2020-22208 ritikchaddha 74cms cve cve2020 sqli vkev vuln cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">74cms - ajax_street.php &#39;x&#39; SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2020/CVE-2020-22208.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2020-22208.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2020-22208" target="_blank" rel="noopener" class="nt-cve-link">CVE-2020-22208</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)74cms&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">SQL Injection in 74cms 3.2.0 via the x parameter to plus/ajax_street.php.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could lead to unauthorized access, data leakage, and potential compromise of the underlying database.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the vendor-provided patch or update to the latest version of 74cms to mitigate the SQL Injection vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">74cms</span><span class="nt-tag">cve</span><span class="nt-tag">cve2020</span><span class="nt-tag">sqli</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/blindkey/cve_like/issues/10" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2020-22208" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/ARPSyndicate/kenzer-templates" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="ac centralized management system - default password high identify default logins in web-based control panels ac centralized management system default login credentials were discovered. sleepingbag945 default-login vuln ways-ac" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">AC Centralized Management System - Default password</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/wayos/ac-weak-login.yaml" target="_blank" rel="noopener" class="nt-source-link">ac-weak-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> SleepingBag945</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 5, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)安网科技-智能路由系统&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">AC Centralized Management System default login credentials were discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">vuln</span><span class="nt-tag">ways-ac</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/Ershu1/2021_Hvv/blob/main/Wayos%20AC%E9%9B%86%E4%B8%AD%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F%E5%BC%B1%E5%8F%A3%E4%BB%A4.md" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/chaitin/xray/blob/master/pocs/secnet-ac-default-password.yml" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="ac smart ii - authentication bypass high identify critical remote vulnerabilities ac smart ii contains an authentication bypass caused by a hidden password reset form that can be manipulated to change the administrator password without verifying login or permissions, letting attackers change admin passwords without authorization. cve-2025-10204 theeldruin auth-bypass cve cve2025 unauth vkev cwe-306" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">AC Smart II - Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-10204.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-10204.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> theeldruin</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 27, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/306.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-306</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-10204" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-10204</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Doc/WebLogin\\.asp&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">AC Smart II contains an authentication bypass caused by a hidden password reset form that can be manipulated to change the administrator password without verifying login or permissions, letting attackers change admin passwords without authorization.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can change the administrator password without authorization, leading to full system takeover.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest version that properly verifies login status and user permissions before password reset.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">unauth</span><span class="nt-tag">vkev</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.notion.so/eldruin/Unauthenticated-Administrator-Password-Reset-AC-Smart-II-v2-1-9-Rev-2251-24d27474cccb80a68e47f907b94abed9" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-10204" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="acme challenge path - reflected cross-site scripting low identify critical remote vulnerabilities detects xss vulnerabilities in acme http-01 challenge implementations where hosting providers reflect the challenge key from the url without proper sanitization pussycat0x acme misconfig vuln xss cwe-80" data-nt-sev="low">
  <div class="nt-card-header">
    <div class="nt-title">ACME Challenge Path - Reflected Cross-Site Scripting</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/vulnerabilities/acme-challenge-path-xss.yaml" target="_blank" rel="noopener" class="nt-source-link">acme-challenge-path-xss.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 4, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/80.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-80</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)acme-challenge&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detects XSS vulnerabilities in ACME http-01 challenge implementations where hosting providers reflect the challenge key from the URL without proper sanitization</div></div></div>
  <div class="nt-tags"><span class="nt-tag">acme</span><span class="nt-tag">misconfig</span><span class="nt-tag">vuln</span><span class="nt-tag">xss</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://labs.detectify.com/security-guidance/xss-using-quirky-implementations-of-acme-http-01/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.acunetix.com/vulnerabilities/web/cross-site-scripting-in-http-01-acme-challenge-implementation/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="acti video monitoring panel - detection info identify web-based control panels  dhiyaneshdk acti panel login detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">ACTi Video Monitoring Panel - Detection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/acti-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">acti-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 4, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Web Configurator&#34;})</code></div>
  <div class="nt-tags"><span class="nt-tag">acti</span><span class="nt-tag">panel</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="aic intelligent campus system - password exposure medium identify critical remote vulnerabilities due to the design logic defects, the super password is leaked, which can kill more than 40 campus systems.&lt;br&gt; sleepingbag945 aic exposure password vuln" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">AIC Intelligent Campus System - Password Exposure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/vulnerabilities/other/aic-intelligent-password-exposure.yaml" target="_blank" rel="noopener" class="nt-source-link">aic-intelligent-password-exposure.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> SleepingBag945</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 18, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)AIC智能校园系统&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Due to the design logic defects, the super password is leaked, which can kill more than 40 campus systems.&lt;br&gt;</div></div></div>
  <div class="nt-tags"><span class="nt-tag">aic</span><span class="nt-tag">exposure</span><span class="nt-tag">password</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="aj-report &lt; 1.4.1 - remote code execution critical identify critical remote vulnerabilities aj-report before version 1.4.1 is affected by an authentication bypass vulnerability. a remote and unauthenticated attacker can append &#34;;swagger-ui&#34; to http requests to bypass authentication and execute arbitrary java code on the victim server through script engine injection in the validation rules functionality. cve-2024-7314 ritikchaddha aj-report anji-plus cve cve2024 rce swagger vkev vuln cwe-280" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">AJ-Report &lt; 1.4.1 - Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-7314.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-7314.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 4, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/280.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-280</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-7314" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-7314</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)AJ-Report&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">AJ-Report before version 1.4.1 is affected by an authentication bypass vulnerability. A remote and unauthenticated attacker can append &#34;;swagger-ui&#34; to HTTP requests to bypass authentication and execute arbitrary Java code on the victim server through script engine injection in the validation rules functionality.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can bypass authentication and execute arbitrary Java code on the server through script engine injection, achieving complete system compromise and access to all application data.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to AJ-Report version 1.4.1 or later which includes security fixes.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">aj-report</span><span class="nt-tag">anji-plus</span><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">rce</span><span class="nt-tag">swagger</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/vulhub/vulhub/tree/master/aj-report/CNVD-2024-15077" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/yuebusao/AJ-REPORT-EXPLOIT" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://xz.aliyun.com/t/14460" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-7314" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="akhq panel - detect info identify web-based control panels akhq panel was discovered. dhiyaneshdk akhq panel login detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">AKHQ Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/akhq-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">akhq-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 8, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;855432563&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">AKHQ Panel was discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">akhq</span><span class="nt-tag">panel</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="amd pensando psm - default login high identify default logins in web-based control panels the amd pensando policy and services manager used a default password for the admin account.this allowed instances to be accessed using the default credentials. tpierru pensando default-login vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">AMD Pensando PSM - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/pensando/pensando-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">pensando-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> tpierru</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 20, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1907840597&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The AMD Pensando Policy and Services Manager used a default password for the admin account.This allowed instances to be accessed using the default credentials.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">pensando</span><span class="nt-tag">default-login</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.amd.com/en/solutions/data-center/networking.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://arubanetworking.hpe.com/techdocs/Pensando/AMD_Pensando_PSM_for_DSS_Guide-1.72.1-T.pdf" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="amr printer management dashboard - exposure medium identify critical remote vulnerabilities unauthorized access to the amr printer management dashboard was possible, potentially exposing sensitive printer configuration and management interfaces without proper authentication. ritikchaddha network iot printer misconfig unauth vuln" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">AMR Printer Management Dashboard - Exposure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/misconfiguration/amr-printer-management-unauth.yaml" target="_blank" rel="noopener" class="nt-source-link">amr-printer-management-unauth.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 17, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)AMR Printer Management&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Unauthorized access to the AMR Printer Management dashboard was possible, potentially exposing sensitive printer configuration and management interfaces without proper authentication.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">network</span><span class="nt-tag">iot</span><span class="nt-tag">printer</span><span class="nt-tag">misconfig</span><span class="nt-tag">unauth</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="apc rack pdu default login high identify default logins in web-based control panels apc rack pdu with default administrator credentials discovered. tdiderich default-login apc pdu runzero" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">APC Rack PDU Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/schneider-electric/apc.yaml" target="_blank" rel="noopener" class="nt-source-link">apc.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> tdiderich</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 26, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">asset[&#34;hw&#34;] matches `Schneider\s+Electric` || asset[&#34;os&#34;] matches `Schneider\s+Electric\s+AOS` || any(each(service[&#34;html.titles&#34;]), {# matches `APC \| Log On`})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">APC Rack PDU with default administrator credentials discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">apc</span><span class="nt-tag">pdu</span><span class="nt-tag">runzero</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://iportal2.schneider-electric.com/Contents/docs/UPS-PMAR-9LLJMN_R0_EN.PDF" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="arl default admin login high identify default logins in web-based control panels an arl default admin login was discovered. pikpikcu arl default-login vuln cwe-522" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">ARL Default Admin Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/arl/arl-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">arl-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pikpikcu</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/522.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-522</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.url&#34;] contains &#34;:5003/&#34; &amp;&amp; service[&#34;http.body&#34;] contains &#34;Powered by TCC&#34; &amp;&amp; service[&#34;http.body&#34;] contains &#34;ARL&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An ARL default admin login was discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">arl</span><span class="nt-tag">default-login</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="arris touchstone telephony modem - panel detect info identify web-based control panels arris touchstone telephony modem status panel was detected. gy741 arris commscope discovery panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">ARRIS Touchstone Telephony Modem - Panel Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/arris-modem-detect.yaml" target="_blank" rel="noopener" class="nt-source-link">arris-modem-detect.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> gy741</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)phy\\.htm&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">ARRIS Touchstone Telephony Modem status panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">arris</span><span class="nt-tag">commscope</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="asus aicloud panel - detect info identify web-based control panels asus aicloud panel was detected. ritikchaddha panel asus aicloud detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">ASUS AiCloud Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/asus-aicloud-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">asus-aicloud-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 4, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)AiCloud&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">ASUS AiCloud Panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">asus</span><span class="nt-tag">aicloud</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.asus.com/in/content/aicloud/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="asus rt-n16 - default login high identify default logins in web-based control panels asus rt-n16 contains a default login vulnerability. default admin login password &#39;admin&#39; was found. ritikchaddha asus default-login rt-n16 vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">ASUS RT-N16 - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/asus/asus-rtn16-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">asus-rtn16-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 11, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;http.head.wwwAuthentications&#34;]), {# contains &#39;realm=&#34;RT-N16&#39;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">ASUS RT-N16 contains a default login vulnerability. Default admin login password &#39;admin&#39; was found.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">asus</span><span class="nt-tag">default-login</span><span class="nt-tag">rt-n16</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="asus wl-500g - default login high identify default logins in web-based control panels asus wl-500 contains a default login vulnerability. default admin login password &#39;admin&#39; was found. ritikchaddha asus default-login vuln wl-500" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">ASUS WL-500G - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/asus/asus-wl500g-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">asus-wl500g-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 11, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;http.head.wwwAuthentications&#34;]), {# matches &#39;(?i)realm=&#34;WL-500G&#39;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">ASUS WL-500 contains a default login vulnerability. Default admin login password &#39;admin&#39; was found.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">asus</span><span class="nt-tag">default-login</span><span class="nt-tag">vuln</span><span class="nt-tag">wl-500</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="asus wl-520gu - default login high identify default logins in web-based control panels asus wl-520gu contains a default login vulnerability. the default admin login password &#39;admin&#39; was found. ritikchaddha asus default-login vuln wl-520gu" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">ASUS WL-520GU - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/asus/asus-wl520GU-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">asus-wl520GU-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 11, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;http.head.wwwAuthentications&#34;]), {# contains &#39;realm=&#34;WL-520GU&#39;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">ASUS WL-520GU contains a default login vulnerability. The default admin login password &#39;admin&#39; was found.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">asus</span><span class="nt-tag">default-login</span><span class="nt-tag">vuln</span><span class="nt-tag">wl-520gu</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="asustor adm 3.1.0.rfq3 - sql injection critical identify critical remote vulnerabilities asustor adm version 3.1.0.rfq3 is vulnerable to sql injection via the album_id parameter in the /photo-gallery/api/album/tree_lists/ endpoint. an attacker can exploit this vulnerability to execute arbitrary sql commands on the database, potentially leading to information disclosure or further compromise of the affected system. cve-2018-11511 ritikchaddha adm asustor cve cve2018 sqli vkev vuln cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">ASUSTOR ADM 3.1.0.RFQ3 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2018/CVE-2018-11511.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2018-11511.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 5, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2018-11511" target="_blank" rel="noopener" class="nt-cve-link">CVE-2018-11511</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)ASUSTOR&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">ASUSTOR ADM version 3.1.0.RFQ3 is vulnerable to SQL injection via the album_id parameter in the /photo-gallery/api/album/tree_lists/ endpoint. An attacker can exploit this vulnerability to execute arbitrary SQL commands on the database, potentially leading to information disclosure or further compromise of the affected system.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can execute arbitrary SQL commands to access, modify, or delete database contents, potentially compromising the entire ASUSTOR ADM system and accessing stored data.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to a patched version of ASUSTOR ADM or apply vendor-provided security updates.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">adm</span><span class="nt-tag">asustor</span><span class="nt-tag">cve</span><span class="nt-tag">cve2018</span><span class="nt-tag">sqli</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.exploit-db.com/exploits/44909" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2018-11511" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="atutor &lt; 2.2.1 - cross site scripting medium identify critical remote vulnerabilities atutor &lt; 2.2.1 was discovered with a vulnerability, a reflected cross-site scripting (xss), in attutor 2.2.1 via token body parameter. cve-2023-27008 r3y3r53 atutor cve cve2023 vkev vuln xss cwe-79" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">ATutor &lt; 2.2.1 - Cross Site Scripting</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-27008.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-27008.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> r3Y3r53</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-79</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-27008" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-27008</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)atutor&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">ATutor &lt; 2.2.1 was discovered with a vulnerability, a reflected cross-site scripting (XSS), in ATtutor 2.2.1 via token body parameter.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to inject malicious scripts into web pages viewed by users, leading to potential data theft, session hijacking, or defacement of the affected website.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade ATutor to version 2.2.2 or above to mitigate this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">atutor</span><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">xss</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-27008" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://plantplants213607121.wordpress.com/2023/02/16/atutor-2-2-1-cross-site-scripting-via-the-token-body-parameter/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/ARPSyndicate/cvemon" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="aveva edge scada - login panel info identify web-based control panels aveva edge scada web interface panel has been detected. rxerium aveva discovery edge ics panel scada" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">AVEVA Edge SCADA - Login Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/aveva-edge-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">aveva-edge-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 27, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches `content\s*=\s*&#34;AVEVA Edge&#34;`</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">AVEVA Edge SCADA web interface panel has been detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">aveva</span><span class="nt-tag">discovery</span><span class="nt-tag">edge</span><span class="nt-tag">ics</span><span class="nt-tag">panel</span><span class="nt-tag">scada</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.aveva.com/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="aveva intouch access anywhere - panel info identify web-based control panels detected aveva intouch access anywhere was a secure gateway that provided browser-based remote access to intouch hmi applications over the internet. it was widely used in industrial process control, utilities, and manufacturing environments. exposed instances may have provided access to industrial hmi displays and scada interfaces. rxerium aveva discovery hmi ics intouch panel scada" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">AVEVA InTouch Access Anywhere - Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/aveva-intouch-access-anywhere-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">aveva-intouch-access-anywhere-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 27, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)InTouch Access Anywhere Server&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detected AVEVA InTouch Access Anywhere was a secure gateway that provided browser-based remote access to InTouch HMI applications over the internet. It was widely used in industrial process control, utilities, and manufacturing environments. Exposed instances may have provided access to industrial HMI displays and SCADA interfaces.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">aveva</span><span class="nt-tag">discovery</span><span class="nt-tag">hmi</span><span class="nt-tag">ics</span><span class="nt-tag">intouch</span><span class="nt-tag">panel</span><span class="nt-tag">scada</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.aveva.com/en/products/intouch-hmi/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.aveva.com/en/products/intouch-access-anywhere/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="avm fritz!box 7530 ax - unauthorized access high identify critical remote vulnerabilities an access control issue in the component /juis_boxinfo.xml of avm fritz!box 7530 ax v7.59 allows attackers to obtain sensitive information without authentication. cve-2024-54767 dhiyaneshdk cve cve2024 fritz!box info-leak unauth vuln cwe-203" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">AVM FRITZ!Box 7530 AX - Unauthorized Access</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-54767.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-54767.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 11, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/203.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-203</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-54767" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-54767</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)FRITZ!Box 7530&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An access control issue in the component /juis_boxinfo.xml of AVM FRITZ!Box 7530 AX v7.59 allows attackers to obtain sensitive information without authentication.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can access sensitive device information including firmware version, serial numbers, and configuration details through the boxinfo XML endpoint.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update AVM FRITZ!Box 7530 AX to a version later than 7.59 that addresses the unauthorized access vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">fritz!box</span><span class="nt-tag">info-leak</span><span class="nt-tag">unauth</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/Shuanunio/CVE_Requests/blob/main/AVM/fritz/AVM_FRITZ%21Box_7530%20AX_unauthorized_access_vulnerability_first.md" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="avtech dvr - login verification code bypass low identify critical remote vulnerabilities avtech dvr products are vulnerable to verification code bypass just by entering the &#34;login=quick&#34; parameter to bypass verification code. cve-2013-4982 ritikchaddha avtech bypass cve cve2013 iot verify vuln cwe-287" data-nt-sev="low">
  <div class="nt-card-header">
    <div class="nt-title">AVTECH DVR - Login Verification Code Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2013/CVE-2013-4982.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2013-4982.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 13, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/287.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-287</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2013-4982" target="_blank" rel="noopener" class="nt-cve-link">CVE-2013-4982</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)login\&#34; product:\&#34;Avtech&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">AVTECH DVR products are vulnerable to verification code bypass just by entering the &#34;login=quick&#34; parameter to bypass verification code.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can bypass authentication mechanisms and gain unauthorized access to the DVR system, potentially viewing camera feeds, modifying settings, or compromising the device.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest firmware version or contact the vendor for a security patch.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">avtech</span><span class="nt-tag">bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2013</span><span class="nt-tag">iot</span><span class="nt-tag">verify</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2013-4982" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="avtech dvr - ssrf medium identify critical remote vulnerabilities avtech dvr device, search.cgi can be accessed directly. search.cgi is responsible for searching and accessing cameras in the local network. search.cgi provides the cgi_query function. ritikchaddha avtech iot ssrf unauth vuln cwe-918" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">AVTECH DVR - SSRF</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/vulnerabilities/avtech/avtech-dvr-ssrf.yaml" target="_blank" rel="noopener" class="nt-source-link">avtech-dvr-ssrf.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 16, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/918.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-918</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)login\&#34; product:\&#34;Avtech&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">AVTECH DVR device, Search.cgi can be accessed directly. Search.cgi is responsible for searching and accessing cameras in the local network. Search.cgi provides the cgi_query function.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">avtech</span><span class="nt-tag">iot</span><span class="nt-tag">ssrf</span><span class="nt-tag">unauth</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="avtech room alert login panel - detect info identify web-based control panels avtech room alert login panel was detected. gy741 avtech discovery panel room-alert cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">AVTECH Room Alert Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/room-alert-detect.yaml" target="_blank" rel="noopener" class="nt-source-link">room-alert-detect.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> gy741</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Room Alert&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">AVTECH Room Alert login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">avtech</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">room-alert</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://avtech.com/articles/166/how-to-access-a-room-alert-monitors-settings-pages-2/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="avtech video surveillance product - authentication bypass high identify critical remote vulnerabilities avtech video surveillance products password disclosure through /cgi-bin/user/config.cgi. ritikchaddha exposure avtech auth-bypass password vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">AVTECH Video Surveillance Product - Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/vulnerabilities/avtech/avtech-auth-bypass.yaml" target="_blank" rel="noopener" class="nt-source-link">avtech-auth-bypass.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 15, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)login\&#34; product:\&#34;Avtech&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">AVTECH Video Surveillance Products password disclosure through /cgi-bin/user/Config.cgi.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">exposure</span><span class="nt-tag">avtech</span><span class="nt-tag">auth-bypass</span><span class="nt-tag">password</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="avtech video surveillance product - unauthenticated file download high identify critical remote vulnerabilities avtech video surveillance products unauthenticated file download from web root through /cgi-bin/cgibox, since the .cab string is verified by the strstr method, the file download can be realized by adding ?.cab at the end of the file name. ritikchaddha exposure avtech unauth download iot vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">AVTECH Video Surveillance Product - Unauthenticated File Download</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/vulnerabilities/avtech/avtech-unauth-file-download.yaml" target="_blank" rel="noopener" class="nt-source-link">avtech-unauth-file-download.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 15, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)login\&#34; product:\&#34;Avtech&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">AVTECH video surveillance products unauthenticated file download from web root through /cgi-bin/cgibox, Since the .cab string is verified by the strstr method, the file download can be realized by adding ?.cab at the end of the file name.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">exposure</span><span class="nt-tag">avtech</span><span class="nt-tag">unauth</span><span class="nt-tag">download</span><span class="nt-tag">iot</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="avideo &lt;= 26.0 - wwbn avideo - remote code execution critical identify critical remote vulnerabilities wwbn avideo &lt;= 26.0 contains multiple vulnerabilities in the clonesite plugin including unauthenticated exposure of clone secret keys and os command injection in rsync command construction, letting unauthenticated attackers achieve remote code execution. pussycat0x avideo clonesite cve cve2026 oss unauth vkev" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">AVideo &lt;= 26.0 - WWBN AVideo - Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2026/CVE-2026-33478.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2026-33478.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 8, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)AVideo&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">WWBN AVideo &lt;= 26.0 contains multiple vulnerabilities in the CloneSite plugin including unauthenticated exposure of clone secret keys and OS command injection in rsync command construction, letting unauthenticated attackers achieve remote code execution.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can execute arbitrary system commands, leading to full server compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the version including commit c85d076375fab095a14170df7ddb27058134d38c or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">avideo</span><span class="nt-tag">clonesite</span><span class="nt-tag">cve</span><span class="nt-tag">cve2026</span><span class="nt-tag">oss</span><span class="nt-tag">unauth</span><span class="nt-tag">vkev</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/WWBN/AVideo/security/advisories/GHSA-687q-32c6-8x68" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="aws ec2 auto scaling lab info identify web-based control panels  dhiyaneshdk exposure ec2 aws amazon panel discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">AWS EC2 Auto Scaling Lab</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/aws-ec2-autoscale.yaml" target="_blank" rel="noopener" class="nt-source-link">aws-ec2-autoscale.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 20, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)AWS EC2 Auto Scaling Lab&#34;</code></div>
  <div class="nt-tags"><span class="nt-tag">exposure</span><span class="nt-tag">ec2</span><span class="nt-tag">aws</span><span class="nt-tag">amazon</span><span class="nt-tag">panel</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.facebook.com/photo/?fbid=620605120110011&amp;set=a.467014098802448" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="aws elastic beanstalk dockerrun.aws.json - exposure medium identify critical remote vulnerabilities detected aws elastic beanstalk dockerrun.aws.json configuration file was publicly accessible, potentially revealing docker container definitions, image names, hostnames, port mappings, and infrastructure details. 0x_akoko aws docker config exposure misconfig cwe-200" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">AWS Elastic Beanstalk Dockerrun.aws.json - Exposure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposures/configs/dockerrun-aws-json-exposure.yaml" target="_blank" rel="noopener" class="nt-source-link">dockerrun-aws-json-exposure.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_Akoko</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 22, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)AWSEBDockerrunVersion&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detected AWS Elastic Beanstalk Dockerrun.aws.json configuration file was publicly accessible, potentially revealing Docker container definitions, image names, hostnames, port mappings, and infrastructure details.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">aws</span><span class="nt-tag">docker</span><span class="nt-tag">config</span><span class="nt-tag">exposure</span><span class="nt-tag">misconfig</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://docs.aws.amazon.com/elasticbeanstalk/latest/dg/create_deploy_docker_v2config.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="awstats &lt;= 7.5 - full path disclosure medium identify critical remote vulnerabilities awstats 7.6 contains a full path disclosure caused by improper handling of framename and update parameters in awstats.pl, letting remote attackers determine server file paths, exploit requires sending crafted parameters. cve-2018-10245 0x_akoko awstats cve cve2018 disclosure exposure fpd cwe-200" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">AWStats &lt;= 7.5 - Full Path Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2018/CVE-2018-10245.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2018-10245.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_Akoko</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 29, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2018-10245" target="_blank" rel="noopener" class="nt-cve-link">CVE-2018-10245</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;product&#34;] contains &#34;Laurent Destailleur:AWStats&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">AWStats 7.6 contains a full path disclosure caused by improper handling of framename and update parameters in awstats.pl, letting remote attackers determine server file paths, exploit requires sending crafted parameters.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can discover server file paths, aiding further exploitation or reconnaissance.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest version of AWStats or apply security patches addressing this issue.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">awstats</span><span class="nt-tag">cve</span><span class="nt-tag">cve2018</span><span class="nt-tag">disclosure</span><span class="nt-tag">exposure</span><span class="nt-tag">fpd</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/eldy/awstats" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://awstats.sourceforge.io/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="abandoned cart lite for woocommerce &lt; 5.2.0 - cross-site scripting high identify critical remote vulnerabilities the abandoned cart lite for woocommerce and abandoned cart pro for woocommerce plugins for wordpress are vulnerable to stored cross-site scripting via multiple parameters in versions up to, and including, 5.1.3 and 7.12.0 respectively, due to insufficient input sanitization and output escaping. cve-2019-25152 dhiyaneshdk cve cve2019 passive vkev vuln woocommerce-abandoned-cart wordpress wp wp-plugin wpscan xss" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Abandoned Cart Lite for WooCommerce &lt; 5.2.0 - Cross-Site Scripting</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2019/CVE-2019-25152.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2019-25152.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 7, 2025</span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2019-25152" target="_blank" rel="noopener" class="nt-cve-link">CVE-2019-25152</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/woocommerce-abandoned-cart/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The Abandoned Cart Lite for WooCommerce and Abandoned Cart Pro for WooCommerce plugins for WordPress are vulnerable to Stored Cross-Site Scripting via multiple parameters in versions up to, and including, 5.1.3 and 7.12.0 respectively, due to insufficient input sanitization and output escaping.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">This makes it possible for unauthenticated attackers to inject arbitrary web scripts in user input that will execute on the admin dashboard.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Fixed in 5.2.0</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2019</span><span class="nt-tag">passive</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">woocommerce-abandoned-cart</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">wpscan</span><span class="nt-tag">xss</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wpscan.com/vulnerability/915420b1-f476-481e-9b11-b736a7cfdda7/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://wpscan.com/vulnerability/9229" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a9cc5c6d-4396-4ebf-8788-f01dd9e9cfbc?source=cve" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25152" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="academy lms 6.2 - sql injection critical identify critical remote vulnerabilities a vulnerability was found in academy lms 6.2. it has been rated as critical. affected by this issue is some unknown functionality of the file /academy/tutor/filter of the component get parameter handler. the manipulation of the argument price_min/price_max leads to sql injection. the attack may be launched remotely. vdb-239750 is the identifier assigned to this vulnerability. note: the vendor was contacted early about this disclosure but did not respond in any way. cve-2023-4974 theamanrawat academy creativeitem cve cve2023 lms packetstorm sqli time-based-sqli vuln cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Academy LMS 6.2 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-4974.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-4974.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> theamanrawat</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 17, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-4974" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-4974</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)academy lms&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A vulnerability was found in Academy LMS 6.2. It has been rated as critical. Affected by this issue is some unknown functionality of the file /academy/tutor/filter of the component GET Parameter Handler. The manipulation of the argument price_min/price_max leads to sql injection. The attack may be launched remotely. VDB-239750 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can execute arbitrary SQL queries, potentially extracting sensitive database information including user credentials and payment data.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update Academy LMS to version 6.3 or later which includes proper SQL injection prevention.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">academy</span><span class="nt-tag">creativeitem</span><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">lms</span><span class="nt-tag">packetstorm</span><span class="nt-tag">sqli</span><span class="nt-tag">time-based-sqli</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://demo.creativeitem.com/academy/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://packetstormsecurity.com/files/174681/Academy-LMS-6.2-SQL-Injection.html" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-4974" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="http://packetstormsecurity.com/files/174681/Academy-LMS-6.2-SQL-Injection.html" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://vuldb.com/?ctiid.239750" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="acenet acereporter report panel - detect info identify web-based control panels  dhiyaneshdk panel login acenet acereporter discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">AceNet AceReporter Report Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/acenet-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">acenet-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 4, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-1595726841&#34;</code></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">login</span><span class="nt-tag">acenet</span><span class="nt-tag">acereporter</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="ackee panel - detect info identify web-based control panels self-hosted, node.js based analytics tool for those who care about privacy. userdehghani panel ackee login detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Ackee Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/ackee-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">ackee-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> userdehghani</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 13, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-1495233116&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">self-hosted, node.js based analytics tool for those who care about privacy.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">ackee</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://ackee.electerious.com/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://docs.ackee.electerious.com/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="acrolinx dashboard info identify web-based control panels an acrolinx analytics dashboard was detected. ffffffff0x acrolinx panel discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Acrolinx Dashboard</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/acrolinx-dashboard.yaml" target="_blank" rel="noopener" class="nt-source-link">acrolinx-dashboard.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ffffffff0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Acrolinx Dashboard&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An Acrolinx Analytics dashboard was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">acrolinx</span><span class="nt-tag">panel</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://docs.acrolinx.com/coreplatform/latest/en/analytics/acrolinx-analytics-dashboards" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="actifio resource center - panel info identify web-based control panels actifio resource center was detected. splint3r7 panel actifio login detect discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Actifio Resource Center - Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/actifio-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">actifio-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Splint3r7</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 30, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Actifio Resource Center&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Actifio Resource Center was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">actifio</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="activepieces panel - detect info identify web-based control panels activepieces was detected. activepieces was an open-source automation platform with ai and llm integrations. exposed instances may allow access to workflow automation configurations and connected integrations. rxerium activepieces ai automation detect discovery panel" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Activepieces Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/activepieces-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">activepieces-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 14, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Activepieces&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Activepieces was detected. Activepieces was an open-source automation platform with AI and LLM integrations. Exposed instances may allow access to workflow automation configurations and connected integrations.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">activepieces</span><span class="nt-tag">ai</span><span class="nt-tag">automation</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/activepieces/activepieces" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.activepieces.com/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="acutoweb server/10.5.0.7577c8b - cross-site scripting medium identify critical remote vulnerabilities acutoweb server/10.5.0.7577c8b is vulnerable to reflected cross-site scripting (xss) via the portgw parameter. unsanitized user input is reflected in the response, allowing arbitrary javascript execution. cve-2024-42852 ritikchaddha acutoweb cve cve2024 opentext vkev vuln xss cwe-79" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">AcuToWeb server/10.5.0.7577c8b - Cross-Site Scripting</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-42852.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-42852.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 16, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-79</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-42852" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-42852</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)AcuToWeb&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">AcuToWeb server/10.5.0.7577c8b is vulnerable to reflected cross-site scripting (XSS) via the portgw parameter. Unsanitized user input is reflected in the response, allowing arbitrary JavaScript execution.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this XSS vulnerability allows attackers to execute arbitrary JavaScript code in victims&#39; browsers, potentially leading to session hijacking, credential theft, or other malicious activities.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update AcuToWeb to the latest version. Implement proper input validation and output encoding for all user-supplied data, especially the portgw parameter.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">acutoweb</span><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">opentext</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">xss</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/Hebing123/cve/issues/64" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-42852" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="acunetix login panel - detect info identify web-based control panels acunetix login panel was detected. tess acunetix discovery panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Acunetix Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/acunetix-login.yaml" target="_blank" rel="noopener" class="nt-source-link">acunetix-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> tess</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Acunetix&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Acunetix login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">acunetix</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="adguard panel - detect info identify web-based control panels adguard panel has been detected. ritikchaddha adguard panel login detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">AdGuard Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/adguard-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">adguard-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 18, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)AdGuard Home&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">AdGuard panel has been detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">adguard</span><span class="nt-tag">panel</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="adapt authoring tool - panel info identify web-based control panels login panel for adapt was detected. splint3r7 panel adapt login detect discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Adapt Authoring Tool - Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/adapt-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">adapt-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Splint3r7</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 5, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Adapt authoring tool&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Login panel for adapt was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">adapt</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="addonfinance portal - detect info identify web-based control panels addonfinance portal panel was detected. ritikchaddha panel addon finance detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">AddOnFinance Portal - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/addonfinance-portal.yaml" target="_blank" rel="noopener" class="nt-source-link">addonfinance-portal.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 5, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)AddOnFinancePortal&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">AddOnFinance Portal Panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">addon</span><span class="nt-tag">finance</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="adfinity login panel - detect info identify web-based control panels adfinity products was detected. righettod panel adfinity login discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Adfinity Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/adfinity-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">adfinity-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 3, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Adfinity&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Adfinity products was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">adfinity</span><span class="nt-tag">login</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://easi.net/en/solutions/adfinity" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="adminer 4.6.2 - 5.4.1 unauthenticated persistent dos high identify critical remote vulnerabilities adminer &lt;= 5.4.1 contains a denial of service caused by lack of origin validation in version check endpoint, letting attackers trigger server errors via crafted post requests, exploit requires no special privileges. cve-2026-25892 dhiyaneshdk adminer cve cve2026 passive cwe-20" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Adminer 4.6.2 - 5.4.1 Unauthenticated Persistent DoS</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2026/CVE-2026-25892.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2026-25892.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 12, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/20.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-20</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2026-25892" target="_blank" rel="noopener" class="nt-cve-link">CVE-2026-25892</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;product&#34;] contains &#34;Adminer:Adminer&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Adminer &lt;= 5.4.1 contains a denial of service caused by lack of origin validation in version check endpoint, letting attackers trigger server errors via crafted POST requests, exploit requires no special privileges.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can cause server errors resulting in denial of service for all users.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to Adminer 5.4.2 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">adminer</span><span class="nt-tag">cve</span><span class="nt-tag">cve2026</span><span class="nt-tag">passive</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/vrana/adminer/security/advisories/GHSA-q4f2-39gr-45jh" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/vrana/adminer/commit/21d3a3150388677b18647d68aec93b7850e457d3" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="adminer &lt;4.7.9 - server-side request forgery high identify critical remote vulnerabilities adminer before 4.7.9 is susceptible to server-side request forgery due to exposure of sensitive information in error messages. users of adminer versions bundling all drivers, e.g. adminer.php, are affected. an attacker can possibly obtain this information, modify data, and/or execute unauthorized administrative operations in the context of the affected site. cve-2021-21311 adam crosser,pwnhxl adminer cve cve2021 kev ssrf vkev vuln cwe-918" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Adminer &lt;4.7.9 - Server-Side Request Forgery</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2021/CVE-2021-21311.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2021-21311.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Adam Crosser,pwnhxl</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/918.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-918</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2021-21311" target="_blank" rel="noopener" class="nt-cve-link">CVE-2021-21311</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)login - adminer&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Adminer before 4.7.9 is susceptible to server-side request forgery due to exposure of sensitive information in error messages. Users of Adminer versions bundling all drivers, e.g. adminer.php, are affected. An attacker can possibly obtain this information, modify data, and/or execute unauthorized administrative operations in the context of the affected site.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could lead to unauthorized access to internal resources and potential data leakage.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to version 4.7.9 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">adminer</span><span class="nt-tag">cve</span><span class="nt-tag">cve2021</span><span class="nt-tag">kev</span><span class="nt-tag">ssrf</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/vrana/adminer/security/advisories/GHSA-x5r2-hj5c-8jx6" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/vrana/adminer/files/5957311/Adminer.SSRF.pdf" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://packagist.org/packages/vrana/adminer" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2021-21311" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/vrana/adminer/commit/ccd2374b0b12bd547417bf0dacdf153826c83351" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="adminer &lt;=4.8.0 - cross-site scripting medium identify critical remote vulnerabilities adminer 4.6.1 to 4.8.0 contains a cross-site scripting vulnerability which affects users of mysql, mariadb, pgsql, and sqlite in browsers without csp when adminer uses a `pdo_` extension to communicate with the database (it is used if the native extensions are not enabled). cve-2021-29625 daffainfo adminer cve cve2021 sqli vuln xss cwe-79" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Adminer &lt;=4.8.0 - Cross-Site Scripting</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2021/CVE-2021-29625.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2021-29625.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> daffainfo</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-79</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2021-29625" target="_blank" rel="noopener" class="nt-cve-link">CVE-2021-29625</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)login - adminer&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Adminer 4.6.1 to 4.8.0 contains a cross-site scripting vulnerability which affects users of MySQL, MariaDB, PgSQL, and SQLite in browsers without CSP when Adminer uses a `pdo_` extension to communicate with the database (it is used if the native extensions are not enabled).</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to inject malicious scripts into the Adminer interface, potentially leading to session hijacking, defacement, or theft of sensitive information.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">This vulnerability is patched in version 4.8.1. As workarounds, one can use a browser supporting strict CSP or enable the native PHP extensions (e.g. `mysqli`) or disable displaying PHP errors (`display_errors`).</div></div></div>
  <div class="nt-tags"><span class="nt-tag">adminer</span><span class="nt-tag">cve</span><span class="nt-tag">cve2021</span><span class="nt-tag">sqli</span><span class="nt-tag">vuln</span><span class="nt-tag">xss</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://sourceforge.net/p/adminer/bugs-and-features/797/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/vrana/adminer/commit/4043092ec2c0de2258d60a99d0c5958637d051a7" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2021-29625" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/vrana/adminer/security/advisories/GHSA-2v82-5746-vwqc" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/ARPSyndicate/cvemon" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="adminer default login - detect high identify default logins in web-based control panels adminer contains a default login vulnerability. an attacker can obtain access to user accounts and access sensitive information, modify data, and/or execute unauthorized operations. j4vaovo adminer default-login vuln cwe-522" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Adminer Default Login - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/adminer-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">adminer-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> j4vaovo</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/522.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-522</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)adminer&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Adminer contains a default login vulnerability. An attacker can obtain access to user accounts and access sensitive information, modify data, and/or execute unauthorized operations.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">adminer</span><span class="nt-tag">default-login</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.adminer.org" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="adminer login panel - detect info identify web-based control panels an adminer login panel was detected. random_robbie,meme-lord,ritikchaddha adminer discovery panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Adminer Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/adminer-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">adminer-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> random_robbie,meme-lord,ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)login - adminer&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An Adminer login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">adminer</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://blog.sorcery.ie/posts/adminer/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="adminer login panel - detect info identify web-based control panels adminer login panel was detected. random_robbie,meme-lord adminer discovery fuzz login panel sqli cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Adminer Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/adminer-panel-detect.yaml" target="_blank" rel="noopener" class="nt-source-link">adminer-panel-detect.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> random_robbie,meme-lord</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)login - adminer&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Adminer login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">adminer</span><span class="nt-tag">discovery</span><span class="nt-tag">fuzz</span><span class="nt-tag">login</span><span class="nt-tag">panel</span><span class="nt-tag">sqli</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://blog.sorcery.ie/posts/adminer/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="adobe aem crx package manager - panel detect info identify web-based control panels adobe aem crx package manager panel was detected. dhiyaneshdk adobe aem discovery panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Adobe AEM CRX Package Manager - Panel Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/adobe/aem-crx-package-manager.yaml" target="_blank" rel="noopener" class="nt-source-link">aem-crx-package-manager.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)aem sign in&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Adobe AEM CRX Package Manager panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">adobe</span><span class="nt-tag">aem</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://raw.githubusercontent.com/danielmiessler/SecLists/master/Discovery/Web-Content/aem2.txt" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="adobe aem default login high identify default logins in web-based control panels adobe aem default login credentials were discovered. random-robbie adobe aem default-login vuln cwe-522" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Adobe AEM Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/aem/aem-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">aem-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> random-robbie</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/522.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-522</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] contains `href=&#34;/etc.clientlibs/`</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Adobe AEM default login credentials were discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">adobe</span><span class="nt-tag">aem</span><span class="nt-tag">default-login</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://experienceleague.adobe.com/docs/experience-manager-64/administering/security/security-checklist.html?lang=en" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="adobe aem jcr compare exposure medium identify critical remote vulnerabilities detected an exposed adobe aem jcr compare functionality that was accessible without proper authorization. this exposure may have allowed attackers to infer repository structure or sensitive content through comparison operations. pussycat0x aem adobe exposure misconfiguration jcr" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Adobe AEM JCR Compare Exposure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/misconfiguration/aem/aem-jcr-exposure.yaml" target="_blank" rel="noopener" class="nt-source-link">aem-jcr-exposure.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 2, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;product&#34;] contains &#34;Adobe:Experience Manager&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detected an exposed Adobe AEM JCR compare functionality that was accessible without proper authorization. This exposure may have allowed attackers to infer repository structure or sensitive content through comparison operations.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">aem</span><span class="nt-tag">adobe</span><span class="nt-tag">exposure</span><span class="nt-tag">misconfiguration</span><span class="nt-tag">jcr</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://experienceleague.adobe.com/docs/experience-manager-65/administering/security/security-checklist.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://medium.com/@vsr061/adobe-experience-manager-security-issues-9b5bd24e0eb0" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="adobe coldfusion - access control bypass high identify critical remote vulnerabilities there is an access control bypass vulnerability in adobe coldfusion versions 2023 update 2 and below, 2021 update 8 and below and 2018 update 18 and below, which allows a remote attacker to bypass the coldfusion mechanisms that restrict unauthenticated external access to coldfusion&#39;s administrator. cve-2023-38205 dhiyaneshdk adobe auth-bypass coldfusion cve cve2023 kev vkev vuln cwe-284,nvd-cwe-other" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Adobe ColdFusion - Access Control Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-38205.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-38205.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 20, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/284,NVD-CWE-OTHER.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-284,NVD-CWE-OTHER</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-38205" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-38205</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)coldfusion administrator login&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">There is an access control bypass vulnerability in Adobe ColdFusion versions 2023 Update 2 and below, 2021 Update 8 and below and 2018 update 18 and below, which allows a remote attacker to bypass the ColdFusion mechanisms that restrict unauthenticated external access to ColdFusion&#39;s Administrator.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to bypass access controls and gain unauthorized access to sensitive information or perform unauthorized actions.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the necessary security patches or updates provided by Adobe to mitigate this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">adobe</span><span class="nt-tag">auth-bypass</span><span class="nt-tag">coldfusion</span><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">kev</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.rapid7.com/blog/post/2023/07/19/cve-2023-38205-adobe-coldfusion-access-control-bypass-fixed/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://helpx.adobe.com/security/products/coldfusion/apsb23-47.html" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/Ostorlab/KEV" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/Ostorlab/known_exploited_vulnerbilities_detectors" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="adobe coldfusion - access control bypass high identify critical remote vulnerabilities an attacker is able to access every cfm and cfc endpoint within the coldfusion administrator path /cfide/, of which there are 437 cfm files and 96 cfc files in a coldfusion 2021 update 6 install. cve-2023-29298 rootxharsh,iamnoooob,dhiyaneshdk,pdresearch adobe auth-bypass coldfusion cve cve2023 kev vkev vuln cwe-284,nvd-cwe-other" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Adobe ColdFusion - Access Control Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-29298.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-29298.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rootxharsh,iamnoooob,DhiyaneshDK,pdresearch</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 12, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/284,NVD-CWE-OTHER.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-284,NVD-CWE-OTHER</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-29298" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-29298</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)coldfusion administrator login&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An attacker is able to access every CFM and CFC endpoint within the ColdFusion Administrator path /CFIDE/, of which there are 437 CFM files and 96 CFC files in a ColdFusion 2021 Update 6 install.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to bypass access controls and gain unauthorized access to sensitive information or perform unauthorized actions.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches or updates provided by Adobe to fix the access control bypass vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">adobe</span><span class="nt-tag">auth-bypass</span><span class="nt-tag">coldfusion</span><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">kev</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.rapid7.com/blog/post/2023/07/11/cve-2023-29298-adobe-coldfusion-access-control-bypass/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://helpx.adobe.com/security/products/coldfusion/apsb23-40.html" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/Ostorlab/KEV" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/Ostorlab/known_exploited_vulnerbilities_detectors" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/XRSec/AWVS-Update" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="adobe coldfusion - arbitrary file read high identify critical remote vulnerabilities coldfusion versions 2023.6, 2021.12 and earlier are affected by an improper access control vulnerability that could lead to arbitrary file system read. an attacker could leverage this vulnerability to bypass security measures and gain unauthorized access to sensitive files and perform arbitrary file system write. exploitation of this issue does not require user interaction. cve-2024-20767 iamnoooob,rootxharsh,pdresearch adobe coldfusion cve cve2024 kev lfr vkev vuln cwe-284" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Adobe ColdFusion - Arbitrary File Read</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-20767.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-20767.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> iamnoooob,rootxharsh,pdresearch</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 26, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/284.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-284</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-20767" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-20767</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.head.server&#34;] matches `(?i)coldfusion`</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">ColdFusion versions 2023.6, 2021.12 and earlier are affected by an Improper Access Control vulnerability that could lead to arbitrary file system read. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access to sensitive files and perform arbitrary file system write. Exploitation of this issue does not require user interaction.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can read and write arbitrary files on the server, potentially leading to complete system compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update Adobe ColdFusion to version 2023.7, 2021.13 or later depending on your version.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">adobe</span><span class="nt-tag">coldfusion</span><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">kev</span><span class="nt-tag">lfr</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://jeva.cc/2973.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-20767" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://helpx.adobe.com/security/products/coldfusion/apsb24-14.html" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/Praison001/CVE-2024-20767-Adobe-ColdFusion" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/Hatcat123/my_stars" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="adobe coldfusion - cross-site scripting medium identify critical remote vulnerabilities adobe coldfusion versions 2016 (update 16 and earlier), 2018 (update 10 and earlier) and 2021.0.0.323925 are affected by an improper neutralization of input during web page generation (&#39;cross-site scripting&#39;) vulnerability. an attacker could abuse this vulnerability to execute arbitrary javascript code in context of the current user. exploitation of this issue requires user interaction. cve-2021-21087 daviey adobe coldfusion cve cve2021 misc vkev vuln xss cwe-79" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Adobe ColdFusion - Cross-Site Scripting</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2021/CVE-2021-21087.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2021-21087.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Daviey</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-79</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2021-21087" target="_blank" rel="noopener" class="nt-cve-link">CVE-2021-21087</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)coldfusion administrator login&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Adobe Coldfusion versions 2016 (update 16 and earlier), 2018 (update 10 and earlier) and 2021.0.0.323925 are affected by an Improper Neutralization of Input During Web Page Generation (&#39;Cross-site Scripting&#39;) vulnerability. An attacker could abuse this vulnerability to execute arbitrary JavaScript code in context of the current user. Exploitation of this issue requires user interaction.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute malicious scripts in the context of the victim&#39;s browser, potentially leading to session hijacking, defacement, or theft of sensitive information.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches or updates provided by Adobe to mitigate this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">adobe</span><span class="nt-tag">coldfusion</span><span class="nt-tag">cve</span><span class="nt-tag">cve2021</span><span class="nt-tag">misc</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">xss</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://helpx.adobe.com/security/products/coldfusion/apsb21-16.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://twitter.com/Daviey/status/1374070630283415558" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2021-21087" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/ARPSyndicate/cvemon" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/ARPSyndicate/kenzer-templates" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="adobe coldfusion - local file read high identify critical remote vulnerabilities unauthenticated arbitrary file read vulnerability due to deserialization of untrusted data in adobe coldfusion. the vulnerability affects coldfusion 2021 update 5 and earlier as well as coldfusion 2018 update 15 and earlier cve-2023-26360 dhiyaneshdk,7own adobe coldfusion cve cve2023 kev lfi packetstorm vkev vuln cwe-284" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Adobe ColdFusion - Local File Read</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-26360.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-26360.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK,7own</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 9, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/284.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-284</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-26360" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-26360</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)coldfusion administrator login&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Unauthenticated Arbitrary File Read vulnerability due to deserialization of untrusted data in Adobe ColdFusion. The vulnerability affects ColdFusion 2021 Update 5 and earlier as well as ColdFusion 2018 Update 15 and earlier</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">This vulnerability can lead to unauthorized access to sensitive information stored on the server.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the necessary security patches or updates provided by Adobe to fix the vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">adobe</span><span class="nt-tag">coldfusion</span><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">kev</span><span class="nt-tag">lfi</span><span class="nt-tag">packetstorm</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://attackerkb.com/topics/F36ClHTTIQ/cve-2023-26360/rapid7-analysis" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-26360" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://helpx.adobe.com/security/products/coldfusion/apsb23-25.html" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="http://packetstormsecurity.com/files/172079/Adobe-ColdFusion-Unauthenticated-Remote-Code-Execution.html" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/Ostorlab/KEV" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="adobe coldfusion 8.0/8.0.1/9.0/9.0.1 lfi high identify critical remote vulnerabilities multiple directory traversal vulnerabilities in the administrator console in adobe coldfusion 9.0.1 and earlier allow remote attackers to read arbitrary files via the locale parameter to (1) cfide/administrator/settings/mappings.cfm, (2) logging/settings.cfm, (3) datasources/index.cfm, (4) j2eepackaging/editarchive.cfm, and (5) enter.cfm in cfide/administrator/. cve-2010-2861 pikpikcu adobe coldfusion cve cve2010 kev lfi vkev vulhub vuln cwe-22" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Adobe ColdFusion 8.0/8.0.1/9.0/9.0.1 LFI</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2010/CVE-2010-2861.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2010-2861.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pikpikcu</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2010-2861" target="_blank" rel="noopener" class="nt-cve-link">CVE-2010-2861</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)coldfusion administrator login&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Multiple directory traversal vulnerabilities in the administrator console in Adobe ColdFusion 9.0.1 and earlier allow remote attackers to read arbitrary files via the locale parameter to (1) CFIDE/administrator/settings/mappings.cfm, (2) logging/settings.cfm, (3) datasources/index.cfm, (4) j2eepackaging/editarchive.cfm, and (5) enter.cfm in CFIDE/administrator/.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">This vulnerability can lead to unauthorized access to sensitive information and potential compromise of the affected system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to the latest version to mitigate this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">adobe</span><span class="nt-tag">coldfusion</span><span class="nt-tag">cve</span><span class="nt-tag">cve2010</span><span class="nt-tag">kev</span><span class="nt-tag">lfi</span><span class="nt-tag">vkev</span><span class="nt-tag">vulhub</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/vulhub/vulhub/tree/master/coldfusion/CVE-2010-2861" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="http://www.adobe.com/support/security/bulletins/apsb10-18.html" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="http://securityreason.com/securityalert/8148" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="http://securityreason.com/securityalert/8137" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="http://www.gnucitizen.org/blog/coldfusion-directory-traversal-faq-cve-2010-2861/" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="adobe coldfusion component browser login panel info identify web-based control panels an adobe coldfusion component browser login panel was detected. dhiyaneshdk adobe coldfusion discovery edb panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Adobe ColdFusion Component Browser Login Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/adobe/adobe-component-login.yaml" target="_blank" rel="noopener" class="nt-source-link">adobe-component-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)coldfusion administrator login&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An Adobe ColdFusion Component Browser login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">adobe</span><span class="nt-tag">coldfusion</span><span class="nt-tag">discovery</span><span class="nt-tag">edb</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.exploit-db.com/ghdb/6846" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="adobe coldfusion wddx deserialization gadgets critical identify critical remote vulnerabilities adobe coldfusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an deserialization of untrusted data vulnerability that could result in arbitrary code execution. exploitation of this issue does not require user interaction. cve-2023-44353 salts adobe coldfusion cve cve2023 deserialization vkev vuln xss cwe-502" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Adobe ColdFusion WDDX Deserialization Gadgets</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-44353.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-44353.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> salts</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 7, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/502.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-502</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-44353" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-44353</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)coldfusion administrator login&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation of this issue does not require user interaction.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can exploit WDDX deserialization vulnerabilities in Adobe ColdFusion to execute arbitrary code without user interaction and completely compromise ColdFusion installations.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">To mitigate this vulnerability, it is recommended to apply the latest security patches or upgrade to a newer version of OpenCATS that addresses the XSS vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">adobe</span><span class="nt-tag">coldfusion</span><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">deserialization</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">xss</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-44353" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://helpx.adobe.com/security/products/coldfusion/apsb23-52.html" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://research.nccgroup.com/2023/11/21/technical-advisory-adobe-coldfusion-wddx-deserialization-gadgets/#coldfusion-wddx.py" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/JC175/CVE-2023-44353-Nuclei-Template" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/nomi-sec/PoC-in-GitHub" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="adobe coldfusion - authentication bypass high identify critical remote vulnerabilities adobe coldfusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an improper access control vulnerability that could result in a security feature bypass. an unauthenticated attacker could leverage this vulnerability to access the administration cfm and cfc endpoints. exploitation of this issue does not require user interaction. cve-2023-26347 salts adobe auth-bypass coldfusion cve cve2023 vkev vuln cwe-284" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Adobe Coldfusion - Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-26347.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-26347.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> salts</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 23, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/284.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-284</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-26347" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-26347</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)coldfusion administrator login&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An unauthenticated attacker could leverage this vulnerability to access the administration CFM and CFC endpoints. Exploitation of this issue does not require user interaction.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can bypass access controls to access Adobe ColdFusion administration endpoints, potentially allowing full control over the ColdFusion server and access to sensitive application data.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to Adobe ColdFusion 2023.6 or 2021.12 or later versions that address this access control vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">adobe</span><span class="nt-tag">auth-bypass</span><span class="nt-tag">coldfusion</span><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-26347" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://helpx.adobe.com/security/products/coldfusion/apsb23-52.html" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="adobe coldfusion - cross-site scripting medium identify critical remote vulnerabilities adobe coldfusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by a reflected cross-site scripting (xss) vulnerability. if an unauthenticated attacker is able to convince a victim to visit a url referencing a vulnerable page, malicious javascript content may be executed within the context of the victim&#39;s browser cve-2023-44352 pwnwithlove adobe coldfusion cve cve2023 vkev vuln xss cwe-79" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Adobe Coldfusion - Cross-Site Scripting</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-44352.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-44352.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pwnwithlove</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 13, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-79</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-44352" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-44352</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)coldfusion administrator login&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an unauthenticated attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim&#39;s browser</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can inject malicious JavaScript through crafted URLs to execute code in victim browsers, potentially stealing ColdFusion administrator session cookies and gaining access to sensitive application configurations.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update Adobe ColdFusion to version 2023.6 or 2021.12 or later that properly escapes URLs in the CFIDE administrator and wizards interfaces.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">adobe</span><span class="nt-tag">coldfusion</span><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">xss</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://helpx.adobe.com/security/products/coldfusion/apsb23-52.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-44352" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="adobe coldfusion &lt;=8.0.1 - cross-site scripting medium identify critical remote vulnerabilities adobe coldfusion server 8.0.1 and earlier contain multiple cross-site scripting vulnerabilities which allow remote attackers to inject arbitrary web script or html via (1) the startrow parameter to administrator/logviewer/searchlog.cfm, or the query string to (2) wizards/common/_logintowizard.cfm, (3) wizards/common/_authenticatewizarduser.cfm, or (4) administrator/enter.cfm. cve-2009-1872 princechaddha,s4e-io adobe coldfusion cve cve2009 tenable vkev vuln xss cwe-79" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Adobe Coldfusion &lt;=8.0.1 - Cross-Site Scripting</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2009/CVE-2009-1872.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2009-1872.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> princechaddha,s4e-io</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-79</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2009-1872" target="_blank" rel="noopener" class="nt-cve-link">CVE-2009-1872</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;product&#34;] contains &#34;Adobe:ColdFusion&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Adobe ColdFusion Server 8.0.1 and earlier contain multiple cross-site scripting vulnerabilities which allow remote attackers to inject arbitrary web script or HTML via (1) the startRow parameter to administrator/logviewer/searchlog.cfm, or the query string to (2) wizards/common/_logintowizard.cfm, (3) wizards/common/_authenticatewizarduser.cfm, or (4) administrator/enter.cfm.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute arbitrary script code in the victim&#39;s browser, potentially leading to session hijacking, defacement, or theft of sensitive information.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade Adobe Coldfusion to a version higher than 8.0.1 or apply the necessary patches provided by the vendor.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">adobe</span><span class="nt-tag">coldfusion</span><span class="nt-tag">cve</span><span class="nt-tag">cve2009</span><span class="nt-tag">tenable</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">xss</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.tenable.com/cve/CVE-2009-1872" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="http://www.adobe.com/support/security/bulletins/apsb09-12.html" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="http://www.dsecrg.com/pages/vul/show.php?id=122" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2009-1872" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/ARPSyndicate/kenzer-templates" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="adobe connect &lt; 12.1.5 - local file disclosure medium identify critical remote vulnerabilities adobe connect versions 11.4.5 (and earlier), 12.1.5 (and earlier) are affected by an improper access control vulnerability that could result in a security feature bypass. an attacker could leverage this vulnerability to impact the integrity of a minor feature. exploitation of this issue does not require user interaction cve-2023-22232 0xr2r adobe cve cve2023 download lfd packetstorm vuln cwe-284,nvd-cwe-noinfo" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Adobe Connect &lt; 12.1.5 - Local File Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-22232.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-22232.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0xr2r</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 9, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/284,NVD-CWE-NOINFO.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-284,NVD-CWE-NOINFO</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-22232" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-22232</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Adobe Connect&#34;}) || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)openvpn connect&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Adobe Connect versions 11.4.5 (and earlier), 12.1.5 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to impact the integrity of a minor feature. Exploitation of this issue does not require user interaction</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can exploit improper access control to download arbitrary files through the system/download endpoint, potentially accessing sensitive Adobe Connect meeting recordings and configuration files.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update Adobe Connect to version 12.1.5 or later that implements proper access control checks for the system/download functionality.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">adobe</span><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">download</span><span class="nt-tag">lfd</span><span class="nt-tag">packetstorm</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://helpx.adobe.com/security/products/connect/apsb23-05.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-22232" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="http://packetstormsecurity.com/files/171390/Adobe-Connect-11.4.5-12.1.5-Local-File-Disclosure.html" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/ARPSyndicate/cvemon" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="adobe connect central login panel info identify web-based control panels an adobe connect central login panel was detected. dhiyaneshdk adobe panel connect-central discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Adobe Connect Central Login Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/adobe/adobe-connect-central-login.yaml" target="_blank" rel="noopener" class="nt-source-link">adobe-connect-central-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)openvpn connect&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An Adobe Connect Central login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">adobe</span><span class="nt-tag">panel</span><span class="nt-tag">connect-central</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.adobe.com/products/adobeconnect.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="adobe experience manager felix console - default login high identify default logins in web-based control panels adobe experience manager felix console contains a default admin login vulnerability. an attacker can obtain access to user accounts and access sensitive information, modify data, and/or execute unauthorized operations. remote code execution may also be possible via installation of osgi bundle. dhiyaneshdk adobe aem default-login misconfig vuln cwe-522" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Adobe Experience Manager Felix Console - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/aem/aem-felix-console.yaml" target="_blank" rel="noopener" class="nt-source-link">aem-felix-console.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/522.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-522</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;AEM Sign In&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Adobe Experience Manager Felix Console contains a default admin login vulnerability. An attacker can obtain access to user accounts and access sensitive information, modify data, and/or execute unauthorized operations. Remote code execution may also be possible via installation of OSGI bundle.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">adobe</span><span class="nt-tag">aem</span><span class="nt-tag">default-login</span><span class="nt-tag">misconfig</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/0ang3el/aem-hacker/blob/master/aem_hacker.py" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/0ang3el/aem-rce-bundle" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="adobe experience manager login panel info identify web-based control panels an adobe experience manager login panel was detected. dhiyaneshdk adobe aem discovery panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Adobe Experience Manager Login Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/adobe/adobe-experience-manager-login.yaml" target="_blank" rel="noopener" class="nt-source-link">adobe-experience-manager-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)aem sign in&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An Adobe Experience Manager login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">adobe</span><span class="nt-tag">aem</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://business.adobe.com/products/experience-manager/adobe-experience-manager.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="adobe experience manager sling user login - detect info identify web-based control panels adobe experience manager sling user login panel was detected. dhiyaneshdk adobe aem discovery panel sling cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Adobe Experience Manager Sling User Login - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/adobe/aem-sling-login.yaml" target="_blank" rel="noopener" class="nt-source-link">aem-sling-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)aem sign in&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Adobe Experience Manager Sling user login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">adobe</span><span class="nt-tag">aem</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">sling</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://raw.githubusercontent.com/danielmiessler/SecLists/master/Discovery/Web-Content/aem2.txt" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="adobe media server login panel info identify web-based control panels an adobe media server login panel was detected. dhiyaneshdk panel adobe discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Adobe Media Server Login Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/adobe/adobe-media-server.yaml" target="_blank" rel="noopener" class="nt-source-link">adobe-media-server.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Adobe Media Server&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An Adobe Media Server login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">adobe</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://helpx.adobe.com/support/adobe-media-server.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="ads pro plugin &lt;= 4.89 - local file inclusion critical identify critical remote vulnerabilities the ads pro plugin - multi-purpose wordpress advertising manager plugin for wordpress is vulnerable to local file inclusion in all versions up to, and including, 4.89 via the &#39;bsa_template&#39; parameter of the `bsa_preview_callback` function. this makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any php code in those files. this can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases .php files can can be uploaded and included, or already exist on the site. cve-2025-4380 iamnoooob,rootxharsh,pdresearch ads-pro cve cve2025 lfi scripteo vuln wordpress wp wp-plugin cwe-98" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Ads Pro Plugin &lt;= 4.89 - Local File Inclusion</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-4380.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-4380.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> iamnoooob,rootxharsh,pdresearch</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 9, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/98.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-98</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-4380" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-4380</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/ap-plugin-scripteo&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.89 via the &#39;bsa_template&#39; parameter of the `bsa_preview_callback` function. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases .php files can can be uploaded and included, or already exist on the site.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation could allow an attacker to execute arbitrary code on the affected system through deserialization of malicious JSON payloads.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update the Ads Pro Plugin to version later than 4.89. Alternatively, disable polymorphic type handling or implement proper input validation and deserialization controls.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">ads-pro</span><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">lfi</span><span class="nt-tag">scripteo</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wpscan.com/vulnerability/63964564-73e6-45e2-8145-33e2e30d1d57/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-4380" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="advanced email solution deepmail - panel info identify web-based control panels advanced email solution deepmail login panel was detected. splint3r7 panel deepmail login detect discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Advanced eMail Solution DEEPMail - Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/deepmail-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">deepmail-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Splint3r7</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 30, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Advanced eMail Solution DEEPMail&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Advanced eMail Solution DEEPMail login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">deepmail</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="advantech r-seenet - cross-site scripting medium identify critical remote vulnerabilities advantech r-seenet contains a cross-site scripting vulnerability in the device_graph_page.php script via the graph parameter. a specially crafted url by an attacker can lead to arbitrary javascript code execution. cve-2021-21801 gy741 advantech cve cve2021 graph rseenet vkev vuln xss cwe-79" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Advantech R-SeeNet - Cross-Site Scripting</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2021/CVE-2021-21801.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2021-21801.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> gy741</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-79</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2021-21801" target="_blank" rel="noopener" class="nt-cve-link">CVE-2021-21801</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)r-seenet&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Advantech R-SeeNet contains a cross-site scripting vulnerability in the device_graph_page.php script via the graph parameter. A specially crafted URL by an attacker can lead to arbitrary JavaScript code execution.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute arbitrary JavaScript code in the context of the victim&#39;s browser, leading to session hijacking, defacement, or theft of sensitive information.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches or updates provided by Advantech to fix the XSS vulnerability in the R-SeeNet application.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">advantech</span><span class="nt-tag">cve</span><span class="nt-tag">cve2021</span><span class="nt-tag">graph</span><span class="nt-tag">rseenet</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">xss</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://talosintelligence.com/vulnerability_reports/TALOS-2021-1272" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2021-21801" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/ARPSyndicate/cvemon" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/ARPSyndicate/kenzer-templates" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="advantech r-seenet 2.4.12 - os command injection critical identify critical remote vulnerabilities advantech r-seenet 2.4.12 is susceptible to remote os command execution via the ping.php script functionality. an attacker, via a specially crafted http request, can execute malware, obtain sensitive information, modify data, and/or gain full control over a compromised system without entering necessary credentials. cve-2021-21805 arafatansari advantech cve cve2021 r-seenet rce vkev vuln cwe-78" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Advantech R-SeeNet 2.4.12 - OS Command Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2021/CVE-2021-21805.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2021-21805.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> arafatansari</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/78.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-78</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2021-21805" target="_blank" rel="noopener" class="nt-cve-link">CVE-2021-21805</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)r-seenet&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Advantech R-SeeNet 2.4.12 is susceptible to remote OS command execution via the ping.php script functionality. An attacker, via a specially crafted HTTP request, can execute malware, obtain sensitive information, modify data, and/or gain full control over a compromised system without entering necessary credentials.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability allows remote attackers to execute arbitrary commands on the affected system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest version of Advantech R-SeeNet to mitigate this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">advantech</span><span class="nt-tag">cve</span><span class="nt-tag">cve2021</span><span class="nt-tag">r-seenet</span><span class="nt-tag">rce</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://talosintelligence.com/vulnerability_reports/TALOS-2021-1274" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-21805" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2021-21805" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/ARPSyndicate/cvemon" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/ARPSyndicate/kenzer-templates" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="advantech webaccess/scada - panel info identify web-based control panels detected advantech webaccess/scada login panel, a web-browser-based hmi/scada software used in critical manufacturing, energy, and water systems. 0x_akoko advantech discovery hmi ics panel scada webaccess" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Advantech WebAccess/SCADA - Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/advantech-webaccess-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">advantech-webaccess-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_Akoko</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 2, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Advantech WebAccess&#34;}) and service[&#34;favicon.ico.image.mmh3&#34;] == &#34;2047556588&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detected Advantech WebAccess/SCADA login panel, a web-browser-based HMI/SCADA software used in critical manufacturing, energy, and water systems.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">advantech</span><span class="nt-tag">discovery</span><span class="nt-tag">hmi</span><span class="nt-tag">ics</span><span class="nt-tag">panel</span><span class="nt-tag">scada</span><span class="nt-tag">webaccess</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.advantech.com/en-us/products/webaccess-scada/sub_a7b4308c-a3d0-446c-8f03-0d098d4b2c31" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.cisa.gov/news-events/ics-advisories/icsa-23-150-01" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="aerohive netconfig ui info identify web-based control panels an aerohive netconfig user interface was detected. the netconfig ui provides a fundamental set of configurations for configuring basic network and hivemanager connectivity settings, and uploading new iq engine images to extreme networks aps. pussycat0x aerohive discovery hiveos panel tech cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Aerohive NetConfig UI</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/aerohive-netconfig-ui.yaml" target="_blank" rel="noopener" class="nt-source-link">aerohive-netconfig-ui.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Aerohive NetConfig UI&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An Aerohive NetConfig user interface was detected. The NetConfig UI provides a fundamental set of configurations for configuring basic network and HiveManager connectivity settings, and uploading new IQ Engine images to Extreme Networks APs.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">aerohive</span><span class="nt-tag">discovery</span><span class="nt-tag">hiveos</span><span class="nt-tag">panel</span><span class="nt-tag">tech</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://docs.aerohive.com/330000/docs/help/english/ng/Content/reference/docs/online-help-systems.htm" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="aethra telecommunications login - panel info identify web-based control panels aethra telecommunication login panel was detected. splint3r7 panel aethra login detect discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Aethra Telecommunications Login - Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/aethra-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">aethra-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Splint3r7</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 30, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Aethra Telecommunications Operating System&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Aethra Telecommunication login Panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">aethra</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="agent-zero 0.8.0 - 0.9.4 - arbitrary file download high identify critical remote vulnerabilities agent-zero v0.8.0 - 0.9.4 contains a path traversal caused by improper validation in /api/download_work_dir_file.py, letting attackers access unauthorized files, exploit requires crafted request. cve-2025-55523 0x_akoko agent-zero cve cve2025 lfi traversal unauth vkev cwe-22" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Agent-Zero 0.8.0 - 0.9.4 - Arbitrary File Download</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-55523.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-55523.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_Akoko</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 19, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-55523" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-55523</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Agent Zero&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Agent-Zero v0.8.0 - 0.9.4 contains a path traversal caused by improper validation in /api/download_work_dir_file.py, letting attackers access unauthorized files, exploit requires crafted request.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can access unauthorized files, potentially exposing sensitive data or system information.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest version of Agent-Zero</div></div></div>
  <div class="nt-tags"><span class="nt-tag">agent-zero</span><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">lfi</span><span class="nt-tag">traversal</span><span class="nt-tag">unauth</span><span class="nt-tag">vkev</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-55523" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/agent0ai/agent-zero/issues/687" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="agentgpt panel - detect info identify web-based control panels agentgpt was detected. agentgpt was a browser-based autonomous ai agent platform that allows users to create, configure and deploy ai agents directly in the browser. rxerium agent agentgpt ai detect discovery panel" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">AgentGPT Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/agentgpt-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">agentgpt-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 14, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)AgentGPT&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">AgentGPT was detected. AgentGPT was a browser-based autonomous AI agent platform that allows users to create, configure and deploy AI agents directly in the browser.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">agent</span><span class="nt-tag">agentgpt</span><span class="nt-tag">ai</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/reworkd/AgentGPT" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://agentgpt.reworkd.ai/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="agentejo cockpit &lt; 0.11.2 - nosql injection critical identify critical remote vulnerabilities agentejo cockpit before 0.11.2 allows nosql injection via the controller/auth.php check function. the $eq operator matches documents where the value of a field equals the specified value. cve-2020-35846 dwisiswant0 agentejo cockpit cve cve2020 injection nosqli sqli vuln cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Agentejo Cockpit &lt; 0.11.2 - NoSQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2020/CVE-2020-35846.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2020-35846.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dwisiswant0</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2020-35846" target="_blank" rel="noopener" class="nt-cve-link">CVE-2020-35846</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;688609340&#34; || service[&#34;http.body&#34;] matches &#34;(?i)cockpit&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php check function. The $eq operator matches documents where the value of a field equals the specified value.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could lead to unauthorized access, data leakage, or data manipulation.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade Agentejo Cockpit to version 0.11.2 or later to mitigate the vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">agentejo</span><span class="nt-tag">cockpit</span><span class="nt-tag">cve</span><span class="nt-tag">cve2020</span><span class="nt-tag">injection</span><span class="nt-tag">nosqli</span><span class="nt-tag">sqli</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://swarm.ptsecurity.com/rce-cockpit-cms/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2020-35846" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://getcockpit.com/" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/agentejo/cockpit/commit/2a385af8d80ed60d40d386ed813c1039db00c466" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/agentejo/cockpit/commit/33e7199575631ba1f74cba6b16b10c820bec59af" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="agentejo cockpit &lt;0.11.2 - nosql injection critical identify critical remote vulnerabilities agentejo cockpit before 0.11.2 allows nosql injection via the controller/auth.php resetpassword function of the auth controller. cve-2020-35847 dwisiswant0 agentejo cockpit cve cve2020 injection nosqli sqli vuln cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Agentejo Cockpit &lt;0.11.2 - NoSQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2020/CVE-2020-35847.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2020-35847.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dwisiswant0</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2020-35847" target="_blank" rel="noopener" class="nt-cve-link">CVE-2020-35847</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;688609340&#34; || service[&#34;http.body&#34;] matches &#34;(?i)cockpit&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php resetpassword function of the Auth controller.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute arbitrary NoSQL queries, potentially leading to unauthorized access, data manipulation, or denial of service.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade Agentejo Cockpit to version 0.11.2 or later to mitigate this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">agentejo</span><span class="nt-tag">cockpit</span><span class="nt-tag">cve</span><span class="nt-tag">cve2020</span><span class="nt-tag">injection</span><span class="nt-tag">nosqli</span><span class="nt-tag">sqli</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://swarm.ptsecurity.com/rce-cockpit-cms/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2020-35847" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://getcockpit.com/" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/agentejo/cockpit/commit/2a385af8d80ed60d40d386ed813c1039db00c466" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/agentejo/cockpit/commit/33e7199575631ba1f74cba6b16b10c820bec59af" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="agentejo cockpit &lt;0.12.0 - nosql injection critical identify critical remote vulnerabilities agentejo cockpit prior to 0.12.0 is vulnerable to nosql injection via the newpassword method of the auth controller, which is responsible for displaying the user password reset form. cve-2020-35848 dwisiswant0 agentejo cockpit cve cve2020 injection nosqli sqli vuln cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Agentejo Cockpit &lt;0.12.0 - NoSQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2020/CVE-2020-35848.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2020-35848.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dwisiswant0</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2020-35848" target="_blank" rel="noopener" class="nt-cve-link">CVE-2020-35848</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;688609340&#34; || service[&#34;http.body&#34;] matches &#34;(?i)cockpit&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Agentejo Cockpit prior to 0.12.0 is vulnerable to NoSQL Injection via the newpassword method of the Auth controller, which is responsible for displaying the user password reset form.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to manipulate database queries, potentially leading to unauthorized access, data leakage, or data corruption.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade Agentejo Cockpit to version 0.12.0 or later to mitigate this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">agentejo</span><span class="nt-tag">cockpit</span><span class="nt-tag">cve</span><span class="nt-tag">cve2020</span><span class="nt-tag">injection</span><span class="nt-tag">nosqli</span><span class="nt-tag">sqli</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://swarm.ptsecurity.com/rce-cockpit-cms/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2020-35848" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://getcockpit.com/" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/agentejo/cockpit/commit/2a385af8d80ed60d40d386ed813c1039db00c466" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/agentejo/cockpit/commit/33e7199575631ba1f74cba6b16b10c820bec59af" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="airnotifier login panel - detect info identify web-based control panels airnotifier login panel was detected. tess panel airnotifier discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">AirNotifier Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/airnotifier-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">airnotifier-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> tess</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)AirNotifier&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">AirNotifier login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">airnotifier</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="airos panel - detect info identify web-based control panels airos panel was detected. rxerium airos panel discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">AirOS Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/airos-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">airos-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 13, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-697231354&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">AirOS panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">airos</span><span class="nt-tag">panel</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="airbyte panel - detect info identify web-based control panels airbyte panel was detected. airbyte is a popular open-source data integration platform. chrisjr404 airbyte detect login panel" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Airbyte Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/airbyte-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">airbyte-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ChrisJr404</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 6, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Airbyte&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Airbyte panel was detected. Airbyte is a popular open-source data integration platform.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">airbyte</span><span class="nt-tag">detect</span><span class="nt-tag">login</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/airbytehq/airbyte" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://airbyte.com/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://docs.airbyte.com/api-documentation" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="airflow experimental &lt;1.10.11 - rest api auth bypass critical identify critical remote vulnerabilities airflow&#39;s experimental api prior 1.10.11 allows all api requests without authentication. cve-2020-13927 pdteam airflow apache auth-bypass cve cve2020 kev packetstorm unauth vkev vuln cwe-1188" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Airflow Experimental &lt;1.10.11 - REST API Auth Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2020/CVE-2020-13927.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2020-13927.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pdteam</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/1188.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-1188</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2020-13927" target="_blank" rel="noopener" class="nt-cve-link">CVE-2020-13927</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)airflow - dags&#34;}) || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)airflow&#34;}) || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)airflow - dags\&#34; \\|\\| http\\.html:\&#34;apache airflow&#34;}) || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)sign in - airflow&#34;}) || service[&#34;http.body&#34;] matches &#34;(?i)apache airflow&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Airflow&#39;s Experimental API prior 1.10.11 allows all API requests without authentication.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Allows unauthorized access to Airflow Experimental REST API</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">From Airflow 1.10.11 forward, the default has been changed to deny all requests by default.  Note - this change fixes it for new installs but existing users need to change their config to default `[api]auth_backend = airflow.api.auth.backend.deny_all` as mentioned in the Updating Guide linked in the references.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">airflow</span><span class="nt-tag">apache</span><span class="nt-tag">auth-bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2020</span><span class="nt-tag">kev</span><span class="nt-tag">packetstorm</span><span class="nt-tag">unauth</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://lists.apache.org/thread.html/r23a81b247aa346ff193670be565b2b8ea4b17ddbc7a35fc099c1aadd%40%3Cdev.airflow.apache.org%3E" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="http://packetstormsecurity.com/files/162908/Apache-Airflow-1.10.10-Remote-Code-Execution.html" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://airflow.apache.org/docs/1.10.11/security.html#api-authenticatio" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2020-13927" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="http://packetstormsecurity.com/files/174764/Apache-Airflow-1.10.10-Remote-Code-Execution.html" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="akuiteo login panel - detect info identify web-based control panels akuiteo products was detected. righettod panel akuiteo login detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Akuiteo Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/akuiteo-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">akuiteo-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 13, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Akuiteo&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Akuiteo products was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">akuiteo</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.akuiteo.com/en/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="alamos gmbh panel - detect info identify web-based control panels alamos gmbh panel was detected. splint3r7 panel alamos login detect discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Alamos GmbH Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/alamos-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">alamos-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Splint3r7</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 16, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Alamos GmbH \\| FE2&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Alamos GmbH panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">alamos</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="alcatel-lucent omnipcx - remote command execution critical identify critical remote vulnerabilities the omnipcx web interface has a script &#34;mastercgi&#34; with a remote command execution vulnerability via the &#34;user&#34; parameter. cve-2007-3010 king-alexander alcatel alcatel-lucent cve cve2007 kev rce vkev vuln cwe-20" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Alcatel-Lucent OmniPCX - Remote Command Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2007/CVE-2007-3010.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2007-3010.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> king-alexander</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 13, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/20.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-20</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2007-3010" target="_blank" rel="noopener" class="nt-cve-link">CVE-2007-3010</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)omnipcx for enterprise&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The OmniPCX web interface has a script &#34;masterCGI&#34; with a remote command execution vulnerability via the &#34;user&#34; parameter.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Any user with access to the web interface could execute arbitrary commands with the permissions of the webservers.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to supported versions that filter shell metacharacters in the &#34;user&#34; parameter.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">alcatel</span><span class="nt-tag">alcatel-lucent</span><span class="nt-tag">cve</span><span class="nt-tag">cve2007</span><span class="nt-tag">kev</span><span class="nt-tag">rce</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2007-3010" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://marc.info/?l=full-disclosure&amp;m=119002152126755&amp;w=2" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="http://www.redteam-pentesting.de/advisories/rt-sa-2007-001.php" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="http://www.vupen.com/english/advisories/2007/3185" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="http://www1.alcatel-lucent.com/psirt/statements/2007002/OXEUMT.htm" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="alfresco - default admin credentials high identify default logins in web-based control panels detected alfresco content services was found to have been using the default administrator credentials (admin:admin). an attacker could have gained full administrative access to manage content, users, and repository configuration. 0x_akoko alfresco auth default-login vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Alfresco - Default Admin Credentials</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/alfresco-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">alfresco-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_Akoko</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 8, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;Alfresco&#34;}) &amp;&amp; service[&#34;http.body&#34;] contains &#34;/share/res/js/alfresco&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detected Alfresco Content Services was found to have been using the default administrator credentials (admin:admin). An attacker could have gained full administrative access to manage content, users, and repository configuration.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">alfresco</span><span class="nt-tag">auth</span><span class="nt-tag">default-login</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://docs.alfresco.com/content-services/community/admin/admin-console/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://docs.alfresco.com/community5.0/references/RESTful-RepositoryLoginPost.html" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="alfresco content app panel - detect info identify web-based control panels alfresco content app panel was detected. splint3r7 panel alfresco login detect discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Alfresco Content App Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/alfresco-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">alfresco-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Splint3r7</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 16, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Alfresco Content App&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Alfresco Content App panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">alfresco</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="alibaba druid monitor default login high identify default logins in web-based control panels alibaba druid monitor default login information (admin/admin) was discovered. pikpikcu,j4vaovo alibaba default-login druid vuln cwe-798" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Alibaba Druid Monitor Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/druid/druid-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">druid-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pikpikcu,j4vaovo</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/798.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-798</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)druid monitor&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Alibaba Druid Monitor default login information (admin/admin) was discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">alibaba</span><span class="nt-tag">default-login</span><span class="nt-tag">druid</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="alibaba nacos - default login high identify default logins in web-based control panels the default username and password for nacos are both nacos. sleepingbag945 alibaba default-login nacos vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Alibaba Nacos - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/nacos/nacos-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">nacos-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> SleepingBag945</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 22, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Nacos&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The default username and password for Nacos are both nacos.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">alibaba</span><span class="nt-tag">default-login</span><span class="nt-tag">nacos</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="alienvault usm login panel info identify web-based control panels an alienvault usm login panel was detected. dhiyaneshdk panel alienvault discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">AlienVault USM Login Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/alienvault-usm.yaml" target="_blank" rel="noopener" class="nt-source-link">alienvault-usm.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)AlienVault USM&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An AlienVault USM login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">alienvault</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="all-in-one wp migration &lt; 7.87 - unauthenticated information disclosure medium identify critical remote vulnerabilities the all-in-one wp migration and backup plugin for wordpress is vulnerable to unauthenticated information disclosure due to its error.log file being publicly accessible in versions before 7.87. flx all-in-one-wp-migration cve cve2024 disclosure vkev wordpress wp wp-plugin wpscan cwe-532" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">All-in-One WP Migration &lt; 7.87 - Unauthenticated Information Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-8852.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-8852.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> FLX</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 12, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/532.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-532</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/all-in-one-wp-migration&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to unauthenticated information disclosure due to its error.log file being publicly accessible in versions before 7.87.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An unauthenticated attacker can access the error.log file, which may contain sensitive information such as full server path disclosures, backup filenames, and other debugging details. This information could be used in further attacks.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update the All-in-One WP Migration and Backup plugin to version 7.87 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">all-in-one-wp-migration</span><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">disclosure</span><span class="nt-tag">vkev</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">wpscan</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wpscan.com/vulnerability/9f533098-8435-4ee1-a423-5142070ceefc/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://wordpress.org/plugins/all-in-one-wp-migration/#developers" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="allied telesis device gui login panel - detect info identify web-based control panels allied telesis device gui login panel was detected. prajiteshsingh allied allied_telesis discovery panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Allied Telesis Device GUI Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/allied-telesis-exposure.yaml" target="_blank" rel="noopener" class="nt-source-link">allied-telesis-exposure.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> prajiteshsingh</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)allied telesis device gui&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Allied Telesis Device GUI login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">allied</span><span class="nt-tag">allied_telesis</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.alliedtelesis.com/in/en" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="allnet - default login high identify default logins in web-based control panels allnet contains a default login vulnerability. default admin login password &#39;admin&#39; was found. ritikchaddha allnet default-login vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Allnet - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/allnet/allnet-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">allnet-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 11, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-121681558&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Allnet contains a default login vulnerability. Default admin login password &#39;admin&#39; was found.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">allnet</span><span class="nt-tag">default-login</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="ally – web accessibility &amp; usability &lt;= 4.0.3 - sql injection high identify critical remote vulnerabilities the ally – web accessibility &amp; usability plugin for wordpress is vulnerable to sql injection via the url path in all versions up to, and including, 4.0.3. this is due to insufficient escaping on the user-supplied url parameter in the `get_global_remediations()` method, where it is directly concatenated into an sql join clause without proper sanitization for sql context. while `esc_url_raw()` is applied for url safety, it does not prevent sql metacharacters (single quotes, parentheses) from being injected. this makes it possible for unauthenticated attackers to append additional sql queries into already existing queries that can be used to extract sensitive information from the database via time-based blind sql injection techniques. the remediation module must be active, which requires the plugin to be connected to an elementor account. cve-2026-2413 shivam kamboj cve cve2026 pojo-accessibility sqli unauth wordpress wp wp-plugin" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Ally – Web Accessibility &amp; Usability &lt;= 4.0.3 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2026/CVE-2026-2413.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2026-2413.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Shivam Kamboj</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 11, 2026</span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2026-2413" target="_blank" rel="noopener" class="nt-cve-link">CVE-2026-2413</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/pojo-accessibility/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The Ally – Web Accessibility &amp; Usability plugin for WordPress is vulnerable to SQL Injection via the URL path in all versions up to, and including, 4.0.3. This is due to insufficient escaping on the user-supplied URL parameter in the `get_global_remediations()` method, where it is directly concatenated into an SQL JOIN clause without proper sanitization for SQL context. While `esc_url_raw()` is applied for URL safety, it does not prevent SQL metacharacters (single quotes, parentheses) from being injected. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database via time-based blind SQL injection techniques. The Remediation module must be active, which requires the plugin to be connected to an Elementor account.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can extract sensitive database information via blind SQL injection, risking data disclosure.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to a version later than 4.0.3 or the latest available version.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2026</span><span class="nt-tag">pojo-accessibility</span><span class="nt-tag">sqli</span><span class="nt-tag">unauth</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/pojo-accessibility/ally-web-accessibility-usability-403-unauthenticated-sql-injection-via-url-path" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2413" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="alphaweb xe default login medium identify default logins in web-based control panels an alphaweb xe default login was discovered. lark lab alphaweb default-login vuln cwe-522" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">AlphaWeb XE Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/alphaweb/alphaweb-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">alphaweb-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Lark Lab</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/522.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-522</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] contains &#34;&gt;AlphaWeb XE&lt;&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An AlphaWeb XE default login was discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">AlphaWeb</span><span class="nt-tag">default-login</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wiki.zenitel.com/wiki/AlphaWeb" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="altenergy power control software - sql injection medium identify critical remote vulnerabilities a vulnerability classified as critical was found in altenergy power control software up to 20241108. this vulnerability affects the function get_status_zigbee of the file /index.php/display/status_zigbee. the manipulation of the argument date leads to sql injection. the attack can be initiated remotely. cve-2024-11305 s4e-io altenergy cve cve2024 iot sqli vkev vuln cwe-74" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Altenergy Power Control Software - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-11305.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-11305.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> s4e-io</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 6, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/74.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-74</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-11305" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-11305</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)altenergy power control software&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A vulnerability classified as critical was found in Altenergy Power Control Software up to 20241108. This vulnerability affects the function get_status_zigbee of the file /index.php/display/status_zigbee. The manipulation of the argument date leads to sql injection. The attack can be initiated remotely.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Authenticated attackers can execute SQL injection through the date parameter in the status_zigbee function to extract sensitive power system data including energy metrics and device configurations.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Validate and sanitize all user inputs before processing them in SQL queries. Use parameterized queries or prepared statements to prevent SQL injection attacks.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">altenergy</span><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">iot</span><span class="nt-tag">sqli</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://blog.csdn.net/ZeroDay001/article/details/143878599" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://cn-sec.com/archives/3447233.html" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-11305" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="alternc desktop panel - detect info identify web-based control panels alternc desktop panel was detected. splint3r7 panel alternc login detect discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">AlternC Desktop Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/alternc-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">alternc-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Splint3r7</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 16, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)AlternC Desktop&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">AlternC Desktop panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">alternc</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="amazon ec2 - server-side request forgery (ssrf) critical identify critical remote vulnerabilities ssrf vulnerability exists in amazon ec2, or amazon elastic compute cloud which is a web service provided by amazon web services (aws) that offers resizable compute capacity in the cloud. dhiyaneshdk amazon aws ec2 ssrf vuln cwe-441,cwe-918" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Amazon EC2 - Server-side request forgery (SSRF)</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/vulnerabilities/amazon/amazon-ec2-ssrf.yaml" target="_blank" rel="noopener" class="nt-source-link">amazon-ec2-ssrf.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/441,CWE-918.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-441,CWE-918</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.head.server&#34;] matches &#34;EC2ws&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">SSRF vulnerability exists in Amazon EC2, or Amazon Elastic Compute Cloud which is a web service provided by Amazon Web Services (AWS) that offers resizable compute capacity in the cloud.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">amazon</span><span class="nt-tag">aws</span><span class="nt-tag">ec2</span><span class="nt-tag">ssrf</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="ambassador api gateway diagnostics - exposure medium identify critical remote vulnerabilities detected ambassador api gateway diagnostics portal, revealing service mappings, api endpoints, routing configurations, and internal cluster information. 0x_akoko exposure ambassador api gateway misconfig" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Ambassador API Gateway Diagnostics - Exposure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposures/apis/ambassador-api-diagnostics-exposure.yaml" target="_blank" rel="noopener" class="nt-source-link">ambassador-api-diagnostics-exposure.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_Akoko</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 12, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Ambassador Diagnostic Overview&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detected Ambassador API Gateway diagnostics portal, revealing service mappings, API endpoints, routing configurations, and internal cluster information.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">exposure</span><span class="nt-tag">ambassador</span><span class="nt-tag">api</span><span class="nt-tag">gateway</span><span class="nt-tag">misconfig</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.getambassador.io/docs/edge-stack/latest/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.getambassador.io/docs/edge-stack/latest/topics/running/diagnostics/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="amcrest ip camera web management - data exposure critical identify critical remote vulnerabilities amcrest ipm-721s v2.420.ac00.16.r.20160909 devices allow an unauthenticated attacker to download the administrative credentials. cve-2017-8229 pussycat0x amcrest cve cve2017 iot packetstorm seclists vuln cwe-255" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Amcrest IP Camera Web Management - Data Exposure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2017/CVE-2017-8229.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2017-8229.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 10, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/255.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-255</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2017-8229" target="_blank" rel="noopener" class="nt-cve-link">CVE-2017-8229</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Amcrest&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Amcrest IPM-721S V2.420.AC00.16.R.20160909 devices allow an unauthenticated attacker to download the administrative credentials.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can gain unauthorized access to sensitive data.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest firmware update provided by the vendor to fix the vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">amcrest</span><span class="nt-tag">cve</span><span class="nt-tag">cve2017</span><span class="nt-tag">iot</span><span class="nt-tag">packetstorm</span><span class="nt-tag">seclists</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2017-8229" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="http://packetstormsecurity.com/files/153224/Amcrest-IPM-721S-Credential-Disclosure-Privilege-Escalation.html" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/ethanhunnt/IoT_vulnerabilities/blob/master/Amcrest_sec_issues.pdf" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://seclists.org/bugtraq/2019/Jun/8" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/d4n-sec/d4n-sec.github.io" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="amcrest login info identify web-based control panels an amcrest ldap user login was discovered. dhiyaneshdk amcrest camera discovery edb panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Amcrest Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/amcrest-login.yaml" target="_blank" rel="noopener" class="nt-source-link">amcrest-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)amcrest&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An Amcrest LDAP user login was discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">amcrest</span><span class="nt-tag">camera</span><span class="nt-tag">discovery</span><span class="nt-tag">edb</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.exploit-db.com/ghdb/7273" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="ampjuke - default login high identify default logins in web-based control panels ampjuke contains a default login vulnerability. default admin login password &#39;pass&#39; was found. ritikchaddha ampjuke default-login vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">AmpJuke - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/ampjuke-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">ampjuke-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 11, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-121681558&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">AmpJuke contains a default login vulnerability. Default admin login password &#39;pass&#39; was found.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">ampjuke</span><span class="nt-tag">default-login</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="ampache login panel - detect info identify web-based control panels ampache login panel was detected. ritikchaddha ampache discovery panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Ampache Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/ampache-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">ampache-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)for the love of music&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Ampache login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">ampache</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="anaqua login - panel info identify web-based control panels checks for the presence of anaqua login page ep1csage anaqua login panel discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Anaqua Login - Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/anaqua-login-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">anaqua-login-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Ep1cSage</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 17, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Anaqua User Sign On&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Checks for the presence of Anaqua login page</div></div></div>
  <div class="nt-tags"><span class="nt-tag">anaqua</span><span class="nt-tag">login</span><span class="nt-tag">panel</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="andover continuum bms - login panel info identify web-based control panels andover continuum building management system panel has been detected. rxerium andover bms continuum discovery ics panel" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Andover Continuum BMS - Login Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/andover-continuum-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">andover-continuum-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 27, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Andover Continuum&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Andover Continuum Building Management System panel has been detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">andover</span><span class="nt-tag">bms</span><span class="nt-tag">continuum</span><span class="nt-tag">discovery</span><span class="nt-tag">ics</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.carrier.com/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="ansible semaphore panel detect info identify web-based control panels an ansible semaphore login panel was detected. yuzhe-zhang-0 ansible cicd discovery oss panel semaphore cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Ansible Semaphore Panel Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/ansible-semaphore-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">ansible-semaphore-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Yuzhe-zhang-0</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Semaphore&lt;/title&gt;&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An Ansible Semaphore login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">ansible</span><span class="nt-tag">cicd</span><span class="nt-tag">discovery</span><span class="nt-tag">oss</span><span class="nt-tag">panel</span><span class="nt-tag">semaphore</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://ansible-semaphore.com/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/ansible-semaphore/semaphore" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="ansible tower - detect info identify web-based control panels ansible tower was detected. ansible tower is a commercial offering that helps teams manage complex multi-tier deployments by adding control, knowledge, and delegation to ansible-powered environments. pdteam,idealphase ansible discovery panel redhat cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Ansible Tower - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/ansible-tower-exposure.yaml" target="_blank" rel="noopener" class="nt-source-link">ansible-tower-exposure.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pdteam,idealphase</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)ansible tower&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Ansible Tower was detected. Ansible Tower is a commercial offering that helps teams manage complex multi-tier deployments by adding control, knowledge, and delegation to Ansible-powered environments.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">ansible</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">redhat</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://docs.ansible.com/ansible-tower/3.8.4/html/administration/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://docs.ansible.com/ansible-tower/latest/html/release-notes/index.html" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="anteeowms &lt; v4.7.34 - sql injection critical identify critical remote vulnerabilities a sql injection vulnerability in login portal in anteeowms before v4.7.34 allows unauthenticated attackers to execute arbitrary sql commands via the username parameter and disclosure of some data in the underlying db. cve-2024-44349 iamnoooob,rootxharsh,pdresearch anteeowms cve cve2024 sqli vuln cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">AnteeoWMS &lt; v4.7.34 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-44349.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-44349.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> iamnoooob,rootxharsh,pdresearch</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 9, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-44349" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-44349</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)ANTEEO&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A SQL injection vulnerability in login portal in AnteeoWMS before v4.7.34 allows unauthenticated attackers to execute arbitrary SQL commands via the username parameter and disclosure of some data in the underlying DB.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can execute arbitrary SQL commands via the username parameter, potentially extracting sensitive database information.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update AnteeoWMS to version 4.7.34 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">anteeowms</span><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">sqli</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://blog.cybergon.com/posts/cve-2024-44349/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="http://nvd.nist.gov/vuln/detail/CVE-2024-44349" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="anyscale ray - remote code execution critical identify critical remote vulnerabilities anyscale ray 2.6.3 and 2.8.0 contain a remote code execution vulnerability due to insecure job submission api, allowing attackers to execute arbitrary code remotely if they have network access to the ray dashboard api. cve-2023-48022 riteshs4hu anyscale cve cve2023 ray rce vkev vuln cwe-78" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Anyscale Ray - Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-48022.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-48022.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> riteshs4hu</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 22, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/78.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-78</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-48022" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-48022</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;463802404&#34; || service[&#34;http.body&#34;] matches &#34;(?i)ray dashboard&#34; || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)ray dashboard&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Anyscale Ray 2.6.3 and 2.8.0 contain a remote code execution vulnerability due to insecure job submission API, allowing attackers to execute arbitrary code remotely if they have network access to the Ray Dashboard API.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers with network access to the Ray Dashboard API can execute arbitrary code remotely as root, leading to complete system compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade Anyscale Ray to version 2.6.4 or later, or version 2.8.1 or later, and restrict network access to the Ray Dashboard API.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">anyscale</span><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">ray</span><span class="nt-tag">rce</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://bishopfox.com/blog/ray-versions-2-6-3-2-8-0" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://vulncheck.com/xdb/497d7fb3b118" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/jakabakos/ShadowRay-RCE-PoC-CVE-2023-48022" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://vulncheck.com/xdb/d3bafad9c9f6" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/0x656565/CVE-2023-48022" target="_blank" rel="noopener" class="nt-ref-link">[5]</a> <a href="https://nvd.nist.gov/vuln/detail/cve-2023-48022" target="_blank" rel="noopener" class="nt-ref-link">[6]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="anythingllm - information disclosure high identify critical remote vulnerabilities anythingllm suffers from an information disclosure vulnerability through the `/api/setup-complete` api endpoint. by accessing this endpoint, a remote and unauthenticated attacker can access sensitive configuration of the target anythingllm instance. this detection is included in the ai and llm category. cve-2024-6842 ingbunga,rahaaaiii,asteria121,breakpack,gy741 ai anything-llm cve cve2024 exposure mintplex-labs unauth vuln cwe-200" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">AnythingLLM - Information Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-6842.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-6842.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ingbunga,rahaaaiii,asteria121,breakpack,gy741</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 31, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-6842" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-6842</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)AnythingLLM&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">AnythingLLM suffers from an information disclosure vulnerability through the `/api/setup-complete` API endpoint. By accessing this endpoint, a remote and unauthenticated attacker can access sensitive configuration of the target AnythingLLM instance. This detection is included in the AI and LLM category.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can use the vulnerability to obtain device administrator rights.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update AnythingLLM to the latest version and implement proper authentication for the setup-complete API endpoint.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">ai</span><span class="nt-tag">anything-llm</span><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">exposure</span><span class="nt-tag">mintplex-Labs</span><span class="nt-tag">unauth</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://huntr.com/bounties/cd911fc7-ac6b-4974-acd0-9cc926fa8d9e" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-6842" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="anythingllm - information disclosure high identify critical remote vulnerabilities anythingllm is an application that turns pieces of content into context that any llm can use as references during chatting. if anythingllm prior to version 1.10.0 is configured to use qdrant as the vector database with an api key, this qdrantapikey could be exposed in plain text to unauthenticated users via the `/api/setup-complete` endpoint. leakage of qdrantapikey allows an unauthenticated attacker full read/write access to the qdrant vector database instance used by anythingllm. since qdrant often stores the core knowledge base for rag in anythingllm, this can lead to complete compromise of the semantic search / retrieval functionality and indirect leakage of confidential uploaded documents. version 1.10.0 patches the issue. cve-2026-24477 dhiyaneshdk anything-llm api cve cve2026 info-leak vkev cwe-201" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">AnythingLLM - Information Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2026/CVE-2026-24477.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2026-24477.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 17, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/201.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-201</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2026-24477" target="_blank" rel="noopener" class="nt-cve-link">CVE-2026-24477</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)AnythingLLM&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. If AnythingLLM prior to version 1.10.0 is configured to use Qdrant as the vector database with an API key, this QdrantApiKey could be exposed in plain text to unauthenticated users via the `/api/setup-complete` endpoint. Leakage of QdrantApiKey allows an unauthenticated attacker full read/write access to the Qdrant vector database instance used by AnythingLLM. Since Qdrant often stores the core knowledge base for RAG in AnythingLLM, this can lead to complete compromise of the semantic search / retrieval functionality and indirect leakage of confidential uploaded documents. Version 1.10.0 patches the issue.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can read and write to the Qdrant database, compromising semantic search and leaking confidential documents.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to version 1.10.0 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">anything-llm</span><span class="nt-tag">api</span><span class="nt-tag">cve</span><span class="nt-tag">cve2026</span><span class="nt-tag">info-leak</span><span class="nt-tag">vkev</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/Mintplex-Labs/anything-llm/security/advisories/GHSA-gm94-qc2p-xcwf" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24477" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="anythingllm panel - detect info identify web-based control panels detects the anythingllm web interface. rxerium ai anythingllm detect discovery llm panel" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">AnythingLLM Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/anythingllm-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">anythingllm-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 14, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)AnythingLLM \\| Your personal LLM trained on anything&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detects the AnythingLLM web interface.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">ai</span><span class="nt-tag">anythingllm</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">llm</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/Mintplex-Labs/anything-llm" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://anythingllm.com/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="apache 2.4.49 - path traversal and remote code execution high identify critical remote vulnerabilities a flaw was found in a change made to path normalization in apache http server 2.4.49. an attacker could use a path traversal attack to map urls to files outside the expected document root. if files outside of the document root are not protected by &#34;require all denied&#34; these requests can succeed. additionally, this flaw could leak the source of interpreted files like cgi scripts. this issue is known to be exploited in the wild. this issue only affects apache 2.4.49 and not earlier versions. cve-2021-41773 daffainfo,666asd apache cve cve2021 kev lfi misconfig rce traversal vkev vuln cwe-22" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Apache 2.4.49 - Path Traversal and Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2021/CVE-2021-41773.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2021-41773.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> daffainfo,666asd</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2021-41773" target="_blank" rel="noopener" class="nt-cve-link">CVE-2021-41773</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.head.server&#34;] matches `Apache/2\.4\.49`</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path traversal attack to map URLs to files outside the expected document root. If files outside of the document root are not protected by &#34;require all denied&#34; these requests can succeed. Additionally, this flaw could leak the source of interpreted files like CGI scripts. This issue is known to be exploited in the wild. This issue only affects Apache 2.4.49 and not earlier versions.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability can lead to unauthorized access, data leakage, and remote code execution.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade Apache to version 2.4.50 or apply the relevant patch provided by the vendor.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">apache</span><span class="nt-tag">cve</span><span class="nt-tag">cve2021</span><span class="nt-tag">kev</span><span class="nt-tag">lfi</span><span class="nt-tag">misconfig</span><span class="nt-tag">rce</span><span class="nt-tag">traversal</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/apache/httpd/commit/e150697086e70c552b2588f369f2d17815cb1782" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2021-41773" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-41773" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://twitter.com/ptswarm/status/1445376079548624899" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://twitter.com/h4x0r_dz/status/1445401960371429381" target="_blank" rel="noopener" class="nt-ref-link">[5]</a> <a href="https://github.com/blasty/CVE-2021-41773" target="_blank" rel="noopener" class="nt-ref-link">[6]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="apache 2.4.49/2.4.50 - path traversal and remote code execution critical identify critical remote vulnerabilities a flaw was found in a change made to path normalization in apache http server 2.4.49 and 2.4.50. an attacker could use a path traversal attack to map urls to files outside the expected document root. if files outside of the document root are not protected by &#34;require all denied&#34; these requests can succeed. additionally, this flaw could leak the source of interpreted files like cgi scripts. in certain configurations, for instance if mod_cgi is enabled, this flaw can lead to remote code execution. this issue only affects apache 2.4.49 and 2.4.50 and not earlier versions. note - cve-2021-42013 is due to an incomplete fix for the original vulnerability cve-2021-41773. cve-2021-42013 nvn1729,0xd0ff9,666asd apache cve cve2021 kev lfi misconfig rce traversal vkev vuln cwe-22" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Apache 2.4.49/2.4.50 - Path Traversal and Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2021/CVE-2021-42013.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2021-42013.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> nvn1729,0xd0ff9,666asd</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2021-42013" target="_blank" rel="noopener" class="nt-cve-link">CVE-2021-42013</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.head.server&#34;] matches `Apache/2\.4\.(49|59)`</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49 and 2.4.50. An attacker could use a path traversal attack to map URLs to files outside the expected document root. If files outside of the document root are not protected by &#34;require all denied&#34; these requests can succeed. Additionally, this flaw could leak the source of interpreted files like CGI scripts. In certain configurations, for instance if mod_cgi is enabled, this flaw can lead to remote code execution. This issue only affects Apache 2.4.49 and 2.4.50 and not earlier versions. Note - CVE-2021-42013 is due to an incomplete fix for the original vulnerability CVE-2021-41773.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code and gain unauthorized access to sensitive information.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to Apache HTTP Server 2.4.51 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">apache</span><span class="nt-tag">cve</span><span class="nt-tag">cve2021</span><span class="nt-tag">kev</span><span class="nt-tag">lfi</span><span class="nt-tag">misconfig</span><span class="nt-tag">rce</span><span class="nt-tag">traversal</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://httpd.apache.org/security/vulnerabilities_24.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/apache/httpd/commit/5c385f2b6c8352e2ca0665e66af022d6e936db6d" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2021-42013" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://twitter.com/itsecurityco/status/1446136957117943815" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="http://jvn.jp/en/jp/JVN51106450/index.html" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="apache apisix login panel - detect info identify web-based control panels an apache apisix login panel was detected. pikpikcu,righettod apache apisix detect discovery login panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Apache APISIX Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/apache/apache-apisix-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">apache-apisix-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pikpikcu,righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)apache apisix dashboard&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An Apache APISIX login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">apache</span><span class="nt-tag">apisix</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">login</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="apache activemq 6.x &lt; 6.1.2 - broken access control high identify critical remote vulnerabilities apache activemq 6.x contains an unauthenticated api web context caused by default configuration lacking security measures in the jetty server, letting anyone interact with broker apis and messaging layers, exploit requires no authentication. cve-2024-32114 chrisjr404 activemq apache cve cve2024 jolokia vkev cwe-1188" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Apache ActiveMQ 6.x &lt; 6.1.2 - Broken Access Control</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-32114.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-32114.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ChrisJr404</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 6, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/1188.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-1188</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-32114" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-32114</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)ActiveMQ&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Apache ActiveMQ 6.x contains an unauthenticated API web context caused by default configuration lacking security measures in the Jetty server, letting anyone interact with broker APIs and messaging layers, exploit requires no authentication.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated users can interact with the broker, potentially producing, consuming, or deleting messages and accessing sensitive management APIs.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to Apache ActiveMQ 6.1.2 or later, or update `conf/jetty.xml` to require authentication on the `/api/` web context.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">activemq</span><span class="nt-tag">apache</span><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">jolokia</span><span class="nt-tag">vkev</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://activemq.apache.org/security-advisories.data/CVE-2024-32114-announcement.txt" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/vulhub/vulhub/tree/master/activemq/CVE-2024-32114" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/advisories/GHSA-gj5m-m88j-v7c3" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-32114" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="apache activemq artemis console default login high identify default logins in web-based control panels detected apache activemq artemis console default login credentials were discovered. pdteam activemq apache artemis default-login vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Apache ActiveMQ Artemis Console Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/activemq/activemq-artemis-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">activemq-artemis-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pdteam</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 5, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# contains &#34;ActiveMQ Artemis Console&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detected Apache ActiveMQ Artemis console default login credentials were discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">activemq</span><span class="nt-tag">apache</span><span class="nt-tag">artemis</span><span class="nt-tag">default-login</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://activemq.apache.org/components/artemis/documentation/latest/management-console.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="apache activemq default login high identify default logins in web-based control panels apache activemq default login credentials were discovered. pdteam activemq apache default-login vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Apache ActiveMQ Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/activemq/activemq-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">activemq-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pdteam</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# contains &#34;Apache ActiveMQ&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Apache ActiveMQ default login credentials were discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">activemq</span><span class="nt-tag">apache</span><span class="nt-tag">default-login</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/apache/activemq-artemis/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="apache activemq exposure info identify web-based control panels an apache activemq implementation was discovered. pdteam,righettod panel activemq apache login discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Apache ActiveMQ Exposure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/activemq-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">activemq-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pdteam,righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Apache ActiveMQ&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An Apache ActiveMQ implementation was discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">activemq</span><span class="nt-tag">apache</span><span class="nt-tag">login</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://activemq.apache.org/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://activemq.apache.org/components/classic/documentation/rest" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="apache airflow &lt;1.10.14 - authentication bypass high identify critical remote vulnerabilities apache airflow prior to 1.10.14 contains an authentication bypass vulnerability via incorrect session validation with default configuration. an attacker on site a can access unauthorized airflow on site b through the site a session. cve-2020-17526 piyushchhiroliya airflow apache auth-bypass cve cve2020 vuln cwe-287" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Apache Airflow &lt;1.10.14 - Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2020/CVE-2020-17526.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2020-17526.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> piyushchhiroliya</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/287.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-287</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2020-17526" target="_blank" rel="noopener" class="nt-cve-link">CVE-2020-17526</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)airflow - dags\&#34; \\|\\| http\\.html:\&#34;apache airflow&#34;}) || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)sign in - airflow&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Apache Airflow prior to 1.10.14 contains an authentication bypass vulnerability via incorrect session validation with default configuration. An attacker on site A can access unauthorized Airflow on site B through the site A session.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability can lead to unauthorized access to sensitive information or unauthorized execution of arbitrary code.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Change default value for [webserver] secret_key config.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">airflow</span><span class="nt-tag">apache</span><span class="nt-tag">auth-bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2020</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://kloudle.com/academy/authentication-bypass-in-apache-airflow-cve-2020-17526-and-aws-cloud-platform-compromise" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://lists.apache.org/thread.html/rbeeb73a6c741f2f9200d83b9c2220610da314810c4e8c9cf881d47ef%40%3Cusers.airflow.apache.org%3E" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="http://www.openwall.com/lists/oss-security/2020/12/21/1" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2020-17526" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://lists.apache.org/thread.html/r466759f377651f0a690475d5a52564d0e786e82c08d5a5730a4f8352@%3Cannounce.apache.org%3E" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="apache airflow &lt;=1.10.10 - remote code execution high identify critical remote vulnerabilities apache airflow versions 1.10.10 and below are vulnerable to remote code/command injection vulnerabilities in one of the example dags shipped with airflow. this could allow any authenticated user to run arbitrary commands as the user running airflow worker/scheduler (depending on the executor in use). cve-2020-11978 pdteam airflow apache cve cve2020 kev packetstorm rce vkev vuln cwe-78" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Apache Airflow &lt;=1.10.10 - Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2020/CVE-2020-11978.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2020-11978.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pdteam</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/78.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-78</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2020-11978" target="_blank" rel="noopener" class="nt-cve-link">CVE-2020-11978</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)airflow - dags\&#34; \\|\\| http\\.html:\&#34;apache airflow&#34;}) || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)sign in - airflow&#34;}) || service[&#34;http.body&#34;] matches &#34;(?i)apache airflow&#34; || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)airflow - dags&#34;}) || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)airflow&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Apache Airflow versions 1.10.10 and below are vulnerable to remote code/command injection vulnerabilities in one of the example DAGs shipped with Airflow. This could allow any authenticated user to run arbitrary commands as the user running airflow worker/scheduler (depending on the executor in use).</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">If you already have examples disabled by setting load_examples=False in the config then you are not vulnerable.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">airflow</span><span class="nt-tag">apache</span><span class="nt-tag">cve</span><span class="nt-tag">cve2020</span><span class="nt-tag">kev</span><span class="nt-tag">packetstorm</span><span class="nt-tag">rce</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/pberba/CVE-2020-11978" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://twitter.com/wugeej/status/1400336603604668418" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://lists.apache.org/thread.html/r7255cf0be3566f23a768e2a04b40fb09e52fcd1872695428ba9afe91%40%3Cusers.airflow.apache.org%3E" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2020-11978" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="http://packetstormsecurity.com/files/174764/Apache-Airflow-1.10.10-Remote-Code-Execution.html" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="apache airflow admin login panel info identify web-based control panels an apache airflow admin login panel was discovered. pdteam admin airflow apache discovery panel cwe-668" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Apache Airflow Admin Login Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/airflow-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">airflow-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pdteam</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/668.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-668</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)sign in - airflow&#34;}) || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)airflow - dags&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An Apache Airflow admin login panel was discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">admin</span><span class="nt-tag">airflow</span><span class="nt-tag">apache</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://airflow.apache.org/docs/apache-airflow/stable/security/webserver.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="apache airflow default login high identify default logins in web-based control panels apache airflow default login credentials were discovered. pdteam airflow apache default-login vuln cwe-522" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Apache Airflow Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/apache/airflow-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">airflow-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pdteam</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/522.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-522</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;Sign In - Airflow&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Apache Airflow default login credentials were discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">airflow</span><span class="nt-tag">apache</span><span class="nt-tag">default-login</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://airflow.apache.org/docs/apache-airflow/stable/start/docker.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="apache airflow os command injection high identify critical remote vulnerabilities apache airflow prior to version 2.2.4 is vulnerable to os command injection attacks because some example dags do not properly sanitize user-provided parameters, making them susceptible to os command injection from the web ui. cve-2022-24288 xeldax airflow apache cve cve2022 rce vkev vuln cwe-78" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Apache Airflow OS Command Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-24288.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-24288.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> xeldax</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/78.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-78</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-24288" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-24288</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)apache airflow&#34; || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)airflow - dags&#34;}) || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)airflow&#34;}) || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)airflow - dags\&#34; \\|\\| http\\.html:\&#34;apache airflow&#34;}) || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)sign in - airflow&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Apache Airflow prior to version 2.2.4 is vulnerable to OS command injection attacks because some example DAGs do not properly sanitize user-provided parameters, making them susceptible to OS Command Injection from the web UI.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute arbitrary commands on the target system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches or upgrade to a patched version of Apache Airflow.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">airflow</span><span class="nt-tag">apache</span><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">rce</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/advisories/GHSA-3v7g-4pg3-7r6j" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-24288" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://lists.apache.org/thread/dbw5ozcmr0h0lhs0yjph7xdc64oht23t" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/ARPSyndicate/kenzer-templates" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/Hax0rG1rl/my_cve_and_bounty_poc" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="apache airflow v3 default login high identify default logins in web-based control panels apache airflow v3 default login credentials were discovered. pdteam airflow apache default-login vuln cwe-522" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Apache Airflow v3 Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/apache/airflow-v3-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">airflow-v3-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pdteam</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 6, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/522.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-522</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;Airflow&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Apache Airflow v3 default login credentials were discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">airflow</span><span class="nt-tag">apache</span><span class="nt-tag">default-login</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://airflow.apache.org/docs/apache-airflow/stable/start/docker.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="apache ambari default login high identify default logins in web-based control panels an apache ambari default admin login was discovered. pdteam ambari apache default-login vuln cwe-522" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Apache Ambari Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/ambari/ambari-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">ambari-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pdteam</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/522.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-522</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] contains `&gt;See third-party tools/resources that Ambari uses and their respective authors&lt;`</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An Apache Ambari default admin login was discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">ambari</span><span class="nt-tag">apache</span><span class="nt-tag">default-login</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://ambari.apache.org/1.2.0/installing-hadoop-using-ambari/content/ambari-chap3-1.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="apache apisix admin - default login high identify default logins in web-based control panels an apache apisix default admin login was discovered. pdteam apache apisix default-login vuln cwe-522" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Apache Apisix Admin - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/apache/apisix-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">apisix-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pdteam</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/522.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-522</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;Apache APISIX Dashboard&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An Apache Apisix default admin login was discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">apache</span><span class="nt-tag">apisix</span><span class="nt-tag">default-login</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://apisix.apache.org/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="apache apollo - default login high identify default logins in web-based control panels  ritikchaddha apache apollo default-login misconfig vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Apache Apollo - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/apache/apache-apollo-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">apache-apollo-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 1, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;Apache Apollo&#34;})</code></div>
  <div class="nt-tags"><span class="nt-tag">apache</span><span class="nt-tag">apollo</span><span class="nt-tag">default-login</span><span class="nt-tag">misconfig</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="apache apollo panel - detect info identify web-based control panels  ritikchaddha panel apache apollo login detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Apache Apollo Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/apache/apache-apollo-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">apache-apollo-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 1, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Apache Apollo&#34;})</code></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">apache</span><span class="nt-tag">apollo</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="apache axis2 default login critical identify critical remote vulnerabilities apache axis2, as used in dswsbobje.war in sap businessobjects enterprise xi 3.2, ca arcserve d2d r15, and other products, has a default password of axis2 for the admin account, which makes it easier for remote attackers to execute arbitrary code by uploading a crafted web service. cve-2010-0219 pikpikcu apache axis axis2 cve cve2010 default-login vkev vuln cwe-255" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Apache Axis2 Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2010/CVE-2010-0219.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2010-0219.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pikpikcu</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/255.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-255</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2010-0219" target="_blank" rel="noopener" class="nt-cve-link">CVE-2010-0219</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Apache Axis&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products, has a default password of axis2 for the admin account, which makes it easier for remote attackers to execute arbitrary code by uploading a crafted web service.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability can lead to unauthorized access to sensitive information or the ability to modify or delete data.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Disable or restrict access to the Axis2 web interface, or apply the necessary patches or updates provided by the vendor.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">apache</span><span class="nt-tag">axis</span><span class="nt-tag">axis2</span><span class="nt-tag">cve</span><span class="nt-tag">cve2010</span><span class="nt-tag">default-login</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2010-0219" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://knowledge.broadcom.com/external/article/13994/vulnerability-axis2-default-administrato.html" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="http://www.rapid7.com/security-center/advisories/R7-0037.jsp" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="http://www.vupen.com/english/advisories/2010/2673" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="http://retrogod.altervista.org/9sg_ca_d2d.html" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="apache cloudstack - default login high identify default logins in web-based control panels cloudstack instance discovered using weak default credentials, allows the attacker to gain admin privilege. dhiyaneshdk apache cloudstack default-login vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Apache CloudStack - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/apache/cloudstack-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">cloudstack-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 30, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;Apache CloudStack&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">CloudStack instance discovered using weak default credentials, allows the attacker to gain admin privilege.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">apache</span><span class="nt-tag">cloudstack</span><span class="nt-tag">default-login</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="apache cocoon 2.1.12 - xml injection high identify critical remote vulnerabilities apache cocoon 2.1.12 is susceptible to  xml injection. when using the streamgenerator, the code parses a user-provided xml. a specially crafted xml, including external system entities, can be used to access any file on the server system. cve-2020-11991 pikpikcu apache cocoon cve cve2020 vkev vuln xml xxe cwe-611" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Apache Cocoon 2.1.12 - XML Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2020/CVE-2020-11991.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2020-11991.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pikpikcu</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/611.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-611</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2020-11991" target="_blank" rel="noopener" class="nt-cve-link">CVE-2020-11991</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Apache Cocoon&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Apache Cocoon 2.1.12 is susceptible to  XML injection. When using the StreamGenerator, the code parses a user-provided XML. A specially crafted XML, including external system entities, can be used to access any file on the server system.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability can lead to unauthorized access, data leakage, and remote code execution.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to Apache Cocoon 2.1.13 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">apache</span><span class="nt-tag">cocoon</span><span class="nt-tag">cve</span><span class="nt-tag">cve2020</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">xml</span><span class="nt-tag">xxe</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://lists.apache.org/thread/6xg5j4knfczwdhggo3t95owqzol37k1b" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2020-11991" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://lists.apache.org/thread.html/r77add973ea521185e1a90aca00ba9dae7caa8d8b944d92421702bb54%40%3Cusers.cocoon.apache.org%3E" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/ARPSyndicate/cvemon" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/H4ckTh3W0r1d/Goby_POC" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="apache dolphinscheduler default login high identify default logins in web-based control panels apache dolphinscheduler default admin credentials were discovered. for3stco1d apache default-login dolphinscheduler oss vuln cwe-522" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Apache DolphinScheduler Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/apache/dolphinscheduler-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">dolphinscheduler-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> For3stCo1d</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/522.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-522</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;DolphinScheduler&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Apache DolphinScheduler default admin credentials were discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">apache</span><span class="nt-tag">default-login</span><span class="nt-tag">dolphinscheduler</span><span class="nt-tag">oss</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/apache/dolphinscheduler" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="apache doris - default login high identify default logins in web-based control panels tests if apache doris panel, it is an easy-to-use, high performance and unified analytics database, is using the default password on root/admin user accounts. icarot apache default-login doris vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Apache Doris - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/apache/doris-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">doris-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> icarot</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 21, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;24048806&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Tests if Apache Doris Panel, it is an easy-to-use, high performance and unified analytics database, is using the default password on root/admin user accounts.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">apache</span><span class="nt-tag">default-login</span><span class="nt-tag">doris</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="apache flink - local file inclusion high identify critical remote vulnerabilities apache flink 1.11.0 (and released in 1.11.1 and 1.11.2 as well) allows attackers to read any file on the local filesystem of the jobmanager through the rest interface of the jobmanager process (aka local file inclusion). cve-2020-17519 pdteam apache cve cve2020 flink kev lfi vkev vuln cwe-552" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Apache Flink - Local File Inclusion</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2020/CVE-2020-17519.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2020-17519.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pdteam</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/552.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-552</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2020-17519" target="_blank" rel="noopener" class="nt-cve-link">CVE-2020-17519</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches `^Apache Flink Web Dashboard`})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Apache Flink 1.11.0 (and released in 1.11.1 and 1.11.2 as well) allows attackers to read any file on the local filesystem of the JobManager through the REST interface of the JobManager process (aka local file inclusion).</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can read arbitrary files from the JobManager local filesystem, potentially exposing sensitive configuration files, credentials, and proprietary data.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches or upgrade to a patched version of Apache Flink to mitigate the vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">apache</span><span class="nt-tag">cve</span><span class="nt-tag">cve2020</span><span class="nt-tag">flink</span><span class="nt-tag">kev</span><span class="nt-tag">lfi</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/B1anda0/CVE-2020-17519" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://lists.apache.org/thread.html/r6843202556a6d0bce9607ebc02e303f68fc88e9038235598bde3b50d%40%3Cdev.flink.apache.org%3E" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://lists.apache.org/thread.html/r6843202556a6d0bce9607ebc02e303f68fc88e9038235598bde3b50d@%3Cdev.flink.apache.org%3E" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://lists.apache.org/thread.html/r6843202556a6d0bce9607ebc02e303f68fc88e9038235598bde3b50d@%3Cuser.flink.apache.org%3E" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2020-17519" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="apache http server - acl bypass high identify critical remote vulnerabilities encoding problem in mod_proxy in apache http server 2.4.59 and earlier allows request urls with incorrect encoding to be sent to backend services, potentially bypassing authentication via crafted requests. cve-2024-38473 pdteam acl-bypass apache cve cve2024 mod_proxy php-fpm vuln cwe-116" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Apache HTTP Server - ACL Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-38473.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-38473.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pdteam</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 30, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/116.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-116</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-38473" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-38473</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;Apache HTTP Server&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Encoding problem in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows request URLs with incorrect encoding to be sent to backend services, potentially bypassing authentication via crafted requests.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Authenticated attackers can bypass ACL restrictions by crafting requests with incorrect encoding, potentially accessing protected backend services or resources that should be restricted by authentication mechanisms.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to Apache HTTP Server version 2.4.60 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">acl-bypass</span><span class="nt-tag">apache</span><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">mod_proxy</span><span class="nt-tag">php-fpm</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://blog.orange.tw/2024/08/confusion-attacks-en.html#%E2%9A%94%EF%B8%8F-Primitive-1-2-ACL-Bypass" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.cvedetails.com/cve/CVE-2024-38473/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-38473" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://httpd.apache.org/security/vulnerabilities_24.html" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://security.netapp.com/advisory/ntap-20240712-0001/" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="apache hertzbeat - default credentials high identify default logins in web-based control panels apache hertzbeat enables default admin (and others) credentials. an attacker can execute unauthorized operations. securitytaters,icarot apache hertzbeat default-login vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Apache HertzBeat - Default Credentials</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/apache/apache-hertzbeat-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">apache-hertzbeat-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> securitytaters,icarot</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 2, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;HertzBeat&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Apache HertzBeat enables default admin (and others) credentials. An attacker can execute unauthorized operations.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">apache</span><span class="nt-tag">hertzbeat</span><span class="nt-tag">default-login</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/apache/hertzbeat" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="apache hugegraph-server &lt;1.5.0 - authentication bypass critical identify critical remote vulnerabilities apache hugegraph-server versions prior to 1.5.0 contain an authentication bypass vulnerability caused by assumed-immutable data. this flaw allows attackers to bypass authentication mechanisms without requiring specific privileges or user interaction. cve-2024-43441 wn147 apache auth-bypass cve cve2024 hugegraph vuln cwe-302" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Apache HugeGraph-Server &lt;1.5.0 - Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-43441.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-43441.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> wn147</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 25, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/302.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-302</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-43441" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-43441</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;product&#34;] contains &#34;Apache:HugeGraph&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Apache HugeGraph-Server versions prior to 1.5.0 contain an authentication bypass vulnerability caused by assumed-immutable data. This flaw allows attackers to bypass authentication mechanisms without requiring specific privileges or user interaction.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can bypass authentication, gaining unauthorized access to sensitive data or functionalities.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to Apache HugeGraph-Server version 1.5.0 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">apache</span><span class="nt-tag">auth-bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">hugegraph</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/advisories/GHSA-f697-gm3h-xrf9" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/apache/incubator-hugegraph/commit/03b40a52446218c83e98cb43020e0593a744a246" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://lists.apache.org/thread/h2607yv32wgcrywov960jpxhvsmmlf12" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="http://www.openwall.com/lists/oss-security/2024/12/24/2" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/J1ezds/Vulnerability-Wiki-page" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="apache jmeter dashboard login panel - detect info identify web-based control panels apache jmeter dashboard login panel was detected. tess apache discovery jmeter panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Apache JMeter Dashboard Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/apache-jmeter-dashboard.yaml" target="_blank" rel="noopener" class="nt-source-link">apache-jmeter-dashboard.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> tess</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)apache jmeter dashboard&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Apache JMeter Dashboard login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">apache</span><span class="nt-tag">discovery</span><span class="nt-tag">jmeter</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="apache kafka center default login high identify default logins in web-based control panels apache kafka center default admin credentials were discovered. dhiyaneshdk default-login kafka vuln cwe-522" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Apache Kafka Center Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/apache/kafka-center-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">kafka-center-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/522.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-522</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;Kafka Center&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Apache Kafka Center default admin credentials were discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">kafka</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://developer.ibm.com/tutorials/kafka-authn-authz/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="apache kafka consumer offset monitor panel - detect info identify web-based control panels apache kafka consumer offset monitor panel was detected. dhiyaneshdk apache discovery kafka panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Apache Kafka Consumer Offset Monitor Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/kafka-consumer-monitor.yaml" target="_blank" rel="noopener" class="nt-source-link">kafka-consumer-monitor.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)kafka consumer offset monitor&#34;}) || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)kafka center&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Apache Kafka Consumer Offset Monitor panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">apache</span><span class="nt-tag">discovery</span><span class="nt-tag">kafka</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="apache kafka control center login panel - detect info identify web-based control panels apache kafka control center login panel was detected. dhiyaneshdk apache discovery kafka panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Apache Kafka Control Center Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/kafka-center-login.yaml" target="_blank" rel="noopener" class="nt-source-link">kafka-center-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)kafka center&#34;}) || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)kafka consumer offset monitor&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Apache Kafka Control Center login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">apache</span><span class="nt-tag">discovery</span><span class="nt-tag">kafka</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="apache kafka monitor login panel - detect info identify web-based control panels apache kafka monitor login panel was detected. pdteam apache discovery kafka panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Apache Kafka Monitor Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/kafka-monitoring.yaml" target="_blank" rel="noopener" class="nt-source-link">kafka-monitoring.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pdteam</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)kafka center&#34;}) || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)kafka consumer offset monitor&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Apache Kafka Monitor login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">apache</span><span class="nt-tag">discovery</span><span class="nt-tag">kafka</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="apache karaf - default login high identify default logins in web-based control panels apache karaf contains a default login vulnerability. default login credentials were detected. an attacker can obtain access to user accounts and access sensitive information, modify data, and/or execute unauthorized operations. s0obi apache default-login karaf vuln cwe-522" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Apache Karaf - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/apache/karaf-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">karaf-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> s0obi</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/522.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-522</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;http.head.wwwAuthentications&#34;]), {# contains &#39;realm=&#34;karaf&#39;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Apache Karaf contains a default login vulnerability. Default login credentials were detected. An attacker can obtain access to user accounts and access sensitive information, modify data, and/or execute unauthorized operations.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">apache</span><span class="nt-tag">default-login</span><span class="nt-tag">karaf</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://karaf.apache.org/manual/latest/webconsole" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="apache mesos - panel detect info identify web-based control panels apache mesos panel was detected. pikpikcu apache discovery mesos panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Apache Mesos - Panel Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/apache/apache-mesos-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">apache-mesos-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pikpikcu</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)mesos&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Apache Mesos panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">apache</span><span class="nt-tag">discovery</span><span class="nt-tag">mesos</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="apache nifi - information disclosure medium identify critical remote vulnerabilities apache nifi 1.10.0 through 2.0.0 are missing fine-grained authorization checking for parameter contexts, referenced controller services, and referenced parameter providers, when creating new process groups. creating a new process group can include binding to a parameter context, but in cases where the process group did not reference any parameter values, the framework did not check user authorization for the bound parameter context. missing authorization for a bound parameter context enabled clients to download non-sensitive parameter values after creating the process group. cve-2024-56512 dhiyaneshdk cve cve2024 exposure nifi vuln" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Apache NiFi - Information Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-56512.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-56512.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 7, 2025</span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-56512" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-56512</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Nifi&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Apache NiFi 1.10.0 through 2.0.0 are missing fine-grained authorization checking for Parameter Contexts, referenced Controller Services, and referenced Parameter Providers, when creating new Process Groups. Creating a new Process Group can include binding to a Parameter Context, but in cases where the Process Group did not reference any Parameter values, the framework did not check user authorization for the bound Parameter Context. Missing authorization for a bound Parameter Context enabled clients to download non-sensitive Parameter values after creating the Process Group.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can create Process Groups bound to Parameter Contexts without proper authorization checks, enabling them to download non-sensitive parameter values and potentially access sensitive configuration data.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update Apache NiFi to version 2.1.0 or later to address the missing authorization checks for Parameter Contexts.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">exposure</span><span class="nt-tag">nifi</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://lists.apache.org/thread/cjc8fns5kjsho0s7vonlnojokyfx47wn" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="http://www.openwall.com/lists/oss-security/2024/12/28/1" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/absholi7ly/CVE-2024-56512-Apache-NiFi-Exploit/" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-56512" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="apache nifi - remote code execution critical identify critical remote vulnerabilities apache nifi is designed for data streaming. it supports highly configurable data routing, transformation, and system mediation logic that indicate graphs. the system has unauthorized remote command execution vulnerability. arliya apache nifi packetstorm rce vuln" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Apache NiFi - Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/vulnerabilities/apache/apache-nifi-rce.yaml" target="_blank" rel="noopener" class="nt-source-link">apache-nifi-rce.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> arliya</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 22, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)NiFi&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Apache NiFi is designed for data streaming. It supports highly configurable data routing, transformation, and system mediation logic that indicate graphs. The system has unauthorized remote command execution vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">apache</span><span class="nt-tag">nifi</span><span class="nt-tag">packetstorm</span><span class="nt-tag">rce</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/imjdl/Apache-NiFi-Api-RCE" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://labs.withsecure.com/tools/metasploit-modules-for-rce-in-apache-nifi-and-kong-api-gateway" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://packetstormsecurity.com/files/160260/apache_nifi_processor_rce.rb.txt" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="apache ofbiz - directory traversal &amp; remote code execution critical identify critical remote vulnerabilities improper limitation of a pathname to a restricted directory (&#39;path traversal&#39;) vulnerability in apache ofbiz. this issue affects apache ofbiz: before 18.12.14. users are recommended to upgrade to version 18.12.14, which fixes the issue. cve-2024-36104 co5mos apache cve cve2024 lfi ofbiz vkev vuln cwe-22" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Apache OFBiz - Directory Traversal &amp; Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-36104.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-36104.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Co5mos</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 5, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-36104" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-36104</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)ofbiz&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Improper Limitation of a Pathname to a Restricted Directory (&#39;Path Traversal&#39;) vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.14. Users are recommended to upgrade to version 18.12.14, which fixes the issue.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can exploit this directory traversal vulnerability to execute arbitrary code remotely, potentially compromising the entire system and accessing sensitive data.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches and updates from the vendor to address this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">apache</span><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">lfi</span><span class="nt-tag">ofbiz</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="http://www.openwall.com/lists/oss-security/2024/06/03/1" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://issues.apache.org/jira/browse/OFBIZ-13092" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://lists.apache.org/thread/sv0xr8b1j7mmh5p37yldy9vmnzbodz2o" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://ofbiz.apache.org/download.html" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://ofbiz.apache.org/security.html" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="apache ofbiz - improper authorization &amp; remote code execution critical identify critical remote vulnerabilities improper authorization vulnerability in apache ofbiz. this issue affects apache ofbiz: through 18.12.14. users are recommended to upgrade to version 18.12.15, which fixes the issue. unauthenticated endpoints could allow execution of screen rendering code of screens if some preconditions are met (such as when the screen definitions don&#39;t explicitly check user&#39;s permissions because they rely on the configuration of their endpoints). co5mos apache cve cve2024 kev ofbiz rce vkev vuln cwe-22" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Apache OFBiz - Improper Authorization &amp; Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-38856.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-38856.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Co5mos</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 5, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)OFBiz&#34;}) || service[&#34;http.head.setCookie&#34;] matches &#34;^OFBiz.Visitor&#34; || service[&#34;last.http.head.setCookie&#34;] matches &#34;^OFBiz.Visitor&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Improper Authorization vulnerability in Apache OFBiz. This issue affects Apache OFBiz: through 18.12.14. Users are recommended to upgrade to version 18.12.15, which fixes the issue. Unauthenticated endpoints could allow execution of screen rendering code of screens if some preconditions are met (such as when the screen definitions don&#39;t explicitly check user&#39;s permissions because they rely on the configuration of their endpoints).</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can exploit this directory traversal vulnerability to execute arbitrary code remotely, potentially compromising the entire system and accessing sensitive data.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches and updates from the vendor to address this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">apache</span><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">kev</span><span class="nt-tag">ofbiz</span><span class="nt-tag">rce</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://unam4.github.io/2024/08/05/CVE-2024-38856-ofbiz-12-14-filter%E7%BB%95%E8%BF%87%E5%88%B0rce/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://issues.apache.org/jira/browse/OFBIZ-13128" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://lists.apache.org/thread/olxxjk6b13sl3wh9cmp0k2dscvp24l7w" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://ofbiz.apache.org/download.html" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://ofbiz.apache.org/security.html" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="apache ofbiz - xml external entity injection high identify critical remote vulnerabilities the /webtools/control/xmlrpc endpoint in ofbiz xml-rpc event handler is exposed to external entity injection by passing doctype declarations with executable payloads that discloses the contents of files in the filesystem. in addition, it can also be used to probe for open network ports, and figure out from returned error messages whether a file exists or not. this affects ofbiz 16.11.01 to 16.11.04. cve-2011-3600 daffainfo,pikpikcu apache cve cve2011 ofbiz vkev vuln xxe cwe-611" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Apache OFBiz - XML External Entity Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2011/CVE-2011-3600.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2011-3600.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> daffainfo,pikpikcu</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 6, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/611.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-611</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2011-3600" target="_blank" rel="noopener" class="nt-cve-link">CVE-2011-3600</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)ofbiz&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The /webtools/control/xmlrpc endpoint in OFBiz XML-RPC event handler is exposed to External Entity Injection by passing DOCTYPE declarations with executable payloads that discloses the contents of files in the filesystem. In addition, it can also be used to probe for open network ports, and figure out from returned error messages whether a file exists or not. This affects OFBiz 16.11.01 to 16.11.04.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can disclose sensitive filesystem data, probe network ports, and determine file existence, leading to information disclosure and potential further exploitation.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest OFBiz version or apply security patches addressing XML external entity vulnerabilities.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">apache</span><span class="nt-tag">cve</span><span class="nt-tag">cve2011</span><span class="nt-tag">ofbiz</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">xxe</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://lists.apache.org/thread/cwz2v0b6pnxvqrnsd0hj3l80g9qq5kd8" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2011-3600" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="apache ofbiz 17.12.03 - cross-site scripting medium identify critical remote vulnerabilities apache ofbiz 17.12.03 contains cross-site scripting and unsafe deserialization vulnerabilities via an xml-rpc request. cve-2020-9496 dwisiswant0 apache cve cve2020 java ofbiz packetstorm vkev vuln cwe-502" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Apache OFBiz 17.12.03 - Cross-Site Scripting</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2020/CVE-2020-9496.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2020-9496.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dwisiswant0</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/502.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-502</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2020-9496" target="_blank" rel="noopener" class="nt-cve-link">CVE-2020-9496</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)ofbiz&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Apache OFBiz 17.12.03 contains cross-site scripting and unsafe deserialization vulnerabilities via an XML-RPC request.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute arbitrary script code in the context of the victim&#39;s browser, potentially leading to session hijacking, defacement, or theft of sensitive information.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches or upgrade to a non-vulnerable version of Apache OFBiz.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">apache</span><span class="nt-tag">cve</span><span class="nt-tag">cve2020</span><span class="nt-tag">java</span><span class="nt-tag">ofbiz</span><span class="nt-tag">packetstorm</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="http://packetstormsecurity.com/files/158887/Apache-OFBiz-XML-RPC-Java-Deserialization.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="http://packetstormsecurity.com/files/161769/Apache-OFBiz-XML-RPC-Java-Deserialization.html" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://securitylab.github.com/advisories/GHSL-2020-069-apache_ofbiz" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://s.apache.org/l0994" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2020-9496" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="apache ofbiz &lt; 18.12.07 - local file inclusion high identify critical remote vulnerabilities arbitrary file reading vulnerability in apache software foundation apache ofbiz when using the solr plugin. this is a  pre-authentication attack. this issue affects apache ofbiz: before 18.12.07. cve-2022-47501 your3cho apache cve cve2022 lfi ofbiz vkev vuln cwe-22" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Apache OFBiz &lt; 18.12.07 - Local File Inclusion</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-47501.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-47501.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> your3cho</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 12, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-47501" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-47501</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)OFBiz&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Arbitrary file reading vulnerability in Apache Software Foundation Apache OFBiz when using the Solr plugin. This is a  pre-authentication attack. This issue affects Apache OFBiz: before 18.12.07.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can read arbitrary files from the server filesystem through the Solr plugin debug endpoint in Apache OFBiz, potentially accessing configuration files, credentials, and other sensitive system information.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to Apache OFBiz version 18.12.07 or later to mitigate this local file inclusion vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">apache</span><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">lfi</span><span class="nt-tag">ofbiz</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://lists.apache.org/thread/k8s76l0whydy45bfm4b69vq0mf94p3wc" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="http://www.openwall.com/lists/oss-security/2023/04/18/5" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-47501" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="http://www.openwall.com/lists/oss-security/2023/04/18/9" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="http://www.openwall.com/lists/oss-security/2023/04/19/1" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="apache ofbiz &lt;=16.11.07 - cross-site scripting medium identify critical remote vulnerabilities apache ofbiz 16.11.01 to 16.11.07 is vulnerable to cross-site scripting because data sent with contentid to /control/stream is not sanitized. cve-2020-1943 pdteam apache cve cve2020 ofbiz vkev vuln xss cwe-79" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Apache OFBiz &lt;=16.11.07 - Cross-Site Scripting</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2020/CVE-2020-1943.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2020-1943.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pdteam</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-79</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2020-1943" target="_blank" rel="noopener" class="nt-cve-link">CVE-2020-1943</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)ofbiz&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Apache OFBiz 16.11.01 to 16.11.07 is vulnerable to cross-site scripting because data sent with contentId to /control/stream is not sanitized.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute malicious scripts in the context of the victim&#39;s browser, potentially leading to session hijacking, defacement, or theft of sensitive information.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade Apache OFBiz to a version higher than 16.11.07 to mitigate this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">apache</span><span class="nt-tag">cve</span><span class="nt-tag">cve2020</span><span class="nt-tag">ofbiz</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">xss</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://lists.apache.org/thread.html/rf867d9a25fa656b279b16e27b8ff6fcda689cfa4275a26655c685702%40%3Cdev.ofbiz.apache.org%3E" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://s.apache.org/pr5u8" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://lists.apache.org/thread.html/r034123f2767830169fd04c922afb22d2389de6e2faf3a083207202bc@%3Ccommits.ofbiz.apache.org%3E" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://lists.apache.org/thread.html/r8efd5b62604d849ae2f93b2eb9ce0ce0356a4cf5812deed14030a757@%3Cdev.ofbiz.apache.org%3E" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2020-1943" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="apache ofbiz directory traversal - remote code execution high identify critical remote vulnerabilities improper limitation of a pathname to a restricted directory (&#39;path traversal&#39;) vulnerability in apache ofbiz. this issue affects apache ofbiz: before 18.12.13 cve-2024-32113 dhiyaneshdk apache cve cve2024 kev ofbiz rce vkev vuln cwe-22" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Apache OFBiz Directory Traversal - Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-32113.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-32113.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 14, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-32113" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-32113</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)OFBiz&#34;}) || service[&#34;http.head.setCookie&#34;] matches &#34;^OFBiz.Visitor&#34; || service[&#34;last.http.head.setCookie&#34;] matches &#34;^OFBiz.Visitor&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Improper Limitation of a Pathname to a Restricted Directory (&#39;Path Traversal&#39;) vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.13</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can exploit this directory traversal vulnerability to execute arbitrary code remotely, potentially compromising the entire system and accessing sensitive data.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Users are recommended to upgrade to version 18.12.13, which fixes the issue.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">apache</span><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">kev</span><span class="nt-tag">ofbiz</span><span class="nt-tag">rce</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://issues.apache.org/jira/browse/OFBIZ-13006" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://lists.apache.org/thread/w6s60okgkxp2th1sr8vx0ndmgk68fqrd" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://ofbiz.apache.org/download.html" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://ofbiz.apache.org/security.html" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/absholi7ly/Apache-OFBiz-Directory-Traversal-exploit" target="_blank" rel="noopener" class="nt-ref-link">[5]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-32113" target="_blank" rel="noopener" class="nt-ref-link">[6]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="apache ofbiz default login high identify default logins in web-based control panels apache ofbiz default admin credentials were discovered. pdteam apache default-login ofbiz vuln cwe-522" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Apache OfBiz Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/ofbiz/ofbiz-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">ofbiz-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pdteam</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/522.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-522</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.head.setCookie&#34;] matches &#34;^OFBiz.Visitor=&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Apache OfBiz default admin credentials were discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">apache</span><span class="nt-tag">default-login</span><span class="nt-tag">ofbiz</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://cwiki.apache.org/confluence/display/OFBIZ/Apache+OFBiz+Technical+Production+Setup+Guide" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="apache pinot &lt; 1.3.0 - authentication bypass critical identify critical remote vulnerabilities this vulnerability allows remote attackers to bypass authentication on affected installations of apache pinot. authentication is not required to exploit this vulnerability.the specific flaw exists within the authenticationfilter class. the issue results from insufficient neutralization of special characters in a uri. an attacker can leverage this vulnerability to bypass authentication on the system. cve-2024-56325 iamnoooob,rootxharsh,pdresearch apache auth-bypass cve cve2024 pinot vuln cwe-288" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Apache Pinot &lt; 1.3.0 - Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-56325.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-56325.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> iamnoooob,rootxharsh,pdresearch</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 3, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/288.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-288</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-56325" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-56325</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1696974531&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">This vulnerability allows remote attackers to bypass authentication on affected installations of Apache Pinot. Authentication is not required to exploit this vulnerability.The specific flaw exists within the AuthenticationFilter class. The issue results from insufficient neutralization of special characters in a URI. An attacker can leverage this vulnerability to bypass authentication on the system.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can bypass authentication by injecting special characters in URIs, gaining unauthorized access to Apache Pinot administrative functions.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update Apache Pinot to version 1.3.0 or later to address the authentication bypass vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">apache</span><span class="nt-tag">auth-bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">pinot</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.zerodayinitiative.com/advisories/ZDI-25-109/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/advisories/GHSA-6jwp-4wvj-6597" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://lists.apache.org/thread/ksf8qsndr1h66otkbjz2wrzsbw992r8v" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="http://www.openwall.com/lists/oss-security/2025/03/27/8" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="apache polaris - default login high identify default logins in web-based control panels the apache polaris server is configured with default administrative credentials, allowing an attacker to perform unauthorized operations. this template verifies the use of the default username root and password s3cr3t. icarot apache polaris default-login vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Apache Polaris - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/apache/apache-polaris-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">apache-polaris-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> icarot</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 17, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Apache Polaris&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The Apache Polaris server is configured with default administrative credentials, allowing an attacker to perform unauthorized operations. This template verifies the use of the default username root and password s3cr3t.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">apache</span><span class="nt-tag">polaris</span><span class="nt-tag">default-login</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/apache/polaris" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="apache polaris - information disclosure medium identify critical remote vulnerabilities detects a apache polaris server, the interoperable, open source catalog for apache iceberg. icarot apache polaris exposure metrics misconfig" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Apache Polaris - Information Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposures/configs/apache-polaris-metrics-exposure.yaml" target="_blank" rel="noopener" class="nt-source-link">apache-polaris-metrics-exposure.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> icarot</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 17, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)org\\.apache\\.polaris&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detects a Apache Polaris server, the interoperable, open source catalog for Apache Iceberg.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">apache</span><span class="nt-tag">polaris</span><span class="nt-tag">exposure</span><span class="nt-tag">metrics</span><span class="nt-tag">misconfig</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/apache/polaris" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="apache ranger - default login high identify default logins in web-based control panels apache ranger contains a default login vulnerability. an attacker can obtain access to user accounts and access sensitive information, modify data, and/or execute unauthorized operations. for3stco1d apache default-login ranger vuln cwe-522" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Apache Ranger - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/apache/ranger-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">ranger-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> For3stCo1d</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/522.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-522</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;Ranger - Sign In&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Apache Ranger contains a default login vulnerability. An attacker can obtain access to user accounts and access sensitive information, modify data, and/or execute unauthorized operations.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">apache</span><span class="nt-tag">default-login</span><span class="nt-tag">ranger</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/apache/ranger" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="apache rocketmq console panel - detect info identify web-based control panels apache rocketmq console panel was detected. pdteam apache discovery panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Apache RocketMQ Console Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/rocketmq-console-exposure.yaml" target="_blank" rel="noopener" class="nt-source-link">rocketmq-console-exposure.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pdteam</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)rocketmq&#34;}) || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)rocketmq-console-ng&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Apache RocketMQ Console panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">apache</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="apache s2-032 struts - remote code execution high identify critical remote vulnerabilities apache struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when dynamic method invocation is enabled, allows remote attackers to execute arbitrary code via method: prefix (related to chained expressions). cve-2016-3081 dhiyaneshdk apache cve cve2016 rce struts vuln cwe-77" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Apache S2-032 Struts - Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2016/CVE-2016-3081.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2016-3081.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/77.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-77</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2016-3081" target="_blank" rel="noopener" class="nt-cve-link">CVE-2016-3081</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)struts2 showcase&#34;}) || service[&#34;http.body&#34;] matches &#34;(?i)struts problem report&#34; || service[&#34;http.body&#34;] matches &#34;(?i)apache struts&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when dynamic method invocation is enabled, allows remote attackers to execute arbitrary code via method: prefix (related to chained expressions).</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Remote code execution</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to Apache Struts version 2.3.20.2, 2.3.24.2, or 2.3.28.1.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">apache</span><span class="nt-tag">cve</span><span class="nt-tag">cve2016</span><span class="nt-tag">rce</span><span class="nt-tag">struts</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://cwiki.apache.org/confluence/display/WW/S2-032" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://struts.apache.org/docs/s2-032.html" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2016-3081" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="http://web.archive.org/web/20211207042547/https://securitytracker.com/id/1035665" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20160527-01-struts2-en" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="apache shardingsphere elasticjob-ui privilege escalation medium identify critical remote vulnerabilities exposure of sensitive information to an unauthorized actor vulnerability in apache shardingsphere elasticjob-ui allows an attacker who has guest account to do privilege escalation. this issue affects apache shardingsphere elasticjob-ui apache shardingsphere elasticjob-ui 3.x version 3.0.0 and prior versions. cve-2022-22733 zeyad azima apache cve cve2022 exposure sharingsphere vuln cwe-200" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Apache ShardingSphere ElasticJob-UI privilege escalation</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-22733.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-22733.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Zeyad Azima</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 11, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-22733" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-22733</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;816588900&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache ShardingSphere ElasticJob-UI allows an attacker who has guest account to do privilege escalation. This issue affects Apache ShardingSphere ElasticJob-UI Apache ShardingSphere ElasticJob-UI 3.x version 3.0.0 and prior versions.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could result in unauthorized access and control of the ElasticJob-UI application.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches or updates provided by Apache ShardingSphere to mitigate the privilege escalation vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">apache</span><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">exposure</span><span class="nt-tag">sharingsphere</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.vicarius.io/vsociety/blog/cve-2022-22733-apache-shardingsphere-elasticjob-ui-privilege-escalation" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-22733" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://lists.apache.org/thread/qpdsm936n9bhksb0rzn6bq1h7ord2nm6" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="http://www.openwall.com/lists/oss-security/2022/01/20/2" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/Zeyad-Azima/CVE-2022-22733" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="apache sling - default login high identify default logins in web-based control panels apache sling default login was discovered. icarot apache default-login sling" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Apache Sling - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/apache/apache-sling-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">apache-sling-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> icarot</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 8, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Apache Sling&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Apache Sling default login was discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">apache</span><span class="nt-tag">default-login</span><span class="nt-tag">sling</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/apache/sling" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="apache solr - authentication bypass critical identify critical remote vulnerabilities solr instances using the pkiauthenticationplugin, which is enabled by default when solr authentication is used, are vulnerable to authentication bypass.a fake ending at the end of any solr api url path, will allow requests to skip authentication while maintaining the api contract with the original url path.this fake ending looks like an unprotected api path, however it is stripped off internally after authentication but before api routing.this issue affects apache solr- from 5.3.0 before 8.11.4, from 9.0.0 before 9.7.0. cve-2024-45216 gumgum apache auth-bypass cve cve2024 solr vkev vuln cwe-287,cwe-863" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Apache Solr - Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-45216.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-45216.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> gumgum</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 29, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/287,CWE-863.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-287,CWE-863</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-45216" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-45216</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Apache Solr&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Solr instances using the PKIAuthenticationPlugin, which is enabled by default when Solr Authentication is used, are vulnerable to Authentication bypass.A fake ending at the end of any Solr API URL path, will allow requests to skip Authentication while maintaining the API contract with the original URL Path.This fake ending looks like an unprotected API path, however it is stripped off internally after authentication but before API routing.This issue affects Apache Solr- from 5.3.0 before 8.11.4, from 9.0.0 before 9.7.0.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Users are recommended to upgrade to version 9.7.0, or 8.11.4, which fix the issue.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches and updates from the vendor to address this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">apache</span><span class="nt-tag">auth-bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">solr</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://shfsec.com/cve-2024-45216-authentication-bypass-in-apache-solr" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-45216" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://solr.apache.org/security html#cve-2024-45216-apache-solr-authentication-bypass-possible-using-a-fake-url-path-ending" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="apache solr - host environment variables leak via metrics api medium identify critical remote vulnerabilities exposure of sensitive information to an unauthorized actor vulnerability in apache solr.
the solr metrics api publishes all unprotected environment variables available to each apache solr instance. users can specify which environment variables to hide, however, the default list is designed to work for known secret java system properties. environment variables cannot be strictly defined in solr, like java system properties can be, and may be set for the entire host,unlike java system properties which are set per-java-proccess. cve-2023-50290 banana69,dhiyaneshdk apache cve cve2023 exposure solr vuln cwe-200,nvd-cwe-noinfo" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Apache Solr - Host Environment Variables Leak via Metrics API</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-50290.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-50290.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Banana69,DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 17, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200,NVD-CWE-NOINFO.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200,NVD-CWE-NOINFO</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-50290" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-50290</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)apache solr&#34;}) || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)solr admin&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Exposure of Sensitive Information to an Unauthorized Actor Vulnerability in Apache Solr.
The Solr Metrics API publishes all unprotected environment variables available to each Apache Solr instance. Users can specify which environment variables to hide, however, the default list is designed to work for known secret Java system properties. Environment variables cannot be strictly defined in Solr, like Java system properties can be, and may be set for the entire host,unlike Java system properties which are set per-Java-proccess.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">This vulnerability can lead to the exposure of sensitive information, potentially allowing an attacker to gain unauthorized access or perform further attacks.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Users are recommended to upgrade to version 9.3.0 or later, in which environment variables are not published via the Metrics API.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">apache</span><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">exposure</span><span class="nt-tag">solr</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://solr.apache.org/security.html#cve-2023-50290-apache-solr-allows-read-access-to-host-environment-variables" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://x.com/sirifu4k1/status/1746755165066236216?s=20" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-50290" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/wy876/POC" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/wy876/wiki" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="apache solr admin panel - detect info identify web-based control panels apache solr admin panel was detected. pdteam admin apache discovery panel solr cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Apache Solr Admin Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/solr-panel-exposure.yaml" target="_blank" rel="noopener" class="nt-source-link">solr-panel-exposure.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pdteam</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)solr admin&#34;}) || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)apache solr&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Apache Solr admin panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">admin</span><span class="nt-tag">apache</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">solr</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="apache spark panel - detect info identify web-based control panels apache spark panel was detected. righettod apache discovery panel spark cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Apache Spark Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/spark-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">spark-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/apps/imt/html/&#34; || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)spark master at&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Apache Spark panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">apache</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">spark</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.hypeinnovation.com" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="apache spark ui - remote command injection high identify critical remote vulnerabilities apache spark ui is susceptible to remote command injection. acls can be enabled via the configuration option spark.acls.enable. with an authentication filter, this checks whether a user has access permissions to view or modify the application. if acls are enabled, a code path in httpsecurityfilter can allow impersonation by providing an arbitrary user name. an attacker can potentially reach a permission check function that will ultimately build a unix shell command based on input and execute it, resulting in arbitrary shell command execution. affected versions are 3.0.3 and earlier, 3.1.1 to 3.1.2, and 3.2.0 to 3.2.1. cve-2022-33891 princechaddha apache cve cve2022 kev packetstorm spark vkev vuln cwe-78" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Apache Spark UI - Remote Command Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-33891.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-33891.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> princechaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/78.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-78</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-33891" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-33891</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)spark master at&#34;}) || service[&#34;http.body&#34;] matches &#34;(?i)/apps/imt/html/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Apache Spark UI is susceptible to remote command injection. ACLs can be enabled via the configuration option spark.acls.enable. With an authentication filter, this checks whether a user has access permissions to view or modify the application. If ACLs are enabled, a code path in HttpSecurityFilter can allow impersonation by providing an arbitrary user name. An attacker can potentially reach a permission check function that will ultimately build a Unix shell command based on input and execute it, resulting in arbitrary shell command execution. Affected versions are 3.0.3 and earlier, 3.1.1 to 3.1.2, and 3.2.0 to 3.2.1.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability can lead to unauthorized access, data leakage, and potential compromise of the entire system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches or updates provided by Apache Spark to fix the remote command injection vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">apache</span><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">kev</span><span class="nt-tag">packetstorm</span><span class="nt-tag">spark</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/W01fh4cker/cve-2022-33891" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://lists.apache.org/thread/p847l3kopoo5bjtmxrcwk21xp6tjxqlc" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="http://packetstormsecurity.com/files/168309/Apache-Spark-Unauthenticated-Command-Injection.html" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-33891" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="http://www.openwall.com/lists/oss-security/2023/05/02/1" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="apache streampipes &lt;= 0.93.0 - use of cryptographically weak prng in recovery token generation critical identify critical remote vulnerabilities apache streampipes from version 0.69.0 through 0.93.0 uses a cryptographically weak pseudo-random number generator (prng) in the recovery token generation mechanism. given a valid token it&#39;s possible to predict all past and future generated tokens. cve-2024-29868 alessandro albani - devisions account-takeover apache cve cve2024 passive streampipes vuln cwe-338" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Apache StreamPipes &lt;= 0.93.0 - Use of Cryptographically Weak PRNG in Recovery Token Generation</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-29868.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-29868.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Alessandro Albani - DEVisions</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 25, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/338.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-338</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-29868" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-29868</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)apache streampipes&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Apache StreamPipes from version 0.69.0 through 0.93.0 uses a cryptographically weak Pseudo-Random Number Generator (PRNG) in the recovery token generation mechanism. Given a valid token it&#39;s possible to predict all past and future generated tokens.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to take over user accounts.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to Apache StreamPipes 0.95.0 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">account-takeover</span><span class="nt-tag">apache</span><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">passive</span><span class="nt-tag">streampipes</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://labs.yarix.com/2024/06/cve-2024-29868" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.cve.org/CVERecord?id=CVE-2024-29868" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://lists.apache.org/thread/g7t7zctvq2fysrw1x17flnc12592nhx7" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-29868" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="apache streampark - default login high identify default logins in web-based control panels apache streampark server enables default admin credentials. an attacker can execute unauthorized operations. icarot apache default-login streampark vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Apache Streampark - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/apache/apache-streampark-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">apache-streampark-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> icarot</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 6, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Apache StreamPark&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Apache Streampark server enables default admin credentials. An attacker can execute unauthorized operations.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">apache</span><span class="nt-tag">default-login</span><span class="nt-tag">streampark</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/apache/streampark" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="apache struts 2 - defaultactionmapper prefixes ognl code execution critical identify critical remote vulnerabilities in struts 2 before 2.3.15.1 the information following &#34;action:&#34;, &#34;redirect:&#34;, or &#34;redirectaction:&#34; is not properly sanitized and will be evaluated as an ognl expression against the value stack. this introduces the possibility to inject server side code. cve-2013-2251 exploitation,dwisiswant0,alex apache cve cve2013 kev ognl rce struts vkev vuln cwe-20" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Apache Struts 2 - DefaultActionMapper Prefixes OGNL Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2013/CVE-2013-2251.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2013-2251.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> exploitation,dwisiswant0,alex</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/20.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-20</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2013-2251" target="_blank" rel="noopener" class="nt-cve-link">CVE-2013-2251</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)struts problem report&#34; || service[&#34;http.body&#34;] matches &#34;(?i)apache struts&#34; || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)struts2 showcase&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">In Struts 2 before 2.3.15.1 the information following &#34;action:&#34;, &#34;redirect:&#34;, or &#34;redirectAction:&#34; is not properly sanitized and will be evaluated as an OGNL expression against the value stack. This introduces the possibility to inject server side code.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">This vulnerability can lead to remote code execution, allowing attackers to take control of the affected system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Developers should immediately upgrade to Struts 2.3.15.1 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">apache</span><span class="nt-tag">cve</span><span class="nt-tag">cve2013</span><span class="nt-tag">kev</span><span class="nt-tag">ognl</span><span class="nt-tag">rce</span><span class="nt-tag">struts</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="http://struts.apache.org/release/2.3.x/docs/s2-016.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://cwiki.apache.org/confluence/display/WW/S2-016" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2013-2251" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="http://archiva.apache.org/security.html" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="http://cxsecurity.com/issue/WLB-2014010087" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="apache struts 2 - remote command execution critical identify critical remote vulnerabilities apache struts 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 is susceptible to remote command injection attacks. the jakarta multipart parser has incorrect exception handling and error-message generation during file upload attempts, which can allow an attacker to execute arbitrary commands via a crafted content-type, content-disposition, or content-length http header. this was exploited in march 2017 with a content-type header containing a #cmd= string. cve-2017-5638 random_robbie apache cve cve2017 kev msf rce struts vkev vuln cwe-20" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Apache Struts 2 - Remote Command Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2017/CVE-2017-5638.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2017-5638.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Random_Robbie</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/20.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-20</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2017-5638" target="_blank" rel="noopener" class="nt-cve-link">CVE-2017-5638</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)apache struts&#34; || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)struts2 showcase&#34;}) || service[&#34;http.body&#34;] matches &#34;(?i)struts problem report&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Apache Struts 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 is susceptible to remote command injection attacks. The Jakarta Multipart parser has incorrect exception handling and error-message generation during file upload attempts, which can allow an attacker to execute arbitrary commands via a crafted Content-Type, Content-Disposition, or Content-Length HTTP header. This was exploited in March 2017 with a Content-Type header containing a #cmd= string.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Remote attackers can execute arbitrary commands on the target system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to Apache Struts 2.3.32 or 2.5.10.1 or apply the necessary patches.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">apache</span><span class="nt-tag">cve</span><span class="nt-tag">cve2017</span><span class="nt-tag">kev</span><span class="nt-tag">msf</span><span class="nt-tag">rce</span><span class="nt-tag">struts</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/mazen160/struts-pwn" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://isc.sans.edu/diary/22169" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/rapid7/metasploit-framework/issues/8064" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2017-5638" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="http://blog.talosintelligence.com/2017/03/apache-0-day-exploited.html" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="apache struts 2.0.0-2.5.25 - remote code execution critical identify critical remote vulnerabilities apache struts 2.0.0 through struts 2.5.25 is susceptible to remote code execution because forced ognl evaluation, when evaluated on raw user input in tag attributes, may allow it. cve-2020-17530 pikpikcu apache cve cve2020 kev packetstorm rce struts vkev vuln cwe-917" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Apache Struts 2.0.0-2.5.25 - Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2020/CVE-2020-17530.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2020-17530.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pikpikcu</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/917.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-917</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2020-17530" target="_blank" rel="noopener" class="nt-cve-link">CVE-2020-17530</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)apache struts&#34; || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)struts2 showcase&#34;}) || service[&#34;http.body&#34;] matches &#34;(?i)struts problem report&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Apache Struts 2.0.0 through Struts 2.5.25 is susceptible to remote code execution because forced OGNL evaluation, when evaluated on raw user input in tag attributes, may allow it.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected server.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches or upgrade to a non-vulnerable version of Apache Struts.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">apache</span><span class="nt-tag">cve</span><span class="nt-tag">cve2020</span><span class="nt-tag">kev</span><span class="nt-tag">packetstorm</span><span class="nt-tag">rce</span><span class="nt-tag">struts</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="http://packetstormsecurity.com/files/160721/Apache-Struts-2-Forced-Multi-OGNL-Evaluation.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="http://jvn.jp/en/jp/JVN43969166/index.html" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://cwiki.apache.org/confluence/display/WW/S2-061" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://security.netapp.com/advisory/ntap-20210115-0005/" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2020-17530" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="apache struts &lt;=2.5.20 - remote code execution critical identify critical remote vulnerabilities apache struts 2.0.0 to 2.5.20 forced double ognl evaluation when evaluated on raw user input in tag attributes, which may lead to remote code execution. cve-2019-0230 geeknik apache cve cve2019 packetstorm rce struts tenable vuln cwe-1321" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Apache Struts &lt;=2.5.20 - Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2019/CVE-2019-0230.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2019-0230.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> geeknik</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/1321.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-1321</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2019-0230" target="_blank" rel="noopener" class="nt-cve-link">CVE-2019-0230</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)struts2 showcase&#34;}) || service[&#34;http.body&#34;] matches &#34;(?i)struts problem report&#34; || service[&#34;http.body&#34;] matches &#34;(?i)apache struts&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Apache Struts 2.0.0 to 2.5.20 forced double OGNL evaluation when evaluated on raw user input in tag attributes, which may lead to remote code execution.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability allows an attacker to execute arbitrary code on the affected server.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade Apache Struts to a version higher than 2.5.20 or apply the necessary patches provided by the vendor.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">apache</span><span class="nt-tag">cve</span><span class="nt-tag">cve2019</span><span class="nt-tag">packetstorm</span><span class="nt-tag">rce</span><span class="nt-tag">struts</span><span class="nt-tag">tenable</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2019-0230" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://cwiki.apache.org/confluence/display/WW/S2-059" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.tenable.com/blog/cve-2019-0230-apache-struts-potential-remote-code-execution-vulnerability" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="http://packetstormsecurity.com/files/160108/Apache-Struts-2.5.20-Double-OGNL-Evaluation.html" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://cwiki.apache.org/confluence/display/ww/s2-059" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="apache struts2 s2-008 rce medium identify critical remote vulnerabilities the cookieinterceptor component in apache struts before 2.3.1.1 does not use the parameter-name whitelist, which allows remote attackers to execute arbitrary commands via a crafted http cookie header that triggers java code execution through a static method. cve-2012-0392 pikpikcu apache cve cve2012 edb java rce struts vuln nvd-cwe-noinfo" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Apache Struts2 S2-008 RCE</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2012/CVE-2012-0392.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2012-0392.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pikpikcu</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/NVD-CWE-NOINFO.html" target="_blank" rel="noopener" class="nt-cwe-link">NVD-CWE-NOINFO</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2012-0392" target="_blank" rel="noopener" class="nt-cve-link">CVE-2012-0392</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)apache struts&#34; || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)struts2 showcase&#34;}) || service[&#34;http.body&#34;] matches &#34;(?i)struts problem report&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The CookieInterceptor component in Apache Struts before 2.3.1.1 does not use the parameter-name whitelist, which allows remote attackers to execute arbitrary commands via a crafted HTTP Cookie header that triggers Java code execution through a static method.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability can lead to remote code execution on the affected server.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Developers should immediately upgrade to at least Struts 2.3.18.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">apache</span><span class="nt-tag">cve</span><span class="nt-tag">cve2012</span><span class="nt-tag">edb</span><span class="nt-tag">java</span><span class="nt-tag">rce</span><span class="nt-tag">struts</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://cwiki.apache.org/confluence/display/WW/S2-008 https://blog.csdn.net/weixin_43416469/article/details/113850545" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="http://www.exploit-db.com/exploits/18329" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://lists.immunityinc.com/pipermail/dailydave/2012-January/000011.html" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="http://web.archive.org/web/20150110183326/http://secunia.com:80/advisories/47393" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="http://struts.apache.org/2.x/docs/s2-008.html" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="apache struts2 s2-012 rce critical identify critical remote vulnerabilities apache struts showcase app 2.0.0 through 2.3.13, as used in struts 2 before 2.3.14.3, allows remote attackers to execute arbitrary ognl code via a crafted parameter name that is not properly handled when invoking a redirect. cve-2013-1965 pikpikcu apache cve cve2013 ognl rce struts vuln cwe-94" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Apache Struts2 S2-012 RCE</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2013/CVE-2013-1965.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2013-1965.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pikpikcu</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/94.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-94</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2013-1965" target="_blank" rel="noopener" class="nt-cve-link">CVE-2013-1965</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)apache struts&#34; || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)struts2 showcase&#34;}) || service[&#34;http.body&#34;] matches &#34;(?i)struts problem report&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Apache Struts Showcase App 2.0.0 through 2.3.13, as used in Struts 2 before 2.3.14.3, allows remote attackers to execute arbitrary OGNL code via a crafted parameter name that is not properly handled when invoking a redirect.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability can lead to remote code execution on the affected server.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Developers should immediately upgrade to Struts 2.3.14.3 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">apache</span><span class="nt-tag">cve</span><span class="nt-tag">cve2013</span><span class="nt-tag">ognl</span><span class="nt-tag">rce</span><span class="nt-tag">struts</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="http://struts.apache.org/development/2.x/docs/s2-012.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2013-1965" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://bugzilla.redhat.com/show_bug.cgi?id=967655" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/CrackerCat/myhktools" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/GhostTroops/myhktools" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="apache struts2 s2-053 - remote code execution critical identify critical remote vulnerabilities apache struts 2.0.0 through 2.3.33 and 2.5 through 2.5.10.1 uses an unintentional expression in a freemarker tag instead of string literals, which makes it susceptible to remote code execution attacks. cve-2017-12611 pikpikcu apache cve cve2017 rce struts vkev vuln cwe-20" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Apache Struts2 S2-053 - Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2017/CVE-2017-12611.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2017-12611.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pikpikcu</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/20.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-20</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2017-12611" target="_blank" rel="noopener" class="nt-cve-link">CVE-2017-12611</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)apache struts&#34; || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)struts2 showcase&#34;}) || service[&#34;http.body&#34;] matches &#34;(?i)struts problem report&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Apache Struts 2.0.0 through 2.3.33 and 2.5 through 2.5.10.1 uses an unintentional expression in a Freemarker tag instead of string literals, which makes it susceptible to remote code execution attacks.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Remote code execution</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches or upgrade to a non-vulnerable version of Apache Struts2.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">apache</span><span class="nt-tag">cve</span><span class="nt-tag">cve2017</span><span class="nt-tag">rce</span><span class="nt-tag">struts</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://struts.apache.org/docs/s2-053.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2017-12611" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://kb.netapp.com/support/s/article/ka51A000000CgttQAC/NTAP-20170911-0001" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2017-003.txt" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="http://www.oracle.com/technetwork/security-advisory/alert-cve-2017-9805-3889403.html" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="apache struts2 s2-053 - remote code execution critical identify critical remote vulnerabilities apache struts 2.1.x and 2.3.x  with the struts 1 plugin might allow remote code execution via a malicious field value passed in a raw message to the actionmessage. cve-2017-9791 pikpikcu apache cve cve2017 kev rce struts vkev vuln cwe-20" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Apache Struts2 S2-053 - Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2017/CVE-2017-9791.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2017-9791.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pikpikcu</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/20.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-20</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2017-9791" target="_blank" rel="noopener" class="nt-cve-link">CVE-2017-9791</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)struts problem report&#34; || service[&#34;http.body&#34;] matches &#34;(?i)apache struts&#34; || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)struts2 showcase&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Apache Struts 2.1.x and 2.3.x  with the Struts 1 plugin might allow remote code execution via a malicious field value passed in a raw message to the ActionMessage.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Remote code execution</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches or upgrade to a non-vulnerable version of Apache Struts2.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">apache</span><span class="nt-tag">cve</span><span class="nt-tag">cve2017</span><span class="nt-tag">kev</span><span class="nt-tag">rce</span><span class="nt-tag">struts</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="http://www.oracle.com/technetwork/security-advisory/alert-cve-2017-9805-3889403.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="http://struts.apache.org/docs/s2-048.html" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="http://web.archive.org/web/20211207175819/https://securitytracker.com/id/1038838" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="http://www.securitytracker.com/id/1038838" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://security.netapp.com/advisory/ntap-20180706-0002/" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="apache struts2 s2-057 - remote code execution high identify critical remote vulnerabilities apache struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible remote code execution when alwaysselectfullnamespace is true (either by user or a plugin like convention plugin) and then: results are used with no namespace and in same time, its upper package have no or wildcard namespace and similar to results, same possibility when using url tag which doesn&#39;&#39;t have value and action set and in same time, its upper package have no or wildcard namespace. cve-2018-11776 pikpikcu apache cve cve2018 kev packetstorm rce struts vkev vuln cwe-20" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Apache Struts2 S2-057 - Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2018/CVE-2018-11776.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2018-11776.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pikpikcu</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/20.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-20</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2018-11776" target="_blank" rel="noopener" class="nt-cve-link">CVE-2018-11776</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)struts2 showcase&#34;}) || service[&#34;http.body&#34;] matches &#34;(?i)struts problem report&#34; || service[&#34;http.body&#34;] matches &#34;(?i)apache struts&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible remote code execution when alwaysSelectFullNamespace is true (either by user or a plugin like Convention Plugin) and then: results are used with no namespace and in same time, its upper package have no or wildcard namespace and similar to results, same possibility when using url tag which doesn&#39;&#39;t have value and action set and in same time, its upper package have no or wildcard namespace.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Remote code execution</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches or upgrade to a non-vulnerable version of Apache Struts2.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">apache</span><span class="nt-tag">cve</span><span class="nt-tag">cve2018</span><span class="nt-tag">kev</span><span class="nt-tag">packetstorm</span><span class="nt-tag">rce</span><span class="nt-tag">struts</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/jas502n/St2-057" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://cwiki.apache.org/confluence/display/WW/S2-057" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://security.netapp.com/advisory/ntap-20180822-0001/" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2018-11776" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="http://packetstormsecurity.com/files/172830/Apache-Struts-Remote-Code-Execution.html" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="apache superset - authentication bypass critical identify critical remote vulnerabilities session validation attacks in apache superset versions up to and including 2.0.1. installations that have not altered the default configured secret_key according to installation instructions allow for an attacker to authenticate and access unauthorized resources. this does not affect superset administrators who have changed the default value for secret_key config. cve-2023-27524 dhiyaneshdk,_0xf4n9x_ apache auth-bypass cve cve2023 kev packetstorm superset vkev vuln cwe-1188" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Apache Superset - Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-27524.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-27524.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK,_0xf4n9x_</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/1188.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-1188</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-27524" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-27524</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1582430156&#34; || service[&#34;http.body&#34;] matches &#34;(?i)apache superset&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Session Validation attacks in Apache Superset versions up to and including 2.0.1. Installations that have not altered the default configured SECRET_KEY according to installation instructions allow for an attacker to authenticate and access unauthorized resources. This does not affect Superset administrators who have changed the default value for SECRET_KEY config.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to bypass authentication and gain unauthorized access to sensitive information.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches or upgrade to a patched version of Apache Superset.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">apache</span><span class="nt-tag">auth-bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">kev</span><span class="nt-tag">packetstorm</span><span class="nt-tag">superset</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/horizon3ai/CVE-2023-27524" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.horizon3.ai/cve-2023-27524-insecure-default-configuration-in-apache-superset-leads-to-remote-code-execution/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-27524" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="http://packetstormsecurity.com/files/172522/Apache-Superset-2.0.0-Authentication-Bypass.html" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="http://www.openwall.com/lists/oss-security/2023/04/24/2" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="apache superset - default login high identify default logins in web-based control panels apache superset instance discovered using weak default credentials, allows the attacker to gain admin privilege. theamanrawat apache default-login superset vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Apache Superset - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/apache/superset-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">superset-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> theamanrawat</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 23, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">(any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Superset&#34;}) &amp;&amp; service[&#34;http.body&#34;] contains `alt=&#34;Superset&#34;`) || service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1582430156&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Apache Superset instance discovered using weak default credentials, allows the attacker to gain admin privilege.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">apache</span><span class="nt-tag">default-login</span><span class="nt-tag">superset</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://superset.apache.org/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="apache superset login panel - detect info identify web-based control panels apache superset login panel was detected. dhiyaneshdk,righettod,icarot apache discovery panel superset cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Apache Superset Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/superset-login.yaml" target="_blank" rel="noopener" class="nt-source-link">superset-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk,righettod,icarot</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1582430156&#34; || service[&#34;http.body&#34;] matches &#34;(?i)apache superset&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Apache Superset login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">apache</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">superset</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="apache tika - xml external entity injection high identify critical remote vulnerabilities apache tika tika-core (1.13-3.2.1), tika-pdf-module (2.0.0-3.2.1), and tika-parsers (1.13-1.28.5) contain an xml external entity injection caused by processing crafted xfa files inside pdfs, letting attackers perform xxe attacks remotely, exploit requires crafted pdf input. cve-2025-66516 mathematiciangoat apache cve cve2025 lfr pdf tika xxe cwe-611" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Apache Tika - XML External Entity Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-66516.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-66516.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> MathematicianGoat</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 19, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/611.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-611</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-66516" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-66516</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Apache Tika&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Apache Tika tika-core (1.13-3.2.1), tika-pdf-module (2.0.0-3.2.1), and tika-parsers (1.13-1.28.5) contain an XML External Entity injection caused by processing crafted XFA files inside PDFs, letting attackers perform XXE attacks remotely, exploit requires crafted PDF input.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can exploit XXE to read local files or cause denial of service, potentially exposing sensitive information or disrupting service.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade tika-core to \u003E= 3.2.2 and ensure tika-pdf-module and tika-parsers are updated to latest versions.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">apache</span><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">lfr</span><span class="nt-tag">pdf</span><span class="nt-tag">tika</span><span class="nt-tag">xxe</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/chasingimpact/CVE-2025-66516-Writeup-POC" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66516" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="apache tomcat - default login discovery info identify default logins in web-based control panels apache tomcat 10.1.0-m1 to 10.1.0-m16, 10.0.0-m1 to 10.0.22, 9.0.30 to 9.0.64 and 8.5.50 to 8.5.81  default login credentials were successful. 0xelkomy &amp; c0nqr0r default-login tomcat vuln cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Apache Tomcat - Default Login Discovery</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/apache/tomcat-examples-login.yaml" target="_blank" rel="noopener" class="nt-source-link">tomcat-examples-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0xelkomy &amp; C0NQR0R</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.head.server&#34;] contains &#34;Apache Tomcat&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Apache Tomcat 10.1.0-M1 to 10.1.0-M16, 10.0.0-M1 to 10.0.22, 9.0.30 to 9.0.64 and 8.5.50 to 8.5.81  default login credentials were successful.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">tomcat</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://c0nqr0r.github.io/CVE-2022-34305/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="apache tomcat - http request smuggling medium identify critical remote vulnerabilities apache tomcat from versions 8.5.0 to 8.5.93, 9.0.0-m1 to 9.0.81, 10.1.0-m1 to 10.1.13, and 11.0.0-m1 to 11.0.0-m11 contain an improper input validation caused by incorrect parsing of http trailer headers, letting attackers craft headers to cause request smuggling, exploit requires sending malicious trailer headers. cve-2023-45648 0x_akoko apache cve cve2023 http-smuggling passive tomcat cwe-444" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Apache Tomcat - HTTP Request Smuggling</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-45648.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-45648.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_Akoko</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 29, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/444.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-444</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-45648" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-45648</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Apache Tomcat&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Apache Tomcat from versions 8.5.0 to 8.5.93, 9.0.0-M1 to 9.0.81, 10.1.0-M1 to 10.1.13, and 11.0.0-M1 to 11.0.0-M11 contain an improper input validation caused by incorrect parsing of HTTP trailer headers, letting attackers craft headers to cause request smuggling, exploit requires sending malicious trailer headers.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can perform request smuggling, potentially leading to cache poisoning, session hijacking, or bypassing security controls.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to version 11.0.0-M12, 10.1.14, 9.0.81, or 8.5.94 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">apache</span><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">http-smuggling</span><span class="nt-tag">passive</span><span class="nt-tag">tomcat</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://lists.apache.org/thread/2pv8yz1pyp088tsxfb7ogltk9msk0jdp" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://hackerone.com/reports/2299692" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-45648" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="apache tomcat jk connect &lt;=1.2.44 - manager access high identify critical remote vulnerabilities apache tomcat jk (mod_jk) connector 1.2.0 to 1.2.44 allows specially constructed requests to expose application functionality through the reverse proxy. it is also possible in some configurations for a specially constructed request to bypass the access controls configured in httpd. while there is some overlap between this issue and cve-2018-1323, they are not identical. cve-2018-11759 harshbothra_ apache cve cve2018 httpd mod-jk tomcat vkev vuln cwe-22" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Apache Tomcat JK Connect &lt;=1.2.44 - Manager Access</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2018/CVE-2018-11759.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2018-11759.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> harshbothra_</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2018-11759" target="_blank" rel="noopener" class="nt-cve-link">CVE-2018-11759</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Apache Tomcat&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Apache Tomcat JK (mod_jk) Connector 1.2.0 to 1.2.44 allows specially constructed requests to expose application functionality through the reverse proxy. It is also possible in some configurations for a specially constructed request to bypass the access controls configured in httpd. While there is some overlap between this issue and CVE-2018-1323, they are not identical.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can gain unauthorized access to the Apache Tomcat Manager interface, potentially leading to further compromise of the server.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to a patched version of Apache Tomcat JK Connect (1.2.45 or higher) or apply the recommended security patches.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">apache</span><span class="nt-tag">cve</span><span class="nt-tag">cve2018</span><span class="nt-tag">httpd</span><span class="nt-tag">mod-jk</span><span class="nt-tag">tomcat</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/immunIT/CVE-2018-11759" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://lists.apache.org/thread.html/6d564bb0ab73d6b3efdd1d6b1c075d1a2c84ecd84a4159d6122529ad@%3Cannounce.tomcat.apache.org%3E" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://lists.debian.org/debian-lts-announce/2018/12/msg00007.html" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2018-11759" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://access.redhat.com/errata/RHSA-2019:0366" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="apache tomcat manager default login high identify default logins in web-based control panels apache tomcat manager default login credentials were discovered. pdteam,sinkettu,nybble04 apache default-login tomcat vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Apache Tomcat Manager Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/apache/tomcat-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">tomcat-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pdteam,sinKettu,nybble04</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;Apache Tomcat&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Apache Tomcat Manager default login credentials were discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">apache</span><span class="nt-tag">default-login</span><span class="nt-tag">tomcat</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.rapid7.com/db/vulnerabilities/apache-tomcat-default-ovwebusr-password/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/danielmiessler/SecLists/blob/master/Passwords/Default-Credentials/tomcat-betterdefaultpasslist.txt" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="apache tomcat manager login panel - detect info identify web-based control panels apache tomcat manager login panel was detected. ahmed sherif,geeknik,sinkettu apache discovery panel tomcat cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Apache Tomcat Manager Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/apache/public-tomcat-manager.yaml" target="_blank" rel="noopener" class="nt-source-link">public-tomcat-manager.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Ahmed Sherif,geeknik,sinKettu</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)apache tomcat&#34;}) || service[&#34;http.body&#34;] matches &#34;(?i)apache tomcat&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Apache Tomcat Manager login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">apache</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">tomcat</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="apache tomcat remote command execution high identify critical remote vulnerabilities when using apache tomcat versions 10.0.0-m1 to 10.0.0-m4, 9.0.0.m1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if
a) an attacker is able to control the contents and name of a file on the server; and
b) the server is configured to use the persistencemanager with a filestore; and
c) the persistencemanager is configured with sessionattributevalueclassnamefilter=&#34;null&#34; (the default unless a securitymanager is used) or a sufficiently lax filter to allow the attacker provided object to be deserialized; and
d) the attacker knows the relative file path from the storage location used by filestore to the file the attacker has control over; then, using a specifically crafted request, the attacker will be able to trigger remote code execution via deserialization of the file under their control.
note that all of conditions a) to d) must be true for the attack to succeed. cve-2020-9484 dwisiswant0 apache cve cve2020 packetstorm rce tomcat vuln cwe-502" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Apache Tomcat Remote Command Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2020/CVE-2020-9484.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2020-9484.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dwisiswant0</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/502.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-502</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2020-9484" target="_blank" rel="noopener" class="nt-cve-link">CVE-2020-9484</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)apache tomcat&#34; || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)apache tomcat&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if
a) an attacker is able to control the contents and name of a file on the server; and
b) the server is configured to use the PersistenceManager with a FileStore; and
c) the PersistenceManager is configured with sessionAttributeValueClassNameFilter=&#34;null&#34; (the default unless a SecurityManager is used) or a sufficiently lax filter to allow the attacker provided object to be deserialized; and
d) the attacker knows the relative file path from the storage location used by FileStore to the file the attacker has control over; then, using a specifically crafted request, the attacker will be able to trigger remote code execution via deserialization of the file under their control.
Note that all of conditions a) to d) must be true for the attack to succeed.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability can lead to remote code execution, allowing attackers to execute arbitrary commands on the affected system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches provided by Apache to mitigate this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">apache</span><span class="nt-tag">cve</span><span class="nt-tag">cve2020</span><span class="nt-tag">packetstorm</span><span class="nt-tag">rce</span><span class="nt-tag">tomcat</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="http://packetstormsecurity.com/files/157924/Apache-Tomcat-CVE-2020-9484-Proof-Of-Concept.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2020-9484" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://lists.apache.org/thread.html/r77eae567ed829da9012cadb29af17f2df8fa23bf66faf88229857bb1%40%3Cannounce.tomcat.apache.org%3E" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://lists.apache.org/thread.html/rf70f53af27e04869bdac18b1fc14a3ee529e59eb12292c8791a77926@%3Cusers.tomcat.apache.org%3E" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00057.html" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="apache tomcat `cgiservlet` enablecmdlinearguments - remote code execution high identify critical remote vulnerabilities when running on windows with enablecmdlinearguments enabled, the cgi servlet in apache tomcat 9.0.0.m1 to 9.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 is vulnerable to remote code execution due to a bug in the way the jre passes command line arguments to windows. the cgi servlet is disabled by default. the cgi option enablecmdlinearguments is disable by default in tomcat 9.0.x (and will be disabled by default in all versions in response to this vulnerability). for a detailed explanation of the jre behaviour, see markus wulftange&#39;s blog (https-//codewhitesec.blogspot.com/2016/02/java-and-command-line-injections-in-windows.html) and this archived msdn blog (https-//web.archive.org/web/20161228144344/https-//blogs.msdn.microsoft.com/twistylittlepassagesallalike/2011/04/23/everyone-quotes-command-line-arguments-the-wrong-way/). cve-2019-0232 dhiyaneshdk apache cve cve2019 packetstorm seclists tomcat vkev vuln cwe-78" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Apache Tomcat `CGIServlet` enableCmdLineArguments - Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2019/CVE-2019-0232.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2019-0232.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 23, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/78.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-78</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2019-0232" target="_blank" rel="noopener" class="nt-cve-link">CVE-2019-0232</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)apache tomcat&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 is vulnerable to Remote Code Execution due to a bug in the way the JRE passes command line arguments to Windows. The CGI Servlet is disabled by default. The CGI option enableCmdLineArguments is disable by default in Tomcat 9.0.x (and will be disabled by default in all versions in response to this vulnerability). For a detailed explanation of the JRE behaviour, see Markus Wulftange&#39;s blog (https-//codewhitesec.blogspot.com/2016/02/java-and-command-line-injections-in-windows.html) and this archived MSDN blog (https-//web.archive.org/web/20161228144344/https-//blogs.msdn.microsoft.com/twistylittlepassagesallalike/2011/04/23/everyone-quotes-command-line-arguments-the-wrong-way/).</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can execute arbitrary system commands on Windows systems when CGI Servlet is enabled with enableCmdLineArguments, leading to complete server compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to Tomcat 9.0.18, 8.5.40, 7.0.94 or later, and ensure enableCmdLineArguments is disabled.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">apache</span><span class="nt-tag">cve</span><span class="nt-tag">cve2019</span><span class="nt-tag">packetstorm</span><span class="nt-tag">seclists</span><span class="nt-tag">tomcat</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="http://packetstormsecurity.com/files/153506/Apache-Tomcat-CGIServlet-enableCmdLineArguments-Remote-Code-Execution.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="http://seclists.org/fulldisclosure/2019/May/4" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://access.redhat.com/errata/RHSA-2019:1712" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://blog.trendmicro.com/trendlabs-security-intelligence/uncovering-cve-2019-0232-a-remote-code-execution-vulnerability-in-apache-tomcat/" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://codewhitesec.blogspot.com/2016/02/java-and-command-line-injections-in-windows.html" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="apache `mod_proxy_cluster` cluster manager interface - exposure info identify web-based control panels the apache mod_proxy_cluster management interface provides administrative control and visibility into the load balancer’s nodes and contexts. oleveloper apache mod_proxy cluster exposure discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Apache `mod_proxy_cluster` Cluster Manager Interface - Exposure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/apache/apache-mod-cluster-exposure.yaml" target="_blank" rel="noopener" class="nt-source-link">apache-mod-cluster-exposure.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> oleveloper</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 10, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] contains &#34;Mod_cluster Status&#34; || service[&#34;http.body&#34;] contains &#34;mod_proxy_cluster&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The Apache mod_proxy_cluster management interface provides administrative control and visibility into the load balancer’s nodes and contexts.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">apache</span><span class="nt-tag">mod_proxy</span><span class="nt-tag">cluster</span><span class="nt-tag">exposure</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://httpd.apache.org/docs/2.4/mod/mod_proxy_cluster.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="apereo cas cross-site scripting medium identify critical remote vulnerabilities apereo cas through 6.4.1 allows cross-site scripting via post requests sent to the rest api endpoints. cve-2021-42567 pdteam apereo cas cve cve2021 vkev vuln xss cwe-79" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Apereo CAS Cross-Site Scripting</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2021/CVE-2021-42567.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2021-42567.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pdteam</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-79</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2021-42567" target="_blank" rel="noopener" class="nt-cve-link">CVE-2021-42567</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)&#39;CAS - Central Authentication Service&#39;&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Apereo CAS through 6.4.1 allows cross-site scripting via POST requests sent to the REST API endpoints.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute malicious scripts in the context of a victim&#39;s browser, potentially leading to session hijacking, data theft, or defacement.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches or updates provided by the vendor to mitigate this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">apereo</span><span class="nt-tag">cas</span><span class="nt-tag">cve</span><span class="nt-tag">cve2021</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">xss</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://apereo.github.io/2021/10/18/restvuln/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.sudokaikan.com/2021/12/exploit-cve-2021-42567-post-based-xss.html" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/sudohyak/exploit/blob/dcf04f704895fe7e042a0cfe9c5ead07797333cc/CVE-2021-42567/README.md" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2021-42567" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/apereo/cas/releases" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="aperio eslidemanager - panel info identify web-based control panels aperio eslidemanager login panel was discovered. th3l0newolf aperio eslidemanager login panel discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Aperio eSlideManager - Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/aperio-eslidemanager-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">aperio-eslidemanager-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Th3l0newolf</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 12, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)eSlideManager - Login&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Aperio eSlideManager Login Panel was discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">aperio</span><span class="nt-tag">eslidemanager</span><span class="nt-tag">login</span><span class="nt-tag">panel</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.leicabiosystems.com/digital-pathology/eslidemanager/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="apigee login panel - detect info identify web-based control panels apigee login panel was detected. righettod panel apigee login discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Apigee Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/apigee-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">apigee-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 12, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-839356603&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Apigee login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">apigee</span><span class="nt-tag">login</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://cloud.google.com/apigee?hl=en" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="apollo default login high identify default logins in web-based control panels an apollo default login was discovered. paperpen apollo default-login vuln cwe-522" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Apollo Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/apollo/apollo-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">apollo-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> PaperPen</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/522.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-522</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;11794165&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An Apollo default login was discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">apollo</span><span class="nt-tag">default-login</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/apolloconfig/apollo" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="application management panel - detect info identify web-based control panels application management panel was detected. dhiyaneshdk amp cubecoders discovery panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Application Management Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/amp-application-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">amp-application-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)amp - application management panel&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Application Management Panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">amp</span><span class="nt-tag">cubecoders</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="appsmith user login - panel detect info identify web-based control panels appsmith user login panel was detected. powerexploit panel appsmith discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Appsmith User Login - Panel Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/appsmith-web-login.yaml" target="_blank" rel="noopener" class="nt-source-link">appsmith-web-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> powerexploit</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)appsmith&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Appsmith user login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">appsmith</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.appsmith.com" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="appspace login panel - detect info identify web-based control panels appspace is the workplace experience platform for your whole team that lets you manage it all – from employee communications to your physical office spaces. ritikchaddha appspace detect discovery panel" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Appspace Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/appspace-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">appspace-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 25, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)appspace&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Appspace is the workplace experience platform for your whole team that lets you manage it all – from employee communications to your physical office spaces.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">appspace</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.appspace.com/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="appsuite login panel - detect info identify web-based control panels  dhiyaneshdk appsuite detect discovery open-xchange panel" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Appsuite Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/appsuite-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">appsuite-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 7, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)appsuite&#34;</code></div>
  <div class="nt-tags"><span class="nt-tag">appsuite</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">open-xchange</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="appwrite login panel - detect info identify web-based control panels appwrite login panel was detected. ritikchaddha appwrite detect discovery panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Appwrite Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/appwrite-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">appwrite-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)sign in - appwrite&#34;}) || service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-633108100&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Appwrite login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">appwrite</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="aptus login - panel detect info identify web-based control panels aptus login panel was detected. princechaddha aptus discovery panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Aptus Login - Panel Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/aptus-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">aptus-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> princechaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Aptus Login&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Aptus login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">aptus</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="aqua enterprise - panel detect info identify web-based control panels aqua enterprise panel was detected. idealphase panel aqua aquasec discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Aqua Enterprise - Panel Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/aqua-enterprise-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">aqua-enterprise-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> idealphase</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Aqua Enterprise&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Aqua Enterprise panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">aqua</span><span class="nt-tag">aquasec</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.aquasec.com/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="aquatronica controller system &lt;= 5.1.6 - information disclosure high identify critical remote vulnerabilities aquatronica controller system firmware 5.1.6 and earlier and web interface 2.0 and earlier contain an information disclosure vulnerability caused by unauthenticated access to tcp.php endpoint, letting remote attackers retrieve sensitive configuration data including plaintext credentials, exploit requires no authentication. cve-2025-25037 s4e-io aquatronica cve cve2025 info-leak vkev vuln cwe-200" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Aquatronica Controller System &lt;= 5.1.6 - Information Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-25037.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-25037.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> s4e-io</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 5, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-25037" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-25037</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)aquatronica&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Aquatronica Controller System firmware 5.1.6 and earlier and web interface 2.0 and earlier contain an information disclosure vulnerability caused by unauthenticated access to tcp.php endpoint, letting remote attackers retrieve sensitive configuration data including plaintext credentials, exploit requires no authentication.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can retrieve sensitive configuration data including plaintext credentials through the tcp.php endpoint, potentially gaining full administrative access to the controller system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to Aquatronica Controller System firmware version 5.1.7 or later and web interface version 2.1 or later that implements proper authentication controls.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">aquatronica</span><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">info-leak</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.zeroscience.mk/en/vulnerabilities/ZSL-2024-5824.php" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.exploit-db.com/exploits/52028" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://vulncheck.com/advisories/aquatronica-controller-system-credential-leak" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-25037" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="arangodb web interface - detect info identify web-based control panels arangodb web interface was detected. pussycat0x arangodb discovery login panel" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">ArangoDB Web Interface - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/arangodb-web-Interface.yaml" target="_blank" rel="noopener" class="nt-source-link">arangodb-web-Interface.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 4, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)arangodb web interface&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">ArangoDB Web Interface was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">arangodb</span><span class="nt-tag">discovery</span><span class="nt-tag">login</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.arangodb.com/docs/stable/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="arcgis rest services directory - detect info identify web-based control panels check for the existence of the &#34;/arcgis/rest/services&#34; path on an arcgis server. heeress api arcgis detect discovery esri panel rest" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">ArcGIS REST Services Directory - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/arcgis/arcgis-services.yaml" target="_blank" rel="noopener" class="nt-source-link">arcgis-services.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> HeeresS</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)arcgis&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Check for the existence of the &#34;/arcgis/rest/services&#34; path on an ArcGIS server.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">api</span><span class="nt-tag">arcgis</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">esri</span><span class="nt-tag">panel</span><span class="nt-tag">rest</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://enterprise.arcgis.com/en/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="arcserve panel - detect info identify web-based control panels  dhiyaneshdk arcserve detect discovery login panel" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">ArcServe Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/arcserve-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">arcserve-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 29, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-1889244460&#34;</code></div>
  <div class="nt-tags"><span class="nt-tag">arcserve</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">login</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://twitter.com/HunterMapping/status/1674267368359444480" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/mdsecactivebreach/CVE-2023-26258-ArcServe" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="arcane login panel - detect info identify web-based control panels detects the presence of the arcane login panel, a modern docker management platform. kazgangap arcane login-panel docker" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Arcane Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/arcane-login-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">arcane-login-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Kazgangap</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 24, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-313371739&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detects the presence of the Arcane login panel, a modern Docker management platform.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">arcane</span><span class="nt-tag">login-panel</span><span class="nt-tag">docker</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="archibus web central login - panel detect info identify web-based control panels archibus web central login panel was detected. righettod,pjborah,hardik-rathod archibus discovery panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Archibus Web Central Login - Panel Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/archibus-webcentral-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">archibus-webcentral-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod,PJBorah,Hardik-Rathod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;889652940&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Archibus Web Central login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">archibus</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://archibus.com/products/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="arcserve udp &lt;= 9.0.6034 - authentication bypass critical identify critical remote vulnerabilities arcserve udp through 9.0.6034 allows authentication bypass. the method getversioninfo at webserviceimpl/services/flashserviceimpl leaks the authuuid token. this token can be used at /webserviceimpl/services/virtualstandbyserviceimpl to obtain a valid session. this session can be used to execute any task as administrator. cve-2023-26258 daffainfo arcserve auth-bypass cve cve2023 vkev vuln cwe-863" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Arcserve UDP &lt;= 9.0.6034 - Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-26258.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-26258.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> daffainfo</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 20, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/863.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-863</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-26258" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-26258</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-1889244460&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Arcserve UDP through 9.0.6034 allows authentication bypass. The method getVersionInfo at WebServiceImpl/services/FlashServiceImpl leaks the AuthUUID token. This token can be used at /WebServiceImpl/services/VirtualStandbyServiceImpl to obtain a valid session. This session can be used to execute any task as administrator.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can bypass authentication by leaking the AuthUUID token, allowing them to execute any administrative task and potentially compromise all backup data managed by Arcserve UDP.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to Arcserve UDP version 9.1 or later that addresses this authentication bypass vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">arcserve</span><span class="nt-tag">auth-bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.mdsec.co.uk/2023/06/cve-2023-26258-remote-code-execution-in-arcserve-udp-backup/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-26258" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="arcserve unified data protection - authentication bypass critical identify critical remote vulnerabilities an authentication bypass vulnerability exists in arcserve unified data protection 9.2 and 8.1 in the edge-app-base-webui.jar!com.ca.arcserve.edge.app.base.ui.server.edgeloginserviceimpl.dologin() function within wizardlogin. cve-2024-0799 daffainfo arcserve auth-bypass cve cve2024 vkev cwe-287" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Arcserve Unified Data Protection - Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-0799.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-0799.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> daffainfo</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 5, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/287.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-287</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-0799" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-0799</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1015186617&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An authentication bypass vulnerability exists in Arcserve Unified Data Protection 9.2 and 8.1 in the edge-app-base-webui.jar!com.ca.arcserve.edge.app.base.ui.server.EdgeLoginServiceImpl.doLogin() function within wizardLogin.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can bypass authentication, gaining unauthorized access to the system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest version of Arcserve Unified Data Protection or apply security patches provided by the vendor.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">arcserve</span><span class="nt-tag">auth-bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">vkev</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.tenable.com/security/research/tra-2024-07" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-0799" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="argilla panel - detect info identify web-based control panels argilla is an open-source data labelling platform for ai and llm fine-tuning workflows.
it provides a web interface for annotating datasets used in machine learning model training. rxerium ai argilla data-labelling detect discovery llm panel" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Argilla Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/argilla-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">argilla-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 27, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;^Argilla&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Argilla is an open-source data labelling platform for AI and LLM fine-tuning workflows.
It provides a web interface for annotating datasets used in machine learning model training.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">ai</span><span class="nt-tag">argilla</span><span class="nt-tag">data-labelling</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">llm</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/argilla-io/argilla" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://argilla.io" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="argo cd login panel info identify web-based control panels an argo cd login panel was discovered. adam crosser,daffainfo,aringo argocd discovery kubernetes login panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Argo CD Login Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/argocd-login.yaml" target="_blank" rel="noopener" class="nt-source-link">argocd-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Adam Crosser,daffainfo,aringo</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Argo CD&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An Argo CD login panel was discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">argocd</span><span class="nt-tag">discovery</span><span class="nt-tag">kubernetes</span><span class="nt-tag">login</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://argoproj.github.io/cd/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="argo cd unauthenticated access to sensitive setting medium identify critical remote vulnerabilities argo cd is a declarative, gitops continuous delivery tool for kubernetes. the vulnerability allows unauthorized access to the sensitive settings exposed by /api/v1/settings endpoint without authentication. all sensitive settings are hidden except passwordpattern. cve-2024-37152 dhiyaneshdk argo-cd cve cve2024 info-leak vuln cwe-306" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Argo CD Unauthenticated Access to sensitive setting</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-37152.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-37152.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 26, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/306.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-306</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-37152" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-37152</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Argo CD&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. The vulnerability allows unauthorized access to the sensitive settings exposed by /api/v1/settings endpoint without authentication. All sensitive settings are hidden except passwordPattern.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can access sensitive password patterns and application settings exposed by the /api/v1/settings endpoint.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update Argo CD to a version that patches CVE-2024-37152.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">argo-cd</span><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">info-leak</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/argoproj/argo-cd/security/advisories/GHSA-87p9-x75h-p4j2" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-37152" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="aria2 webui - path traversal high identify critical remote vulnerabilities webui-aria2 commit 4fe2e was discovered to contain a path traversal vulnerability. cve-2023-39141 dhiyaneshdk aria2 cve cve2023 lfi unauth vuln webui ziahamza cwe-22" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Aria2 WebUI - Path traversal</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-39141.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-39141.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 23, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-39141" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-39141</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)aria2 webui&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">webui-aria2 commit 4fe2e was discovered to contain a path traversal vulnerability.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can access sensitive files on the server, potentially leading to unauthorized disclosure of sensitive information.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to the latest version of Aria2 WebUI to fix the path traversal vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">aria2</span><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">lfi</span><span class="nt-tag">unauth</span><span class="nt-tag">vuln</span><span class="nt-tag">webui</span><span class="nt-tag">ziahamza</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://twitter.com/win3zz/status/1694239332465520684" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://gist.github.com/JafarAkhondali/528fe6c548b78f454911fb866b23f66e" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/ziahamza/webui-aria2/blob/109903f0e2774cf948698cd95a01f77f33d7dd2c/node-server.js#L10" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/codeb0ss/CVE-2023-39141-PoC" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/nomi-sec/PoC-in-GitHub" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="arize phoenix - detect info identify web-based control panels arize phoenix is an open-source ai observability and evaluation platform for monitoring,
debugging, and evaluating llm applications. rxerium ai arize detect discovery llm observability panel phoenix" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Arize Phoenix - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/arize-phoenix-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">arize-phoenix-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 27, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches `(?i)Arize Phoenix`</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Arize Phoenix is an open-source AI observability and evaluation platform for monitoring,
debugging, and evaluating LLM applications.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">ai</span><span class="nt-tag">arize</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">llm</span><span class="nt-tag">observability</span><span class="nt-tag">panel</span><span class="nt-tag">phoenix</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/Arize-ai/phoenix" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://phoenix.arize.com" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="artica pandora fms 7.44 - remote code execution high identify critical remote vulnerabilities artica pandora fms 7.44 allows remote command execution via the events feature. cve-2020-13851 theamanrawat artica cve cve2020 packetstorm pandora pandorafms rce unauth vkev vuln cwe-78" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Artica Pandora FMS 7.44 - Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2020/CVE-2020-13851.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2020-13851.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> theamanrawat</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 17, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/78.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-78</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2020-13851" target="_blank" rel="noopener" class="nt-cve-link">CVE-2020-13851</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)pandora fms&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Artica Pandora FMS 7.44 allows remote command execution via the events feature.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can execute arbitrary system commands via the events feature, leading to complete server compromise and access to all monitoring data.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to Pandora FMS version 7.45 or later, or apply vendor-provided security patches.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">artica</span><span class="nt-tag">cve</span><span class="nt-tag">cve2020</span><span class="nt-tag">packetstorm</span><span class="nt-tag">pandora</span><span class="nt-tag">pandorafms</span><span class="nt-tag">rce</span><span class="nt-tag">unauth</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://packetstormsecurity.com/files/158390/Pandora-FMS-7.0-NG-7XX-Remote-Command-Execution.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2020-13851" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.coresecurity.com/advisories" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/hadrian3689/pandorafms_7.44" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="artica pandora fms &lt;=7.42 - arbitrary file read medium identify critical remote vulnerabilities artica pandora fms through 7.42 is susceptible to arbitrary file read. an attacker can read the chat history, which is in json format and contains user names, user ids, private messages, and timestamps. this can potentially lead to unauthorized data modification and other operations. cve-2020-8497 gy741 artica cve cve2020 fms vkev vuln cwe-306" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Artica Pandora FMS &lt;=7.42 - Arbitrary File Read</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2020/CVE-2020-8497.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2020-8497.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> gy741</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/306.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-306</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2020-8497" target="_blank" rel="noopener" class="nt-cve-link">CVE-2020-8497</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)pandora fms&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Artica Pandora FMS through 7.42 is susceptible to arbitrary file read. An attacker can read the chat history, which is in JSON format and contains user names, user IDs, private messages, and timestamps. This can potentially lead to unauthorized data modification and other operations.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can exploit this vulnerability to gain unauthorized access to sensitive information, potentially leading to further compromise of the system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade Artica Pandora FMS to version 7.43 or later to mitigate this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">artica</span><span class="nt-tag">cve</span><span class="nt-tag">cve2020</span><span class="nt-tag">fms</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://k4m1ll0.com/cve-2020-8497.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2020-8497" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/ARPSyndicate/cvemon" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/ARPSyndicate/kenzer-templates" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="artica proxy - unauthenticated lfi high identify critical remote vulnerabilities the artica proxy administrative web application will deserialize arbitrary php objects supplied by unauthenticated users and subsequently enable code execution as the &#34;www-data&#34; user. this issue was demonstrated on version 4.50 of the the artica-proxy administrative web application attempts to prevent local file inclusion. these protections can be bypassed and arbitrary file requests supplied by unauthenticated users will be returned according to the privileges of the &#34;www-data&#34; user. cve-2024-2053 pussycat0x artica-proxy articatech cve cve2024 lfi vkev vuln cwe-23" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Artica Proxy - Unauthenticated LFI</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-2053.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-2053.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 30, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/23.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-23</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-2053" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-2053</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)artica&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The Artica Proxy administrative web application will deserialize arbitrary PHP objects supplied by unauthenticated users and subsequently enable code execution as the &#34;www-data&#34; user. This issue was demonstrated on version 4.50 of the The Artica-Proxy administrative web application attempts to prevent local file inclusion. These protections can be bypassed and arbitrary file requests supplied by unauthenticated users will be returned according to the privileges of the &#34;www-data&#34; user.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can read arbitrary files on the server including configuration files with credentials and other sensitive data.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update Artica Proxy to a version newer than 4.50.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">artica-proxy</span><span class="nt-tag">articatech</span><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">lfi</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/0xMarcio/cve/blob/main/2024/CVE-2024-2053.md#cve-2024-2053" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://seclists.org/fulldisclosure/2024/Mar/11" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://korelogic.com/Resources/Advisories/KL-001-2024-001.txt" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="artica proxy 4.30.000000 - cross-site scripting medium identify critical remote vulnerabilities artica proxy 4.30.000000 contains a cross-site scripting vulnerability via the password parameter in /fw.login.php. cve-2022-37153 arafatansari artica articatech cve cve2022 vkev vuln xss cwe-79" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Artica Proxy 4.30.000000 - Cross-Site Scripting</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-37153.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-37153.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> arafatansari</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-79</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-37153" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-37153</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Artica&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Artica Proxy 4.30.000000 contains a cross-site scripting vulnerability via the password parameter in /fw.login.php.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can inject malicious JavaScript through the password parameter in the Artica Proxy login page that reflects back to users, potentially stealing credentials or session tokens when victims submit the login form.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to a patched version of Artica Proxy or apply the vendor-supplied patch to mitigate the vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">artica</span><span class="nt-tag">articatech</span><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">xss</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/Fjowel/CVE-2022-37153" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-37153" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/SYRTI/POC_to_review" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/WhooAmii/POC_to_review" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/k0mi-tg/CVE-POC" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="artica proxy community edition &lt;4.30.000000 - local file inclusion high identify critical remote vulnerabilities artica proxy community edition before 4.30.000000 is vulnerable to local file inclusion via the fw.progrss.details.php popup parameter. cve-2020-13158 0x_akoko artica articatech cve cve2020 lfi vkev vuln cwe-22" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Artica Proxy Community Edition &lt;4.30.000000 - Local File Inclusion</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2020/CVE-2020-13158.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2020-13158.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_Akoko</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2020-13158" target="_blank" rel="noopener" class="nt-cve-link">CVE-2020-13158</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)artica&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Artica Proxy Community Edition before 4.30.000000 is vulnerable to local file inclusion via the fw.progrss.details.php popup parameter.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to read arbitrary files on the server, potentially leading to further compromise of the system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to Artica Proxy Community Edition version 4.30.000000 or later to fix the Local File Inclusion vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">artica</span><span class="nt-tag">articatech</span><span class="nt-tag">cve</span><span class="nt-tag">cve2020</span><span class="nt-tag">lfi</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/InfoSec4Fun/CVE-2020-13158" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://sourceforge.net/projects/artica-squid/files/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2020-13158" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/nomi-sec/PoC-in-GitHub" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/soosmile/POC" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="aruba instant - default login high identify default logins in web-based control panels aruba instant is an ap device. the device has a default password, and attackers can control the entire platform through the default password admin/admin vulnerability, and use administrator privileges to operate core functions. sleepingbag945 aruba default-login vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Aruba Instant - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/others/aruba-instant-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">aruba-instant-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> SleepingBag945</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 8, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)jscripts/third_party/raphael-treemap\\.min\\.js&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Aruba Instant is an AP device. The device has a default password, and attackers can control the entire platform through the default password admin/admin vulnerability, and use administrator privileges to operate core functions.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">aruba</span><span class="nt-tag">default-login</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.192-168-1-1-ip.co/aruba-networks/routers/179/#:~:text=The%20default%20username%20for%20your,control%20panel%20of%20your%20router." target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="astrbot - default login high identify default logins in web-based control panels astrbot contains a default login vulnerability. an attacker can access the astrbot dashboard using default credentials and gain control over the chatbot framework, modify configurations, manage llm providers, and execute unauthorized operations. theamanrawat astrbot default-login cwe-798" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">AstrBot - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/astrbot-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">astrbot-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> theamanrawat</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 14, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/798.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-798</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)AstrBot&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">AstrBot contains a default login vulnerability. An attacker can access the AstrBot dashboard using default credentials and gain control over the chatbot framework, modify configurations, manage LLM providers, and execute unauthorized operations.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">astrbot</span><span class="nt-tag">default-login</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/Soulter/AstrBot" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="astrbot webui login panel - detect info identify web-based control panels astrbot webui login panel was detected. theamanrawat astrbot login panel" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">AstrBot WebUI Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/astrbot-panel-detect.yaml" target="_blank" rel="noopener" class="nt-source-link">astrbot-panel-detect.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> theamanrawat</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 14, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)AstrBot&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Astrbot WebUI login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">astrbot</span><span class="nt-tag">login</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/AstrBotDevs/AstrBot" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="astro - information disclosure medium identify critical remote vulnerabilities astro versions v5.0.3 through v5.0.7 and astro v4.16.17 or older with sourcemaps enabled contain a source code disclosure caused by sourcemap files being publicly accessible in the build output folder, letting unauthenticated users read server source code, exploit requires sourcemaps to be enabled. cve-2024-56159 theamanrawat astro cve cve2024 exposure sourcemap vkev cwe-219" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Astro - Information Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-56159.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-56159.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> theamanrawat</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 14, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/219.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-219</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-56159" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-56159</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)astro&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Astro versions v5.0.3 through v5.0.7 and Astro v4.16.17 or older with sourcemaps enabled contain a source code disclosure caused by sourcemap files being publicly accessible in the build output folder, letting unauthenticated users read server source code, exploit requires sourcemaps to be enabled.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated users can access server source code, potentially leading to discovery of further vulnerabilities or sensitive information.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update Astro to version 5.0.8 or later for server-output projects, and to 5.0.9 or later (or 4.16.18 for Astro v4) for static-output projects with sourcemaps enabled.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">astro</span><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">exposure</span><span class="nt-tag">sourcemap</span><span class="nt-tag">vkev</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/withastro/astro/security/advisories/GHSA-49w6-73cw-chjr" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-56159" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="astro - reflected xss via server islands feature high identify critical remote vulnerabilities astro 5.15.8 contains a reflected xss caused by improper handling of server islands feature, letting remote attackers execute scripts, exploit requires use of server islands in the application. cve-2025-64764 dhiyaneshdk,zhero___ astro cve cve2025 vkev xss cwe-80" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Astro - Reflected XSS via server islands feature</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-64764.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-64764.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk,zhero___</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 21, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/80.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-80</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-64764" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-64764</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)_server-islands&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Astro 5.15.8 contains a reflected XSS caused by improper handling of server islands feature, letting remote attackers execute scripts, exploit requires use of server islands in the application.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Remote attackers can execute scripts in users&#39; browsers, potentially leading to session hijacking or data theft.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to version 5.15.8 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">astro</span><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">vkev</span><span class="nt-tag">xss</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://zhero-web-sec.github.io/research-and-things/unlocking-reflected-xss-in-the-astro-framework" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="atarim &lt; 4.2.2 - sensitive information exposure high identify critical remote vulnerabilities vito peleg atarim &lt;= 4.2 contains an insertion of sensitive information into sent data vulnerability caused by improper handling of embedded sensitive data, letting attackers retrieve embedded sensitive data remotely, exploit requires no special privileges. cve-2025-60188 m4sh_wacker cve cve2025 wordpress wp-plugin atarim exposure cwe-201" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Atarim &lt; 4.2.2 - Sensitive Information Exposure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-60188.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-60188.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> m4sh_wacker</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 8, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/201.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-201</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-60188" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-60188</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)atarim&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Vito Peleg Atarim &lt;= 4.2 contains an insertion of sensitive information into sent data vulnerability caused by improper handling of embedded sensitive data, letting attackers retrieve embedded sensitive data remotely, exploit requires no special privileges.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can retrieve embedded sensitive data, potentially leading to information disclosure.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest version beyond 4.2.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">atarim</span><span class="nt-tag">exposure</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/m4sh-wacker/CVE-2025-60188-Atarim-Plugin-Exploit" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="atlantis panel - detect info identify web-based control panels atlantis panel was detected. jonathanwalker panel atlantis runatlantis discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Atlantis Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/atlantis-detect.yaml" target="_blank" rel="noopener" class="nt-source-link">atlantis-detect.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> jonathanwalker</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-1706783005&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Atlantis panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">atlantis</span><span class="nt-tag">runatlantis</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/runatlantis/atlantis" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="atlassian bamboo login panel - detect info identify web-based control panels atlassian bamboo login panel was detected. righettod panel bamboo login detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Atlassian Bamboo Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/atlassian-bamboo-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">atlassian-bamboo-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 10, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Bamboo&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Atlassian Bamboo login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">bamboo</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.atlassian.com/software/bamboo" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="atlassian confluence end-of-life - detect info identify web-based control panels detected atlassian confluence instances versions that have reached end-of-life (eol) and no longer receive security updates. shivam kamboj tech confluence eol" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Atlassian Confluence End-of-Life - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/technologies/eol/confluence-eol.yaml" target="_blank" rel="noopener" class="nt-source-link">confluence-eol.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Shivam Kamboj</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 15, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;product&#34;] contains &#34;Atlassian:Confluence&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detected Atlassian Confluence instances versions that have reached End-of-Life (EOL) and no longer receive security updates.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">tech</span><span class="nt-tag">confluence</span><span class="nt-tag">eol</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://endoflife.date/confluence" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://confluence.atlassian.com/support/atlassian-support-end-of-life-policy-201851003.html" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="atlassian jira server-side template injection critical identify critical remote vulnerabilities jira server and data center is susceptible to a server-side template injection vulnerability via the contactadministrators and sendbulkmail actions. an attacker is able to remotely execute code on systems that run a vulnerable version of jira server or data center. all versions of jira server and data center from 4.4.0 before 7.6.14, from 7.7.0 before 7.13.5, from 8.0.0 before 8.0.3, from 8.1.0 before 8.1.2, and from 8.2.0 before 8.2.3 are affected by this vulnerability. cve-2019-11581 ree4pwn atlassian cve cve2019 jira kev rce ssti vkev vuln cwe-74" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Atlassian Jira Server-Side Template Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2019/CVE-2019-11581.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2019-11581.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ree4pwn</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/74.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-74</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2019-11581" target="_blank" rel="noopener" class="nt-cve-link">CVE-2019-11581</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches `(?i)^system\s+dashboard\s+-\s+`}) || service[&#34;favicon.ico.image.md5&#34;] matches `(?i)^(1391664373e72311a656c4a5504682af|88717398db158e3330ce94fc1784e4a7|04d89d5b7a290334f5ce37c7e8b6a349|08aa365c2d0863df2735d386f77c22c2)$`</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Jira Server and Data Center is susceptible to a server-side template injection vulnerability via the ContactAdministrators and SendBulkMail actions. An attacker is able to remotely execute code on systems that run a vulnerable version of Jira Server or Data Center. All versions of Jira Server and Data Center from 4.4.0 before 7.6.14, from 7.7.0 before 7.13.5, from 8.0.0 before 8.0.3, from 8.1.0 before 8.1.2, and from 8.2.0 before 8.2.3 are affected by this vulnerability.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability can lead to remote code execution, compromising the confidentiality, integrity, and availability of the affected system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the necessary security patches or upgrade to a fixed version provided by Atlassian to mitigate this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">atlassian</span><span class="nt-tag">cve</span><span class="nt-tag">cve2019</span><span class="nt-tag">jira</span><span class="nt-tag">kev</span><span class="nt-tag">rce</span><span class="nt-tag">ssti</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/jas502n/CVE-2019-11581" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://jira.atlassian.com/browse/JRASERVER-69532" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2019-11581" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/0x48piraj/jiraffe" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/bakery312/Vulhub-Reproduce" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="atlassian questions for confluence - hardcoded credentials critical identify critical remote vulnerabilities atlassian questions for confluence contains a hardcoded credentials vulnerability. when installing versions 2.7.34, 2.7.35, and 3.0.2, a confluence user account is created in the confluence-users group with the username disabledsystemuser and a hardcoded password. a remote, unauthenticated attacker with knowledge of the hardcoded password can exploit this vulnerability to log into confluence and access all content accessible to users in the confluence-users group. cve-2022-26138 httpvoid atlassian confluence cve cve2022 default-login kev vkev vuln cwe-798" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Atlassian Questions For Confluence - Hardcoded Credentials</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-26138.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-26138.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> HTTPVoid</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/798.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-798</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-26138" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-26138</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)confluence&#34;}) || service[&#34;favicon.ico.image.md5&#34;] matches `(?i)^(bad2c1f96cd66e70b4aa119e7270cc62|966e60f8eb85b7ea43a7b0095f3e2336)$`</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Atlassian Questions For Confluence contains a hardcoded credentials vulnerability. When installing versions 2.7.34, 2.7.35, and 3.0.2, a Confluence user account is created in the confluence-users group with the username disabledsystemuser and a hardcoded password. A remote, unauthenticated attacker with knowledge of the hardcoded password can exploit this vulnerability to log into Confluence and access all content accessible to users in the confluence-users group.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability can lead to unauthorized access to sensitive information and potential compromise of the Confluence instance.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update the Atlassian Questions For Confluence plugin to the latest version, which removes the hardcoded credentials.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">atlassian</span><span class="nt-tag">confluence</span><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">default-login</span><span class="nt-tag">kev</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://twitter.com/fluepke/status/1549892089181257729" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://confluence.atlassian.com/doc/questions-for-confluence-security-advisory-2022-07-20-1142446709.html" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://confluence.atlassian.com/doc/confluence-security-advisory-2022-07-20-1142446709.html" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-26138" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://jira.atlassian.com/browse/CONFSERVER-79483" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="atom.cms 2.0 - sql injection critical identify critical remote vulnerabilities atom.cms 2.0 is vulnerable to sql injection via atom.cms_admin_uploads.php which allows an attacker to execute arbitrary sql commands. cve-2022-28033 ritikchaddha atom cms cve cve2022 sqli vuln cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Atom.CMS 2.0 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-28033.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-28033.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 6, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-28033" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-28033</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)atomcms&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Atom.CMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_uploads.php which allows an attacker to execute arbitrary SQL commands.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation could lead to unauthorized access, data leakage, and potential data manipulation.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches provided by the vendor to mitigate the SQL Injection vulnerability in Atom.CMS 2.0.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">atom</span><span class="nt-tag">cms</span><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">sqli</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/thedigicraft/Atom.CMS/issues/259" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-28033" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="audiocodes 310hd, 320hd, 420hd, 430hd &amp; 440hd - default login high identify default logins in web-based control panels audiocodes devices 310hd, 320hd, 420hd, 430hd &amp; 440hd contain a default login vulnerability. default login credentials were discovered. an attacker can obtain access to user accounts and access sensitive information, modify data, and/or execute unauthorized operations. d4vy audiocodes default-login iot vuln cwe-798" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">AudioCodes 310HD, 320HD, 420HD, 430HD &amp; 440HD - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/audiocodes/audiocodes-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">audiocodes-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> d4vy</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/798.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-798</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.head.server&#34;] contains &#34;AudioCodes Web Server&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">AudioCodes devices 310HD, 320HD, 420HD, 430HD &amp; 440HD contain a default login vulnerability. Default login credentials were discovered. An attacker can obtain access to user accounts and access sensitive information, modify data, and/or execute unauthorized operations.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">audiocodes</span><span class="nt-tag">default-login</span><span class="nt-tag">iot</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wiki.freepbx.org/display/FPG/Supported+Devices-Audio+Codes#:~:text=Reset%20to%20Factory%20Defaults,-Press%20the%20Menu&amp;text=Then%2C%20enter%20the%20Admin%20password,is%20%221234%22%20by%20default" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="audiocodes device manager express - sql injection critical identify critical remote vulnerabilities an issue was discovered in audiocodes device manager express through 7.8.20002.47752. it is an unauthenticated sql injection in the p parameter of the process_login.php login form. cve-2022-24627 geeknik audiocodes cve cve2022 seclists sqli vuln cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">AudioCodes Device Manager Express - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-24627.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-24627.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> geeknik</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 12, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-24627" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-24627</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)audiocodes&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. It is an unauthenticated SQL injection in the p parameter of the process_login.php login form.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can exploit SQL injection in the login form to bypass authentication, extract sensitive VoIP configuration data, and potentially gain administrative access to the AudioCodes Device Manager system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update AudioCodes Device Manager Express to a version newer than 7.8.20002.47752 that uses parameterized queries and properly validates input.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">audiocodes</span><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">seclists</span><span class="nt-tag">sqli</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://seclists.org/fulldisclosure/2023/Feb/12" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-24627" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/tr3ss/newclei" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="audiocodes login - panel detect info identify web-based control panels audiocodes login panel was detected. princechaddha audiocodes discovery panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">AudioCodes Login - Panel Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/audiocodes-detect.yaml" target="_blank" rel="noopener" class="nt-source-link">audiocodes-detect.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> princechaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Audiocodes&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">AudioCodes login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">audiocodes</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="audiobookshelf login panel - detect info identify web-based control panels  ritikchaddha audiobookshelf detect discovery panel" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Audiobookshelf Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/audiobookshelf-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">audiobookshelf-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 9, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Audiobookshelf&#34;})</code></div>
  <div class="nt-tags"><span class="nt-tag">audiobookshelf</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/advplyr/audiobookshelf" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="aurelia-path &lt; 1.1.7 - prototype pollution high identify critical remote vulnerabilities aurelia-path before 1.1.7 contains a prototype pollution caused by parsing malicious url parameters, letting attackers modify object.prototype, exploit requires the application to parse user-controlled urls. cve-2021-41097 0x_akoko aurelia cve cve2021 javascript passive prototype-pollution cwe-1321" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Aurelia-Path &lt; 1.1.7 - Prototype Pollution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2021/CVE-2021-41097.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2021-41097.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_Akoko</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 28, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/1321.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-1321</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2021-41097" target="_blank" rel="noopener" class="nt-cve-link">CVE-2021-41097</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;product&#34;] contains &#34;Blue Spire:Aurelia&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Aurelia-path before 1.1.7 contains a prototype pollution caused by parsing malicious URL parameters, letting attackers modify Object.prototype, exploit requires the application to parse user-controlled URLs.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Update to version 1.1.7 or later.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Aurelia-path parseQueryString function was found vulnerable to prototype pollution via crafted __proto__ URL parameters.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">aurelia</span><span class="nt-tag">cve</span><span class="nt-tag">cve2021</span><span class="nt-tag">javascript</span><span class="nt-tag">passive</span><span class="nt-tag">prototype-pollution</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/aurelia/path/issues/44" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://security.snyk.io/vuln/SNYK-JS-AURELIAPATH-1579475" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2021-41097" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="authelia panel - detect info identify web-based control panels authelia is an open-source authentication and authorisation service providing two-factor authentication and single sign-on (sso) for applications via a web portal. rxerium login panel authelia discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Authelia Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/authelia-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">authelia-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 27, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Login - Authelia&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Authelia is an open-source authentication and authorisation service providing two-factor authentication and single sign-on (SSO) for applications via a web portal.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">login</span><span class="nt-tag">panel</span><span class="nt-tag">authelia</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/authelia/authelia" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.authelia.com/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="authentik panel - detect info identify web-based control panels an authentik search engine was detected. rxerium authentik sso mfa panel detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Authentik Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/authentik-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">authentik-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 9, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-178113786&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An Authentik search engine was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">authentik</span><span class="nt-tag">sso</span><span class="nt-tag">mfa</span><span class="nt-tag">panel</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/goauthentik/authentik" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="autoset page - detect info identify web-based control panels  mastercho tech php autoset apache panel discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">AutoSet Page - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/autoset-detect.yaml" target="_blank" rel="noopener" class="nt-source-link">autoset-detect.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> MaStErCho</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 31, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)AutoSet&#34;})</code></div>
  <div class="nt-tags"><span class="nt-tag">tech</span><span class="nt-tag">php</span><span class="nt-tag">autoset</span><span class="nt-tag">apache</span><span class="nt-tag">panel</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="http://autoset.net/xe/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="automation by autonami &lt; 3.3.0 - sql injection high identify critical remote vulnerabilities the recover woocommerce cart abandonment, newsletter, email marketing, marketing automation by funnelkit wordpress plugin before 3.3.0 does not sanitize and escape the bwfan-track-id  parameter before using it in a sql statement, allowing unauthenticated users to perform sql injection attacks. cve-2024-9186 s4e-io cve cve2024 sqli time-based-sqli vuln wordpress wp wp-marketing-automations wp-plugin cwe-89" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Automation By Autonami &lt; 3.3.0 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-9186.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-9186.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> s4e-io</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 28, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-9186" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-9186</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)wp-content/plugins/wp-marketing-automations/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit WordPress plugin before 3.3.0 does not sanitize and escape the bwfan-track-id  parameter before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can exploit time-based SQL injection through the bwfan-track-id parameter to extract sensitive database information including user credentials, email addresses, WooCommerce customer data, and marketing automation information.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Fixed in 3.3.0</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">sqli</span><span class="nt-tag">time-based-sqli</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-marketing-automations</span><span class="nt-tag">wp-plugin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wpscan.com/vulnerability/fab29b59-7e87-4289-88dd-ed5520260c26/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-9186" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="automatisch panel - detect info identify web-based control panels the open source zapier alternative. rxerium panel automatisch detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Automatisch Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/automatisch-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">automatisch-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 27, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Automatisch&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The open source Zapier alternative.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">automatisch</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://automatisch.io/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/automatisch/automatisch" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="avantfax login panel info identify web-based control panels an avantfax login panel was discovered. pikpikcu,daffainfo avantfax discovery login panel cwe-668" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">AvantFAX Login Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/avantfax-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">avantfax-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pikpikcu,daffainfo</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/668.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-668</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)avantfax - login&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An AvantFAX login panel was discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">avantfax</span><span class="nt-tag">discovery</span><span class="nt-tag">login</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="http://www.avantfax.com/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="avatier password management panel info identify web-based control panels an avatier password management panel was detected. praetorian-thendrickson,iamthefrogy,dhiyaneshdk edb panel avatier aims discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Avatier Password Management Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/avatier-password-management.yaml" target="_blank" rel="noopener" class="nt-source-link">avatier-password-management.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> praetorian-thendrickson,iamthefrogy,dhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;983734701&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An Avatier password management panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">edb</span><span class="nt-tag">panel</span><span class="nt-tag">avatier</span><span class="nt-tag">aims</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.exploit-db.com/ghdb/6576" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.avatier.com/products/identity-management/password-management/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="avaya phone web interface - default login high identify default logins in web-based control panels avaya phone web interface contains a default login vulnerability. an attacker can obtain access to sensitive information, modify data, and/or execute unauthorized operations. tpierru avaya default-login misconfig cwe-1392" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Avaya Phone Web Interface - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/avaya-phone-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">avaya-phone-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> tpierru</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 23, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/1392.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-1392</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches `(?i)Avaya J1\d9 Phone`</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Avaya phone web interface contains a default login vulnerability. An attacker can obtain access to sensitive information, modify data, and/or execute unauthorized operations.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">avaya</span><span class="nt-tag">default-login</span><span class="nt-tag">misconfig</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://documentation.avaya.com/bundle/InstallandadminJ100seriesIPPhone_r4.1.x/page/Logging_into_web_UI.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="aviatrix cloud controller panel info identify web-based control panels an aviatrix cloud controller login panel was detected. pikpikcu,philippedelteil,daffainfo aviatrix discovery panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Aviatrix Cloud Controller Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/aviatrix-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">aviatrix-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pikpikcu,philippedelteil,daffainfo</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)aviatrix cloud controller&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An Aviatrix Cloud Controller login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">aviatrix</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://docs.aviatrix.com/HowTos/controller_config.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="avigilon login panel - detect info identify web-based control panels avigilon login panel was detected. robotshell avigilon discovery panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Avigilon Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/avigilon-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">avigilon-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> robotshell</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)login - avigilon control center&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Avigilon login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">avigilon</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="avtech avn801 network camera admin panel - detect info identify web-based control panels an avtech avn801 network camera administration panel was detected. idealphase panel avtech iot camera discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Avtech AVN801 Network Camera Admin Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/avtech-avn801-camera-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">avtech-avn801-camera-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> idealphase</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches `(?i):::\s+login\s+:::`})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An Avtech AVN801 Network Camera administration panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">avtech</span><span class="nt-tag">iot</span><span class="nt-tag">camera</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="http://www.avtech.com.tw" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="axel webserver - panel detect info identify web-based control panels axel webserver panel was detected. pikpikcu panel axel webserver discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Axel WebServer - Panel Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/axel-webserver.yaml" target="_blank" rel="noopener" class="nt-source-link">axel-webserver.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pikpikcu</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Axel&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Axel WebServer panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">axel</span><span class="nt-tag">webserver</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="axigen web admin detection info identify web-based control panels an axigen web admin panel was discovered. dhiyaneshdk axigen discovery panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Axigen Web Admin Detection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/axigen-webadmin.yaml" target="_blank" rel="noopener" class="nt-source-link">axigen-webadmin.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Axigen\u00a0WebAdmin&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An Axigen Web Admin panel was discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">axigen</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.axigen.com/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="axigen webmail paneldetection info identify web-based control panels an axigen webmail panel was discovered. dhiyaneshdk,idealphase axigen discovery panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Axigen WebMail PanelDetection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/axigen-webmail.yaml" target="_blank" rel="noopener" class="nt-source-link">axigen-webmail.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDk,idealphase</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Axigen WebMail&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An Axigen webmail panel was discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">axigen</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.axigen.com/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="axway api manager panel - detect info identify web-based control panels axway api manager panel was detected. johnk3r,righettod panel axway detect login discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Axway API Manager Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/axway-api-manager-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">axway-api-manager-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> johnk3r,righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 25, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Axway API Manager Login&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Axway API Manager panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">axway</span><span class="nt-tag">detect</span><span class="nt-tag">login</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://docs.axway.com/bundle/axway-open-docs/page/docs/index.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.postman.com/api-evangelist/axway/api/06c40de2-3954-4c68-ae10-a7eded330b05" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.postman.com/api-evangelist/axway/api/ce2ac156-4353-46b9-b148-944ab7721ed6" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="axway securetransport login panel - detect info identify web-based control panels axway securetransport login panel was detected. righettod axway discovery panel securetransport cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Axway SecureTransport Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/axway-securetransport-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">axway-securetransport-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)securetransport&#34;}) || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)st web client&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">AXWAY SecureTransport login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">axway</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">securetransport</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.axway.com/en/products/managed-file-transfer/securetransport" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="axway securetransport web client panel - detect info identify web-based control panels axway secure transport web client panel was detected. righettod axway discovery panel securetransport webclient cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Axway SecureTransport Web Client Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/axway-securetransport-webclient.yaml" target="_blank" rel="noopener" class="nt-source-link">axway-securetransport-webclient.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)st web client&#34;}) || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)securetransport&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">AXWAY Secure Transport Web Client panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">axway</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">securetransport</span><span class="nt-tag">webclient</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.axway.com/en/products/managed-file-transfer/securetransport" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="axxon next client login - detect info identify web-based control panels axxon one is a limitlessly scalable video management software irshadahamed axxon axxonsoft detect discovery login panel vms cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Axxon Next Client Login - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/axxon-client-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">axxon-client-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> irshadahamed</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 22, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)axxon next client&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Axxon One is a limitlessly scalable video management software</div></div></div>
  <div class="nt-tags"><span class="nt-tag">axxon</span><span class="nt-tag">axxonsoft</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">login</span><span class="nt-tag">panel</span><span class="nt-tag">vms</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.axxonsoft.com/products/video-management-software" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="azkaban web client info identify web-based control panels an azkaban web client panel was discovered. dhiyaneshdk azkaban discovery panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Azkaban Web Client</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/azkaban-web-client.yaml" target="_blank" rel="noopener" class="nt-source-link">azkaban-web-client.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Azkaban Web Client&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An Azkaban web client panel was discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">azkaban</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://azkaban.github.io/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="azkaban web client default credential high identify default logins in web-based control panels azkaban is a batch workflow job scheduler created at linkedin to run hadoop jobs.  default web client credentials were discovered. pussycat0x azkaban default-login vuln cwe-798" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Azkaban Web Client Default Credential</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/azkaban/azkaban-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">azkaban-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/798.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-798</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;Azkaban Web Client&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Azkaban is a batch workflow job scheduler created at LinkedIn to run Hadoop jobs.  Default web client credentials were discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">azkaban</span><span class="nt-tag">default-login</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="bedita login panel - detect info identify web-based control panels bedita login panel was detected. pikpikcu,daffainfo bedita discovery panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">BEdita Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/bedita-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">bedita-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pikpikcu,daffainfo</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)bedita&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">BEdita login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">bedita</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.bedita.com/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="bmc control-m mft login panel - detect info identify web-based control panels bmc control-m mft products was detected. righettod panel bmc login detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">BMC Control-M MFT Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/bmc/bmc-controlm-mft-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">bmc-controlm-mft-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 17, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)File Exchange&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">BMC Control-M MFT products was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">bmc</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://documents.bmc.com/supportu/9.0.21/en-US/Documentation/Managed_File_Transfer.htm" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://documents.bmc.com/supportu/9.0.21/en-US/Documentation/home.htm" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="bmc discovery login panel - detect info identify web-based control panels bmc discovery login panel was detected. daffainfo panel bmc discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">BMC Discovery Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/bmc/bmc-discovery-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">bmc-discovery-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> daffainfo</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)BMC Software&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">BMC Discovery login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">bmc</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://docs.bmc.com/docs/discovery/documentation-home-1098837931.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="bmc footprints - authentication bypass medium identify critical remote vulnerabilities bmc footprints versions 20.20.02 through 20.24.01.001 contain an authentication bypass vulnerability in the password reset functionality. unauthenticated attackers can access the /footprints/servicedesk/passwordreset/request/ endpoint to obtain a valid sec_token session cookie without proper authentication. this vulnerability enables exploitation of other vulnerabilities in the chain including cve-2025-71258 and cve-2025-71259 (ssrf) and cve-2025-71260 (deserialization rce). cve-2025-71257 watchtowr,dhiyaneshdk auth-bypass bmc bmc-software cve cve2025 footprints servicedesk vkev cwe-287" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">BMC FootPrints - Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-71257.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-71257.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> watchTowr,DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 18, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/287.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-287</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-71257" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-71257</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/footprints/servicedesk/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">BMC FootPrints versions 20.20.02 through 20.24.01.001 contain an authentication bypass vulnerability in the password reset functionality. Unauthenticated attackers can access the /footprints/servicedesk/passwordreset/request/ endpoint to obtain a valid SEC_TOKEN session cookie without proper authentication. This vulnerability enables exploitation of other vulnerabilities in the chain including CVE-2025-71258 and CVE-2025-71259 (SSRF) and CVE-2025-71260 (deserialization RCE).</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can bypass access controls to access and modify application data and system resources.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the hotfixes released by BMC on September 2, 2025 for all affected branches. Update to the latest patched version of BMC FootPrints.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">bmc</span><span class="nt-tag">bmc-software</span><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">footprints</span><span class="nt-tag">servicedesk</span><span class="nt-tag">vkev</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://labs.watchtowr.com/thanks-itsms-threat-actors-have-never-been-so-organized-bmc-footprints-pre-auth-remote-code-execution-chains/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://docs.bmc.com/xwiki/bin/view/More-Products/Footprints/FootPrints/fp2024/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="bmc remedy sso login panel - detect info identify web-based control panels bmc remedy single sign-on domain data entry login panel was detected. righettod panel bmc login detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">BMC Remedy SSO Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/bmc/bmc-remedy-sso-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">bmc-remedy-sso-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 21, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)BMC Remedy Single Sign-On domain data entry&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">BMC Remedy Single Sign-On domain data entry login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">bmc</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.bmc.com/it-solutions/remedy-itsm.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="barco clickshare - default login high identify default logins in web-based control panels barco clickshare contains a default login vulnerability. default login password &#39;admin&#39; was found. ritikchaddha barco clickshare default-login vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Barco ClickShare - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/barco-clickshare-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">barco-clickshare-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 11, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.head.setCookie&#34;] contains &#34;ClickShareSession&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Barco ClickShare contains a default login vulnerability. Default login password &#39;admin&#39; was found.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">barco</span><span class="nt-tag">clickshare</span><span class="nt-tag">default-login</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="barracuda message archiver - panel detect info identify web-based control panels barracuda networks barracuda message archiver (bma) panel was detected. inokii barracuda panel login discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Barracuda Message Archiver - Panel Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/barracuda-message-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">barracuda-message-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> inokii</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 15, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1436966696&#34; || any([service[&#34;http.body&#34;], service[&#34;last.http.body&#34;]], {# matches &#34;/css/archiver.css&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Barracuda Networks Barracuda Message Archiver (BMA) panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">barracuda</span><span class="nt-tag">panel</span><span class="nt-tag">login</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.barracuda.com/products/email-protection/message-archiver" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="baserow login - panel detect info identify web-based control panels baserow login interface was discovered. th3l0newolf baserow discovery login panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Baserow Login - Panel Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/baserow-login-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">baserow-login-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Th3l0newolf</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 2, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches `^Login \/\/ Baserow`})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Baserow login interface was discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">baserow</span><span class="nt-tag">discovery</span><span class="nt-tag">login</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="batflat cms - default login high identify default logins in web-based control panels batflat cms is vulnerable to default login vulnerability that most commonly affects devices having some pre-set (default) administrative credentials to access all configuration settings. r3y3r53 batflat default-login vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Batflat CMS - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/batflat/batflat-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">batflat-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> r3Y3r53</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 17, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] contains &#34;Powered by Batflat&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Batflat CMS is vulnerable to default login vulnerability that most commonly affects devices having some pre-set (default) administrative credentials to access all configuration settings.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">batflat</span><span class="nt-tag">default-login</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.exploitalert.com/view-details.html?id=34749" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://cxsecurity.com/issue/WLB-2020010100" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="bazarr &lt; 1.4.3 - arbitrary file read high identify critical remote vulnerabilities bazarr 1.4.3 and earlier versions have a arbitrary file read vulnerability. cve-2024-40348 s4e-io bazarr cve cve2024 lfi vuln cwe-22" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Bazarr &lt; 1.4.3 - Arbitrary File Read</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-40348.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-40348.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> s4e-io</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 22, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-40348" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-40348</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Bazarr&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Bazarr 1.4.3 and earlier versions have a arbitrary file read vulnerability.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can read arbitrary files from the Bazarr server via path traversal.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update Bazarr to version 1.4.4 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">bazarr</span><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">lfi</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/4rdr/proofs/blob/main/info/Bazaar_1.4.3_File_Traversal_via_Filename.md" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.bazarr.media/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/bigb0x/CVE-2024-40348" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="beckhoff twincat hmi server - login panel info identify web-based control panels beckhoff twincat hmi (human machine interface) server is part of the twincat
industrial automation platform used in manufacturing, robotics, and process
automation. it exposes a web-based hmi accessible via browser for monitoring
and controlling plc-driven systems. rxerium automation beckhoff discovery hmi ics panel plc scada twincat" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Beckhoff TwinCAT HMI Server - Login Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/beckhoff-twincat-hmi-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">beckhoff-twincat-hmi-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 27, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)TwinCAT&#34; &amp;&amp; service[&#34;http.body&#34;] matches &#34;(?i)Beckhoff&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Beckhoff TwinCAT HMI (Human Machine Interface) Server is part of the TwinCAT
industrial automation platform used in manufacturing, robotics, and process
automation. It exposes a web-based HMI accessible via browser for monitoring
and controlling PLC-driven systems.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">automation</span><span class="nt-tag">beckhoff</span><span class="nt-tag">discovery</span><span class="nt-tag">hmi</span><span class="nt-tag">ics</span><span class="nt-tag">panel</span><span class="nt-tag">plc</span><span class="nt-tag">scada</span><span class="nt-tag">twincat</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.beckhoff.com/en-en/products/automation/twincat/te2xxx-twincat-3-target/te2000.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://infosys.beckhoff.com/english.php?content=../content/1033/te2000_tc3_hmi_engineering/index.html" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="beego admin dashboard panel- detect medium identify web-based control panels beego admin dashboard panel was detected. dhiyaneshdk beego discovery panel unauth cwe-200" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Beego Admin Dashboard Panel- Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/beego-admin-dashboard.yaml" target="_blank" rel="noopener" class="nt-source-link">beego-admin-dashboard.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)beego admin dashboard&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Beego Admin Dashboard panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">beego</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">unauth</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/beego" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://twitter.com/shaybt12/status/1584112903577567234/photo/1" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="beszel login panel - detect info identify web-based control panels beszel products was detected. righettod panel beszel login discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Beszel Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/beszel-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">beszel-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 1, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)beszel&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Beszel products was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">beszel</span><span class="nt-tag">login</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/henrygd/beszel" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://beszel.dev/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="beszel unfinished installation high identify critical remote vulnerabilities detected beszel server monitoring hub had an unfinished installation with no admin account configured, allowing attackers to create an admin account and gain full control. 0x_akoko beszel misconfig install exposure" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Beszel Unfinished Installation</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/misconfiguration/installer/beszel-unfinished-installation.yaml" target="_blank" rel="noopener" class="nt-source-link">beszel-unfinished-installation.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_Akoko</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 20, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)globalThis\\.BESZEL&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detected Beszel server monitoring hub had an unfinished installation with no admin account configured, allowing attackers to create an admin account and gain full control.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">beszel</span><span class="nt-tag">misconfig</span><span class="nt-tag">install</span><span class="nt-tag">exposure</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/henrygd/beszel" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="better search replace &lt; 1.4.5 - php object injection critical identify critical remote vulnerabilities the better search replace plugin for wordpress is vulnerable to php object injection in all versions up to, and including, 1.4.4 via deserialization of untrusted input. this makes it possible for unauthenticated attackers to inject a php object. no pop chain is present in the vulnerable plugin. if a pop chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code. cve-2023-6933 pussycat0x better-search-replace cve cve2023 passive vkev vuln wordpress wp wp-plugin wpscan cwe-502" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Better Search Replace &lt; 1.4.5 - PHP Object Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-6933.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-6933.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 24, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/502.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-502</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-6933" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-6933</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/better-search-replace/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The Better Search Replace plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.4 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can execute arbitrary code, delete files, or retrieve sensitive data on the server.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest version of the plugin, version 1.4.5 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">better-search-replace</span><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">passive</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">wpscan</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://posimyth.ticksy.com/ticket/2713734/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.wordfence.com/blog/2021/03/critical-0-day-in-the-plus-addons-for-elementor-allows-site-takeover/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="beyondtrust login panel - detect info identify web-based control panels beyondtrust login panel was detected. r3dg33k,nuk3s3c beyondtrust discovery pam panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">BeyondTrust Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/beyondtrust-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">beyondtrust-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> r3dg33k,nuk3s3c</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)BeyondInsight&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">BeyondTrust login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">beyondtrust</span><span class="nt-tag">discovery</span><span class="nt-tag">pam</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="beyondtrust privileged remote access - panel info identify web-based control panels beyondtrust privileged remote access login panel was detected. righettod panel beyondtrust login detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">BeyondTrust Privileged Remote Access - Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/beyondtrust-priv-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">beyondtrust-priv-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 10, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)BeyondTrust Privileged Remote Access Login&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">BeyondTrust Privileged Remote Access login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">beyondtrust</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.beyondtrust.com/products/privileged-remote-access" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="beyondtrust remote support panel - detect info identify web-based control panels detect beyondtrust remote support panel. darses beyondtrust detect discovery panel" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">BeyondTrust Remote Support Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/beyondtrust-remotesupport-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">beyondtrust-remotesupport-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> darses</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 21, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-694003434&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detect BeyondTrust Remote Support Panel.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">beyondtrust</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="bigant - default password critical identify default logins in web-based control panels misconfiguratoin leads to default login into bigant super admin account. ritikchaddha bigant default-login vuln cwe-522" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">BigAnt - Default Password</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/bigant/bigant-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">bigant-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 6, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/522.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-522</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;BigAnt&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Misconfiguratoin leads to Default Login into BigAnt Super Admin Account.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">bigant</span><span class="nt-tag">default-login</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.bigantsoft.com/support/faq/2-4_How_to_switch_login_accounts_System_admin_Security_admin_Audit_admin_super_admin.html#:~:text=How%2Dto-,How%20to%20switch%20login%20accounts%3A%20System%20admin%2FSecurity%20admin%2F,password%20is%20123456%20by%20default." target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="bigant admin login panel - detect info identify web-based control panels bigant admin login panel was detected. princechaddha panel bigant discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">BigAnt Admin Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/bigant-login-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">bigant-login-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> princechaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)BigAnt Admin&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">BigAnt admin login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">bigant</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="bigant server 5.6.06 - improper access control medium identify critical remote vulnerabilities bigant server 5.6.06 is susceptible to improper access control. the software utililizes weak password hashes. an attacker can craft a password hash and thereby possibly possibly obtain sensitive information, modify data, and/or execute unauthorized operations. cve-2022-23348 arafatansari bigant bigantsoft cve cve2022 exposure unauth vuln cwe-916" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">BigAnt Server 5.6.06 - Improper Access Control</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-23348.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-23348.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> arafatansari</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/916.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-916</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-23348" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-23348</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)bigant&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">BigAnt Server 5.6.06 is susceptible to improper access control. The software utililizes weak password hashes. An attacker can craft a password hash and thereby possibly possibly obtain sensitive information, modify data, and/or execute unauthorized operations.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can access the ms_admin.php file containing weak password hashes for administrative accounts, potentially facilitating password cracking and unauthorized access.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches or updates provided by the vendor to fix the access control issue.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">bigant</span><span class="nt-tag">bigantsoft</span><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">exposure</span><span class="nt-tag">unauth</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/bzyo/cve-pocs/tree/master/CVE-2022-23348" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="http://bigant.com" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-23348" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://www.bigantsoft.com/" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/ARPSyndicate/cvemon" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="bigant server v5.6.06 - local file inclusion high identify critical remote vulnerabilities bigant server v5.6.06 is vulnerable to local file inclusion. cve-2022-23347 0x_akoko bigant bigantsoft cve cve2022 lfi vkev vuln cwe-22" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">BigAnt Server v5.6.06 - Local File Inclusion</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-23347.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-23347.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_Akoko</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-23347" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-23347</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)BigAnt&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">BigAnt Server v5.6.06 is vulnerable to local file inclusion.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability can lead to unauthorized access to sensitive files, remote code execution, and potential compromise of the server.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest patch or update provided by the vendor to fix the LFI vulnerability in BigAnt Server v5.6.06.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">bigant</span><span class="nt-tag">bigantsoft</span><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">lfi</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/bzyo/cve-pocs/tree/master/CVE-2022-23347" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-23347" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="http://bigant.com" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://www.bigantsoft.com/" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/ARPSyndicate/cvemon" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="biotime web login panel - detect info identify web-based control panels biotime web login panel was detected. robotshell biotime discovery panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">BioTime Web Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/biotime-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">biotime-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> robotshell</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)BioTime&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">BioTime Web login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">biotime</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="bitbucket panel - detect info identify web-based control panels bitbucket panel was detected. bitbucket is a git-based source code repository hosting service owned by atlassian, providing ci/cd and collaboration features. shivam kamboj panel bitbucket login detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Bitbucket Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/bitbucket-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">bitbucket-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Shivam Kamboj</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 27, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;product&#34;] contains &#34;Atlassian:Bitbucket&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Bitbucket panel was detected. Bitbucket is a Git-based source code repository hosting service owned by Atlassian, providing CI/CD and collaboration features.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">bitbucket</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://bitbucket.org/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.atlassian.com/software/bitbucket" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="bitdefender gravityzone panel - detect info identify web-based control panels bitdefender gravityzone panel was detected. dhiyaneshdk bitdefender discovery panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Bitdefender GravityZone Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/bitdefender-gravityzone.yaml" target="_blank" rel="noopener" class="nt-source-link">bitdefender-gravityzone.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)bitdefender gravityzone&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Bitdefender GravityZone panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">bitdefender</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="bitrix component - cross-site scripting critical identify critical remote vulnerabilities global variable extraction in bitrix/modules/main/tools.php in bitrix24 22.0.300 allows unauthenticated remote attackers to (1) enumerate attachments on the server and (2) execute arbitrary javascript code in the victim’s browser, and possibly execute arbitrary php code on the server if the victim has administrator privilege, via overwriting uninitialised variables. cve-2023-1719 dhiyaneshdk bitrix bitrix24 cve cve2023 vuln xss cwe-665" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Bitrix Component - Cross-Site Scripting</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-1719.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-1719.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 6, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/665.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-665</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-1719" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-1719</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/bitrix/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Global variable extraction in bitrix/modules/main/tools.php in Bitrix24 22.0.300 allows unauthenticated remote attackers to (1) enumerate attachments on the server and (2) execute arbitrary JavaScript code in the victim’s browser, and possibly execute arbitrary PHP code on the server if the victim has administrator privilege, via overwriting uninitialised variables.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can inject malicious JavaScript and potentially execute arbitrary PHP code if the victim has administrator privileges, compromising the entire Bitrix24 collaboration platform and accessing sensitive business data.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update Bitrix24 to a version newer than 22.0.300 that properly initializes variables and sanitizes input in the bitrix/modules/main/tools.php component.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">bitrix</span><span class="nt-tag">bitrix24</span><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">vuln</span><span class="nt-tag">xss</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://starlabs.sg/advisories/23/23-1719/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-1719" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/20142995/sectool" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="bitrix login panel info identify web-based control panels bitrix24 is a unified work space that places a complete set of business tools into a single, intuitive interface. juicypotato1,malwarework panel bitrix login discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Bitrix Login Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/bitrix-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">bitrix-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> juicypotato1,malwarework</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/bitrix/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Bitrix24 is a unified work space that places a complete set of business tools into a single, intuitive interface.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">bitrix</span><span class="nt-tag">login</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="bitrix path disclosure low identify critical remote vulnerabilities detected full path disclosure (fpd) in bitrix by sending requests request to specific paths and identifying fatal error stack traces that leaked absolute filesystem paths. dhiyaneshdk debug bitrix fpd vuln" data-nt-sev="low">
  <div class="nt-card-header">
    <div class="nt-title">Bitrix Path Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/misconfiguration/bitrix-fpd.yaml" target="_blank" rel="noopener" class="nt-source-link">bitrix-fpd.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 26, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/bitrix/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detected Full Path Disclosure (FPD) in Bitrix by sending requests request to specific paths and identifying fatal error stack traces that leaked absolute filesystem paths.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">debug</span><span class="nt-tag">bitrix</span><span class="nt-tag">fpd</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.bitrix24.in/tools/crm/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="bitrix site manager - log file disclosure medium identify critical remote vulnerabilities detected bitrix site manager log files, potentially exposing sensitive information including database credentials, file paths, sql queries, and user session data. 0x_akoko exposure bitrix logs files disclosure cwe-532" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Bitrix Site Manager - Log File Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposures/logs/bitrix-log-file-disclosure.yaml" target="_blank" rel="noopener" class="nt-source-link">bitrix-log-file-disclosure.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_Akoko</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 5, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/532.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-532</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)bitrix&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detected Bitrix Site Manager log files, potentially exposing sensitive information including database credentials, file paths, SQL queries, and user session data.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">exposure</span><span class="nt-tag">bitrix</span><span class="nt-tag">logs</span><span class="nt-tag">files</span><span class="nt-tag">disclosure</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://dev.1c-bitrix.ru/learning/course/index.php?COURSE_ID=43&amp;LESSON_ID=2795" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://dev.1c-bitrix.ru/api_help/main/general/error.php" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="bitrix24 &lt;=20.0.0 - cross-site scripting medium identify critical remote vulnerabilities the web application firewall in bitrix24 up to and including 20.0.0 allows xss via the items[items][id] parameter to the components/bitrix/mobileapp.list/ajax.php/ uri. cve-2020-13483 pikpikcu,3th1c_yuk1,s4e-io bitrix bitrix24 cve cve2020 vkev vuln xss cwe-79" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Bitrix24 &lt;=20.0.0 - Cross-Site Scripting</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2020/CVE-2020-13483.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2020-13483.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pikpikcu,3th1c_yuk1,s4e-io</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-79</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2020-13483" target="_blank" rel="noopener" class="nt-cve-link">CVE-2020-13483</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/bitrix/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The Web Application Firewall in Bitrix24 up to and including 20.0.0 allows XSS via the items[ITEMS][ID] parameter to the components/bitrix/mobileapp.list/ajax.php/ URI.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute arbitrary JavaScript code in the context of the victim&#39;s browser, leading to session hijacking, defacement, or theft of sensitive information.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to a patched version of Bitrix24 (version &gt;20.0.0) to mitigate this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">bitrix</span><span class="nt-tag">bitrix24</span><span class="nt-tag">cve</span><span class="nt-tag">cve2020</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">xss</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://gist.github.com/mariuszpoplwski/ca6258cf00c723184ebd2228ba81f558" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://twitter.com/brutelogic/status/1483073170827628547" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2020-13483" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/afinepl/research" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/ARPSyndicate/cvemon" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="bitwarden web vault login panel - detect info identify web-based control panels  ritikchaddha bitwarden detect discovery panel vault" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Bitwarden Web Vault Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/bitwarden-vault-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">bitwarden-vault-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 9, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)bitwarden web vault&#34;})</code></div>
  <div class="nt-tags"><span class="nt-tag">bitwarden</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">vault</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://bitwarden.com/?utm_source=google&amp;utm_medium=cpc&amp;utm_campaign=AW_ALL_NU_CL_Bitwarden_en_GSN_DTMB_Brand-Login_KW:Brand-Login_Consolidated&amp;utm_content=646427936792&amp;utm_term=bitwarden%20vault%20login|kwd-826827349840&amp;hsa_acc=2567950947&amp;hsa_cam=19621984700&amp;hsa_grp=145977914135&amp;hsa_ad=646427936792&amp;hsa_src=g&amp;hsa_tgt=kwd-826827349840&amp;hsa_kw=bitwarden%20vault%20login&amp;hsa_mt=e&amp;hsa_net=adwords&amp;hsa_ver=3&amp;gad=1&amp;gclid=Cj0KCQjwpompBhDZARIsAFD_Fp-07Mni-xzuKd5Ewi6I7qzRTdZOYSxMsMVvKVWhGm5qg2KUiY2Z7SQaAvSIEALw_wcB" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="black duck login panel - detect info identify web-based control panels black duck login panel was detected. idealphase,ritikchaddha blackduck discovery panel synopsys cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Black Duck Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/black-duck-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">black-duck-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> idealphase,ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Black Duck&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Black Duck login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">blackduck</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">synopsys</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.blackducksoftware.com/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.synopsys.com/software-integrity/security-testing/software-composition-analysis.html" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="blinko - login panel detection info identify web-based control panels detected a blinko self-hosted personal note application login panel. 0x_akoko blinko detect login panel" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Blinko - Login Panel Detection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/blinko-login-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">blinko-login-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_Akoko</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 11, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Blinko&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detected A Blinko self-hosted personal note application login panel.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">blinko</span><span class="nt-tag">detect</span><span class="nt-tag">login</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/blinko-space/blinko" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="blue iris login panel - detect info identify web-based control panels blue iris login panel was detected. dhiyaneshdk,idealphase panel blueiris edb discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Blue Iris Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/blue-iris-login.yaml" target="_blank" rel="noopener" class="nt-source-link">blue-iris-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDK,idealphase</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Blue Iris Login&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Blue Iris login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">blueiris</span><span class="nt-tag">edb</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.exploit-db.com/ghdb/6814" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://blueirissoftware.com/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="blue yonder panel - detect info identify web-based control panels blue yonder login panel was discovered sorrowx3 panel login blue-yonder detect discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Blue Yonder Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/blue-yonder-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">blue-yonder-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> sorrowx3</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 27, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)title=\\\\&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Blue Yonder login panel was discovered</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">login</span><span class="nt-tag">blue-yonder</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="bluemind panel - detect info identify web-based control panels bluemind application panel was discovered. tigibus bluemind login panel detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Bluemind Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/bluemind-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">bluemind-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Tigibus</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 30, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Welcome to BlueMind&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Bluemind application panel was discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">bluemind</span><span class="nt-tag">login</span><span class="nt-tag">panel</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://bluemind.net/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="boa 0.94.13 - information disclosure high identify critical remote vulnerabilities boa 0.94.13 allows remote attackers to obtain sensitive information via a misconfiguration involving backup.html, preview.html, js/log.js, log.html, email.html, online-users.html, and config.js. note- multiple third parties report that this is a site-specific issue because those files are not part of boa. cve-2021-33558 dhiyaneshdk boa cve cve2021 info-leak vkev vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Boa 0.94.13 - Information Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2021/CVE-2021-33558.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2021-33558.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 9, 2025</span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2021-33558" target="_blank" rel="noopener" class="nt-cve-link">CVE-2021-33558</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.head.server&#34;] matches &#34;Boa/0.94.13&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Boa 0.94.13 allows remote attackers to obtain sensitive information via a misconfiguration involving backup.html, preview.html, js/log.js, log.html, email.html, online-users.html, and config.js. NOTE- multiple third parties report that this is a site-specific issue because those files are not part of Boa.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can access sensitive JavaScript files exposing logging functionality and potentially other configuration details.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update Boa web server to a version newer than 0.94.13 or apply vendor security patches.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">boa</span><span class="nt-tag">cve</span><span class="nt-tag">cve2021</span><span class="nt-tag">info-leak</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://sourceforge.net/projects/boa/files/boa/0.94.13/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/anldori/CVE-2021-33558" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="bonita - default login high identify default logins in web-based control panels bonita login was using default credentials which can led to gain super administrator access. dhiyaneshdk bonita default-login misconfig vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Bonita - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/bonita/bonita-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">bonita-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 17, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-1197926023&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Bonita login was using default credentials which can led to gain super administrator access.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">bonita</span><span class="nt-tag">default-login</span><span class="nt-tag">misconfig</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="bonita portal login - detect info identify web-based control panels detects the presence of bonita portal login page. dhiyaneshdk bonita login panel discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Bonita Portal Login - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/bonita-portal-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">bonita-portal-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 17, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-1197926023&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detects the presence of Bonita Portal login page.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">bonita</span><span class="nt-tag">login</span><span class="nt-tag">panel</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="bonobo git server login panel - detect info identify web-based control panels bonobo git server login panel was detected. bhutch panel bonobo git login detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Bonobo Git Server Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/bonobo-server-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">bonobo-server-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> bhutch</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 23, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-219625874&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Bonobo Git Server login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">bonobo</span><span class="nt-tag">git</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="bookstack login panel - detect info identify web-based control panels bookstack login panel was detected. cyllective,daffainfo bookstack bookstackapp discovery panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">BookStack Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/bookstack-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">bookstack-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> cyllective,daffainfo</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)bookstack&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Bookstack login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">bookstack</span><span class="nt-tag">bookstackapp</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/BookStackApp/BookStack" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="bootstrap multiselect &lt;= 1.1.2 - cross-site scripting medium identify critical remote vulnerabilities a php script in the source code release echoes arbitrary post data. if a developer adopts this structure wholesale in a live application, it could create a reflective cross-site scripting (xss) vulnerability exploitable through cross-site request forgery (csrf). r3naissance bootstrap-multiselect cve cve2025 vkev vuln xss" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Bootstrap Multiselect &lt;= 1.1.2 - Cross-Site Scripting</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-47204.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-47204.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> r3naissance</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 6, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)bootstrap-multiselect&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A PHP script in the source code release echoes arbitrary POST data. If a developer adopts this structure wholesale in a live application, it could create a Reflective Cross-Site Scripting (XSS) vulnerability exploitable through Cross-Site Request Forgery (CSRF).</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute malicious scripts in the context of the victim&#39;s browser, leading to potential data theft, session hijacking, or defacement of the affected application.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Only use the necessary components (css/js) in production applications</div></div></div>
  <div class="nt-tags"><span class="nt-tag">bootstrap-multiselect</span><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">xss</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-47204" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="botpress admin panel - detect info identify web-based control panels botpress admin panel was detected. botpress is an open-source conversational ai platform for building chatbots and virtual assistants. rxerium ai botpress chatbot detect discovery panel" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Botpress Admin Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/botpress-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">botpress-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 27, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)@botpress/ui-admin&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Botpress admin panel was detected. Botpress is an open-source conversational AI platform for building chatbots and virtual assistants.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">ai</span><span class="nt-tag">botpress</span><span class="nt-tag">chatbot</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/botpress/botpress" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://botpress.com/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="brickcom camera - default login high identify default logins in web-based control panels detected brickcom ip cameras accessible using default credentials (admin/admin). successful authentication exposed full camera configuration, live video streams, led control, and network settings to remote attackers. 0x_akoko iot camera default-login" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Brickcom Camera - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/brickcom-camera-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">brickcom-camera-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_Akoko</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 18, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;http.head.wwwAuthentications&#34;]), {# contains &#39;realm=&#34;Brickcom&#39;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detected Brickcom IP cameras accessible using default credentials (admin/admin). Successful authentication exposed full camera configuration, live video streams, LED control, and network settings to remote attackers.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">iot</span><span class="nt-tag">camera</span><span class="nt-tag">default-login</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.brickcom.com/support/faq_contents.php?id=48" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://cxsecurity.com/issue/WLB-2026020031" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="brickcom camera - unauthenticated snapshot access high identify critical remote vulnerabilities detected brickcom ip cameras was exposed live camera snapshots without authentication via the onvif media endpoint. 0xr2r iot camera default-login exposure unauth" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Brickcom Camera - Unauthenticated Snapshot Access</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/misconfiguration/brickcom-camera-unauth-snapshot.yaml" target="_blank" rel="noopener" class="nt-source-link">brickcom-camera-unauth-snapshot.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0xr2r</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 17, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;http.head.wwwAuthentications&#34;]), {# contains &#39;realm=&#34;Brickcom&#39;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detected Brickcom IP cameras was exposed live camera snapshots without authentication via the ONVIF media endpoint.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">iot</span><span class="nt-tag">camera</span><span class="nt-tag">default-login</span><span class="nt-tag">exposure</span><span class="nt-tag">unauth</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://cxsecurity.com/issue/WLB-2026020031" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="brother mfc-l9570cdw - information disclosure medium identify critical remote vulnerabilities an unauthenticated attacker who can access either the http service (tcp port 80), the https service (tcp port 443), or the ipp service (tcp port 631), can leak several pieces of sensitive information from a vulnerable device. the uri path /etc/mnt_info.csv can be accessed via a get request and no authentication is required. the returned result is a comma separated value (csv) table of information. the leaked information includes the device’s model, firmware version, ip address, and serial number. cve-2024-51977 dhiyaneshdk,iamnoooob,darses brother cve cve2024 exposure mfc printer vkev vuln cwe-538" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Brother MFC-L9570CDW - Information Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-51977.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-51977.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK,iamnoooob,darses</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 25, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/538.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-538</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-51977" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-51977</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)MFC-L9570CDW&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An unauthenticated attacker who can access either the HTTP service (TCP port 80), the HTTPS service (TCP port 443), or the IPP service (TCP port 631), can leak several pieces of sensitive information from a vulnerable device. The URI path /etc/mnt_info.csv can be accessed via a GET request and no authentication is required. The returned result is a comma separated value (CSV) table of information. The leaked information includes the device’s model, firmware version, IP address, and serial number.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can exploit this vulnerability to compromise system security.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply security patches to address CVE-2024-51977.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">brother</span><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">exposure</span><span class="nt-tag">mfc</span><span class="nt-tag">printer</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/sfewer-r7/BrotherVulnerabilities/blob/main/CVE-2024-51977.rb" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="browser configuration &#34;browserconfig.xml&#34; exposure info identify critical remote vulnerabilities browser configuration &#34;browserconfig.xml&#34; file was exposed. dhiyaneshdk browserconfig misconfig vuln" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Browser Configuration &#34;browserconfig.xml&#34; Exposure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/misconfiguration/browserconfig-xml.yaml" target="_blank" rel="noopener" class="nt-source-link">browserconfig-xml.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 10, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)browserconfig\\.xml&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Browser Configuration &#34;browserconfig.xml&#34; File was exposed.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">browserconfig</span><span class="nt-tag">misconfig</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.sygnal.com/lessons/browserconfig-xml" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="buddy panel - detect info identify web-based control panels buddy panel was detected. thardt-praetorian panel buddy cicd discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Buddy Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/buddy-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">buddy-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> thardt-praetorian</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-850502287&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Buddy panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">buddy</span><span class="nt-tag">cicd</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://buddy.works" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="budibase login panel - detect info identify web-based control panels budibase login panel was detected. theamanrawat budibase discovery login panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Budibase Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/budibase-login-detect.yaml" target="_blank" rel="noopener" class="nt-source-link">budibase-login-detect.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> theamanrawat</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 8, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)budibase&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Budibase login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">budibase</span><span class="nt-tag">discovery</span><span class="nt-tag">login</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/Budibase/budibase" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="buffalo wsr-2533dhpl2 - path traversal critical identify critical remote vulnerabilities buffalo wsr-2533dhpl2 firmware version &lt;= 1.02 and wsr-2533dhp3 firmware version &lt;= 1.24 are susceptible to a path traversal vulnerability that could allow unauthenticated remote attackers to bypass authentication in their web interfaces. cve-2021-20090 gy741 buffalo cve cve2021 firmware iot kev lfi tenable vkev vuln cwe-22" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Buffalo WSR-2533DHPL2 - Path Traversal</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2021/CVE-2021-20090.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2021-20090.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> gy741</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2021-20090" target="_blank" rel="noopener" class="nt-cve-link">CVE-2021-20090</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;service.port&#34;] == &#34;9000&#34; &amp;&amp; any(each(service[&#34;html.titles&#34;]), {# matches `(?i)^Redirecting...`})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Buffalo WSR-2533DHPL2 firmware version &lt;= 1.02 and WSR-2533DHP3 firmware version &lt;= 1.24 are susceptible to a path traversal vulnerability that could allow unauthenticated remote attackers to bypass authentication in their web interfaces.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can exploit this vulnerability to read sensitive files, such as configuration files, credentials, or other sensitive information.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest firmware update provided by Buffalo to fix the path traversal vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">buffalo</span><span class="nt-tag">cve</span><span class="nt-tag">cve2021</span><span class="nt-tag">firmware</span><span class="nt-tag">iot</span><span class="nt-tag">kev</span><span class="nt-tag">lfi</span><span class="nt-tag">tenable</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.tenable.com/security/research/tra-2021-13" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://medium.com/tenable-techblog/bypassing-authentication-on-arcadyan-routers-with-cve-2021-20090-and-rooting-some-buffalo-ea1dd30980c2" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2021-20090" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://www.kb.cert.org/vuls/id/914124" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://www.secpod.com/blog/arcadyan-based-routers-and-modems-under-active-exploitation/" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="buildbot panel - detect info identify web-based control panels buildbot panel was detected. thardt-praetorian,daffainfo buildbot cicd discovery panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Buildbot Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/buildbot-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">buildbot-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> thardt-praetorian,daffainfo</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)buildbot&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Buildbot panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">buildbot</span><span class="nt-tag">cicd</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://buildbot.net" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="busybox repository browser - detect info identify web-based control panels busybox repository browser was detected. ritikchaddha detect busybox oss panel discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Busybox Repository Browser - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/busybox-repository-browser.yaml" target="_blank" rel="noopener" class="nt-source-link">busybox-repository-browser.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 28, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Busybox Repository Browser&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Busybox Repository Browser was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">detect</span><span class="nt-tag">busybox</span><span class="nt-tag">oss</span><span class="nt-tag">panel</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/mirror/busybox" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="bylancer quicklancer 2.4 g - sql injection high identify critical remote vulnerabilities a sql injection vulnerability exists in the quicklancer 2.4, get parameter &#39;range2&#39;, that has time-based blind sql injection and a boolean-based blind sql injection, which can be exploited remotely by unauthenticated attacker to execute arbitrary sql queries in the database. cve-2024-7188 s4e-io cve cve2024 quicklancer sqli time-based-sqli vuln cwe-89" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Bylancer Quicklancer 2.4 G - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-7188.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-7188.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> s4e-io</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 29, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-7188" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-7188</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1099370896&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A SQL injection vulnerability exists in the Quicklancer 2.4, GET parameter &#39;range2&#39;, that has time-based blind SQL injection and a boolean-based blind SQL injection, which can be exploited remotely by unauthenticated attacker to execute arbitrary SQL queries in the database.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can exploit time-based and boolean-based blind SQL injection to extract sensitive database information, modify data, and potentially compromise the entire Quicklancer application.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update Quicklancer to a version later than 2.4 G to address the SQL injection vulnerability in the range2 parameter.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">quicklancer</span><span class="nt-tag">sqli</span><span class="nt-tag">time-based-sqli</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://cvefeed.io/vuln/detail/CVE-2024-7188" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/bigb0x/CVEs/blob/main/quicklancer-2-4.md" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://codecanyon.net/item/quicklancer-freelance-marketplace-php-script/39087135" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-7188" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="bynder login panel - detect info identify web-based control panels bynder login panel was detected. righettod panel bynder login detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Bynder Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/bynder-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">bynder-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 14, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1017650009&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Bynder login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">bynder</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.bynder.com/en/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="caimore gateway  default login - detect high identify default logins in web-based control panels the gateway of xiamen caimao communication technology co., ltd. is designed with open software architecture. it is a metal shell design, with two ethernet rj45 interfaces, and an industrial design wireless gateway using 3g/4g/5g wide area network for internet communication. there is a command execution vulnerability in the formping file of the gateway of xiamen caimao communication technology co., ltd. an attacker can use this vulnerability to arbitrarily execute code on the server side, write to the back door, obtain server permissions, and then control the entire web server. pussycat0x ciamore-gateway default-login vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">CAIMORE Gateway  Default Login - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/caimore/caimore-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">caimore-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 18, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;http.head.wwwAuthentications&#34;]), {# matches &#39;(?i)realm=&#34;CaiMore Gateway&#39;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The gateway of Xiamen Caimao Communication Technology Co., Ltd. is designed with open software architecture. It is a metal shell design, with two Ethernet RJ45 interfaces, and an industrial design wireless gateway using 3G/4G/5G wide area network for Internet communication. There is a command execution vulnerability in the formping file of the gateway of Xiamen Caimao Communication Technology Co., Ltd. An attacker can use this vulnerability to arbitrarily execute code on the server side, write to the back door, obtain server permissions, and then control the entire web server.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">ciamore-gateway</span><span class="nt-tag">default-login</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="carel boss mini - login panel detected info identify web-based control panels carel boss mini login panel was detected. boss mini is a local supervisor solution by carel used for monitoring and managing hvac/r systems in commercial facilities. exposed panels may indicate misconfigured network segmentation. kazgangap panel carel boss-mini ics login detect" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">CAREL Boss Mini - Login Panel Detected</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/carel-boss-mini-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">carel-boss-mini-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Kazgangap</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 5, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1092427843&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">CAREL Boss Mini login panel was detected. Boss Mini is a local supervisor solution by CAREL used for monitoring and managing HVAC/R systems in commercial facilities. Exposed panels may indicate misconfigured network segmentation.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">carel</span><span class="nt-tag">boss-mini</span><span class="nt-tag">ics</span><span class="nt-tag">login</span><span class="nt-tag">detect</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.carel.com/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="carel boss mini &lt;= 1.4.0 - local file inclusion critical identify critical remote vulnerabilities boss mini 1.4.0 build 6221 contains a file inclusion caused by manipulation of the &#39;path&#39; argument in boss/servlet/document, letting remote attackers include arbitrary files, exploit requires remote access. cve-2023-3643 kazgangap boss-mini carel cve cve2023 file-inclusion ics lfi path-traversal cwe-22" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">CAREL Boss Mini &lt;= 1.4.0 - Local File Inclusion</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-3643.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-3643.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Kazgangap</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 5, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-3643" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-3643</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1092427843&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Boss Mini 1.4.0 Build 6221 contains a file inclusion caused by manipulation of the &#39;path&#39; argument in boss/servlet/document, letting remote attackers include arbitrary files, exploit requires remote access.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Remote attackers can include arbitrary files, potentially leading to remote code execution or full system compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest version of Boss Mini or apply security patches provided by the vendor.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">boss-mini</span><span class="nt-tag">carel</span><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">file-inclusion</span><span class="nt-tag">ics</span><span class="nt-tag">lfi</span><span class="nt-tag">path-traversal</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-3643" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.cisa.gov/news-events/ics-advisories/icsa-24-172-02" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://vuldb.com/?id.233889" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://www.exploit-db.com/exploits/52482" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="cas login panel - detect info identify web-based control panels cas login panel was detected. pdteam apereo cas discovery login panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">CAS Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/cas-login.yaml" target="_blank" rel="noopener" class="nt-source-link">cas-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pdteam</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)&#39;cas&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">CAS login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">apereo</span><span class="nt-tag">cas</span><span class="nt-tag">discovery</span><span class="nt-tag">login</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="cdata api server &lt; 23.4.8844 - path traversal critical identify critical remote vulnerabilities a path traversal vulnerability exists in the java version of cdata api server &lt; 23.4.8844 when running using the embedded jetty server, which could allow an unauthenticated remote attacker to gain complete administrative access to the application. cve-2024-31848 pussycat0x cdata cve cve2024 lfi vuln cwe-22" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">CData API Server &lt; 23.4.8844 - Path Traversal</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-31848.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-31848.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 8, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-31848" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-31848</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)CData - API Server&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A path traversal vulnerability exists in the Java version of CData API Server &lt; 23.4.8844 when running using the embedded Jetty server, which could allow an unauthenticated remote attacker to gain complete administrative access to the application.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can exploit path traversal to gain complete administrative access to the CData API Server.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update CData API Server to version 23.4.8844 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cdata</span><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">lfi</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-31848" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/Stuub/CVE-2024-31848-PoC/blob/main/CVE-2024-31848.py" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.tenable.com/cve/CVE-2024-31848" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://www.tenable.com/security/research/tra-2024-09" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/Stuub/CVE-2024-31848-PoC" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="cdata arc &lt; 23.4.8839 - path traversal high identify critical remote vulnerabilities a path traversal vulnerability exists in the java version of cdata arc &lt; 23.4.8839 when running using the embedded jetty server, which could allow an unauthenticated remote attacker to gain access to sensitive information and perform limited actions. cve-2024-31850 dhiyaneshdk cdata cve cve2024 lfi vuln cwe-22" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">CData Arc &lt; 23.4.8839 - Path Traversal</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-31850.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-31850.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 8, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-31850" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-31850</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)CData Arc&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A path traversal vulnerability exists in the Java version of CData Arc &lt; 23.4.8839 when running using the embedded Jetty server, which could allow an unauthenticated remote attacker to gain access to sensitive information and perform limited actions.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can access sensitive information and perform limited unauthorized actions via path traversal.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update CData Arc to version 23.4.8839 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cdata</span><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">lfi</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.tenable.com/security/research/tra-2024-09" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-31850" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/Stuub/CVE-2024-31848-PoC" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="cdata connect &lt; 23.4.8846 - path traversal critical identify critical remote vulnerabilities a path traversal vulnerability exists in the java version of cdata connect &lt; 23.4.8846 when running using the embedded jetty server, which could allow an unauthenticated remote attacker to gain complete administrative access to the application. cve-2024-31849 dhiyaneshdk cdata cve cve2024 lfi vuln cwe-22" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">CData Connect &lt; 23.4.8846 - Path Traversal</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-31849.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-31849.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 29, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-31849" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-31849</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)CData Connect&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A path traversal vulnerability exists in the Java version of CData Connect &lt; 23.4.8846 when running using the embedded Jetty server, which could allow an unauthenticated remote attacker to gain complete administrative access to the application.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can exploit path traversal to gain complete administrative access to CData Connect.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update CData Connect to version 23.4.8846 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cdata</span><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">lfi</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.tenable.com/security/research/tra-2024-09" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.cdata.com/kb/entries/jetty-cve-0324.rst" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-31849" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/Ostorlab/KEV" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/Stuub/CVE-2024-31848-PoC" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="cdata sync &lt; 23.4.8843 - path traversal high identify critical remote vulnerabilities a path traversal vulnerability exists in the java version of cdata sync &lt; 23.4.8843 when running using the embedded jetty server, which could allow an unauthenticated remote attacker to gain access to sensitive information and perform limited actions. cve-2024-31851 dhiyaneshdk cdata cve cve2024 lfi vuln cwe-22" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">CData Sync &lt; 23.4.8843 - Path Traversal</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-31851.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-31851.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 8, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-31851" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-31851</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)CData Sync&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A path traversal vulnerability exists in the Java version of CData Sync &lt; 23.4.8843 when running using the embedded Jetty server, which could allow an unauthenticated remote attacker to gain access to sensitive information and perform limited actions.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can access sensitive information and perform limited unauthorized actions via path traversal.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update CData Sync to version 23.4.8843 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cdata</span><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">lfi</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.tenable.com/security/research/tra-2024-09" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-31851" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="cerio-dt interface - command execution critical identify critical remote vulnerabilities cerio dt series routers have an operation command injection vulnerability in specific versions. an attacker could exploit this vulnerability to execute commands. pussycat0x cerio rce vuln cwe-78" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">CERIO-DT Interface - Command Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/vulnerabilities/other/cerio-dt-rce.yaml" target="_blank" rel="noopener" class="nt-source-link">cerio-dt-rce.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 23, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/78.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-78</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)DT-100G-N&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">CERIO DT series routers have an operation command injection vulnerability in specific versions. An attacker could exploit this vulnerability to execute commands.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cerio</span><span class="nt-tag">rce</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/20142995/sectool" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/tanjiti/sec_profile" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/wy876/POC/blob/main/D-Link_DAR-8000%E6%93%8D%E4%BD%9C%E7%B3%BB%E7%BB%9F%E5%91%BD%E4%BB%A4%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E(CVE-2023-4542).md" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="cgit - detect info identify web-based control panels cgit panel was detected. tess,righettod cgit_project discovery git panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">CGIT - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/cgit-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">cgit-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> tess,righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 22, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)git repository browser&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">CGIT panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cgit_project</span><span class="nt-tag">discovery</span><span class="nt-tag">git</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://git.zx2c4.com/cgit/about/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="cisco expressway login panel - detect info identify web-based control panels cisco expressway login panel was detected. righettod panel cisco login detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">CISCO Expressway Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/cisco/cisco-expressway-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">cisco-expressway-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 16, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Cisco Expressway&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">CISCO Expressway login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">cisco</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.cisco.com/c/en/us/products/unified-communications/expressway-series/index.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="codesys webvisu - panel info identify web-based control panels codesys webvisu is the web-based hmi (human-machine interface) component of the
codesys industrial automation runtime. it provides browser-based access to plc
visualizations and industrial control interfaces. exposed instances may reveal
real-time process data and control functions without authentication. rxerium codesys discovery ics panel scada webvisu" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">CODESYS WebVisu - Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/codesys-webvisu-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">codesys-webvisu-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 27, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)WEBVISU LOGIN&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">CODESYS WebVisu is the web-based HMI (Human-Machine Interface) component of the
CODESYS industrial automation runtime. It provides browser-based access to PLC
visualizations and industrial control interfaces. Exposed instances may reveal
real-time process data and control functions without authentication.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">codesys</span><span class="nt-tag">discovery</span><span class="nt-tag">ics</span><span class="nt-tag">panel</span><span class="nt-tag">scada</span><span class="nt-tag">webvisu</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.codesys.com/products/codesys-runtime/web-visualization.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="crm perks forms &lt;= 1.1.4 - sql injection critical identify critical remote vulnerabilities crm perks crm perks forms (affected versions 1.1.4 and earlier) contains a sql injection caused by improper neutralization of special elements used in an sql command, letting attackers execute arbitrary sql commands, exploit requires user interaction. cve-2024-30498 shivam kamboj crm-perks-forms cve cve2024 sqli wordpress wp wp-plugin cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">CRM Perks Forms &lt;= 1.1.4 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-30498.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-30498.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Shivam Kamboj</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 8, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-30498" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-30498</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/crm-perks-forms/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">CRM Perks CRM Perks Forms (affected versions 1.1.4 and earlier) contains a SQL injection caused by improper neutralization of special elements used in an SQL command, letting attackers execute arbitrary SQL commands, exploit requires user interaction.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can execute arbitrary SQL commands, potentially leading to data theft, data tampering, or database compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest version of CRM Perks Forms, version 1.1.5 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">crm-perks-forms</span><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">sqli</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/crm-perks-forms/crm-perks-forms-114-unauthenticated-sql-injection" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://patchstack.com/database/wordpress/plugin/crm-perks-forms/vulnerability/wordpress-crm-perks-forms-plugin-1-1-4-unauthenticated-sql-injection-vulnerability" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-30498" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="crmeb v.5.2.2 - sql injection high identify critical remote vulnerabilities sql injection vulnerability in crmeb v.5.2.2 allows a remote attacker to obtain sensitive information via the getproductlist function in the productcontroller.php file. cve-2024-36837 dhiyaneshdk crmeb cve cve2024 sqli vuln cwe-89" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">CRMEB v.5.2.2 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-36837.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-36837.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 18, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-36837" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-36837</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)CRMEB&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">SQL Injection vulnerability in CRMEB v.5.2.2 allows a remote attacker to obtain sensitive information via the getProductList function in the ProductController.php file.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can execute SQL injection via the selectId parameter in getProductList to obtain sensitive database information.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update CRMEB to a version later than 5.2.2 that patches the SQL injection vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">crmeb</span><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">sqli</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/phtcloud-dev/CVE-2024-36837" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-36837" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="cvat computer vision annotation tool - detect info identify web-based control panels cvat (computer vision annotation tool) was detected. cvat is a widely used open-source annotation platform for labelling images, video, and 3d point clouds used to train ai/ml computer vision models. rxerium ai annotation cvat detect discovery ml panel" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">CVAT Computer Vision Annotation Tool - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/cvat-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">cvat-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 14, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Computer Vision Annotation Tool&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">CVAT (Computer Vision Annotation Tool) was detected. CVAT is a widely used open-source annotation platform for labelling images, video, and 3D point clouds used to train AI/ML computer vision models.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">ai</span><span class="nt-tag">annotation</span><span class="nt-tag">cvat</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">ml</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/cvat-ai/cvat" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://cvat.ai/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="cachet &lt;=2.3.18 - sql injection medium identify critical remote vulnerabilities cachet is an open source status page. with cachet prior to and including 2.3.18, there is a sql injection which is in the `searchabletrait#scopesearch()`. attackers without authentication can utilize this vulnerability to exfiltrate sensitive data from the database such as administrator&#39;s password and session. the original repository of cachet &lt;https://github.com/cachethq/cachet&gt; is not active, the stable version 2.3.18 and it&#39;s developing 2.4 branch is affected. cve-2021-39165 tess cachet chachethq cve cve2021 sqli time-based-sqli vuln cwe-287" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Cachet &lt;=2.3.18 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2021/CVE-2021-39165.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2021-39165.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> tess</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 26, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/287.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-287</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2021-39165" target="_blank" rel="noopener" class="nt-cve-link">CVE-2021-39165</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-1606065523&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Cachet is an open source status page. With Cachet prior to and including 2.3.18, there is a SQL injection which is in the `SearchableTrait#scopeSearch()`. Attackers without authentication can utilize this vulnerability to exfiltrate sensitive data from the database such as administrator&#39;s password and session. The original repository of Cachet &lt;https://github.com/CachetHQ/Cachet&gt; is not active, the stable version 2.3.18 and it&#39;s developing 2.4 branch is affected.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized access, data leakage, or data manipulation.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade Cachet to a version higher than 2.3.18 or apply the necessary patches provided by the vendor.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cachet</span><span class="nt-tag">chachethq</span><span class="nt-tag">cve</span><span class="nt-tag">cve2021</span><span class="nt-tag">sqli</span><span class="nt-tag">time-based-sqli</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.leavesongs.com/PENETRATION/cachet-from-laravel-sqli-to-bug-bounty.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/fiveai/Cachet/commit/27bca8280419966ba80c6fa283d985ddffa84bb6" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/W0rty/CVE-2021-39165/blob/main/exploit.py" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2021-39165" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/fiveai/Cachet/security/advisories/GHSA-79mg-4w23-4fqc" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="cacti 1.2.24 - sql injection critical identify critical remote vulnerabilities cacti is an open source operational monitoring and fault management framework. affected versions are subject to a sql injection discovered in graph_view.php. since guest users can access graph_view.php without authentication by default, if guest users are being utilized in an enabled state, there could be the potential for significant damage. attackers may exploit this vulnerability, and there may be possibilities for actions such as the usurpation of administrative privileges or remote code execution. this issue has been addressed in version 1.2.25. users are advised to upgrade. there are no known workarounds for this vulnerability. cve-2023-39361 ritikchaddha cacti cve cve2023 sqli time-based-sqli vuln cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Cacti 1.2.24 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-39361.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-39361.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 6, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-39361" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-39361</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)cacti&#34;}) || service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-1797138069&#34; || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)login to cacti&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a SQL injection discovered in graph_view.php. Since guest users can access graph_view.php without authentication by default, if guest users are being utilized in an enabled state, there could be the potential for significant damage. Attackers may exploit this vulnerability, and there may be possibilities for actions such as the usurpation of administrative privileges or remote code execution. This issue has been addressed in version 1.2.25. Users are advised to upgrade. There are no known workarounds for this vulnerability.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized access, data manipulation, or data leakage.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches and updates from the vendor to address this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cacti</span><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">sqli</span><span class="nt-tag">time-based-sqli</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/Cacti/cacti/security/advisories/GHSA-6r43-q2fw-5wrg" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-39361" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CFH3J2WVBKY4ZJNMARVOWJQK6PSLPHFH/" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WZGB2UXJEUYWWA6IWVFQ3ZTP22FIHMGN/" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WOQFYGLZBAWT4AWNMO7DU73QXWPXTCKH/" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="cacti login panel - detect info identify web-based control panels cacti login panel was detected. geeknik,daffainfo cacti detect discovery login panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Cacti Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/cacti-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">cacti-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> geeknik,daffainfo</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-1797138069&#34; || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)login to cacti&#34;}) || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)cacti&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Cacti login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cacti</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">login</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.cacti.net/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="calibre &lt;= 7.14.0 arbitrary file read high identify critical remote vulnerabilities arbitrary file read via calibre’s content server in calibre &lt;= 7.14.0. cve-2024-6781 dhiyaneshdk calibre cve cve2024 lfi vuln cwe-22" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Calibre &lt;= 7.14.0 Arbitrary File Read</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-6781.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-6781.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 31, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-6781" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-6781</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Calibre&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Arbitrary file read via Calibre’s content server in Calibre &lt;= 7.14.0.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can exploit the content server&#39;s export functionality to read arbitrary files from the system through path traversal.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update Calibre to version 7.15.0 or later to address the arbitrary file read vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">calibre</span><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">lfi</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://starlabs.sg/advisories/24/24-6781/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="calibre &lt;= 7.14.0 remote code execution critical identify critical remote vulnerabilities unauthenticated remote code execution via calibre’s content server in calibre &lt;= 7.14.0. cve-2024-6782 dhiyaneshdk calibre cve cve2024 rce vkev vuln cwe-863" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Calibre &lt;= 7.14.0 Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-6782.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-6782.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 1, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/863.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-863</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-6782" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-6782</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Calibre&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Unauthenticated remote code execution via Calibre’s content server in Calibre &lt;= 7.14.0.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can execute arbitrary Python code through the content server&#39;s template functionality, achieving complete system compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update Calibre to version 7.15.0 or later to address the remote code execution vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">calibre</span><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">rce</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://starlabs.sg/advisories/24/24-6781/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="camaleon cms - default login high identify default logins in web-based control panels camaleon cms default login credentials was discovered. dhiyaneshdk camaleon default-login vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Camaleon CMS - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/camaleon/camaleon-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">camaleon-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 26, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)camaleon_cms&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Camaleon CMS default login credentials was discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">camaleon</span><span class="nt-tag">default-login</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="camaleon cms login - panel info identify web-based control panels camaleon cms admin login panel was discovered. dhiyaneshdk camaleon panel login discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Camaleon CMS Login - Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/camaleon-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">camaleon-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 26, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)camaleon_cms&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Camaleon CMS admin login panel was discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">camaleon</span><span class="nt-tag">panel</span><span class="nt-tag">login</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="camunda - default login high identify default logins in web-based control panels camunda login panel contains a default login vulnerability. bhutch camunda default-login vuln cwe-522" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Camunda - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/camunda/camunda-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">camunda-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> bhutch</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 9, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/522.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-522</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;Camunda Welcome&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Camunda login panel contains a default login vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">camunda</span><span class="nt-tag">default-login</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/camunda/camunda-docs-manual/blob/master/content/webapps/admin/user-management.md" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="canon devices - authentication bypass in catwalk server high identify critical remote vulnerabilities certain canon devices manufactured in 2012 through 2020 (such as imagerunner advance ir-adv c5250), when catwalk server is enabled for http access, allow remote attackers to modify an e-mail address setting, and thus cause the device to send sensitive information through e-mail to the attacker. for example, an incoming fax may be sent through e-mail to the attacker. this occurs when a pin is not required for general user mode, as exploited in the wild in august 2021. cve-2021-38154 daffainfo auth-bypass canon cve cve2021 vkev vuln cwe-732" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Canon Devices - Authentication Bypass in Catwalk Server</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2021/CVE-2021-38154.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2021-38154.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> daffainfo</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 10, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/732.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-732</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2021-38154" target="_blank" rel="noopener" class="nt-cve-link">CVE-2021-38154</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)imageRUNNER&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Certain Canon devices manufactured in 2012 through 2020 (such as imageRUNNER ADVANCE iR-ADV C5250), when Catwalk Server is enabled for HTTP access, allow remote attackers to modify an e-mail address setting, and thus cause the device to send sensitive information through e-mail to the attacker. For example, an incoming FAX may be sent through e-mail to the attacker. This occurs when a PIN is not required for General User Mode, as exploited in the wild in August 2021.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can modify email settings and redirect FAX and scan data to attacker-controlled email addresses when PIN protection is disabled, potentially intercepting sensitive business communications.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Configure a PIN for General User Mode or apply Canon firmware updates that address this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">canon</span><span class="nt-tag">cve</span><span class="nt-tag">cve2021</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://protocolpolice.nl/CVE-2021-38154_Protocol_Police_Catwalk_Alert" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.usa.canon.com/internet/portal/us/home/support/product-advisories" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2021-38154" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="canon r-adv c3325 - default-login high identify default logins in web-based control panels  ritikchaddha c3325 canon default-login misconfig vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Canon R-ADV C3325 - Default-Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/canon/canon-c3325-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">canon-c3325-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 20, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)c3325&#34;})</code></div>
  <div class="nt-tags"><span class="nt-tag">c3325</span><span class="nt-tag">canon</span><span class="nt-tag">default-login</span><span class="nt-tag">misconfig</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://oip.manual.canon/USRMA-0618-zz-CS-enLN/contents/1T0002902253.html#:~:text=The%20default%20user%20name%20for,in%20order%20to%20increase%20security." target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="canon ir-adv panel - detect info identify web-based control panels  ritikchaddha,matejsmycka canon panel login detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Canon iR-ADV Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/canon/canon-ir-adv.yaml" target="_blank" rel="noopener" class="nt-source-link">canon-ir-adv.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha,matejsmycka</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 9, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Canon iR-ADV&#34;})</code></div>
  <div class="nt-tags"><span class="nt-tag">canon</span><span class="nt-tag">panel</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="canopy 5.7ghz access point - default login high identify default logins in web-based control panels cambium networks / motorola canopy 5750ap advantage access point 5.7ghz login credentials were discovered. defektive cambium canopy default-login vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Canopy 5.7GHz Access Point - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/cambium-networks/cambium-networks-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">cambium-networks-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> defektive</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 23, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Welcome to Canopy&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Cambium Networks / Motorola Canopy 5750AP ADVANTAGE Access Point 5.7GHz login credentials were discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cambium</span><span class="nt-tag">canopy</span><span class="nt-tag">default-login</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="caprover - default login high identify default logins in web-based control panels caprover defaultl login has been detected. ritikchaddha caprover default-login misconfig vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Caprover - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/caprover/caprover-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">caprover-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 28, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;988422585&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Caprover defaultl login has been detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">caprover</span><span class="nt-tag">default-login</span><span class="nt-tag">misconfig</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="car rental management system 1.0 - local file inclusion critical identify critical remote vulnerabilities car rental management system 1.0 allows an unauthenticated user to perform a file inclusion attack against the /index.php file with a partial filename in the &#34;page&#34; parameter, leading to code execution. cve-2020-29227 daffainfo car_rental_management_system_project cve cve2020 lfi sqli vkev vuln" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Car Rental Management System 1.0 - Local File Inclusion</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2020/CVE-2020-29227.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2020-29227.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> daffainfo</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2020-29227" target="_blank" rel="noopener" class="nt-cve-link">CVE-2020-29227</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)car rental management system&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Car Rental Management System 1.0 allows an unauthenticated user to perform a file inclusion attack against the /index.php file with a partial filename in the &#34;page&#34; parameter, leading to code execution.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can exploit this vulnerability to read sensitive files on the server, potentially leading to unauthorized access or information disclosure.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest patch or update provided by the vendor to fix the LFI vulnerability in the Car Rental Management System 1.0.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">car_rental_management_system_project</span><span class="nt-tag">cve</span><span class="nt-tag">cve2020</span><span class="nt-tag">lfi</span><span class="nt-tag">sqli</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://loopspell.medium.com/cve-2020-29227-unauthenticated-local-file-inclusion-7d3bd2c5c6a5" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2020-29227" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.sourcecodester.com/php/14544/car-rental-management-system-using-phpmysqli-source-code.html" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/ARPSyndicate/cvemon" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/ARPSyndicate/kenzer-templates" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="car rental management system 1.0 - sql injection high identify critical remote vulnerabilities car rental management system 1.0 contains an sql injection vulnerability via /admin/ajax.php?action=login. an attacker can possibly obtain sensitive information from a database, modify data, and execute unauthorized administrative operations in the context of the affected site. cve-2022-32022 arafatansari car_rental_management_system_project carrental cms cve cve2022 login-bypass sqli vuln cwe-89" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Car Rental Management System 1.0 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-32022.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-32022.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> arafatansari</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-32022" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-32022</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)car rental management system&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Car Rental Management System 1.0 contains an SQL injection vulnerability via /admin/ajax.php?action=login. An attacker can possibly obtain sensitive information from a database, modify data, and execute unauthorized administrative operations in the context of the affected site.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability can lead to unauthorized access, data leakage, and potential manipulation of the database.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to the latest version to mitigate this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">car_rental_management_system_project</span><span class="nt-tag">carrental</span><span class="nt-tag">cms</span><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">login-bypass</span><span class="nt-tag">sqli</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/k0xx11/bug_report/blob/main/vendors/campcodes.com/car-rental-management-system/SQLi-1.md" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-32022" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/k0xx11/bug_report/blob/main/vendors/campcodes.com/car-rental-management-system/SQLi-1.md." target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="carel pcoweb &lt;b1.2.4 - cross-site scripting medium identify critical remote vulnerabilities carel pcoweb prior to b1.2.4 is vulnerable to stored cross-site scripting, as demonstrated by the config/pw_snmp.html &#34;system contact&#34; field. cve-2019-11370 arafatansari carel cve cve2019 edb pcoweb vkev vuln xss cwe-79" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Carel pCOWeb &lt;B1.2.4 - Cross-Site Scripting</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2019/CVE-2019-11370.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2019-11370.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> arafatansari</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-79</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2019-11370" target="_blank" rel="noopener" class="nt-cve-link">CVE-2019-11370</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)pCOWeb&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Carel pCOWeb prior to B1.2.4 is vulnerable to stored cross-site scripting, as demonstrated by the config/pw_snmp.html &#34;System contact&#34; field.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Allows attackers to inject malicious scripts into web pages viewed by users, leading to potential data theft or unauthorized actions.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest patch or upgrade to a version that addresses the vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">carel</span><span class="nt-tag">cve</span><span class="nt-tag">cve2019</span><span class="nt-tag">edb</span><span class="nt-tag">pcoweb</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">xss</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.exploit-db.com/exploits/46897" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/nepenthe0320/cve_poc/blob/master/CVE-2019-11370" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2019-11370" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/ARPSyndicate/kenzer-templates" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="casaos  &lt; 0.4.4 - authentication bypass via internal ip critical identify critical remote vulnerabilities casaos is an open-source personal cloud system. due to a lack of ip address verification an unauthenticated attackers can execute arbitrary commands as `root` on casaos instances. the problem was addressed by improving the detection of client ip addresses in `391dd7f`. this patch is part of casaos 0.4.4. users should upgrade to casaos 0.4.4. if they can&#39;t, they should temporarily restrict access to casaos to untrusted users, for instance by not exposing it publicly. cve-2023-37265 iamnoooob,dhiyaneshdk,pdresearch casaos cve cve2023 icewhale jwt oss vuln cwe-306" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">CasaOS  &lt; 0.4.4 - Authentication Bypass via Internal IP</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-37265.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-37265.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> iamnoooob,DhiyaneshDK,pdresearch</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/306.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-306</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-37265" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-37265</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/casaos-ui/public/index\\.html&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">CasaOS is an open-source Personal Cloud system. Due to a lack of IP address verification an unauthenticated attackers can execute arbitrary commands as `root` on CasaOS instances. The problem was addressed by improving the detection of client IP addresses in `391dd7f`. This patch is part of CasaOS 0.4.4. Users should upgrade to CasaOS 0.4.4. If they can&#39;t, they should temporarily restrict access to CasaOS to untrusted users, for instance by not exposing it publicly.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation allows unauthorized access to the CasaOS system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">The problem was addressed by improving the detection of client IP addresses in 391dd7f. This patch is part of CasaOS 0.4.4.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">casaos</span><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">icewhale</span><span class="nt-tag">jwt</span><span class="nt-tag">oss</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/IceWhaleTech/CasaOS/commit/705bf1facbffd2ca40b159b0303132b6fdf657ad" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/IceWhaleTech/CasaOS/security/advisories/GHSA-m5q5-8mfw-p2hr" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/IceWhaleTech/CasaOS-Gateway/commit/391dd7f0f239020c46bf057cfa25f82031fc15f7" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/IceWhaleTech/CasaOS-Gateway/security/advisories/GHSA-vjh7-5r6x-xh6g" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/komodoooo/Some-things" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="casaos  &lt; 0.4.4 - authentication bypass via random jwt token critical identify critical remote vulnerabilities casaos is an open-source personal cloud system. unauthenticated attackers can craft arbitrary jwts and access features that usually require authentication and execute arbitrary commands as `root` on casaos instances. this problem was addressed by improving the validation of jwts in commit `705bf1f`. this patch is part of casaos 0.4.4. users should upgrade to casaos 0.4.4. if they can&#39;t, they should temporarily restrict access to casaos to untrusted users, for instance by not exposing it publicly. cve-2023-37266 iamnoooob,dhiyaneshdk,pdresearch casaos cve cve2023 icewhale jwt oss vuln cwe-287" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">CasaOS  &lt; 0.4.4 - Authentication Bypass via Random JWT Token</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-37266.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-37266.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> iamnoooob,DhiyaneshDK,pdresearch</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/287.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-287</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-37266" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-37266</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/casaos-ui/public/index\\.html&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">CasaOS is an open-source Personal Cloud system. Unauthenticated attackers can craft arbitrary JWTs and access features that usually require authentication and execute arbitrary commands as `root` on CasaOS instances. This problem was addressed by improving the validation of JWTs in commit `705bf1f`. This patch is part of CasaOS 0.4.4. Users should upgrade to CasaOS 0.4.4. If they can&#39;t, they should temporarily restrict access to CasaOS to untrusted users, for instance by not exposing it publicly.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation allows unauthorized access to the CasaOS system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">The problem was addressed by improving the validation of JWTs in 705bf1f. This patch is part of CasaOS 0.4.4.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">casaos</span><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">icewhale</span><span class="nt-tag">jwt</span><span class="nt-tag">oss</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/IceWhaleTech/CasaOS/commit/705bf1facbffd2ca40b159b0303132b6fdf657ad" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/IceWhaleTech/CasaOS/security/advisories/GHSA-m5q5-8mfw-p2hr" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="casaos login panel - detect info identify web-based control panels casaos login panel was detected. dhiyaneshdk casaos detect discovery login panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">CasaOS Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/casaos-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">casaos-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 21, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)CasaOS&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">CasaOS login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">casaos</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">login</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="cascade cms panel - detect info identify web-based control panels cascade cms was detected — a web content management system for managing stand-out websites. righettod panel cascade detect" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Cascade CMS Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/cascade-cms-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">cascade-cms-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 6, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Cascade CMS&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Cascade CMS was detected — a web content management system for managing stand-out websites.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">cascade</span><span class="nt-tag">detect</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.hannonhill.com/products/cascade-cms-web-content-management/index.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="casdoor - default admin credentials high identify default logins in web-based control panels detected casdoor platform was found to have been using the default administrator credentials (admin:123). an attacker could have gained full administrative access to manage organizations, users, applications, and oauth providers. 0x_akoko auth casdoor default-login vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Casdoor - Default Admin Credentials</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/casdoor-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">casdoor-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_Akoko</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 8, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Casdoor&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detected Casdoor platform was found to have been using the default administrator credentials (admin:123). An attacker could have gained full administrative access to manage organizations, users, applications, and OAuth providers.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth</span><span class="nt-tag">casdoor</span><span class="nt-tag">default-login</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://casdoor.org/docs/basic/core-concepts/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/casdoor/casdoor" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="casdoor 1.13.0 - unauthenticated sql injection high identify critical remote vulnerabilities casdoor version 1.13.0 suffers from a remote unauthenticated sql injection vulnerability via the query api in casdoor before 1.13.1 related to the field and value parameters, as demonstrated by api/get-organizations. cve-2022-24124 cckuailong casbin casdoor cve cve2022 edb packetstorm sqli unauth vuln cwe-89" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Casdoor 1.13.0 - Unauthenticated SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-24124.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-24124.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> cckuailong</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-24124" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-24124</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)casdoor&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Casdoor version 1.13.0 suffers from a remote unauthenticated SQL injection vulnerability via the query API in Casdoor before 1.13.1 related to the field and value parameters, as demonstrated by api/get-organizations.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized accessand data leakage.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to a patched version of Casdoor or apply the necessary security patches to mitigate the SQL injection vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">casbin</span><span class="nt-tag">casdoor</span><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">edb</span><span class="nt-tag">packetstorm</span><span class="nt-tag">sqli</span><span class="nt-tag">unauth</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://packetstormsecurity.com/files/166163/Casdoor-1.13.0-SQL-Injection.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.exploit-db.com/exploits/50792" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/cckuailong/reapoc/tree/main/2022/CVE-2022-24124/vultarget" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-24124" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/casdoor/casdoor/compare/v1.13.0...v1.13.1" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="casdoor login panel - detect info identify web-based control panels casdoor login panel was detected. princechaddha casbin casdoor discovery panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Casdoor Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/casdoor-login.yaml" target="_blank" rel="noopener" class="nt-source-link">casdoor-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> princechaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)casdoor&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Casdoor login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">casbin</span><span class="nt-tag">casdoor</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://casdoor.org/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="casemanager login panel - detect info identify web-based control panels casemanager login panel was detected. ffffffff0x casemanager panel discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">CaseManager Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/casemanager-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">casemanager-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ffffffff0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)CaseManager&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">CaseManager login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">casemanager</span><span class="nt-tag">panel</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="cassia bluetooth gateway panel - detect info identify web-based control panels cassia bluetooth gateway management platform login page was discovered. dhiyaneshdk cassia gateway login panel discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Cassia Bluetooth Gateway Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/cassia-bluetooth-gateway-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">cassia-bluetooth-gateway-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 23, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Cassia Bluetooth Gateway Management Platform&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Cassia Bluetooth Gateway Management Platform login page was discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cassia</span><span class="nt-tag">gateway</span><span class="nt-tag">login</span><span class="nt-tag">panel</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.cassianetworks.com/products/x1000-outdoor-bluetooth-router/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="caton network manager system login panel - detect info identify web-based control panels caton network manager system login panel was detected. pussycat0x caton manager login panel discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Caton Network Manager System Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/caton-network-manager-system.yaml" target="_blank" rel="noopener" class="nt-source-link">caton-network-manager-system.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Caton Network Manager System&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Caton Network Manager System login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">caton</span><span class="nt-tag">manager</span><span class="nt-tag">login</span><span class="nt-tag">panel</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="cellinx nvt web server - local file disclosure high identify critical remote vulnerabilities cellinx nvt v1.0.6.002b was discovered to contain a local file disclosure vulnerability via the component /cgi-bin/getfilecontent.cgi. cve-2023-23063 daffainfo cellinx cve cve2023 lfi nvt vkev vuln cwe-22" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Cellinx NVT Web Server - Local File Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-23063.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-23063.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> daffainfo</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 24, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-23063" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-23063</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/viewer/viewer\\.html&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Cellinx NVT v1.0.6.002b was discovered to contain a local file disclosure vulnerability via the component /cgi-bin/GetFileContent.cgi.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can read arbitrary files from the server through the PATH parameter in GetFileContent.cgi, potentially exposing system credentials, configuration files, and sensitive video surveillance data.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update Cellinx NVT to a version newer than 1.0.6.002b that validates file paths in GetFileContent.cgi and restricts file access to authorized directories only.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cellinx</span><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">lfi</span><span class="nt-tag">nvt</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/ahmedalroky/Disclosures/tree/cellinx" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="http://nvd.nist.gov/vuln/detail/CVE-2023-23063" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="celonis login - panel info identify web-based control panels detects celonis process intelligence login panels. r3dg33k panel celonis login detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Celonis Login - Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/celonis-login-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">celonis-login-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> r3dg33k</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 16, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Amazing insights\\. Better results\\.&#34; || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Celonis&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detects Celonis Process Intelligence login panels.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">celonis</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.celonis.com" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="centos web panel - os command injection critical identify critical remote vulnerabilities the unprivileged user portal part of centos web panel is affected by a command injection vulnerability leading to root remote code execution. cve-2021-31324 ritikchaddha centos cve cve2021 cwpsrv os rce vuln cwe-78" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">CentOS Web Panel - OS Command Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2021/CVE-2021-31324.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2021-31324.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 16, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/78.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-78</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2021-31324" target="_blank" rel="noopener" class="nt-cve-link">CVE-2021-31324</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Login \\| Control WebPanel&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The unprivileged user portal part of CentOS Web Panel is affected by a Command Injection vulnerability leading to root Remote Code Execution.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can execute arbitrary OS commands with root privileges via command injection in the idsession parameter, leading to complete server compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply security updates provided by CentOS Web Panel.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">centos</span><span class="nt-tag">cve</span><span class="nt-tag">cve2021</span><span class="nt-tag">cwpsrv</span><span class="nt-tag">os</span><span class="nt-tag">rce</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.shielder.com/advisories/centos-web-panel-idsession-root-rce/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2021-31324" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="centos web panel - sql injection critical identify critical remote vulnerabilities the unprivileged user portal part of centos web panel is affected by a sql injection via the &#39;idsession&#39; http post parameter. ritikchaddha centos cve cve2021 cwpsrv sqli vuln cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">CentOS Web Panel - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2021/CVE-2021-31316.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2021-31316.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 16, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Login \\| Control WebPanel&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The unprivileged user portal part of CentOS Web Panel is affected by a SQL Injection via the &#39;idsession&#39; HTTP POST parameter.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can exploit SQL injection via the idsession parameter to extract database contents or execute arbitrary commands with root privileges.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply security updates provided by CentOS Web Panel.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">centos</span><span class="nt-tag">cve</span><span class="nt-tag">cve2021</span><span class="nt-tag">cwpsrv</span><span class="nt-tag">sqli</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.shielder.com/advisories/centos-web-panel-idsession-root-rce/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2021-31316" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="centrestack login panel - detect info identify web-based control panels gladinet centrestack login panel was detected. rxerium panel centrestack login gladinet discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">CentreStack Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/gladinet-centrestack-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">gladinet-centrestack-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 9, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)CentreStack&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Gladinet CentreStack login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">centrestack</span><span class="nt-tag">login</span><span class="nt-tag">gladinet</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="centreon login panel - detect info identify web-based control panels centreon login panel was detected. pikpikcu,daffainfo centreon discovery login panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Centreon Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/centreon-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">centreon-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pikpikcu,daffainfo</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)centreon&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Centreon login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">centreon</span><span class="nt-tag">discovery</span><span class="nt-tag">login</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="chainlit panel - detect info identify web-based control panels chainlit panel was detected. chainlit is an open-source framework for building production-ready conversational ai applications. rxerium ai chainlit chatbot detect discovery llm panel" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Chainlit Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/chainlit-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">chainlit-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 27, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches `(?i)content\s*=\s*&#34;https://github.com/Chainlit/chainlit&#34;`</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Chainlit panel was detected. Chainlit is an open-source framework for building production-ready conversational AI applications.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">ai</span><span class="nt-tag">chainlit</span><span class="nt-tag">chatbot</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">llm</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/Chainlit/chainlit" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://chainlit.io/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="chancms &lt;= 3.3.0 - sql injection medium identify critical remote vulnerabilities yanyutao0402 chancms = 3.3.0 contains a sql injection caused by manipulation of the \&#34;key\&#34; argument in app/modules/api/service/api.js search function, letting remote attackers execute arbitrary sql commands, exploit requires crafted request. cve-2025-10210 yu_bao chancms cve cve2025 sqli cwe-89" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">ChanCMS &lt;= 3.3.0 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-10210.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-10210.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Yu_Bao</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 29, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-10210" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-10210</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)ChanCMS&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">yanyutao0402 ChanCMS = 3.3.0 contains a SQL injection caused by manipulation of the \&#34;key\&#34; argument in app/modules/api/service/Api.js Search function, letting remote attackers execute arbitrary SQL commands, exploit requires crafted request.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Remote attackers can execute arbitrary SQL commands, potentially leading to data theft or database compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest version.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">chancms</span><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">sqli</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://gitee.com/yanyutao0402/ChanCMS" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://vuldb.com/?id.323483" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/August829/Yu/blob/main/58ead8e7e08bfb0e5.md" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-10210" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="change detection - server side template injection critical identify critical remote vulnerabilities a server side template injection in changedetection.io caused by usage of unsafe functions of jinja2 allows remote command execution on the server host. cve-2024-32651 edoardottt changedetection cve cve2024 passive rce ssti vuln cwe-1336" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Change Detection - Server Side Template Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-32651.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-32651.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> edoardottt</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 29, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/1336.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-1336</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-32651" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-32651</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Change Detection&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A Server Side Template Injection in changedetection.io caused by usage of unsafe functions of Jinja2 allows Remote Command Execution on the server host.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can execute arbitrary code on the server through Server Side Template Injection.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update changedetection.io to version 0.45.21 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">changedetection</span><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">passive</span><span class="nt-tag">rce</span><span class="nt-tag">ssti</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-32651" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/dgtlmoon/changedetection.io/security/advisories/GHSA-4r7v-whpg-8rx3" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/dgtlmoon/changedetection.io/releases/tag/0.45.21" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://www.onsecurity.io/blog/server-side-template-injection-with-jinja2" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="changedetection.io &lt;= 0.47.4 - path traversal medium identify critical remote vulnerabilities changedetection.io is free, open source web page change detection software. prior to version 0.47.5, when a webdriver is used to fetch files, `source-file-///etc/passwd` can be used to retrieve local system files, where the more traditional `file-///etc/passwd` gets blocked. version 0.47.5 fixes the issue. cve-2024-51483 iamnoooob,rootxharsh,pdresearch changedetection cve cve2024 lfi vuln cwe-22" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Changedetection.io &lt;= 0.47.4 - Path Traversal</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-51483.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-51483.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> iamnoooob,rootxharsh,pdresearch</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 11, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-51483" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-51483</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)change detection&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">changedetection.io is free, open source web page change detection software. Prior to version 0.47.5, when a WebDriver is used to fetch files, `source-file-///etc/passwd` can be used to retrieve local system files, where the more traditional `file-///etc/passwd` gets blocked. Version 0.47.5 fixes the issue.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can exploit this vulnerability to compromise system security.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply security patches to address CVE-2024-51483.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">changedetection</span><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">lfi</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/advisories/GHSA-cwgg-57xj-g77r" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/dgtlmoon/changedetection.io/blob/master/changedetectionio/model/Watch.py#L19" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/dgtlmoon/changedetection.io/blob/master/changedetectionio/processors/__init__.py#L35" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/dgtlmoon/changedetection.io/security/advisories/GHSA-cwgg-57xj-g77r" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/user-attachments/files/17591630/CL-ChangeDetection.io.Path.Travsersal-311024-181039.pdf" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="changedetection.io panel - detect info identify web-based control panels change detection is an open-source service which allows you to detect changes on websites rxerium panel changedetection detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Changedetection.io Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/changedetection-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">changedetection-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 27, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Change Detection&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Change Detection is an open-source service which allows you to detect changes on websites</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">changedetection</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/dgtlmoon/changedetection.io" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://changedetection.io/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="changedetection.io rss single watch - cross-site scripting medium identify critical remote vulnerabilities changedetection.io &lt; 0.54.1 contains a stored xss caused by unescaped reflection of uuid path parameter in rss single-watch endpoint, letting remote attackers execute javascript in victim&#39;s browser, exploit requires victim to visit crafted url. cve-2026-27645 0x_akoko changedetection cve cve2026 rss xss cwe-79" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Changedetection.io RSS Single Watch - Cross-Site Scripting</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2026/CVE-2026-27645.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2026-27645.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_Akoko</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 27, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-79</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2026-27645" target="_blank" rel="noopener" class="nt-cve-link">CVE-2026-27645</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Change Detection&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">changedetection.io &lt; 0.54.1 contains a stored XSS caused by unescaped reflection of UUID path parameter in RSS single-watch endpoint, letting remote attackers execute JavaScript in victim&#39;s browser, exploit requires victim to visit crafted URL.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can execute arbitrary JavaScript in users&#39; browsers, leading to session hijacking or other client-side attacks</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to version 0.54.1 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">changedetection</span><span class="nt-tag">cve</span><span class="nt-tag">cve2026</span><span class="nt-tag">rss</span><span class="nt-tag">xss</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/dgtlmoon/changedetection.io/security/advisories/GHSA-mw8m-398g-h89w" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/dgtlmoon/changedetection.io/commit/a385c89abf44b52fcfa20c7c6a6dd3047c4c1eb5" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27645" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="changjietong remote communication gnremote.dll - sql injection high identify critical remote vulnerabilities chanjetong has a sql injection vulnerability, which can be used by attackers to obtain sensitive information in the database. sleepingbag945 chanjet sqli vuln yonyou cwe-89" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Changjietong Remote Communication GNRemote.dll - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/vulnerabilities/yonyou/chanjet-gnremote-sqli.yaml" target="_blank" rel="noopener" class="nt-source-link">chanjet-gnremote-sqli.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> SleepingBag945</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 15, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)远程通CHANJET_Remote&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Chanjetong has a SQL injection vulnerability, which can be used by attackers to obtain sensitive information in the database.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">chanjet</span><span class="nt-tag">sqli</span><span class="nt-tag">vuln</span><span class="nt-tag">yonyou</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/PeiQi0/PeiQi-WIKI-Book/blob/90103c248a2c52bb0a060d0ee95d5a67e4579c3d/docs/wiki/webapp/%E7%94%A8%E5%8F%8B/%E7%94%A8%E5%8F%8B%20%E7%95%85%E6%8D%B7%E9%80%9A%E8%BF%9C%E7%A8%8B%E9%80%9A%20GNRemote.dll%20SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="check point quantum gateway - information disclosure high identify critical remote vulnerabilities potentially allowing an attacker to read certain information on check point security gateways once connected to the internet and enabled with remote access vpn or mobile access software blades. a security fix that mitigates this vulnerability is available. cve-2024-24919 johnk3r,s4e-io checkpoint cve cve2024 kev lfi vkev vuln cwe-200" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Check Point Quantum Gateway - Information Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-24919.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-24919.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> johnk3r,s4e-io</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 30, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-24919" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-24919</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)check point ssl network&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Software Blades. A Security fix that mitigates this vulnerability is available.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can read arbitrary files on Check Point Security Gateways, potentially exposing sensitive configuration files and credentials.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply Check Point security fixes for CVE-2024-24919 as specified in SK182337.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">checkpoint</span><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">kev</span><span class="nt-tag">lfi</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://labs.watchtowr.com/check-point-wrong-check-point-cve-2024-24919/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://support.checkpoint.com/results/sk/sk182337" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://s4e.io/tools/check-point-quantum-gateway-information-disclosure-cve-2024-24919" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://thehackernews.com/2024/05/check-point-warns-of-zero-day-attacks.html" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://censys.com/cve-2024-24919/" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="checkpoint ssl network extender login panel - detect info identify web-based control panels checkpoint ssl network extender login panel was detected. idealphase checkpoint discovery panel router cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">CheckPoint SSL Network Extender Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/checkpoint/ssl-network-extender.yaml" target="_blank" rel="noopener" class="nt-source-link">ssl-network-extender.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> idealphase</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)check point ssl network extender&#34;}) || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)ssl network extender login&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">CheckPoint SSL Network Extender login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">checkpoint</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">router</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;solutionid=sk65210" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_RemoteAccessVPN_AdminGuide/Topics-VPNRG/SSL-Network-Extender.htm?TocPath=SSL%20Network%20Extender%7C_____0" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="checkmarx login panel - detect info identify web-based control panels checkmarx login panel was detected. joanbonon,righettod panel checkmarx detect login discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Checkmarx Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/checkmk/checkmarx-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">checkmarx-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> joanbonon,righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)CxSASTManagerUri&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Checkmarx login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">checkmarx</span><span class="nt-tag">detect</span><span class="nt-tag">login</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://docs.checkmarx.com/en/34965-44074-checkmarx-sast.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="checkmate login panel - detect info identify web-based control panels checkmate administrative login page was found. theamanrawat checkmate panel discovery login cwe-668" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Checkmate Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/checkmate-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">checkmate-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> theamanrawat</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 12, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/668.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-668</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;^Checkmate$&#34; })</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Checkmate administrative login page was found.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">checkmate</span><span class="nt-tag">panel</span><span class="nt-tag">discovery</span><span class="nt-tag">login</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="checkmk - default login high identify default logins in web-based control panels checkmk monitoring instance is accessible with default credentials (cmkadmin/cmkadmin). this provides full administrative access to the monitoring platform, including the ability to view all monitored hosts, execute commands on agents, and access stored credentials. 0xbassia checkmk default-login monitoring cwe-798" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Checkmk - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/checkmk-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">checkmk-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0xBassia</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 8, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/798.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-798</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Check_MK&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Checkmk monitoring instance is accessible with default credentials (cmkadmin/cmkadmin). This provides full administrative access to the monitoring platform, including the ability to view all monitored hosts, execute commands on agents, and access stored credentials.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker with admin access to Checkmk can view the entire monitored infrastructure, access stored SNMP community strings and SSH credentials, execute commands on monitored hosts via the agent, and gain visibility into the organization&#39;s network topology.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Change the default cmkadmin password immediately after installation using &#39;cmk-passwd cmkadmin&#39; or through the web interface.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">checkmk</span><span class="nt-tag">default-login</span><span class="nt-tag">monitoring</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://docs.checkmk.com/latest/en/intro_setup.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://docs.checkmk.com/latest/en/wato_user.html" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="checkmk login panel - detect info identify web-based control panels checkmk login panel was detected. princechaddha,righettod panel checkmk detect login discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Checkmk Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/checkmk/checkmk-login.yaml" target="_blank" rel="noopener" class="nt-source-link">checkmk-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> princechaddha,righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Check_MK&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Checkmk login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">checkmk</span><span class="nt-tag">detect</span><span class="nt-tag">login</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://checkmk.com/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="chef automate &lt; 4.13.295 — sql injection critical identify critical remote vulnerabilities in progress chef automate, versions earlier than 4.13.295, on linux x86 platform, an authenticated attacker can gain access to chef automate restricted functionality in the compliance service via improperly neutralized inputs used in an sql command using a well-known token. cve-2025-8868 3th1c_yuk1,xbow automate chef cve cve2025 sqli vkev vuln cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Chef Automate &lt; 4.13.295 — SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-8868.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-8868.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 3th1c_yuk1,xbow</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 6, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-8868" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-8868</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Chef Automate&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">In Progress Chef Automate, versions earlier than 4.13.295, on Linux x86 platform, an authenticated attacker can gain access to Chef Automate restricted functionality in the compliance service via improperly neutralized inputs used in an SQL command using a well-known token.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Authenticated attackers with knowledge of a well-known token can execute arbitrary SQL queries through the compliance service, potentially gaining access to restricted functionality and sensitive data.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to version 4.13.295 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">automate</span><span class="nt-tag">chef</span><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">sqli</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://xbow.com/blog/cooking-an-sql-injection-vulnerability-in-chef-automate" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-8868" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="chemotargets clarity vista login panel - detect info identify web-based control panels chemotargets clarity vista login panel was detected. righettod panel chemotargets login detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Chemotargets Clarity Vista Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/chemotargets-clarityvista-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">chemotargets-clarityvista-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 13, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)ClarityVista&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Chemotargets Clarity Vista login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">chemotargets</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://chemotargets.com/clarityvista/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="chirpstack - default login high identify default logins in web-based control panels fresh chirpstack installations use the default credentials (admin/admin), allowing attackers to easily access the admin console. t3l3machus chirpstack default-login vuln cwe-1392" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">ChirpStack - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/chirpstack/chirpstack-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">chirpstack-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> t3l3machus</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 16, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/1392.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-1392</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;ChirpStack LoRaWAN&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Fresh ChirpStack installations use the default credentials (admin/admin), allowing attackers to easily access the admin console.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">chirpstack</span><span class="nt-tag">default-login</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.chirpstack.io/docs/chirpstack/use/login.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="chirpstack lorawan detection info identify web-based control panels detects the presence of chirpstack lorawan network-server by identifying unique page characteristics in the html response. projectdiscoveryai panel chirpstack discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">ChirpStack LoRaWAN Detection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/chirpstack-login.yaml" target="_blank" rel="noopener" class="nt-source-link">chirpstack-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ProjectDiscoveryAI</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 16, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)ChirpStack LoRaWAN&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detects the presence of ChirpStack LoRaWAN Network-Server by identifying unique page characteristics in the HTML response.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">chirpstack</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.chirpstack.io/docs/chirpstack/use/login.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="chronos panel - detect info identify web-based control panels chronos login panel was detected. righettod panel chronos login detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Chronos Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/chronos-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">chronos-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 24, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)chronoslogin\\.js&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Chronos Login Panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">chronos</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.asys.fr/chronos" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="churchcrm - api authentication bypass via url injection critical identify critical remote vulnerabilities churchcrm &lt; 7.1.0 contains an authentication bypass caused by improper api middleware url handling in churchcrm/slim/middleware/authmiddleware.php, letting unauthenticated attackers access protected api endpoints, exploit requires crafted request url with &#39;api/public cve-2026-39339 akhilshekhar auth-bypass churchcrm cve cve2026 cwe-284" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">ChurchCRM - API Authentication Bypass via URL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2026/CVE-2026-39339.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2026-39339.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> akhilshekhar</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 4, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/284.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-284</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2026-39339" target="_blank" rel="noopener" class="nt-cve-link">CVE-2026-39339</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)churchcrm&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">ChurchCRM &lt; 7.1.0 contains an authentication bypass caused by improper API middleware URL handling in ChurchCRM/Slim/Middleware/AuthMiddleware.php, letting unauthenticated attackers access protected API endpoints, exploit requires crafted request URL with &#39;api/public</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can access all protected API endpoints, exposing sensitive church member data and system information.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to version 7.1.0 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">churchcrm</span><span class="nt-tag">cve</span><span class="nt-tag">cve2026</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/ChurchCRM/CRM/security/advisories/GHSA-v3p2-mx78-pxhc" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="churchcrm - cross-site scripting medium identify critical remote vulnerabilities a reflected cross-site scripting (xss) vulnerability was discovered in churchcrm via the &#39;username&#39; parameter in /session/begin. pikpikcu churchcrm crm vuln xss cwe-79,cwe-80" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">ChurchCRM - Cross-Site Scripting</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/vulnerabilities/churchcrm/churchcrm-xss.yaml" target="_blank" rel="noopener" class="nt-source-link">churchcrm-xss.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pikpikcu</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 24, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/79,CWE-80.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-79,CWE-80</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)ChurchCRM&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A reflected cross-site scripting (XSS) vulnerability was discovered in ChurchCRM via the &#39;username&#39; parameter in /session/begin.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">churchcrm</span><span class="nt-tag">crm</span><span class="nt-tag">vuln</span><span class="nt-tag">xss</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/ChurchCRM/CRM/blob/91cfa8eb00aef724705f5e038c236c146c6cf3a6/src/session/templates/begin-session.php#L39" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="churchcrm - default login high identify default logins in web-based control panels churchcrm contains a default login vulnerability. kazgangap default-login churchcrm vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">ChurchCRM - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/churchcrm/churchcrm-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">churchcrm-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Kazgangap</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 4, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)churchcrm&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">ChurchCRM contains a default login vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">churchcrm</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/ChurchCRM/CRM" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="churchcrm panel - detect info identify web-based control panels churchcrm panel was discovered. kazgangap panel login churchcrm detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">ChurchCRM Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/churchcrm-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">churchcrm-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Kazgangap</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 3, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)churchcrm&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">ChurchCRM panel was discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">login</span><span class="nt-tag">churchcrm</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/ChurchCRM/CRM" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="ciphertrust - default login high identify default logins in web-based control panels attackers can control the entire platform through the default password （initpass） vulnerability, and use administrator privileges to operate core functions. sleepingbag945 ciphertrust default-login vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Ciphertrust - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/others/ciphertrust-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">ciphertrust-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> SleepingBag945</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 8, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# contains &#34;(?i)CipherTrust Manager&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Attackers can control the entire platform through the default password （initpass） vulnerability, and use administrator privileges to operate core functions.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">ciphertrust</span><span class="nt-tag">default-login</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.thalesdocs.com/ctp/cm/2.6/get_started/deployment/initial-password/index.html#:~:text=The%20username%20of%20the%20initial,to%20%22admin%22%20in%20lowercase." target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="circutor line-tcprs1 - default login high identify default logins in web-based control panels a default login was discovered on a circutor line-tcprs1 device. an attacker can obtain access to user accounts, access sensitive information, modify data, and execute unauthorized operations. s4e-io circutor iot tcprs1 default-login vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Circutor Line-TCPRS1 - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/circutor/circutor-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">circutor-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> s4e-io</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 2, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Line-TCPRS1&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A default login was discovered on a Circutor Line-TCPRS1 device. An attacker can obtain access to user accounts, access sensitive information, modify data, and execute unauthorized operations.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">circutor</span><span class="nt-tag">iot</span><span class="nt-tag">tcprs1</span><span class="nt-tag">default-login</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://circutor.com/en/products/line-tcprs1/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="cisco ace 4710 device manager login panel - detect info identify web-based control panels cisco ace 4710 device manager login panel was detected. dhiyaneshdk cisco discovery panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Cisco ACE 4710 Device Manager Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/cisco/cisco-ace-device-manager.yaml" target="_blank" rel="noopener" class="nt-source-link">cisco-ace-device-manager.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)ACE 4710 Device Manager&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Cisco ACE 4710 Device Manager login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cisco</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="cisco asa - local file inclusion high identify critical remote vulnerabilities cisco adaptive security appliances (asa) web interfaces could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (dos) condition. it is also possible on certain software releases that the asa will not reload, but an attacker could view sensitive system information without authentication by using directory traversal techniques. the vulnerability is due to lack of proper input validation of the http url. an attacker could exploit this vulnerability by sending a crafted http request to an affected device. an exploit could allow the attacker to cause a dos condition or unauthenticated disclosure of information. this vulnerability applies to ipv4 and ipv6 http traffic. this vulnerability affects cisco asa software and cisco firepower threat defense (ftd) software that is running on the following cisco products: 3000 series industrial security appliance (isa), asa 1000v cloud firewall, asa 5500 series adaptive security appliances, asa 5500-x series next-generation firewalls, asa services module for cisco catalyst 6500 series switches and cisco 7600 series routers, adaptive security virtual appliance (asav), firepower 2100 series security appliance, firepower 4100 series security appliance, firepower 9300 asa security module, ftd virtual (ftdv). cisco bug ids: cscvi16029. cve-2018-0296 organiccrap asa cisco cve cve2018 edb kev lfi traversal vkev vuln cwe-20,cwe-22" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Cisco ASA - Local File Inclusion</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2018/CVE-2018-0296.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2018-0296.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> organiccrap</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/20,CWE-22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-20,CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2018-0296" target="_blank" rel="noopener" class="nt-cve-link">CVE-2018-0296</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">asset[&#34;hw_product&#34;] matches `(?i)adaptive\s+security\s+appliance`</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Cisco Adaptive Security Appliances (ASA) web interfaces could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. It is also possible on certain software releases that the ASA will not reload, but an attacker could view sensitive system information without authentication by using directory traversal techniques. The vulnerability is due to lack of proper input validation of the HTTP URL. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. An exploit could allow the attacker to cause a DoS condition or unauthenticated disclosure of information. This vulnerability applies to IPv4 and IPv6 HTTP traffic. This vulnerability affects Cisco ASA Software and Cisco Firepower Threat Defense (FTD) Software that is running on the following Cisco products: 3000 Series Industrial Security Appliance (ISA), ASA 1000V Cloud Firewall, ASA 5500 Series Adaptive Security Appliances, ASA 5500-X Series Next-Generation Firewalls, ASA Services Module for Cisco Catalyst 6500 Series Switches and Cisco 7600 Series Routers, Adaptive Security Virtual Appliance (ASAv), Firepower 2100 Series Security Appliance, Firepower 4100 Series Security Appliance, Firepower 9300 ASA Security Module, FTD Virtual (FTDv). Cisco Bug IDs: CSCvi16029.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can read sensitive files on the Cisco ASA firewall, potentially leading to unauthorized access or information disclosure.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the necessary security patches or updates provided by Cisco to fix the local file inclusion vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">asa</span><span class="nt-tag">cisco</span><span class="nt-tag">cve</span><span class="nt-tag">cve2018</span><span class="nt-tag">edb</span><span class="nt-tag">kev</span><span class="nt-tag">lfi</span><span class="nt-tag">traversal</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/yassineaboukir/CVE-2018-0296" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180606-asaftd" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.exploit-db.com/exploits/44956/" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2018-0296" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="http://www.securitytracker.com/id/1041076" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="cisco adaptive security appliance (asa)/firepower threat defense (ftd) - local file inclusion high identify critical remote vulnerabilities cisco adaptive security appliance (asa) software and cisco firepower threat defense (ftd) software is vulnerable to local file inclusion due to directory traversal attacks that can read sensitive files on a targeted system because of a lack of proper input validation of urls in http requests processed by an affected device. an attacker could exploit this vulnerability by sending a crafted http request containing directory traversal character sequences to an affected device. a successful exploit could allow the attacker to view arbitrary files within the web services file system on the targeted device. the web services file system is enabled when the affected device is configured with either webvpn or anyconnect features. this vulnerability cannot be used to obtain access to asa or ftd system files or underlying operating system (os) files. cve-2020-3452 pdteam cisco cve cve2020 kev lfi packetstorm vkev vuln cwe-20,cwe-22" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Cisco Adaptive Security Appliance (ASA)/Firepower Threat Defense (FTD) - Local File Inclusion</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2020/CVE-2020-3452.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2020-3452.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pdteam</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/20,CWE-22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-20,CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2020-3452" target="_blank" rel="noopener" class="nt-cve-link">CVE-2020-3452</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">asset[&#34;hw_product&#34;] matches `(?i)adaptive\s+security\s+appliance`</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software is vulnerable to local file inclusion due to directory traversal attacks that can read sensitive files on a targeted system because of a lack of proper input validation of URLs in HTTP requests processed by an affected device. An attacker could exploit this vulnerability by sending a crafted HTTP request containing directory traversal character sequences to an affected device. A successful exploit could allow the attacker to view arbitrary files within the web services file system on the targeted device. The web services file system is enabled when the affected device is configured with either WebVPN or AnyConnect features. This vulnerability cannot be used to obtain access to ASA or FTD system files or underlying operating system (OS) files.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can exploit this vulnerability to read sensitive files on the affected system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the necessary security patches or updates provided by Cisco to fix the vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cisco</span><span class="nt-tag">cve</span><span class="nt-tag">cve2020</span><span class="nt-tag">kev</span><span class="nt-tag">lfi</span><span class="nt-tag">packetstorm</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://twitter.com/aboul3la/status/1286012324722155525" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="http://packetstormsecurity.com/files/158646/Cisco-ASA-FTD-Remote-File-Disclosure.html" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="http://packetstormsecurity.com/files/158647/Cisco-Adaptive-Security-Appliance-Software-9.11-Local-File-Inclusion.html" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="http://packetstormsecurity.com/files/159523/Cisco-ASA-FTD-9.6.4.42-Path-Traversal.html" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="http://packetstormsecurity.com/files/160497/Cisco-ASA-9.14.1.10-FTD-6.6.0.1-Path-Traversal.html" target="_blank" rel="noopener" class="nt-ref-link">[5]</a> <a href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-ro-path-KJuQhB86" target="_blank" rel="noopener" class="nt-ref-link">[6]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2020-3452" target="_blank" rel="noopener" class="nt-ref-link">[7]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="cisco edge 340 panel - detect info identify web-based control panels cisco edge 340 panel was detected. dhiyaneshdk cisco discovery panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Cisco Edge 340 Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/cisco/cisco-edge-340.yaml" target="_blank" rel="noopener" class="nt-source-link">cisco-edge-340.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)cisco edge 340&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Cisco Edge 340 panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cisco</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="cisco email security appliance - panel info identify web-based control panels detected cisco email security appliance login panel. rxerium,darses login cisco panel email discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Cisco Email Security Appliance - Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/cisco-esa-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">cisco-esa-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium,darses</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 19, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Cisco\\s+(?:Cloud\\s+)?Gateway&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detected Cisco Email Security Appliance login panel.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">login</span><span class="nt-tag">cisco</span><span class="nt-tag">panel</span><span class="nt-tag">email</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="cisco ios xe - impant detection critical identify critical remote vulnerabilities cisco is aware of active exploitation of a previously unknown vulnerability in the web ui feature of cisco ios xe software when exposed to the internet or to untrusted networks. this vulnerability allows a remote, unauthenticated attacker to create an account on an affected system with privilege level 15 access. the attacker can then use that account to gain control of the affected system. dhiyaneshdk,rxerium backdoor cisco ios kev vuln" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Cisco IOS XE - Impant Detection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/vulnerabilities/backdoor/cisco-implant-detect.yaml" target="_blank" rel="noopener" class="nt-source-link">cisco-implant-detect.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK,rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 26, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body.mmh3&#34;] == &#34;1076109428&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Cisco is aware of active exploitation of a previously unknown vulnerability in the web UI feature of Cisco IOS XE Software when exposed to the internet or to untrusted networks. This vulnerability allows a remote, unauthenticated attacker to create an account on an affected system with privilege level 15 access. The attacker can then use that account to gain control of the affected system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Disable the HTTP server feature on internet-facing systems by running one of the following commands in global configuration mode: &#39;no ip http server&#39; or &#39;no ip http secure-server&#39;.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">backdoor</span><span class="nt-tag">cisco</span><span class="nt-tag">ios</span><span class="nt-tag">kev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-webui-privesc-j22SaA4z" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.bleepingcomputer.com/news/security/cisco-warns-of-new-ios-xe-zero-day-actively-exploited-in-attacks/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://socradar.io/cisco-warns-of-exploitation-of-a-maximum-severity-zero-day-vulnerability-in-ios-xe-cve-2023-20198" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/vulncheck-oss/cisco-ios-xe-implant-scanner/blob/main/implant-scanner.go" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="cisco ios xe web ui - command injection critical identify critical remote vulnerabilities a vulnerability in the web ui component of cisco ios xe software could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. this vulnerability is due to improper input validation in the web ui. an attacker could exploit this vulnerability by sending crafted http requests to an affected device. a successful exploit could allow the attacker to execute arbitrary commands with root privileges on the underlying operating system. cve-2023-20198 iamnoooob,rootxharsh,pdresearch,nullenc0de cisco cve cve2023 iot kev network rce router vkev vuln" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Cisco IOS XE Web UI - Command Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-20198.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-20198.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> iamnoooob,rootxharsh,pdresearch,nullenc0de</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 18, 2023</span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-20198" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-20198</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body.mmh3&#34;] == &#34;1076109428&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A vulnerability in the web UI component of Cisco IOS XE Software could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. This vulnerability is due to improper input validation in the web UI. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary commands with root privileges on the underlying operating system.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can execute arbitrary commands with root privileges through crafted HTTP requests to the web UI component, potentially compromising the entire Cisco IOS XE router and all managed network traffic.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply Cisco security patches from advisory cisco-sa-iosxe-webui-privesc-j22SaA4z that validate input in the web UI and prevent command injection in the SOAP API.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cisco</span><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">iot</span><span class="nt-tag">kev</span><span class="nt-tag">network</span><span class="nt-tag">rce</span><span class="nt-tag">router</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-webui-privesc-j22SaA4z" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.rapid7.com/blog/post/2023/10/16/etr-cisco-ios-xe-web-ui-cve-2023-20198-active-exploitation/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="cisco ise admin login panel - detect info identify web-based control panels cisco identity services engine (ise) admin login panel was discovered. bhutch cisco ise admin login panel detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Cisco ISE Admin Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/cisco/cisco-ise-admin-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">cisco-ise-admin-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> bhutch</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 11, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Identity Services Engine&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Cisco Identity Services Engine (ISE) admin login panel was discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cisco</span><span class="nt-tag">ise</span><span class="nt-tag">admin</span><span class="nt-tag">login</span><span class="nt-tag">panel</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="cisco identity services engine admin login panel - detect info identify web-based control panels cisco identity services engine admin login panel was detected. dhiyaneshdk cisco discovery panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Cisco Identity Services Engine Admin Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/identity-services-engine.yaml" target="_blank" rel="noopener" class="nt-source-link">identity-services-engine.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)identity services engine&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Cisco Identity Services Engine admin login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cisco</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="cisco prime infrastructure panel - detect info identify web-based control panels a cisco prime infrastructure login panel was discovered. dhiyaneshdk panel cisco discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Cisco Prime Infrastructure Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/cisco/cisco-prime-infrastructure.yaml" target="_blank" rel="noopener" class="nt-source-link">cisco-prime-infrastructure.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)prime infrastructure&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A Cisco Prime Infrastructure login panel was discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">cisco</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="cisco secure cn login panel - detect info identify web-based control panels cisco secure cn login panel was detected. dhiyaneshdk panel cisco discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Cisco Secure CN Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/cisco/cisco-secure-cn.yaml" target="_blank" rel="noopener" class="nt-source-link">cisco-secure-cn.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Cisco Secure CN&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Cisco Secure CN login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">cisco</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="cisco secure firewall asa &amp; ftd - authentication bypass medium identify critical remote vulnerabilities a vulnerability in the vpn web server of cisco secure firewall adaptive security appliance (asa) software and cisco secure firewall threat defense (ftd) software could allow an unauthenticated, remote attacker to access restricted url endpoints that are related to remote access vpn that should otherwise be inaccessible without authentication. this vulnerability is due to improper validation of user-supplied input in http(s) requests. cve-2025-20362 dhiyaneshdk,attackerkb,brendan-rsoc asa auth-bypass cisco cve cve2025 kev vkev vuln cwe-862" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Cisco Secure Firewall ASA &amp; FTD - Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-20362.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-20362.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk,attackerkb,brendan-rsoc</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 6, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/862.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-862</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-20362" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-20362</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/\\+CSCOE\\+/logon\\.html&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to access restricted URL endpoints that are related to remote access VPN that should otherwise be inaccessible without authentication. This vulnerability is due to improper validation of user-supplied input in HTTP(S) requests.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker could exploit this vulnerability by sending crafted HTTP requests to a targeted web server on a device. A successful exploit could allow the attacker to access a restricted URL without authentication.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest available version of Cisco Secure Firewall ASA and FTD Software.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">asa</span><span class="nt-tag">auth-bypass</span><span class="nt-tag">cisco</span><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">kev</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://attackerkb.com/topics/Szq5u0xgUX/cve-2025-20362/rapid7-analysis" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/cve-2025-20362" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="cisco secure firewall management center - authentication bypass critical identify critical remote vulnerabilities cisco secure firewall management center software contains an authentication bypass caused by improper system process creation at boot, letting unauthenticated remote attackers execute scripts and gain root access, exploit requires crafted http requests. cve-2026-20079 theamanrawat auth-bypass cisco cve cve2026 fmc rce unauth cwe-288" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Cisco Secure Firewall Management Center - Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2026/CVE-2026-20079.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2026-20079.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> theamanrawat</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 14, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/288.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-288</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2026-20079" target="_blank" rel="noopener" class="nt-cve-link">CVE-2026-20079</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)BackdraftSyncIntegration&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Cisco Secure Firewall Management Center Software contains an authentication bypass caused by improper system process creation at boot, letting unauthenticated remote attackers execute scripts and gain root access, exploit requires crafted HTTP requests.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated remote attackers can gain root access by executing scripts, leading to full system compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest available version.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">cisco</span><span class="nt-tag">cve</span><span class="nt-tag">cve2026</span><span class="nt-tag">fmc</span><span class="nt-tag">rce</span><span class="nt-tag">unauth</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.vulncheck.com/blog/cisco-fmc-auth-bypass-cve-2026-20079" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20079" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="cisco servicegrid login panel - detect info identify web-based control panels cisco servicegrid login panel was detected. dhiyaneshdk panel cisco discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Cisco ServiceGrid Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/cisco/cisco-sendgrid.yaml" target="_blank" rel="noopener" class="nt-source-link">cisco-sendgrid.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Cisco ServiceGrid&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Cisco ServiceGrid login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">cisco</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="cisco smart software manager on-prem panel - detect info identify web-based control panels cisco smart software manager on-prem is an on-premises software license management solution offered by cisco. it enables organizations to manage and optimize their cisco software licenses, entitlements, and usage in their local data centers, providing greater control and visibility over software assets. irshad ahamed cisco discovery login manager panel" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Cisco Smart Software Manager On-Prem Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/cisco/cisco-onprem-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">cisco-onprem-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> irshad ahamed</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 28, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)on-prem license workspace&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Cisco Smart Software Manager On-Prem is an on-premises software license management solution offered by Cisco. It enables organizations to manage and optimize their Cisco software licenses, entitlements, and usage in their local data centers, providing greater control and visibility over software assets.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cisco</span><span class="nt-tag">discovery</span><span class="nt-tag">login</span><span class="nt-tag">manager</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.cisco.com/c/en/us/products/collateral/cloud-systems-management/smart-software-manager-satellite/datasheet-c78-734539.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ssm-sql-X9MmjSYh" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="cisco systems login panel - detect info identify web-based control panels cisco systems login panel was detected. dhiyaneshdk,idealphase panel cisco discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Cisco Systems Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/cisco/cisco-systems-login.yaml" target="_blank" rel="noopener" class="nt-source-link">cisco-systems-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDk,idealphase</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Cisco Systems Login&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Cisco Systems login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">cisco</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="cisco telepresence login panel - detect info identify web-based control panels cisco telepresence login panel was detected. dhiyaneshdk cisco discovery panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Cisco TelePresence Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/cisco/cisco-telepresence.yaml" target="_blank" rel="noopener" class="nt-source-link">cisco-telepresence.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Cisco Telepresence&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Cisco TelePresence login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cisco</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="cisco ucs manager kvm login panel - detect info identify web-based control panels cisco ucs manager kvm login panel was detected. idealphase cisco discovery kvm panel ucs cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Cisco UCS Manager KVM Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/cisco/cisco-ucs-kvm-login.yaml" target="_blank" rel="noopener" class="nt-source-link">cisco-ucs-kvm-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> idealphase</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)cisco ucs kvm direct&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Cisco UCS Manager KVM login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cisco</span><span class="nt-tag">discovery</span><span class="nt-tag">kvm</span><span class="nt-tag">panel</span><span class="nt-tag">ucs</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.cisco.com/c/en/us/td/docs/unified_computing/ucs/ucs-manager/GUI-User-Guides/Admin-Management/3-1/b_Cisco_UCS_Admin_Mgmt_Guide_3_1/b_Cisco_UCSM_GUI_Admin_Mgmt_Guide_3_1_chapter_01111.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="cisco unified communications manager - cluster enumeration low identify critical remote vulnerabilities enumerated cisco ucm cluster nodes (servers) using the unauthenticated uds api (xml), allowing identification of backend servers without authentication. morgan robertson cisco ucm misconfig" data-nt-sev="low">
  <div class="nt-card-header">
    <div class="nt-title">Cisco Unified Communications Manager - Cluster Enumeration</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/vulnerabilities/cisco/cisco-ucm-cluster-enum.yaml" target="_blank" rel="noopener" class="nt-source-link">cisco-ucm-cluster-enum.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Morgan Robertson</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 28, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;product&#34;] contains &#34;Cisco:Unified Communications Manager&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Enumerated Cisco UCM cluster nodes (servers) using the unauthenticated UDS API (XML), allowing identification of backend servers without authentication.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cisco</span><span class="nt-tag">ucm</span><span class="nt-tag">misconfig</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://developer.cisco.com/site/user-data-services/develop-and-test/api-reference/#servers" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="cisco unified communications self-service user portal - detection info identify web-based control panels detected the presence of the cisco unified communications user management panel. morgan robertson detect cisco ucm panel" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Cisco Unified Communications Self-Service User Portal - Detection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/cisco-ucm-selfcare-portal.yaml" target="_blank" rel="noopener" class="nt-source-link">cisco-ucm-selfcare-portal.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Morgan Robertson</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 25, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;product&#34;] contains &#34;Cisco:Unified Communications Manager&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detected the presence of the Cisco Unified Communications User Management Panel.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">detect</span><span class="nt-tag">cisco</span><span class="nt-tag">ucm</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="cisco unity connection panel - detect info identify web-based control panels a cisco unity connection instance was detected. heeress panel cisco unity login detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Cisco Unity Connection Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/cisco-unity-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">cisco-unity-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> HeeresS</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 29, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Cisco Unity Connection&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A Cisco Unity Connection instance was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">cisco</span><span class="nt-tag">unity</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="cisco web ui login - detect info identify web-based control panels detects the presence of cisco web ui login panels drewvravick webui cisco login panel detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Cisco Web UI Login - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/cisco-webui-login.yaml" target="_blank" rel="noopener" class="nt-source-link">cisco-webui-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> drewvravick</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 26, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)webui-centerpanel&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detects the presence of Cisco Web UI login panels</div></div></div>
  <div class="nt-tags"><span class="nt-tag">webui</span><span class="nt-tag">cisco</span><span class="nt-tag">login</span><span class="nt-tag">panel</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="cisco webex meetings - panel info identify web-based control panels detects cisco webex meetings panel by requesting the modern webex dashboard and matching unique webex html markers. eyonn panel cisco webex detect discovery login" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Cisco Webex Meetings - Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/cisco/cisco-webex-meetings-detect.yaml" target="_blank" rel="noopener" class="nt-source-link">cisco-webex-meetings-detect.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Eyonn</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 22, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Cisco Webex Meetings&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detects Cisco Webex Meetings panel by requesting the modern Webex dashboard and matching unique Webex HTML markers.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">cisco</span><span class="nt-tag">webex</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">login</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.webex.com/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="cisco vmanage login panel - detect info identify web-based control panels cisco vmanage login panel was detected. dhiyaneshdk panel cisco discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Cisco vManage Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/cisco/cisco-vmanage-login.yaml" target="_blank" rel="noopener" class="nt-source-link">cisco-vmanage-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Cisco vManage&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Cisco vManage login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">cisco</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="citrix adc gateway login panel - detect info identify web-based control panels citrix adc gateway login panel was detected. organiccrap panel citrix discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Citrix ADC Gateway Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/citrix-adc-gateway-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">citrix-adc-gateway-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> organiccrap</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 21, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)citrix gateway&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Citrix ADC Gateway login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">citrix</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="citrix bleed - leaking session tokens high identify critical remote vulnerabilities sensitive information disclosure in netscaler adc and netscaler gateway when configured as a gateway (vpn virtual server, ica proxy, cvpn, rdp proxy) or aaa ?virtual?server. cve-2023-4966 dhiyaneshdk adc citrix cve cve2023 exposure info-leak kev vkev vuln cwe-119,nvd-cwe-noinfo" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Citrix Bleed - Leaking Session Tokens</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-4966.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-4966.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 24, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/119,NVD-CWE-NOINFO.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-119,NVD-CWE-NOINFO</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-4966" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-4966</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)citrix gateway\&#34; \\|\\| title:\&#34;netscaler gateway&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA ?virtual?server.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can leak session tokens from memory, potentially hijacking authenticated sessions and accessing sensitive Gateway resources.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply Citrix security updates immediately. Affected versions include NetScaler ADC and Gateway 14.1 before 14.1-8.50, 13.1 before 13.1-49.15, 13.0 before 13.0-92.19, and 12.1 (EOL).</div></div></div>
  <div class="nt-tags"><span class="nt-tag">adc</span><span class="nt-tag">citrix</span><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">exposure</span><span class="nt-tag">info-leak</span><span class="nt-tag">kev</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/assetnote/exploits/blob/main/citrix/CVE-2023-4966/exploit.py" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/Chocapikk/CVE-2023-4966" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.assetnote.io/resources/research/citrix-bleed-leaking-session-tokens-with-cve-2023-4966" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://x.com/assetnote/status/1716757539323564196?s=20" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://www.netscaler.com/blog/news/cve-2023-4966-critical-security-update-now-available-for-netscaler-adc-and-netscaler-gateway/" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="citrix gateway and citrix adc - cross-site scripting medium identify critical remote vulnerabilities citrix adc and citrix gateway versions before 13.1 and 13.1-45.61, 13.0 and 13.0-90.11, 12.1 and 12.1-65.35 contain a cross-site scripting vulnerability due to improper input validation. cve-2023-24488 johnk3r,dhiyaneshdk adc citrix cve cve2023 vkev vuln xss cwe-79" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Citrix Gateway and Citrix ADC - Cross-Site Scripting</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-24488.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-24488.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> johnk3r,DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 30, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-79</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-24488" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-24488</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)citrix gateway&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Citrix ADC and Citrix Gateway versions before 13.1 and 13.1-45.61, 13.0 and 13.0-90.11, 12.1 and 12.1-65.35 contain a cross-site scripting vulnerability due to improper input validation.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute arbitrary scripts in the context of the user&#39;s browser, potentially leading to session hijacking, defacement, or theft of sensitive information.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the necessary patches or updates provided by Citrix to mitigate this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">adc</span><span class="nt-tag">citrix</span><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">xss</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://support.citrix.com/article/CTX477714/citrix-adc-and-citrix-gateway-security-bulletin-for-cve202324487-cve202324488" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://blog.assetnote.io/2023/06/29/citrix-xss-advisory/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-24488" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://twitter.com/infosec_au/status/1674786106381070342" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://twitter.com/bxmbn/status/1675250259608449026" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="citrix netscaler memory disclosure - citrixbleed 2 critical identify critical remote vulnerabilities insufficient input validation leading to memory overread on the netscaler management interface netscaler adc and netscaler gateway cve-2025-5777 watchtowr,dhiyaneshdk,darses citrix cve cve2025 exposure kev netscaler vkev vuln cwe-457" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Citrix NetScaler Memory Disclosure - CitrixBleed 2</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-5777.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-5777.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> watchtowr,DhiyaneshDk,darses</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 5, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/457.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-457</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-5777" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-5777</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)NetScaler Gateway&#34;}) || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)NetScaler AAA&#34;}) || service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-1166125415&#34; || service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-1292923998&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Insufficient input validation leading to memory overread on the NetScaler Management Interface NetScaler ADC and NetScaler Gateway</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can trigger memory overread conditions to leak sensitive information from NetScaler memory, potentially exposing session tokens and credentials similar to CitrixBleed.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the security patches as described in Citrix support article CTX693420 and restrict access to the NetScaler Management Interface.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">citrix</span><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">exposure</span><span class="nt-tag">kev</span><span class="nt-tag">netscaler</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX693420" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://labs.watchtowr.com/how-much-more-must-we-bleed-citrix-netscaler-memory-disclosure-citrixbleed-2-cve-2025-5777/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-5777" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="citrix netscaler adc &amp; gateway - out-of-bounds memory read critical identify critical remote vulnerabilities the vulnerability would enable an attacker to remotely obtain sensitive information from a netscaler appliance configured as a gateway or aaa virtual server via a very commonly connected web interface, and without requiring authentication. this bug is nearly identical to the citrix bleed vulnerability (cve-2023-4966), except it is less likely to return highly sensitive information to an attacker. cve-2023-6549 ice3man citrix cve cve2023 gateway kev netscaller oob vkev vuln cwe-125" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Citrix Netscaler ADC &amp; Gateway - Out-Of-Bounds Memory Read</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-6549.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-6549.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ice3man</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 13, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/125.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-125</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-6549" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-6549</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-1292923998,-1166125415&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The vulnerability would enable an attacker to remotely obtain sensitive information from a NetScaler appliance configured as a Gateway or AAA virtual server via a very commonly connected Web interface, and without requiring authentication. This bug is nearly identical to the Citrix Bleed vulnerability (CVE-2023-4966), except it is less likely to return highly sensitive information to an attacker.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">The vulnerability allows an attacker to recover potentially sensitive data from memory. Although in most cases nothing of value is returned, we have observed instances where POST request bodies are leaked.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to version 13.1-51.15 or later</div></div></div>
  <div class="nt-tags"><span class="nt-tag">citrix</span><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">gateway</span><span class="nt-tag">kev</span><span class="nt-tag">netscaller</span><span class="nt-tag">oob</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://bishopfox.com/blog/netscaler-adc-and-gateway-advisory" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-6549" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="citrix sd-wan and netscaler sd-wan - sql injection critical identify critical remote vulnerabilities citrix sd-wan 10.2.x before 10.2.3 and netscaler sd-wan 10.0.x before 10.0.8 contain an sql injection vulnerability. an unauthenticated attacker can exploit improper validation of input in specific components, which could allow for execution of arbitrary sql queries against the backend database. this could result in information disclosure, manipulation of data, or complete compromise of affected systems. cve-2019-12989 ritikchaddha citrix cve cve2019 kev sqli vkev cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Citrix SD-WAN and NetScaler SD-WAN - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2019/CVE-2019-12989.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2019-12989.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 17, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2019-12989" target="_blank" rel="noopener" class="nt-cve-link">CVE-2019-12989</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)citrix sd-wan&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 contain an SQL injection vulnerability. An unauthenticated attacker can exploit improper validation of input in specific components, which could allow for execution of arbitrary SQL queries against the backend database. This could result in information disclosure, manipulation of data, or complete compromise of affected systems.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation may allow a remote unauthenticated attacker to execute SQL commands on the system, potentially resulting in unauthorized access, data leakage, modification of critical data, or full compromise of the SD-WAN appliance.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the vendor patch: upgrade Citrix SD-WAN to version 10.2.3 or later, and NetScaler SD-WAN to version 10.0.8 or later as detailed in the official Citrix advisory.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">citrix</span><span class="nt-tag">cve</span><span class="nt-tag">cve2019</span><span class="nt-tag">kev</span><span class="nt-tag">sqli</span><span class="nt-tag">vkev</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="http://packetstormsecurity.com/files/153638/Citrix-SD-WAN-Appliance-10.2.2-Authentication-Bypass-Remote-Command-Execution.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://support.citrix.com/article/CTX251987" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.tenable.com/security/research/tra-2019-32" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2019-12989" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="citrix storefront - cross-site scripting medium identify critical remote vulnerabilities reflected cross-site scripting issue which is exploitable without authentication. this vulnerability was exploitable through coercing an error message during an xml parsing procedure in the sso flow. cve-2023-5914 dhiyaneshdk citrix cloud cve cve2023 storefront vkev vuln xss cwe-79" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Citrix StoreFront - Cross-Site Scripting</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-5914.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-5914.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 18, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-79</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-5914" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-5914</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/citrix/storeweb&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Reflected Cross-Site Scripting issue which is exploitable without authentication. This vulnerability was exploitable through coercing an error message during an XML parsing procedure in the SSO flow.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can inject malicious JavaScript via reflected XSS during XML parsing in the SSO flow, potentially stealing user credentials or session tokens.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply Citrix security updates immediately. Update to StoreFront versions 2402, 2203 CU1, 2203 LTSR CU5, 1912 LTSR CU8, or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">citrix</span><span class="nt-tag">cloud</span><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">storefront</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">xss</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.assetnote.io/resources/research/continuing-the-citrix-saga-cve-2023-5914-cve-2023-6184" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://support.citrix.com/article/CTX583759/citrix-storefront-security-bulletin-for-cve20235914" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.youtube.com/watch?v=t8MeUQrPqec" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-5914" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="citrix vpn panel - detect info identify web-based control panels citrix vpn panel was detected. pdteam panel citrix discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Citrix VPN Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/citrix-vpn-detect.yaml" target="_blank" rel="noopener" class="nt-source-link">citrix-vpn-detect.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pdteam</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)citrix gateway&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Citrix VPN panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">citrix</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="claris filemaker server admin console - detect info identify web-based control panels claris filemaker server admin console panel was detected. s4e-io claris detect filemaker panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Claris FileMaker Server Admin Console - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/claris-filemaker-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">claris-filemaker-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> s4e-io</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 4, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Claris FileMaker&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Claris FileMaker Server Admin Console panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">claris</span><span class="nt-tag">detect</span><span class="nt-tag">filemaker</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.claris.com/filemaker/server/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="claris filemaker webdirect panel - detect info identify web-based control panels claris filemaker webdirect panel was detected. dhiyaneshdk panel edb discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Claris FileMaker WebDirect Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/claris-filemaker-webdirect.yaml" target="_blank" rel="noopener" class="nt-source-link">claris-filemaker-webdirect.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Claris FileMaker WebDirect&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Claris FileMaker WebDirect panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">edb</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.exploit-db.com/ghdb/5669" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="cleanweb login panel - detect info identify web-based control panels cleanweb login panel was detected. righettod panel cleanweb login detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">CleanWeb Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/cleanweb-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">cleanweb-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 9, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)CleanWeb&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">CleanWeb login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">cleanweb</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://tentelemed.com/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="clear-com core configuration manager panel - detect info identify web-based control panels clear-com core configuration manager panel was detected. failopen panel clearcom ccm discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Clear-Com Core Configuration Manager Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/ccm-detect.yaml" target="_blank" rel="noopener" class="nt-source-link">ccm-detect.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> failOpen</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)CCM - Authentication Failure&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Clear-Com Core Configuration Manager panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">clearcom</span><span class="nt-tag">ccm</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.clearcom.com/DownloadCenter/manuals/FreeSpeakII_Online_Manual/UserGuide/Content/Base/CCM/CCM.htm" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="clearml panel - detect info identify web-based control panels clearml was detected. clearml is an open-source mlops platform for experiment tracking, model management, and pipeline orchestration. exposed instances may allow access to ml experiments, models, and infrastructure configurations. rxerium ai clearml detect discovery mlops panel" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">ClearML Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/clearml-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">clearml-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 14, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)ClearML&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">ClearML was detected. ClearML is an open-source MLOps platform for experiment tracking, model management, and pipeline orchestration. Exposed instances may allow access to ML experiments, models, and infrastructure configurations.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">ai</span><span class="nt-tag">clearml</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">mlops</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/allegroai/clearml" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://clear.ml/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="clearpass policy manager login panel - detect info identify web-based control panels clearpass policy manager login panel was detected. dhiyaneshdk aruba arubanetworks discovery panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">ClearPass Policy Manager Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/clearpass-policy-manager.yaml" target="_blank" rel="noopener" class="nt-source-link">clearpass-policy-manager.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)clearpass policy manager&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">ClearPass Policy Manager login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">aruba</span><span class="nt-tag">arubanetworks</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="cleo harmony &lt; 5.8.0.21 - arbitary file read high identify critical remote vulnerabilities in cleo harmony before 5.8.0.21, vltrader before 5.8.0.21, and lexicom before 5.8.0.21, there is an unrestricted file upload and download that could lead to remote code execution. cve-2024-50623 dhiyaneshdk cleo cve cve2024 harmony kev lexicom lfi vkev vltrader vuln cwe-434" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Cleo Harmony &lt; 5.8.0.21 - Arbitary File Read</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-50623.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-50623.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 11, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/434.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-434</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-50623" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-50623</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.head.server&#34;] matches &#34;Cleo&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download that could lead to remote code execution.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can exploit vulnerabilities to compromise the system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest patched version addressing CVE-2024-50623.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cleo</span><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">harmony</span><span class="nt-tag">kev</span><span class="nt-tag">lexicom</span><span class="nt-tag">lfi</span><span class="nt-tag">vkev</span><span class="nt-tag">vltrader</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://support.cleo.com/hc/en-us/articles/27140294267799-Cleo-Product-Security-Advisory" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/watchtowrlabs/CVE-2024-50623" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://labs.watchtowr.com/cleo-cve-2024-50623/" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-50623" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="cloud oa system - sql injection high identify critical remote vulnerabilities cloud oa system /oa/pm/svc.asmx page parameters are not properly filtered, resulting in a sql injection vulnerability, which can be used to obtain sensitive information in the database. sleepingbag945 cloud cloudoa sqli vuln cwe-89" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Cloud OA System - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/vulnerabilities/other/cloud-oa-system-sqli.yaml" target="_blank" rel="noopener" class="nt-source-link">cloud-oa-system-sqli.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> SleepingBag945</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 18, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)全程云办公&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">cloud OA system /OA/PM/svc.asmx page parameters are not properly filtered, resulting in a SQL injection vulnerability, which can be used to obtain sensitive information in the database.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cloud</span><span class="nt-tag">cloudoa</span><span class="nt-tag">sqli</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/GREENHAT7/pxplan/blob/e2fc04893ca95e177021ddf61cc2134ecc120a8e/xray_pocs/yaml-poc-eqccd-eqccd_oa-sql_injection-CT-456760.yml#L8" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="cloudpanel login - detect info identify web-based control panels  dhiyaneshdk cloudpanel detect discovery login mgt-commerce panel" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">CloudPanel Login - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/cloudpanel-login.yaml" target="_blank" rel="noopener" class="nt-source-link">cloudpanel-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 29, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;151132309&#34; || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)cloudpanel&#34;})</code></div>
  <div class="nt-tags"><span class="nt-tag">cloudpanel</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">login</span><span class="nt-tag">mgt-commerce</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="cloudera hue default admin login high identify default logins in web-based control panels cloudera hue default admin credentials were discovered. for3stco1d cloudera default-login hue oss vuln cwe-522" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Cloudera Hue Default Admin Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/cobbler/hue-default-credential.yaml" target="_blank" rel="noopener" class="nt-source-link">hue-default-credential.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> For3stCo1d</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/522.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-522</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;Hue - Welcome to Hue&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Cloudera Hue default admin credentials were discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cloudera</span><span class="nt-tag">default-login</span><span class="nt-tag">hue</span><span class="nt-tag">oss</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/cloudera/hue" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="cloudflare access - login panel detection info identify web-based control panels detected exposed cloudflare access login pages. rxerium cloudflare panel discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Cloudflare Access - Login Panel Detection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/cloudflare-access-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">cloudflare-access-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 5, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Cloudflare Access&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detected exposed Cloudflare Access login pages.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">- Ensure Cloudflare Access policies are properly configured to restrict access to authorized users only
- Review and enforce appropriate authentication rules and multi-factor authentication requirements
- Limit exposure of Access login pages to necessary endpoints only</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cloudflare</span><span class="nt-tag">panel</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://developers.cloudflare.com/cloudflare-one/applications/configure-apps/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://developers.cloudflare.com/cloudflare-one/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="cloudlog panel - detect info identify web-based control panels cloudlog panel was discovered. s4e-io panel login cloudlog detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Cloudlog Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/cloudlog-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">cloudlog-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> s4e-io</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 3, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Login - Cloudlog&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Cloudlog panel was discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">login</span><span class="nt-tag">cloudlog</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/magicbug/Cloudlog" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://lab.uberspace.de/guide_cloudlog/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="cloudphysician radar login panel - detect info identify web-based control panels cloudphysician radar login panel was detected. dhiyaneshdk panel edb discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Cloudphysician RADAR Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/cloudphysician-radar.yaml" target="_blank" rel="noopener" class="nt-source-link">cloudphysician-radar.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Cloudphysician RADAR&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Cloudphysician RADAR login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">edb</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.exploit-db.com/ghdb/7466" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="cluster control cmon api - directory traversal high identify critical remote vulnerabilities directory traversal vulnerability in severalnines cluster control 1.9.8 before 1.9.8-9778, 2.0.0 before 2.0.0-9779, and 2.1.0 before 2.1.0-9780 allows a remote attacker to include and display file content in an http request via the cmon api. cve-2024-41628 s4e-io cluster-control cve cve2024 lfi severalnines vuln cwe-22" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Cluster Control CMON API - Directory Traversal</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-41628.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-41628.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> s4e-io</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 5, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-41628" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-41628</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;160707013&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Directory Traversal vulnerability in Severalnines Cluster Control 1.9.8 before 1.9.8-9778, 2.0.0 before 2.0.0-9779, and 2.1.0 before 2.1.0-9780 allows a remote attacker to include and display file content in an HTTP request via the CMON API.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can exploit directory traversal to read arbitrary files from the Cluster Control server.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update Severalnines Cluster Control to version 1.9.8-9778, 2.0.0-9779, or 2.1.0-9780 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cluster-control</span><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">lfi</span><span class="nt-tag">severalnines</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://cvefeed.io/vuln/detail/CVE-2024-41628" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/Redshift-CyberSecurity/CVE-2024-41628" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://vuldb.com/?id.272533" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://vulmon.com/vulnerabilitydetails?qid=CVE-2024-41628" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="cnzxsoft system - default login high identify default logins in web-based control panels cnzxsoft golden shield information security management system has a default weak password. sleepingbag945 cnzxsoft default-login vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Cnzxsoft System - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/others/cnzxsoft-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">cnzxsoft-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> SleepingBag945</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 5, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)中新金盾信息安全管理系统&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Cnzxsoft Golden Shield Information Security Management System has a default weak password.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cnzxsoft</span><span class="nt-tag">default-login</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="cobbler &#39;xml-rpc&#39; - authentication bypass critical identify critical remote vulnerabilities cobbler, a linux installation server that allows for rapid setup of network installation environments, has an improper authentication vulnerability starting in version 3.0.0 and prior to versions 3.2.3 and 3.3.7. `utils.get_shared_secret()` always returns `-1`, which allows anyone to connect to cobbler xml-rpc as user `&#39;&#39;` password `-1` and make any changes. this gives anyone with network access to a cobbler server full control of the server. versions 3.2.3 and 3.3.7 fix the issue. cve-2024-47533 songyaeji auth-bypass cobbler cve cve2024 unauth vuln xmlrpc cwe-287" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Cobbler &#39;XML-RPC&#39; - Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-47533.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-47533.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> songyaeji</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 8, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/287.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-287</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-47533" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-47533</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Cobbler Web Interface&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Cobbler, a Linux installation server that allows for rapid setup of network installation environments, has an improper authentication vulnerability starting in version 3.0.0 and prior to versions 3.2.3 and 3.3.7. `utils.get_shared_secret()` always returns `-1`, which allows anyone to connect to cobbler XML-RPC as user `&#39;&#39;` password `-1` and make any changes. This gives anyone with network access to a cobbler server full control of the server. Versions 3.2.3 and 3.3.7 fix the issue.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Anyone with network access can connect to Cobbler XML-RPC with default credentials and make arbitrary changes, gaining full control.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update Cobbler to version 3.2.3 or 3.3.7 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">cobbler</span><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">unauth</span><span class="nt-tag">vuln</span><span class="nt-tag">xmlrpc</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/cobbler/cobbler/commit/32c5cada013dc8daa7320a8eda9932c2814742b0" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/cobbler/cobbler/commit/e19717623c10b29e7466ed4ab23515a94beb2dda" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/cobbler/cobbler/security/advisories/GHSA-m26c-fcgh-cp6h" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="cobbler - authentication bypass critical identify critical remote vulnerabilities cobbler versions 2.6.11+, but code inspection suggests at least 2.0.0+ and possibly even older versions, may be vulnerable to an authentication bypass vulnerability in xmlrpc api (/cobbler_api) that can result in privilege escalation, data manipulation or exfiltration, and ldap credential harvesting. this attack appear to be exploitable via &#34;network connectivity&#34;. taking advantage of improper validation of security tokens in api endpoints. please note this is a different issue than cve-2018-10931. cve-2018-1000226 c-sh0 auth-bypass cobbler cobblerd cve cve2018 vuln cwe-732" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Cobbler - Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2018/CVE-2018-1000226.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2018-1000226.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> c-sh0</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/732.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-732</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2018-1000226" target="_blank" rel="noopener" class="nt-cve-link">CVE-2018-1000226</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)cobbler web interface&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Cobbler versions 2.6.11+, but code inspection suggests at least 2.0.0+ and possibly even older versions, may be vulnerable to an authentication bypass vulnerability in XMLRPC API (/cobbler_api) that can result in privilege escalation, data manipulation or exfiltration, and LDAP credential harvesting. This attack appear to be exploitable via &#34;network connectivity&#34;. Taking advantage of improper validation of security tokens in API endpoints. Please note this is a different issue than CVE-2018-10931.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can bypass authentication to gain unauthorized access, leading to privilege escalation, data manipulation or exfiltration, and LDAP credential harvesting.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches or updates provided by the vendor to fix the authentication bypass vulnerability in Cobbler.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">cobbler</span><span class="nt-tag">cobblerd</span><span class="nt-tag">cve</span><span class="nt-tag">cve2018</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/cobbler/cobbler/issues/1916" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://movermeyer.com/2018-08-02-privilege-escalation-exploits-in-cobblers-api/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1000226" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/ARPSyndicate/kenzer-templates" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="cobbler &lt;3.3.0 - remote code execution critical identify critical remote vulnerabilities cobbler before 3.3.0 allows log poisoning and resultant remote code execution via an xmlrpc method. cve-2021-40323 c-sh0 cobbler cobbler_project cve cve2021 rce vuln cwe-94" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Cobbler &lt;3.3.0 - Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2021/CVE-2021-40323.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2021-40323.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> c-sh0</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/94.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-94</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2021-40323" target="_blank" rel="noopener" class="nt-cve-link">CVE-2021-40323</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)cobbler web interface&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Cobbler before 3.3.0 allows log poisoning and resultant remote code execution via an XMLRPC method.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability can lead to unauthorized remote code execution, potentially resulting in complete compromise of the affected system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade Cobbler to version 3.3.0 or later, which includes a fix for this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cobbler</span><span class="nt-tag">cobbler_project</span><span class="nt-tag">cve</span><span class="nt-tag">cve2021</span><span class="nt-tag">rce</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/cobbler/cobbler/releases/tag/v3.3.0" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/cobbler/cobbler/issues/2795" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://tnpitsecurity.com/blog/cobbler-multiple-vulnerabilities/" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2021-40323" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/cobbler/cobbler/commit/d8f60bbf14a838c8c8a1dba98086b223e35fe70a" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="cobbler webgui login panel - detect info identify web-based control panels cobbler webgui login panel was detected. c-sh0 cobbler cobblerd discovery panel webserver cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Cobbler WebGUI Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/cobbler-webgui.yaml" target="_blank" rel="noopener" class="nt-source-link">cobbler-webgui.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> c-sh0</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)cobbler web interface&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Cobbler WebGUI login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cobbler</span><span class="nt-tag">cobblerd</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">webserver</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="cockpit cms 0.6.1 - remote code execution critical identify critical remote vulnerabilities cockpit before 0.6.1 allows an attacker to inject custom php code and achieve remote command execution via registercriteriafunction in lib/mongolite/database.php, as demonstrated by values in json data to the /auth/check or /auth/requestreset uri. cve-2020-35131 dhiyaneshdk cockpit cve cve2020 rce vkev vuln cwe-94" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Cockpit CMS 0.6.1 - Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2020/CVE-2020-35131.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2020-35131.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 27, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/94.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-94</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2020-35131" target="_blank" rel="noopener" class="nt-cve-link">CVE-2020-35131</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)cockpit&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Cockpit before 0.6.1 allows an attacker to inject custom PHP code and achieve Remote Command Execution via registerCriteriaFunction in lib/MongoLite/Database.php, as demonstrated by values in JSON data to the /auth/check or /auth/requestreset URI.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can inject custom PHP code to achieve remote command execution, leading to complete Cockpit CMS compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to Cockpit CMS version 0.6.1 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cockpit</span><span class="nt-tag">cve</span><span class="nt-tag">cve2020</span><span class="nt-tag">rce</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/agentejo/cockpit/commits/next/lib/MongoLite/Database.php" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/agentejo/cockpit/releases/tag/0.6.1" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.exploit-db.com/exploits/49390" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2020-35131" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="cockpit project login panel - detect info identify web-based control panels cockpit project products was detected. righettod panel cockpit login discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Cockpit Project Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/cockpit-project-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">cockpit-project-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 15, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)cockpit/static/login\\.css&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Cockpit Project products was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">cockpit</span><span class="nt-tag">login</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/cockpit-project/cockpit" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://cockpit-project.org/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="code-server login panel - detect info identify web-based control panels code-server login panel was detected. tess panel detect misc coder discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Code-Server Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/code-server-login.yaml" target="_blank" rel="noopener" class="nt-source-link">code-server-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> tess</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)code-server login&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Code-Server login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">detect</span><span class="nt-tag">misc</span><span class="nt-tag">coder</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="codechecker &lt;= 6.24.1 - authentication bypass critical identify critical remote vulnerabilities authentication bypass occurs when the api url ends with authentication, configuration or serverinfo. this bypass allows superuser access to all api endpoints other than authentication. these endpoints include the ability to add, edit, and remove products, among others. cve-2024-10081 iamnoooob,rootxharsh,pdresearch auth-bypass code-checker cve cve2024 vkev vuln cwe-288" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">CodeChecker &lt;= 6.24.1 - Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-10081.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-10081.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> iamnoooob,rootxharsh,pdresearch</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 11, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/288.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-288</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-10081" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-10081</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-1496590341&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Authentication bypass occurs when the API URL ends with Authentication, Configuration or ServerInfo. This bypass allows superuser access to all API endpoints other than Authentication. These endpoints include the ability to add, edit, and remove products, among others.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can bypass authentication by crafting API URLs ending with specific keywords, gaining superuser access to all API endpoints including product management and configuration.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade CodeChecker to version 6.24.2 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">code-checker</span><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/advisories/GHSA-f3f8-vx3w-hp5q" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/Ericsson/codechecker/security/advisories/GHSA-f3f8-vx3w-hp5q" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-10081" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="cofense vision login panel - detect info identify web-based control panels cofense vision login panel was detected. adam crosser panel cofense vision discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Cofense Vision Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/cofense-vision-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">cofense-vision-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Adam Crosser</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;739801466&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Cofense Vision login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">cofense</span><span class="nt-tag">vision</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://cofense.com" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="cogent datahub (opc datahub) - panel info identify web-based control panels cogent datahub (opc datahub) is an industrial middleware platform for opc connectivity,
data bridging, and scada integration. the embedded web server is commonly exposed on
port 80 or 443. rxerium cogent datahub discovery ics opc ot panel scada" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Cogent DataHub (OPC DataHub) - Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/cogent-datahub-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">cogent-datahub-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 27, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;^DataHub Web Server&#34;}) || service[&#34;http.body&#34;] matches &#34;(?i)You have successfully configured the DataHub to run as a web server&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Cogent DataHub (OPC DataHub) is an industrial middleware platform for OPC connectivity,
data bridging, and SCADA integration. The embedded web server is commonly exposed on
port 80 or 443.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cogent</span><span class="nt-tag">datahub</span><span class="nt-tag">discovery</span><span class="nt-tag">ics</span><span class="nt-tag">opc</span><span class="nt-tag">ot</span><span class="nt-tag">panel</span><span class="nt-tag">scada</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.cogentdatahub.com/products/datahub/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.opcdatahub.com/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="cognita panel - detect info identify web-based control panels cognita is an open-source rag framework by truefoundry for building modular and
production-ready rag pipelines. rxerium ai cognita detect discovery llm panel rag" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Cognita Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/cognita-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">cognita-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 27, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;Sign in to Cognita&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Cognita is an open-source RAG framework by Truefoundry for building modular and
production-ready RAG pipelines.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">ai</span><span class="nt-tag">cognita</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">llm</span><span class="nt-tag">panel</span><span class="nt-tag">rag</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/truefoundry/cognita" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://truefoundry.com/cognita" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="coldfusion administrator login panel - detect info identify web-based control panels coldfusion administrator login panel was detected. dhiyaneshdk adobe coldfusion discovery panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">ColdFusion Administrator Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/coldfusion-administrator-login.yaml" target="_blank" rel="noopener" class="nt-source-link">coldfusion-administrator-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)coldfusion administrator login&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">ColdFusion Administrator login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">adobe</span><span class="nt-tag">coldfusion</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="coming soon &amp; maintenance &lt; 4.1.7 - unauthenticated post/page access medium identify critical remote vulnerabilities the plugin does not restrict access to published and non protected posts/pages when the maintenance mode is enabled, allowing unauthenticated users to access them. cve-2023-1263 r3y3r53 cmp-coming-soon-maintenance cve cve2023 niteothemes unauth vuln wordpress wp wp-plugin wpscan cwe-200" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Coming Soon &amp; Maintenance &lt; 4.1.7 - Unauthenticated Post/Page Access</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-1263.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-1263.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> r3Y3r53</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 17, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-1263" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-1263</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/cmp-coming-soon-maintenance/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The plugin does not restrict access to published and non protected posts/pages when the maintenance mode is enabled, allowing unauthenticated users to access them.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can bypass maintenance mode restrictions to access published posts and pages that should be protected during maintenance.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Fixed in version 4.1.7</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cmp-coming-soon-maintenance</span><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">niteothemes</span><span class="nt-tag">unauth</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">wpscan</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wpscan.com/vulnerability/2e07ffd9-8e82-4078-96aa-162ef78c417b" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-1263" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/cmp-coming-soon-maintenance/cmp-coming-soon-maintenance-plugin-by-niteothemes-416-information-exposure" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://wordpress.org/plugins/cmp-coming-soon-maintenance/" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://plugins.trac.wordpress.org/browser/cmp-coming-soon-maintenance/tags/4.1.6/niteo-cmp.php#L2759" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="commvault unauthenticated password disclosure (wt-2025-0047) medium identify critical remote vulnerabilities an issue was discovered in commvault before 11.36.60. a vulnerability in a known login mechanism allows unauthenticated attackers to execute api calls without requiring user credentials. rbac helps limit the exposure but does not eliminate risk. dhiyaneshdk,iamnoooob,pdresearch,watchtowr commandcenter commvault cve cve2025 unauth vkev vuln" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Commvault Unauthenticated Password Disclosure (WT-2025-0047)</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-57788.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-57788.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK,iamnoooob,pdresearch,watchtowr</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 20, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-542502280&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An issue was discovered in Commvault before 11.36.60. A vulnerability in a known login mechanism allows unauthenticated attackers to execute API calls without requiring user credentials. RBAC helps limit the exposure but does not eliminate risk.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can exploit the public sharing login mechanism to access API endpoints and retrieve sensitive user information including passwords.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade Commvault to version 11.36.60 or later that properly restricts API access and removes the vulnerable login mechanism.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">commandcenter</span><span class="nt-tag">commvault</span><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">unauth</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://labs.watchtowr.com/guess-who-would-be-stupid-enough-to-rob-the-same-vault-twice-pre-auth-rce-chains-in-commvault/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://documentation.commvault.com/securityadvisories/CV_2025_08_3.html" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="commvault web console panel - detect info identify web-based control panels commvault web console login panel was detected. rxerium panel commvault backup login detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Commvault Web Console Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/commvault-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">commvault-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 8, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-542502280&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Commvault web console login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">commvault</span><span class="nt-tag">backup</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.commvault.com/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="compalex panel - detect medium identify web-based control panels  mastercho tech php compalex sql panel discovery" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Compalex Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/compalex-panel-detect.yaml" target="_blank" rel="noopener" class="nt-source-link">compalex-panel-detect.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> MaStErCho</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 24, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)COMPALEX&#34;})</code></div>
  <div class="nt-tags"><span class="nt-tag">tech</span><span class="nt-tag">php</span><span class="nt-tag">compalex</span><span class="nt-tag">sql</span><span class="nt-tag">panel</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="http://compalex.net/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="completeview panel - detect info identify web-based control panels completeview panel was detected. tess panel completeview discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">CompleteView Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/completeview-web-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">completeview-web-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> tess</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)CompleteView Web Client&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">CompleteView panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">completeview</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="concourse ci login panel - detect info identify web-based control panels concourse ci login panel was detected. praetorian-thendrickson concourse discovery oss panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Concourse CI Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/concourse-ci-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">concourse-ci-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> praetorian-thendrickson</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Concourse&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Concourse CI login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">concourse</span><span class="nt-tag">discovery</span><span class="nt-tag">oss</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/concourse/concourse" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://concourse-ci.org" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="concrete5 install panel critical identify web-based control panels a concrete5 installation panel was discovered. osamahamad,princechaddha cms concrete concrete5 discovery install panel" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Concrete5 Install Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/concrete5/concrete5-install.yaml" target="_blank" rel="noopener" class="nt-source-link">concrete5-install.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> osamahamad,princechaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)install concrete5&#34;}) || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)concrete5&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A Concrete5 installation panel was discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cms</span><span class="nt-tag">concrete</span><span class="nt-tag">concrete5</span><span class="nt-tag">discovery</span><span class="nt-tag">install</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://documentation.concretecms.org/developers/introduction/installing-concrete-cms" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="concrete5 login panel - detect info identify web-based control panels concrete5 login panel was detected. dhiyaneshdk panel concrete5 cms discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Concrete5 Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/concrete5/concrete5-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">concrete5-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)concrete5&#34;}) || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)install concrete5&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Concrete5 login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">concrete5</span><span class="nt-tag">cms</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="connectwise control remote support software panel - detect info identify web-based control panels  johnk3r connectwise detect discovery panel screenconnect cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">ConnectWise Control Remote Support Software Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/connectwise-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">connectwise-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> johnk3r</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 21, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-82958153&#34;</code></div>
  <div class="nt-tags"><span class="nt-tag">connectwise</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">screenconnect</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="connectwise screenconnect 23.9.7 - authentication bypass critical identify critical remote vulnerabilities connectwise screenconnect 23.9.7 and prior are affected by an authentication bypass using an alternate path or channel vulnerability, which may allow an attacker direct access to confidential information or critical systems. cve-2024-1709 johnk3r auth-bypass connectwise cve cve2024 kev screenconnect vkev vuln cwe-288,nvd-cwe-other" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">ConnectWise ScreenConnect 23.9.7 - Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-1709.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-1709.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> johnk3r</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 22, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/288,NVD-CWE-OTHER.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-288,NVD-CWE-OTHER</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-1709" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-1709</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-82958153&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">ConnectWise ScreenConnect 23.9.7 and prior are affected by an Authentication Bypass Using an Alternate Path or Channel vulnerability, which may allow an attacker direct access to confidential information or critical systems.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can bypass authentication to access confidential information or critical systems, potentially leading to complete system compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update ConnectWise ScreenConnect to version 23.9.8 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">connectwise</span><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">kev</span><span class="nt-tag">screenconnect</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.huntress.com/blog/a-catastrophe-for-control-understanding-the-screenconnect-authentication-bypass" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/watchtowrlabs/connectwise-screenconnect_auth-bypass-add-user-poc" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.connectwise.com/company/trust/security-bulletins/connectwise-screenconnect-23.9.8" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-1709" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/rapid7/metasploit-framework/pull/18870" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="contact form plugin by fluent forms &lt; 5.1.17 - unauthenticated limited privilege escalation critical identify critical remote vulnerabilities the plugin is vulnerable to privilege escalation due to a missing capability check on the /wp-json/fluentform/v1/managers rest api endpoint. this makes it possible for unauthenticated attackers to grant users with fluent form management permissions which gives them access to all of the plugin&#39;s settings and features. this also makes it possible for unauthenticated attackers to delete manager accounts. cve-2024-2771 sourabh-sahu cve cve2024 fluentforms unauth vkev vuln wordpress wp wp-plugin cwe-862" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Contact Form Plugin by Fluent Forms &lt; 5.1.17 - Unauthenticated Limited Privilege Escalation</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-2771.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-2771.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Sourabh-Sahu</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 16, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/862.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-862</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-2771" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-2771</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/fluentform/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The plugin is vulnerable to privilege escalation due to a missing capability check on the /wp-json/fluentform/v1/managers REST API endpoint. This makes it possible for unauthenticated attackers to grant users with Fluent Form management permissions which gives them access to all of the plugin&#39;s settings and features. This also makes it possible for unauthenticated attackers to delete manager accounts.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can grant Fluent Form management permissions to any user account, providing access to all plugin settings and sensitive data.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update Contact Form Plugin by Fluent Forms to version 5.1.17 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">fluentforms</span><span class="nt-tag">unauth</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/whale93/CVE-2024-2771-PoC" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-2771" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/071195d6-3452-4241-a8d3-92efc84e4850?source=cve" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="contao login panel - detect info identify web-based control panels contao login panel was detected. princechaddha contao discovery panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Contao Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/contao-login-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">contao-login-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> princechaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)contao open source cms&#34; || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)contao&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Contao login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">contao</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="content central login panel - detect info identify web-based control panels content central login panel was detected. theabhinavgaur panel content-central discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Content Central Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/content-central-login.yaml" target="_blank" rel="noopener" class="nt-source-link">content-central-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> theabhinavgaur</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Content Central Login&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Content Central login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">content-central</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="contest gallery &lt; 13.1.0.6 - sql injection critical identify critical remote vulnerabilities the plugin does not have capability checks and does not sanitise or escape the cg-search-user-name-original parameter before using it in a sql statement when exporting users from a gallery, which could allow unauthenticated to perform sql injections attacks, as well as get the list of all users registered on the blog, including their username and email address. cve-2021-24915 r3y3r53 contest-gallery contest_gallery cve cve2021 sqli vkev vuln wordpress wp wp-plugin wpscan cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Contest Gallery &lt; 13.1.0.6 - SQL injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2021/CVE-2021-24915.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2021-24915.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> r3Y3r53</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 17, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2021-24915" target="_blank" rel="noopener" class="nt-cve-link">CVE-2021-24915</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/contest-gallery/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The plugin does not have capability checks and does not sanitise or escape the cg-search-user-name-original parameter before using it in a SQL statement when exporting users from a gallery, which could allow unauthenticated to perform SQL injections attacks, as well as get the list of all users registered on the blog, including their username and email address.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can exploit SQL injection to extract database contents and enumerate all registered users including their email addresses, potentially facilitating targeted phishing attacks.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Fixed in version 13.1.0.6</div></div></div>
  <div class="nt-tags"><span class="nt-tag">contest-gallery</span><span class="nt-tag">contest_gallery</span><span class="nt-tag">cve</span><span class="nt-tag">cve2021</span><span class="nt-tag">sqli</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">wpscan</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wpscan.com/vulnerability/45ee86a7-1497-4c81-98b8-9a8e5b3d4fac" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://gist.github.com/tpmiller87/6c05596fe27dd6f69f1aaba4cbb9c917" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://wordpress.org/plugins/contest-gallery/" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="control web panel (cwp) - file inclusion critical identify critical remote vulnerabilities in cwp (control web panel, previously centos web panel) before version 0.9.8.1107, an unauthenticated attacker can abuse null byte (%00) injection with the &#34;scripts&#34; parameter in the /user/loader.php or /user/login.php endpoints to register arbitrary api keys or access sensitive files. this can be exploited by using multiple %00 sequences to traverse directories via crafted requests such as /user/loader.php?api=1&amp;scripts=.%00./.%00./api/account_new_create&amp;acc=guadaapi, or similar payloads with more %00 instances (e.g., .%00%00%00./.%00%00%00./api/account_new_create). attackers may use this flaw for arbitrary file access, privilege escalation, or remote code execution. cve-2021-45467 ritikchaddha centos cve cve2021 cwp lfi rce vkev webpanel cwe-862" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Control Web Panel (CWP) - File Inclusion</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2021/CVE-2021-45467.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2021-45467.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 21, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/862.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-862</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2021-45467" target="_blank" rel="noopener" class="nt-cve-link">CVE-2021-45467</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-356182173&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">In CWP (Control Web Panel, previously CentOS Web Panel) before version 0.9.8.1107, an unauthenticated attacker can abuse null byte (%00) injection with the &#34;scripts&#34; parameter in the /user/loader.php or /user/login.php endpoints to register arbitrary API keys or access sensitive files. This can be exploited by using multiple %00 sequences to traverse directories via crafted requests such as /user/loader.php?api=1&amp;scripts=.%00./.%00./api/account_new_create&amp;acc=guadaapi, or similar payloads with more %00 instances (e.g., .%00%00%00./.%00%00%00./api/account_new_create). Attackers may use this flaw for arbitrary file access, privilege escalation, or remote code execution.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">A remote, unauthenticated attacker can leverage this vulnerability to register arbitrary API keys, access sensitive files (such as /etc/passwd), and potentially achieve remote code execution. Successful exploitation results in full compromise of the web panel and host system, allowing for exposure of confidential data, server takeover, and further attacks on internal infrastructure.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to version 0.9.8.1107 or later to fix input validation issues.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">centos</span><span class="nt-tag">cve</span><span class="nt-tag">cve2021</span><span class="nt-tag">cwp</span><span class="nt-tag">lfi</span><span class="nt-tag">rce</span><span class="nt-tag">vkev</span><span class="nt-tag">webpanel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://octagon.net/blog/2022/01/22/cve-2021-45467-cwp-centos-web-panel-preauth-rce/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2021-45467" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="control web panel login panel - detect info identify web-based control panels control web panel login panel was detected. ffffffff0x centos discovery panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Control Web Panel Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/cwp-webpanel.yaml" target="_blank" rel="noopener" class="nt-source-link">cwp-webpanel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ffffffff0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)CWP \\|用户&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Control Web Panel login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">centos</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="copa-data zenon - login panel info identify web-based control panels copa-data zenon is an industrial automation platform used in manufacturing,
energy, and infrastructure. the zenon web server and smart server expose a
browser-based hmi interface for remote monitoring and control of scada processes. rxerium copa-data discovery hmi ics panel scada zenon" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Copa-Data zenon - Login Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/copa-data-zenon-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">copa-data-zenon-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 27, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)zenon Web Server&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Copa-Data zenon is an industrial automation platform used in manufacturing,
energy, and infrastructure. The zenon Web Server and Smart Server expose a
browser-based HMI interface for remote monitoring and control of SCADA processes.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">copa-data</span><span class="nt-tag">discovery</span><span class="nt-tag">hmi</span><span class="nt-tag">ics</span><span class="nt-tag">panel</span><span class="nt-tag">scada</span><span class="nt-tag">zenon</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.copadata.com/en/products/zenon-software-platform/zenon-supervisor/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.copadata.com/en/support-services/knowledge-base-documents/zenon-web-server/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="copyparty v1.8.6 - cross site scripting medium identify critical remote vulnerabilities copyparty is a portable file server. versions prior to 1.8.6 are subject to a reflected cross-site scripting (xss) attack.vulnerability that exists in the web interface of the application could allow an attacker to execute malicious javascript code by tricking users into accessing a malicious link. cve-2023-38501 ctflearner,r3y3r53 copyparty copyparty_project cve cve2023 oss packetstorm vuln xss cwe-79" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">CopyParty v1.8.6 - Cross Site Scripting</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-38501.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-38501.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ctflearner,r3Y3r53</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 5, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-79</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-38501" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-38501</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)copyparty&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Copyparty is a portable file server. Versions prior to 1.8.6 are subject to a reflected cross-site scripting (XSS) Attack.Vulnerability that exists in the web interface of the application could allow an attacker to execute malicious javascript code by tricking users into accessing a malicious link.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can inject malicious JavaScript through the k304 parameter to steal user session cookies when users click malicious links to CopyParty.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Fixed in v1.8.6</div></div></div>
  <div class="nt-tags"><span class="nt-tag">copyparty</span><span class="nt-tag">copyparty_project</span><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">oss</span><span class="nt-tag">packetstorm</span><span class="nt-tag">vuln</span><span class="nt-tag">xss</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.exploit-db.com/exploits/51635" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/9001/copyparty/releases/tag/v1.8.6" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-38501" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="http://packetstormsecurity.com/files/173821/Copyparty-1.8.6-Cross-Site-Scripting.html" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/9001/copyparty/commit/007d948cb982daa05bc6619cd20ee55b7e834c38" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="copyparty &lt;= 1.8.2 - directory traversal high identify critical remote vulnerabilities copyparty is a portable file server. versions prior to 1.8.2 are subject to a path traversal vulnerability detected in the `.cpr` subfolder. the path traversal attack technique allows an attacker access to files, directories, and commands that reside outside the web document root directory. this issue has been addressed in commit `043e3c7d` which has been included in release 1.8.2. users are advised to upgrade. there are no known workarounds for this vulnerability. cve-2023-37474 shankar acharya,theamanrawat copyparty copyparty_project cve cve2023 packetstorm traversal vuln cwe-22" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Copyparty &lt;= 1.8.2 - Directory Traversal</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-37474.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-37474.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> shankar acharya,theamanrawat</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 11, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-37474" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-37474</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)copyparty&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Copyparty is a portable file server. Versions prior to 1.8.2 are subject to a path traversal vulnerability detected in the `.cpr` subfolder. The Path Traversal attack technique allows an attacker access to files, directories, and commands that reside outside the web document root directory. This issue has been addressed in commit `043e3c7d` which has been included in release 1.8.2. Users are advised to upgrade. There are no known workarounds for this vulnerability.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can exploit path traversal in the .cpr subfolder to read arbitrary files from the file server, potentially accessing sensitive system files and user data stored outside the web document root.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update Copyparty to version 1.8.2 or later that properly validates file paths in the .cpr subfolder and prevents directory traversal attacks.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">copyparty</span><span class="nt-tag">copyparty_project</span><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">packetstorm</span><span class="nt-tag">traversal</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/9001/copyparty/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.exploit-db.com/exploits/51636" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-37474" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="http://packetstormsecurity.com/files/173822/Copyparty-1.8.2-Directory-Traversal.html" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/9001/copyparty/commit/043e3c7dd683113e2b1c15cacb9c8e68f76513ff" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="copyparty &lt;=1.18.6 - cross-site scripting medium identify critical remote vulnerabilities copyparty before 1.18.7 is vulnerable to reflected cross-site scripting (xss) via the &#39;filter&#39; parameter in the &#39;/?ru&#39; endpoint. unsanitized user input is reflected in the html response, allowing attackers to execute arbitrary javascript in the context of the victim&#39;s browser. cve-2025-54589 s-cu-bot copyparty cve cve2025 vuln xss cwe-79" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Copyparty &lt;=1.18.6 - Cross-Site Scripting</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-54589.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-54589.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> s-cu-bot</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 6, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-79</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-54589" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-54589</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)copyparty&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Copyparty before 1.18.7 is vulnerable to reflected cross-site scripting (XSS) via the &#39;filter&#39; parameter in the &#39;/?ru&#39; endpoint. Unsanitized user input is reflected in the HTML response, allowing attackers to execute arbitrary JavaScript in the context of the victim&#39;s browser.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can execute arbitrary JavaScript in victim browsers through malicious URLs containing XSS payloads in the filter parameter, potentially leading to session hijacking.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade Copyparty to version 1.18.7 or later to mitigate this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">copyparty</span><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">vuln</span><span class="nt-tag">xss</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/9001/copyparty" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://secalerts.co/vulnerability/CVE-2025-54589" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/9001/copyparty/security/advisories/GHSA-8mx2-rjh8-q3jq" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54589" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="cortex xsoar login panel - detect info identify web-based control panels cortex xsoar login panel was detected. dhiyaneshdk,r3dg33k detect discovery login paloaltonetworks panel soar cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Cortex XSOAR Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/cortex-xsoar-login.yaml" target="_blank" rel="noopener" class="nt-source-link">cortex-xsoar-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDK,r3dg33k</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)cortex xsoar&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Cortex XSOAR login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">login</span><span class="nt-tag">paloaltonetworks</span><span class="nt-tag">panel</span><span class="nt-tag">soar</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="couchdb - default login high identify default logins in web-based control panels couchdb weak admin credentials were discovered. thefoggiest couchdb default-login misconfig vuln cwe-522" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">CouchDB - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/couchdb/couchdb-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">couchdb-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> thefoggiest</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 31, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/522.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-522</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.head.server&#34;] matches `^CouchDB/`</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">CouchDB weak admin credentials were discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">couchdb</span><span class="nt-tag">default-login</span><span class="nt-tag">misconfig</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="couchdb erlang distribution - remote command execution critical identify critical remote vulnerabilities in apache couchdb prior to 3.2.2, an attacker can access an improperly secured default installation without authenticating and gain admin privileges. cve-2022-24706 mzack9999,pussycat0x apache couch couchdb cve cve2022 kev network rce tcp vkev vuln cwe-1188" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">CouchDB Erlang Distribution - Remote Command Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/network/cves/2022/CVE-2022-24706.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-24706.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Mzack9999,pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 2, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/1188.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-1188</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-24706" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-24706</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;service.transport&#34;] == &#34;tcp&#34; and service[&#34;protocol&#34;] contains &#34;couchdb&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">In Apache CouchDB prior to 3.2.2, an attacker can access an improperly secured default installation without authenticating and gain admin privileges.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute arbitrary commands on the affected system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to versions 3.2.2 or newer. Starting from CouchDB 3.2.2, the previous default Erlang cookie value &#34;monster&#34; will be rejected upon startup. Upgraded installations will be required to select an alternative value.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">apache</span><span class="nt-tag">couch</span><span class="nt-tag">couchdb</span><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">kev</span><span class="nt-tag">network</span><span class="nt-tag">rce</span><span class="nt-tag">tcp</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.exploit-db.com/exploits/50914" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/sadshade/CVE-2022-24706-CouchDB-Exploit/blob/main/CVE-2022-24706-Exploit.py" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-24706" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="http://www.openwall.com/lists/oss-security/2022/04/26/1" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="http://www.openwall.com/lists/oss-security/2022/05/09/1" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="couchbase server - broken access control critical identify critical remote vulnerabilities couchbase server versions 4.0.0, 4.1.0, 4.1.1, 4.5.0, 4.5.1, 4.6.0-4.6.5, 5.0.0, 5.1.1, 5.5.0, and 5.5.1 contain insecure permissions for the projector and indexer rest endpoints caused by unauthenticated access, letting attackers access administrative apis without authentication, exploit requires no special conditions. cve-2020-9039 pussycat0x cve cve2020 couchbase unauth cwe-276" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Couchbase Server - Broken Access Control</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2020/CVE-2020-9039.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2020-9039.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 15, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/276.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-276</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2020-9039" target="_blank" rel="noopener" class="nt-cve-link">CVE-2020-9039</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Couchbase&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Couchbase Server versions 4.0.0, 4.1.0, 4.1.1, 4.5.0, 4.5.1, 4.6.0-4.6.5, 5.0.0, 5.1.1, 5.5.0, and 5.5.1 contain insecure permissions for the projector and indexer REST endpoints caused by unauthenticated access, letting attackers access administrative APIs without authentication, exploit requires no special conditions.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can access and modify administrative settings, potentially leading to data tampering or system compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest version where the /settings REST endpoint requires authentication.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2020</span><span class="nt-tag">couchbase</span><span class="nt-tag">unauth</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://docs.couchbase.com/server/current/index-rest-settings/index.html#Settings" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="couchbase server console - detect info identify web-based control panels couchbase server administrative console was discovered. th3l0newolf console couchbase detect login panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Couchbase Server Console - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/couchbase-server-console.yaml" target="_blank" rel="noopener" class="nt-source-link">couchbase-server-console.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Th3l0newolf</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 27, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;^Couchbase Console&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Couchbase Server administrative console was discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">console</span><span class="nt-tag">couchbase</span><span class="nt-tag">detect</span><span class="nt-tag">login</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="cox business dominion gateway login panel - detect info identify web-based control panels cox business dominion gateway login page was discovered. dhiyaneshdk cox gateway login panel discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Cox Business Dominion Gateway Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/cox-business-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">cox-business-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 3, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Cox Business&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Cox Business Dominion Gateway Login page was discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cox</span><span class="nt-tag">gateway</span><span class="nt-tag">login</span><span class="nt-tag">panel</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://samcurry.net/hacking-millions-of-modems" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="craft cms - remote code execution via template path manipulation critical identify critical remote vulnerabilities this template identifies a critical remote code execution (rce) vulnerability in craft cms, identified as ghsa-2p6p-9rc9-62j9.
the vulnerability exists due to improper handling of the `--templatespath` query parameter, allowing attackers to execute arbitrary code by referencing malicious twig templates. cve-2024-56145 jackhax craftcms cve cve2024 kev rce ssti vkev vuln cwe-94" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Craft CMS - Remote Code Execution via Template Path Manipulation</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-56145.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-56145.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> jackhax</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 29, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/94.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-94</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-56145" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-56145</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;product&#34;] contains &#34;CraftCMS:Craft CMS&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">This template identifies a critical Remote Code Execution (RCE) vulnerability in Craft CMS, identified as GHSA-2p6p-9rc9-62j9.
The vulnerability exists due to improper handling of the `--templatesPath` query parameter, allowing attackers to execute arbitrary code by referencing malicious Twig templates.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an unauthenticated attacker to perform remote code execution.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade CraftCMS to either &gt;5.5.2 or &gt;4.13.2 or &gt;3.9.14. Or If you can&#39;t upgrade yet, and register_argc_argv is enabled, you can disable it to mitigate the issue.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">craftcms</span><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">kev</span><span class="nt-tag">rce</span><span class="nt-tag">ssti</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/advisories/GHSA-2p6p-9rc9-62j9" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.assetnote.io/resources/research/how-an-obscure-php-footgun-led-to-rce-in-craft-cms" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/Chocapikk/CVE-2024-56145" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/craftcms/cms/commit/82e893fb794d30563da296bca31379c0df0079b3" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/craftcms/cms/security/advisories/GHSA-2p6p-9rc9-62j9" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="craft cms &lt; 3.3.0 - server-side template injection critical identify critical remote vulnerabilities craft cms before 3.3.0 is susceptible to server-side template injection via the seomatic component that could lead to remote code execution via malformed data submitted to the metacontainers controller. cve-2020-9757 dwisiswant0 craftcms cve cve2020 ssti vkev vuln cwe-74" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Craft CMS &lt; 3.3.0 - Server-Side Template Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2020/CVE-2020-9757.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2020-9757.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dwisiswant0</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/74.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-74</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2020-9757" target="_blank" rel="noopener" class="nt-cve-link">CVE-2020-9757</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;product&#34;] contains &#34;CraftCMS:Craft CMS&#34; || service[&#34;product&#34;] contains &#34;nystudio107:SEOmatic&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Craft CMS before 3.3.0 is susceptible to server-side template injection via the SEOmatic component that could lead to remote code execution via malformed data submitted to the metacontainers controller.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the server.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade Craft CMS to version 3.3.0 or higher to mitigate this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">craftcms</span><span class="nt-tag">cve</span><span class="nt-tag">cve2020</span><span class="nt-tag">ssti</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/nystudio107/craft-seomatic/blob/v3/CHANGELOG.md" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/giany/CVE/blob/master/CVE-2020-9757.txt" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/nystudio107/craft-seomatic/commit/65ab659cb6c914c7ad671af1e417c0da2431f79b" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/nystudio107/craft-seomatic/commit/a1c2cad7e126132d2442ec8ec8e9ab43df02cc0f" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2020-9757" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="craft cms &lt;=v3.7.31 - sql injection critical identify critical remote vulnerabilities craft cms up to v3.7.31 was discovered to contain a sql injection vulnerability via the graphql api endpoint. cve-2024-37843 iamnoooob,rootxharsh,pdresearch craftcms cve cve2024 sqli vuln cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Craft CMS &lt;=v3.7.31 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-37843.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-37843.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> iamnoooob,rootxharsh,pdresearch</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 24, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-37843" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-37843</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;product&#34;] contains &#34;CraftCMS:Craft CMS&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Craft CMS up to v3.7.31 was discovered to contain a SQL injection vulnerability via the GraphQL API endpoint.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can execute arbitrary SQL queries via the GraphQL API endpoint, potentially compromising the database.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update Craft CMS to a version later than v3.7.31.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">craftcms</span><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">sqli</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://blog.smithsecurity.biz/craft-cms-unauthenticated-sqli-via-graphql" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/gsmith257-cyber/CVE-2024-37843-POC" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="craft cms admin login panel - detect info identify web-based control panels craft cms admin login panel was detected. supr4s panel craftcms nystudio107 discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Craft CMS Admin Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/craftcms-admin-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">craftcms-admin-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Supr4s</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;product&#34;] contains &#34;CraftCMS:Craft CMS&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Craft CMS admin login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">craftcms</span><span class="nt-tag">nystudio107</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="craft cms installation wizard exposure high identify critical remote vulnerabilities detected craft cms installation wizard was exposed, allowing attackers to complete the installation process and gain administrative access to the cms. 0x_akoko craftcms install exposure misconfig cwe-284" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Craft CMS Installation Wizard Exposure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/misconfiguration/installer/craftcms-install-exposure.yaml" target="_blank" rel="noopener" class="nt-source-link">craftcms-install-exposure.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_Akoko</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 22, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/284.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-284</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;product&#34;] contains &#34;CraftCMS:Craft CMS&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detected Craft CMS installation wizard was exposed, allowing attackers to complete the installation process and gain administrative access to the CMS.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">craftcms</span><span class="nt-tag">install</span><span class="nt-tag">exposure</span><span class="nt-tag">misconfig</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://craftcms.com/docs/4.x/installation.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://craftcms.com/knowledge-base/securing-craft" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="craftcms - remote code execution critical identify critical remote vulnerabilities craft is a flexible, user-friendly cms for creating custom digital experiences on the web and beyond. starting from version 3.0.0-rc1 to before 3.9.15, 4.0.0-rc1 to before 4.14.15, and 5.0.0-rc1 to before 5.6.17, craft is vulnerable to remote code execution. this is a high-impact, low-complexity attack vector. cve-2025-32432 iamnoooob,rootxharsh,pdresearch craftcms cve cve2025 kev rce vkev vuln cwe-94" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">CraftCMS - Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-32432.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-32432.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> iamnoooob,rootxharsh,pdresearch</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 28, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/94.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-94</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-32432" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-32432</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;product&#34;] contains &#34;CraftCMS:Craft CMS&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Starting from version 3.0.0-RC1 to before 3.9.15, 4.0.0-RC1 to before 4.14.15, and 5.0.0-RC1 to before 5.6.17, Craft is vulnerable to remote code execution. This is a high-impact, low-complexity attack vector.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can exploit remote code execution vulnerabilities through unsafe deserialization in the asset transform functionality, achieving complete server compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">This issue has been patched in versions 3.9.15, 4.14.15, and 5.6.17, and is an additional fix for CVE-2023-41892.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">craftcms</span><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">kev</span><span class="nt-tag">rce</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://advisories.dxw.com/advisories/craftcms-remote-code-execution/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/craftcms/cms/commit/1234567890abcdef1234567890abcdef1234567" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/craftcms/cms/security/advisories/GHSA-1234-5678-90ab" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/craftcms/cms/blob/3.x/CHANGELOG.md#3915---2025-04-10-critical" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/craftcms/cms/blob/4.x/CHANGELOG.md#41415---2025-04-10-critical" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="craftcms &lt; 4.4.15 - unauthenticated remote code execution critical identify critical remote vulnerabilities craft cms is a platform for creating digital experiences. this is a high-impact, low-complexity attack vector leading to remote code execution (rce). users running craft installations before 4.4.15 are encouraged to update to at least that version to mitigate the issue. this issue has been fixed in craft cms 4.4.15. cve-2023-41892 iamnoooob,rootxharsh,pdresearch craftcms cve cve2023 rce unauth vkev vuln cwe-94" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">CraftCMS &lt; 4.4.15 - Unauthenticated Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-41892.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-41892.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> iamnoooob,rootxharsh,pdresearch</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 15, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/94.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-94</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-41892" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-41892</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;product&#34;] contains &#34;CraftCMS:Craft CMS&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Craft CMS is a platform for creating digital experiences. This is a high-impact, low-complexity attack vector leading to Remote Code Execution (RCE). Users running Craft installations before 4.4.15 are encouraged to update to at least that version to mitigate the issue. This issue has been fixed in Craft CMS 4.4.15.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the target system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches and updates from the vendor to address this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">craftcms</span><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">rce</span><span class="nt-tag">unauth</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/craftcms/cms/security/advisories/GHSA-4w8r-3xrw-v25g" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://blog.calif.io/p/craftcms-rce" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/craftcms/cms/blob/develop/CHANGELOG.md#4415---2023-07-03-critical" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/craftcms/cms/commit/7359d18d46389ffac86c2af1e0cd59e37c298857" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/craftcms/cms/commit/a270b928f3d34ad3bd953b81c304424edd57355e" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="craftcms debug methods exposed medium identify critical remote vulnerabilities detected craftcms with devmode enabled, which exposed the yii2 debug toolbar and sensitive information. this misconfiguration could have leaked database queries, session data, cookies, stack traces, csrf tokens, and internal application details to unauthenticated users. 0x_akoko craftcms debug misconfiguration exposure yii2" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">CraftCMS Debug Methods Exposed</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/misconfiguration/debug/craftcms-debug-exposure.yaml" target="_blank" rel="noopener" class="nt-source-link">craftcms-debug-exposure.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_Akoko</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 27, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;product&#34;] contains &#34;CraftCMS:Craft CMS&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detected CraftCMS with devMode enabled, which exposed the Yii2 debug toolbar and sensitive information. This misconfiguration could have leaked database queries, session data, cookies, stack traces, CSRF tokens, and internal application details to unauthenticated users.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">craftcms</span><span class="nt-tag">debug</span><span class="nt-tag">misconfiguration</span><span class="nt-tag">exposure</span><span class="nt-tag">yii2</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://craftcms.com/docs/5.x/system/config.html#devmode" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.acunetix.com/vulnerabilities/web/craft-cms-development-mode-enabled/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="craftcms seomatic - server-side template injection critical identify critical remote vulnerabilities in the seomatic plugin up to 3.4.11 for craft cms 3, it is possible for unauthenticated attackers to perform a server-side. template injection, allowing for remote code execution. cve-2021-41749 iamnoooob,ritikchaddha cms craft_cms craftcms cve cve2021 nystudio107 ssti vuln cwe-94" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">CraftCMS SEOmatic - Server-Side Template Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2021/CVE-2021-41749.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2021-41749.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> iamnoooob,ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 12, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/94.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-94</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2021-41749" target="_blank" rel="noopener" class="nt-cve-link">CVE-2021-41749</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;product&#34;] contains &#34;CraftCMS:Craft CMS&#34; || service[&#34;product&#34;] contains &#34;nystudio107:SEOmatic&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">In the SEOmatic plugin up to 3.4.11 for Craft CMS 3, it is possible for unauthenticated attackers to perform a Server-Side. Template Injection, allowing for remote code execution.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can exploit SSTI via X-Forwarded-Host header to execute arbitrary Twig templates and system commands, achieving complete server compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to CraftCMS SEOmatic version 3.4.12 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cms</span><span class="nt-tag">craft_cms</span><span class="nt-tag">craftcms</span><span class="nt-tag">cve</span><span class="nt-tag">cve2021</span><span class="nt-tag">nystudio107</span><span class="nt-tag">ssti</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/nystudio107/craft-seomatic/commit/3fee7d50147cdf3f999cfc1e04cbc3fb3d9f2f7d" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2021-41749" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/nystudio107/craft-seomatic/blob/develop/CHANGELOG.md" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="craftercms engine - cross-site scripting medium identify critical remote vulnerabilities craftercms engine is vulnerable to reflected cross-site scripting (xss) via the transformername parameter in the /api/1/site/url/transform endpoint, allowing attackers to execute arbitrary javascript in the context of the user. cve-2023-4136 ritikchaddha craftercms cve cve2023 vuln xss cwe-79" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">CrafterCMS Engine - Cross-Site Scripting</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-4136.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-4136.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 2, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-79</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-4136" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-4136</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)craftercms&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">CrafterCMS Engine is vulnerable to reflected cross-site scripting (XSS) via the transformerName parameter in the /api/1/site/url/transform endpoint, allowing attackers to execute arbitrary JavaScript in the context of the user.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can inject malicious JavaScript through the transformerName parameter in various API endpoints to steal CrafterCMS user credentials and session data.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update CrafterCMS Engine to the latest version that addresses this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">craftercms</span><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">vuln</span><span class="nt-tag">xss</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://karmainsecurity.com/KIS-2023-09" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-4136" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="craftercms login panel - detect info identify web-based control panels craftercms login panel was detected. righettod panel craftercms login detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">CrafterCMS Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/craftercms-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">craftercms-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 11, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)craftercms&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">CrafterCMS login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">craftercms</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://craftercms.org/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="creatio login panel - detect info identify web-based control panels creatio login panel was detected. theamanrawat panel creatio discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Creatio Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/creatio-login-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">creatio-login-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> theamanrawat</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Creatio&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Creatio login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">creatio</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="crestron airmedia 2.0 - default login high identify default logins in web-based control panels crestron airmedia 2.0 devices contain default credentials (admin:admin) that allow unauthorized administrative access to device configuration and control. andrew lentz crestron default-login iot misconfig vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Crestron Airmedia 2.0 - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/crestron/crestron-airmedia-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">crestron-airmedia-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Andrew Lentz</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 27, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)airmedia&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Crestron AirMedia 2.0 devices contain default credentials (admin:admin) that allow unauthorized administrative access to device configuration and control.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">crestron</span><span class="nt-tag">default-login</span><span class="nt-tag">iot</span><span class="nt-tag">misconfig</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="crontab ui - dashboard exposure high identify web-based control panels  dhiyaneshdk exposure crontab ui panel discovery" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Crontab UI - Dashboard Exposure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/crontab-ui.yaml" target="_blank" rel="noopener" class="nt-source-link">crontab-ui.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 20, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Crontab UI&#34;</code></div>
  <div class="nt-tags"><span class="nt-tag">exposure</span><span class="nt-tag">crontab</span><span class="nt-tag">ui</span><span class="nt-tag">panel</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.facebook.com/photo/?fbid=629288492575007&amp;set=a.467014098802448" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="crushftp - anonymous login high identify default logins in web-based control panels crushftp anonymous login credentials were discovered. pussycat0x anonymous crushftp default-login default-logins vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">CrushFTP - Anonymous Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/crushftp/crushftp-anonymous-login.yaml" target="_blank" rel="noopener" class="nt-source-link">crushftp-anonymous-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 26, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] contains &#34;CrushFTP&#34; || service[&#34;http.head.server&#34;] contains &#34;CrushFTP&#34; || any(each(service[&#34;favicon.ico.image.mmh3&#34;]), {# == &#34;-1022206565&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">CrushFTP Anonymous login credentials were discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">anonymous</span><span class="nt-tag">crushftp</span><span class="nt-tag">default-login</span><span class="nt-tag">default-logins</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="crushftp - authentication bypass critical identify critical remote vulnerabilities crushftp versions 10.0.0 through 10.8.3 and 11.0.0 through 11.3.0 are affected by a vulnerability that may result in unauthenticated access. remote and unauthenticated http requests to crushftp may allow attackers to gain unauthorized access. cve-2025-31161 parthmalhotra,ice3man,dhiyaneshdk,pdresearch,whattheslime auth-bypass crushftp cve cve2025 kev rce unauth vkev vuln cwe-287" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">CrushFTP - Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-31161.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-31161.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> parthmalhotra,Ice3man,DhiyaneshDk,pdresearch,whattheslime</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 14, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/287.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-287</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-31161" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-31161</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)crushftp webinterface&#34;}) || service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-1022206565&#34; || service[&#34;http.body&#34;] matches &#34;(?i)crushftp&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">CrushFTP versions 10.0.0 through 10.8.3 and 11.0.0 through 11.3.0 are affected by a vulnerability that may result in unauthenticated access. Remote and unauthenticated HTTP requests to CrushFTP may allow attackers to gain unauthorized access.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can bypass authentication by forging session cookies, gaining unauthorized administrative access to CrushFTP and potentially compromising the entire file transfer infrastructure.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to CrushFTP version 10.8.4 or 11.3.1 or later that properly validates session authentication.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">crushftp</span><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">kev</span><span class="nt-tag">rce</span><span class="nt-tag">unauth</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://projectdiscovery.io/blog/crushftp-authentication-bypass/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.rapid7.com/blog/post/2025/03/25/etr-notable-vulnerabilities-in-next-js-cve-2025-29927/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.crushftp.com/crush11wiki/Wiki.jsp?page=Update" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-31161" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="crushftp - default login high identify default logins in web-based control panels crushftp default login credentials were discovered. pussycat0x crushftp default-login vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">CrushFTP - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/crushftp/crushftp-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">crushftp-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 26, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] contains &#34;CrushFTP&#34; || service[&#34;http.head.server&#34;] contains &#34;CrushFTP&#34; || any(each(service[&#34;favicon.ico.image.mmh3&#34;]), {# == &#34;-1022206565&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">CrushFTP default login credentials were discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">crushftp</span><span class="nt-tag">default-login</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="crushftp vfs - sandbox escape lfr critical identify critical remote vulnerabilities vfs sandbox escape in crushftp in all versions before 10.7.1 and 11.1.0 on all platforms allows remote attackers with low privileges to read files from the filesystem outside of vfs sandbox. cve-2024-4040 dhiyaneshdk,pussycat0x crushftp cve cve2024 kev lfr vfs vkev vuln cwe-1336,cwe-94" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">CrushFTP VFS - Sandbox Escape LFR</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-4040.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-4040.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK,pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 23, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/1336,CWE-94.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-1336,CWE-94</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-4040" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-4040</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)crushftp&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">VFS Sandbox Escape in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows remote attackers with low privileges to read files from the filesystem outside of VFS Sandbox.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation could lead to unauthorized access to sensitive data.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the vendor-supplied patch or upgrade to the latest version to mitigate CVE-2024-4040.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">crushftp</span><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">kev</span><span class="nt-tag">lfr</span><span class="nt-tag">vfs</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.bleepingcomputer.com/news/security/crushftp-warns-users-to-patch-exploited-zero-day-immediately/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.crushftp.com/crush10wiki/Wiki.jsp?page=Update" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.reddit.com/r/crowdstrike/comments/1c88788/situational_awareness_20240419_crushftp_virtual/" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://www.reddit.com/r/cybersecurity/comments/1c850i2/all_versions_of_crush_ftp_are_vulnerable/" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="crushftp webinterface panel - detect info identify web-based control panels crushftp webinterface login panel was detected. dhiyaneshdk panel edb crushftp detect discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">CrushFTP WebInterface Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/crush-ftp-login.yaml" target="_blank" rel="noopener" class="nt-source-link">crush-ftp-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)crushftp&#34; || any(each(service[&#34;favicon.ico.image.mmh3&#34;]), {# == &#34;-1022206565&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">CrushFTP WebInterface login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">edb</span><span class="nt-tag">crushftp</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.exploit-db.com/ghdb/6591" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="crypto &lt;= 2.15 - authentication bypass critical identify critical remote vulnerabilities the crypto plugin for wordpress is vulnerable to authentication bypass in versions up to, and including, 2.15. this is due a to limited arbitrary method call to &#39;crypto_connect_ajax_process::log_in&#39; function in the &#39;crypto_connect_ajax_process&#39; function. this makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the username. cve-2024-9989 s4e-io auth-bypass crypto cve cve2024 vuln wordpress wp wp-plugin cwe-288" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Crypto &lt;= 2.15 - Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-9989.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-9989.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> s4e-io</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 6, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/288.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-288</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-9989" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-9989</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)wp-content/plugins/crypto&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The Crypto plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.15. This is due a to limited arbitrary method call to &#39;crypto_connect_ajax_process::log_in&#39; function in the &#39;crypto_connect_ajax_process&#39; function. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the username.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can bypass authentication to log in as any existing user including administrators if they know the username, gaining complete control of the WordPress site and all its data.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update Crypto plugin to a version later than 2.15 that properly restricts and validates method calls in the crypto_connect_ajax_process function.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">crypto</span><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/wy876/POC/blob/main/WordPress/WordPress%E6%8F%92%E4%BB%B6Crypto%E8%BA%AB%E4%BB%BD%E8%AE%A4%E8%AF%81%E7%BB%95%E8%BF%87%E6%BC%8F%E6%B4%9E%E5%A4%8D%E7%8E%B0(CVE-2024-9989).md" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://mp.weixin.qq.com/s/hC8A1DeS-LWGpNIFKeiMBQ" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e21bd924-1d96-4371-972a-5c99d67261cc?source=cve" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-9989" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/advisories/GHSA-hmfh-w3mx-w6j4" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="cryptobox panel - detect info identify web-based control panels cryptobox was detected. righettod panel cryptobox login detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Cryptobox Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/cryptobox-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">cryptobox-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 13, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Cryptobox&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Cryptobox was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">cryptobox</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.ercom.com/solutions/cryptobox-presentation" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="cryptocurrency widgets pack &lt; 2.0 - sql injection critical identify critical remote vulnerabilities the plugin does not sanitise and escape some parameter before using it in a sql statement via an ajax action available to unauthenticated users, leading to a sql injection. cve-2022-4059 r3y3r53 blocksera cve cve2022 sqli time-based-sqli vkev vuln wordpress wp wp-plugin wpscan cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Cryptocurrency Widgets Pack &lt; 2.0 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-4059.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-4059.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> r3Y3r53</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 17, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-4059" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-4059</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/cryptocurrency-widgets-pack/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The plugin does not sanitise and escape some parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can execute time-based blind SQL injection through the columns[0][name] parameter in the mcwp_table AJAX action, potentially extracting sensitive database information including cryptocurrency data, user credentials, and plugin configuration.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Fixed in version 2.0</div></div></div>
  <div class="nt-tags"><span class="nt-tag">blocksera</span><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">sqli</span><span class="nt-tag">time-based-sqli</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">wpscan</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wpscan.com/vulnerability/d94bb664-261a-4f3f-8cc3-a2db8230895d" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-4059" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/cyllective/CVEs" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="cryptocurrency widgets pack &lt;= 1.8.1 - sql injection critical identify critical remote vulnerabilities cryptocurrency widgets pack plugin &lt;=1.8.1 for wordpress contains an unauthenticated sql injection caused by unsanitized user input in database queries, letting attackers execute arbitrary sql commands, exploit requires no authentication. cve-2022-44588 shivam kamboj cryptocurrency-widgets-pack cve cve2022 sqli unauth wordpress wp wp-plugin cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Cryptocurrency Widgets Pack &lt;= 1.8.1 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-44588.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-44588.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Shivam Kamboj</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 22, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-44588" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-44588</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)wp-content/plugins/cryptocurrency-widgets-pack&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Cryptocurrency Widgets Pack Plugin &lt;=1.8.1 for WordPress contains an unauthenticated SQL injection caused by unsanitized user input in database queries, letting attackers execute arbitrary SQL commands, exploit requires no authentication.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can execute arbitrary SQL commands, potentially leading to data theft, modification, or deletion of sensitive information.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest version of the plugin where the vulnerability is fixed.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cryptocurrency-widgets-pack</span><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">sqli</span><span class="nt-tag">unauth</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-44588" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/cryptocurrency-widgets-pack/cryptocurrency-widgets-pack-181-unauthenticated-sql-injection-2" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="cudatel login panel - detect info identify web-based control panels cudatel login panel was detected. arafatansari panel cudatel discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">CudaTel Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/cudatel-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">cudatel-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> arafatansari</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)CudaTel&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">CudaTel login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">cudatel</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="cvent login panel - detect info identify web-based control panels cvent login panel was detected. tess panel cvent discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Cvent Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/cvent-panel-detect.yaml" target="_blank" rel="noopener" class="nt-source-link">cvent-panel-detect.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> tess</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Cvent Inc&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Cvent login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">cvent</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="cyber chef panel - detect info identify web-based control panels a cyber chef panel was detected rxerium panel cyberchef login detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Cyber Chef Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/cyberchef-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">cyberchef-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 6, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)CyberChef&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A Cyber Chef Panel was detected</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">cyberchef</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://cyberchef.org" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="cyberpanel - command injection critical identify critical remote vulnerabilities cyberpanel contains a command injection vulnerability in the /ftp/getresetstatus and /dns/getresetstatus endpoints.the vulnerability exists due to improper validation of the &#39;statusfile&#39; parameter, which is directly used in a shell command.the security middleware only validates post requests, allowing attackers to bypass protection using options requests. cve-2024-51378 ritikchaddha cve cve2024 cyberpanel kev rce vkev vuln cwe-78" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">CyberPanel - Command Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-51378.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-51378.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 17, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/78.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-78</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-51378" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-51378</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)cyberpanel&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">CyberPanel contains a command injection vulnerability in the /ftp/getresetstatus and /dns/getresetstatus endpoints.The vulnerability exists due to improper validation of the &#39;statusfile&#39; parameter, which is directly used in a shell command.The security middleware only validates POST requests, allowing attackers to bypass protection using OPTIONS requests.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can exploit this vulnerability to compromise system security and integrity.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches and updates to address this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">cyberpanel</span><span class="nt-tag">kev</span><span class="nt-tag">rce</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.bleepingcomputer.com/news/security/massive-psaux-ransomware-attack-targets-22-000-cyberpanel-instances/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://refr4g.github.io/posts/cyberpanel-command-injection-vulnerability/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-51378" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="cyberpower - missing authentication critical identify critical remote vulnerabilities an issue regarding missing authentication for certain utilities exists in cyberpower powerpanel enterprise prior to v2.8.3. cve-2024-32735 dhiyaneshdk auth-bupass cve cve2024 cyberpower vkev vuln cwe-306" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">CyberPower - Missing Authentication</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-32735.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-32735.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 15, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/306.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-306</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-32735" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-32735</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)&lt;title&gt;PDNU&lt;/title&gt;&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An issue regarding missing authentication for certain utilities exists in CyberPower PowerPanel Enterprise prior to v2.8.3.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An unauthenticated remote attacker can access the PDNU REST APIs, which may result in compromise of the application.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches and updates from the vendor to address this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bupass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">cyberpower</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.cyberpower.com/global/en/File/GetFileSampleByType?fileId=SU-18070002-07&amp;fileSubType=FileReleaseNote" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.tenable.com/security/research/tra-2024-14" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-32735" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="cyberpower - sql injection high identify critical remote vulnerabilities a sql injection vulnerability exists in cyberpower powerpanel enterprise prior to v2.8.3. cve-2024-32738 dhiyaneshdk cve cve2024 cyberpower sqli vkev vuln cwe-89" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">CyberPower - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-32738.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-32738.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 15, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-32738" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-32738</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)&lt;title&gt;PDNU&lt;/title&gt;&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A sql injection vulnerability exists in CyberPower PowerPanel Enterprise prior to v2.8.3.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An unauthenticated remote attacker can leak sensitive information via the &#34;query_ptask_lean&#34; function within MCUDBHelper.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade CyberPower PowerPanel Enterprise to version 2.8.3 or later to address the SQL injection vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">cyberpower</span><span class="nt-tag">sqli</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.cyberpower.com/global/en/File/GetFileSampleByType?fileId=SU-18070002-07&amp;fileSubType=FileReleaseNote" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.tenable.com/security/research/tra-2024-14" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-32738" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="cyberpower - sql injection high identify critical remote vulnerabilities a sql injection vulnerability exists in cyberpower powerpanel enterprise prior to v2.8.3. cve-2024-32737 dhiyaneshdk cve cve2024 cyberpower sqli vkev vuln cwe-89" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">CyberPower - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-32737.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-32737.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 15, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-32737" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-32737</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)&lt;title&gt;PDNU&lt;/title&gt;&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A sql injection vulnerability exists in CyberPower PowerPanel Enterprise prior to v2.8.3.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An unauthenticated remote attacker can leak sensitive information via the &#34;query_contract_result&#34; function within MCUDBHelper.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches and updates from the vendor to address this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">cyberpower</span><span class="nt-tag">sqli</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.cyberpower.com/global/en/File/GetFileSampleByType?fileId=SU-18070002-07&amp;fileSubType=FileReleaseNote" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.tenable.com/security/research/tra-2024-14" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-32737" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="cyberpower &lt; v2.8.3 - sql injection high identify critical remote vulnerabilities a sql injection vulnerability exists in cyberpower powerpanel enterprise prior to . cve-2024-32736 dhiyaneshdk cve cve2024 cyberpower sqli vkev vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">CyberPower &lt; v2.8.3 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-32736.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-32736.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 15, 2024</span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-32736" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-32736</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)&lt;title&gt;PDNU&lt;/title&gt;&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A sql injection vulnerability exists in CyberPower PowerPanel Enterprise prior to .</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An unauthenticated remote attacker can leak sensitive information via the &#34;query_utask_verbose&#34; function within MCUDBHelper.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches and updates from the vendor to address this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">cyberpower</span><span class="nt-tag">sqli</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.cyberpower.com/global/en/File/GetFileSampleByType?fileId=SU-18070002-07&amp;fileSubType=FileReleaseNote" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.tenable.com/security/research/tra-2024-14" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-32736" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="cyberpower &lt; v2.8.3 - sql injection high identify critical remote vulnerabilities a sql injection vulnerability exists in cyberpower powerpanel enterprise prior to v2.8.3. cve-2024-32739 dhiyaneshdk cve cve2024 cyberpower sqli vkev vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">CyberPower &lt; v2.8.3 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-32739.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-32739.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 15, 2024</span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-32739" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-32739</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)&lt;title&gt;PDNU&lt;/title&gt;&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A sql injection vulnerability exists in CyberPower PowerPanel Enterprise prior to v2.8.3.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An unauthenticated remote attacker can leak sensitive information via the &#34;query_ptask_verbose&#34; function within MCUDBHelper.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches and updates from the vendor to address this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">cyberpower</span><span class="nt-tag">sqli</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.cyberpower.com/global/en/File/GetFileSampleByType?fileId=SU-18070002-07&amp;fileSubType=FileReleaseNote" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.tenable.com/security/research/tra-2024-14" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-32739" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="cyberoam ssl vpn panel - detect info identify web-based control panels cyberoam ssl vpn panel was detected. idealphase cyberoam discovery panel sophos vpn cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Cyberoam SSL VPN Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/cyberoam-ssl-vpn-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">cyberoam-ssl-vpn-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> idealphase</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)cyberoam ssl vpn portal&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Cyberoam SSL VPN panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cyberoam</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">sophos</span><span class="nt-tag">vpn</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://docs.sophos.com/nsg/Cyberoam/Version%2010.x/10.6.3/Guides/Cyberoam%20SSL%20VPN%20User%20Guide.pdf" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="cyberpanel login panel - detect info identify web-based control panels cyberpanel login panel was detected. mailler cyberpanel detect discovery login panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Cyberpanel Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/cyberpanel-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">cyberpanel-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> mailler</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 29, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)cyberpanel&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Cyberpanel login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cyberpanel</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">login</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://cyberpanel.net/KnowledgeBase/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="d-link dns-320l,dns-320lw and dns-327l - information disclosure medium identify critical remote vulnerabilities a vulnerability has been found in d-link dns-320l, dns-320lw and dns-327l up to 20240403 and classified as problematic. affected by this vulnerability is an unknown functionality of the file /cgi-bin/info.cgi of the component http get request handler. cve-2024-3274 dhiyaneshdk cve cve2024 dlink exposure vuln cwe-200" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">D-LINK DNS-320L,DNS-320LW and DNS-327L - Information Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-3274.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-3274.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 18, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-3274" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-3274</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Text:In order to access the ShareCenter&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A vulnerability has been found in D-Link DNS-320L, DNS-320LW and DNS-327L up to 20240403 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/info.cgi of the component HTTP GET Request Handler.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can access sensitive system information from D-Link NAS devices.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update D-Link NAS firmware to a version that patches the information disclosure vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">dlink</span><span class="nt-tag">exposure</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/netsecfish/info_cgi" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10383" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-3274" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="d-link ac centralized management system - default login high identify default logins in web-based control panels d-link ac centralized management system default login credentials were discovered. sleepingbag945 default-login dlink vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">D-Link AC Centralized Management System - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/d-link/dlink-centralized-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">dlink-centralized-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> SleepingBag945</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 18, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)AC集中管理平台&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">D-Link AC Centralized Management System default login credentials were discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">dlink</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="d-link central wifi manager cwm(100) - remote code execution critical identify critical remote vulnerabilities /web/lib/action/indexaction.class.php in d-link central wifi manager cwm(100) before v1.03r0100_beta6 allows remote attackers to execute arbitrary php code via a cookie because a cookie&#39;s username field allows eval injection, and an empty password bypasses authentication. cve-2019-13372 dhiyaneshdk cve cve2019 d-link vkev vuln wifimanager cwe-94" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">D-Link Central WiFi Manager CWM(100) - Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2019/CVE-2019-13372.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2019-13372.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 11, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/94.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-94</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2019-13372" target="_blank" rel="noopener" class="nt-cve-link">CVE-2019-13372</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)D-Link Central WiFiManager&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">/web/Lib/Action/IndexAction.class.php in D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6 allows remote attackers to execute arbitrary PHP code via a cookie because a cookie&#39;s username field allows eval injection, and an empty password bypasses authentication.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can execute arbitrary PHP code via cookie manipulation, leading to complete compromise of the D-Link Central WiFi Manager and potential access to all managed WiFi networks.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update D-Link Central WiFi Manager to version 1.03R0100_BETA6 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2019</span><span class="nt-tag">d-link</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">wifimanager</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/unh3x/unh3x.github.io/blob/master/_posts/2019-02-21-D-link-%28CWM-100%29-Multiple-Vulnerabilities.md" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10117" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://unh3x.github.io/2019/02/21/D-link-%28CWM-100%29-Multiple-Vulnerabilities/" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2019-13372" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="d-link d-view 8 v2.0.1.28 - authentication bypass critical identify critical remote vulnerabilities use of a static key to protect a jwt token used in user authentication can allow an for an authentication bypass in d-link d-view 8 v2.0.1.28 cve-2023-5074 dhiyaneshdk auth-bypass cve cve2023 d-link dlink vkev vuln cwe-798" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">D-Link D-View 8 v2.0.1.28 - Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-5074.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-5074.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 26, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/798.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-798</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-5074" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-5074</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-1317621215&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Use of a static key to protect a JWT token used in user authentication can allow an for an authentication bypass in D-Link D-View 8 v2.0.1.28</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can exploit static JWT keys to forge authentication tokens and bypass authentication to gain administrative access to D-Link D-View systems.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to the latest version to mitigate this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">d-link</span><span class="nt-tag">dlink</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.tenable.com/security/research/tra-2023-32" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-5074" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/codeb0ss/CVE-2023-5074-PoC" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/nomi-sec/PoC-in-GitHub" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="d-link dar-8000-10 - command injection critical identify critical remote vulnerabilities d-link dar-8000-10 version has an operating system command injection vulnerability. the vulnerability originates from the parameter id of the file /app/sys1.php which can lead to operating system command injection. cve-2023-4542 pussycat0x cve cve2023 dlink vkev vuln cwe-78" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">D-Link DAR-8000-10 - Command Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-4542.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-4542.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 23, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/78.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-78</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-4542" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-4542</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)dar-8000-10&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">D-Link DAR-8000-10 version has an operating system command injection vulnerability. The vulnerability originates from the parameter id of the file /app/sys1.php which can lead to operating system command injection.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can execute arbitrary operating system commands through the id parameter in /app/sys1.php, potentially gaining full control of the D-Link DAR-8000-10 router and intercepting all network traffic.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update D-Link DAR-8000-10 firmware to a patched version that properly sanitizes the id parameter in sys1.php and prevents operating system command injection.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">dlink</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/20142995/sectool" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/tanjiti/sec_profile" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/wy876/POC/blob/main/D-Link_DAR-8000%E6%93%8D%E4%BD%9C%E7%B3%BB%E7%BB%9F%E5%91%BD%E4%BB%A4%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E(CVE-2023-4542).md" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://vuldb.com/?ctiid.238047" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://vuldb.com/?id.238047" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="d-link dir-605 - information disclosure high identify critical remote vulnerabilities an informtion disclosure issue exists in d-link-dir-605 b2 firmware version - 2.01mt. an attacker can obtain a user name and password by forging a post request to the / getcfg.php page cve-2021-40655 dhiyaneshdk cve cve2021 dir-605 dlink info-leak kev vkev vuln cwe-863" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">D-Link DIR-605 - Information Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2021/CVE-2021-40655.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2021-40655.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 4, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/863.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-863</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2021-40655" target="_blank" rel="noopener" class="nt-cve-link">CVE-2021-40655</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)l_tb&gt;DIR-605&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An informtion disclosure issue exists in D-LINK-DIR-605 B2 Firmware Version - 2.01MT. An attacker can obtain a user name and password by forging a post request to the / getcfg.php page</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can obtain router credentials including usernames and passwords by exploiting information disclosure in the getcfg.php endpoint.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply firmware updates provided by D-Link or replace the device with a supported model.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2021</span><span class="nt-tag">dir-605</span><span class="nt-tag">dlink</span><span class="nt-tag">info-leak</span><span class="nt-tag">kev</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/cve-2021-40655" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/Ilovewomen/D-LINK-DIR-605/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="d-link dir-615 - unauthorized access critical identify critical remote vulnerabilities d-link dir-615 devices with firmware 20.06 are susceptible to unauthorized access. an attacker can access the wan configuration page wan.htm without authentication, which can lead to disclosure of wan settings, data modification, and/or other unauthorized operations. cve-2021-42627 for3stco1d cve cve2021 d-link dir-615 dlink roteador router unauth vuln" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">D-Link DIR-615 - Unauthorized Access</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2021/CVE-2021-42627.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2021-42627.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> For3stCo1d</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2021-42627" target="_blank" rel="noopener" class="nt-cve-link">CVE-2021-42627</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Roteador Wireless&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">D-Link DIR-615 devices with firmware 20.06 are susceptible to unauthorized access. An attacker can access the WAN configuration page wan.htm without authentication, which can lead to disclosure of WAN settings, data modification, and/or other unauthorized operations.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability can lead to unauthorized access to the router, potentially compromising the network and exposing sensitive information.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest firmware update provided by D-Link to fix the vulnerability and ensure strong and unique passwords are set for router administration.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2021</span><span class="nt-tag">d-link</span><span class="nt-tag">dir-615</span><span class="nt-tag">dlink</span><span class="nt-tag">roteador</span><span class="nt-tag">router</span><span class="nt-tag">unauth</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/sanjokkarki/D-Link-DIR-615/blob/main/CVE-2021-42627" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.dlink.com/en/security-bulletin/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2021-42627" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="http://d-link.com" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="http://dlink.com" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="d-link dir-803 - authentication bypass high identify critical remote vulnerabilities an authentication bypass vulnerability exists in d-link dir-803 routers (firmware a1 1.04 and earlier). by manipulating the authorized_group parameter in /getcfg.php via newline injection, an attacker can retrieve xml configuration containing administrator credentials without authentication. cve-2025-14528 dhiyaneshdk auth-bypass cve cve2025 d-link dir disclosure vkev cwe-200" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">D-Link DIR-803 - Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-14528.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-14528.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 10, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-14528" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-14528</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">asset[&#34;hw_vendor&#34;] == &#34;D-Link&#34; &amp;&amp; asset[&#34;hw_product&#34;] matches &#34;(?i)DIR-803&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An authentication bypass vulnerability exists in D-Link DIR-803 routers (firmware A1 1.04 and earlier). By manipulating the AUTHORIZED_GROUP parameter in /getcfg.php via newline injection, an attacker can retrieve XML configuration containing administrator credentials without authentication.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Remote attackers can disclose sensitive information, potentially compromising device confidentiality.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to the latest supported version or replace the device as it is no longer maintained.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">d-link</span><span class="nt-tag">dir</span><span class="nt-tag">disclosure</span><span class="nt-tag">vkev</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/Madgeaaaaa/MY_VULN_2/blob/main/D-Link/vuln-2/DIR-803%20Authentication%20Bypass.md" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://vuldb.com/?id.335869" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-14528" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="d-link dir-816l - improper access control high identify critical remote vulnerabilities d-link dir-816l_fw206b01 is susceptible to improper access control. an attacker can access folders folder_view.php and category_view.php and thereby possibly obtain sensitive information, modify data, and/or execute unauthorized operations. cve-2022-28955 arafatansari cve cve2022 dlink exposure vuln cwe-287" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">D-Link DIR-816L - Improper Access Control</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-28955.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-28955.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> arafatansari</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/287.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-287</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-28955" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-28955</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)dir-816l&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">D-Link DIR-816L_FW206b01 is susceptible to improper access control. An attacker can access folders folder_view.php and category_view.php and thereby possibly obtain sensitive information, modify data, and/or execute unauthorized operations.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability can lead to unauthorized access to sensitive information or control of the affected router.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest firmware update provided by D-Link to fix the access control issue.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">dlink</span><span class="nt-tag">exposure</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/shijin0925/IOT/blob/master/DIR816/1.md" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.dlink.com/en/security-bulletin/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-28955" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/ARPSyndicate/cvemon" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/ARPSyndicate/kenzer-templates" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="d-link dir-859 - information disclosure critical identify critical remote vulnerabilities a critical information disclosure vulnerability exists in d-link devices where sensitive device account information including credentials can be retrieved by sending an unauthenticated request to `/getcfg.php` endpoint with the parameter `services=device.account`. this could allow attackers to obtain administrative credentials and gain full control of the affected device. cve-2024-57045 ritikchaddha cve cve2024 disclosure dlink unauth vuln cwe-200" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">D-Link DIR-859 - Information Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-57045.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-57045.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 11, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-57045" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-57045</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)D-Link&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A critical information disclosure vulnerability exists in D-Link devices where sensitive device account information including credentials can be retrieved by sending an unauthenticated request to `/getcfg.php` endpoint with the parameter `SERVICES=DEVICE.ACCOUNT`. This could allow attackers to obtain administrative credentials and gain full control of the affected device.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can retrieve administrative credentials and sensitive device account information, enabling full device compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update D-Link DIR-859 router to the latest firmware version that addresses CVE-2024-57045 as specified in D-Link&#39;s security bulletin.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">disclosure</span><span class="nt-tag">dlink</span><span class="nt-tag">unauth</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.dlink.com/en/security-bulletin" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-57045" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="d-link dns-320 - remote code execution critical identify critical remote vulnerabilities the login_mgr.cgi script in d-link dns-320 through 2.05.b10 is vulnerable to remote command injection. cve-2019-16057 dhiyaneshdk cve cve2019 dlink kev lfi rce sharecenter vkev vuln cwe-78" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">D-Link DNS-320 - Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2019/CVE-2019-16057.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2019-16057.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 4, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/78.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-78</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2019-16057" target="_blank" rel="noopener" class="nt-cve-link">CVE-2019-16057</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)sharecenter&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The login_mgr.cgi script in D-Link DNS-320 through 2.05.B10 is vulnerable to remote command injection.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability can lead to unauthorized access, data loss, and potential compromise of the affected device.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest firmware update provided by D-Link to mitigate this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2019</span><span class="nt-tag">dlink</span><span class="nt-tag">kev</span><span class="nt-tag">lfi</span><span class="nt-tag">rce</span><span class="nt-tag">sharecenter</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2019-16057" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://web.archive.org/web/20201222035258im_/https://blog.cystack.net/content/images/2019/09/poc.png" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.ftc.gov/system/files/documents/cases/dlink_proposed_order_and_judgment_7-2-19.pdf" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/Ostorlab/known_exploited_vulnerbilities_detectors" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/Z0fhack/Goby_POC" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="d-link dsl-2750b devices command injection vulnerability critical identify critical remote vulnerabilities d-link dsl-2750b devices before 1.05 allow remote unauthenticated command injection via the
login.cgi cli parameter. cve-2016-20017 n3integration cve cve2016 kev vuln passive cwe-77" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">D-Link DSL-2750B Devices Command Injection Vulnerability</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2016/CVE-2016-20017.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2016-20017.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> n3integration</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 14, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/77.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-77</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2016-20017" target="_blank" rel="noopener" class="nt-cve-link">CVE-2016-20017</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">asset[&#34;hw_vendor&#34;] == &#34;D-Link&#34; &amp;&amp; asset[&#34;hw_product&#34;] matches &#34;(?i)DSL-2750B&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">D-Link DSL-2750B devices before 1.05 allow remote unauthenticated command injection via the
login.cgi cli parameter.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2016</span><span class="nt-tag">kev</span><span class="nt-tag">vuln</span><span class="nt-tag">passive</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://seclists.org/fulldisclosure/2016/Feb/53" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10088" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-20017" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="d-link nas - command injection via group parameter critical identify critical remote vulnerabilities a vulnerability was found in d-link dns-320, dns-320lw, dns-325 and dns-340l up to 20241028. it has been rated as critical. affected by this issue is the function cgi_user_add of the file /cgi-bin/account_mgr.cgi?cmd=cgi_user_add. the manipulation of the argument group leads to os command injection. cve-2024-10915 s4e-io cve cve2024 dlink rce sharecenter vkev vuln cwe-707,cwe-78" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">D-Link NAS - Command Injection via Group Parameter</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-10915.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-10915.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> s4e-io</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 12, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/707,CWE-78.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-707,CWE-78</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-10915" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-10915</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)sharecenter&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A vulnerability was found in D-Link DNS-320, DNS-320LW, DNS-325 and DNS-340L up to 20241028. It has been rated as critical. Affected by this issue is the function cgi_user_add of the file /cgi-bin/account_mgr.cgi?cmd=cgi_user_add. The manipulation of the argument group leads to os command injection.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can execute arbitrary OS commands via the group parameter, potentially compromising the entire D-Link NAS device.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update D-Link DNS-320, DNS-320LW, DNS-325, and DNS-340L firmware to versions released after 20241028.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">dlink</span><span class="nt-tag">rce</span><span class="nt-tag">sharecenter</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.usom.gov.tr/bildirim/tr-24-1836" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://netsecfish.notion.site/Command-Injection-Vulnerability-in-group-parameter-for-D-Link-NAS-12d6b683e67c803fa1a0c0d236c9a4c5?pvs=4" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-10915" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="d-link nas - command injection via name parameter critical identify critical remote vulnerabilities a vulnerability was found in d-link dns-320, dns-320lw, dns-325 and dns-340l up to 20241028. it has been declared as critical. affected by this vulnerability is the function cgi_user_add of the file /cgi-bin/account_mgr.cgi?cmd=cgi_user_add. the manipulation of the argument name leads to os command injection. cve-2024-10914 s4e-io cve cve2024 dlink rce sharecenter vkev vuln cwe-707" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">D-Link NAS - Command Injection via Name Parameter</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-10914.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-10914.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> s4e-io</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 12, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/707.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-707</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-10914" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-10914</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)sharecenter&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A vulnerability was found in D-Link DNS-320, DNS-320LW, DNS-325 and DNS-340L up to 20241028. It has been declared as critical. Affected by this vulnerability is the function cgi_user_add of the file /cgi-bin/account_mgr.cgi?cmd=cgi_user_add. The manipulation of the argument name leads to os command injection.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can execute arbitrary OS commands via the name parameter, potentially compromising the entire D-Link NAS device.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update D-Link DNS-320, DNS-320LW, DNS-325, and DNS-340L firmware to versions released after 20241028.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">dlink</span><span class="nt-tag">rce</span><span class="nt-tag">sharecenter</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/verylazytech/CVE-2024-10914" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.usom.gov.tr/bildirim/tr-24-1836" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-10914" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="d-link nas `sc_mgr.cgi` - remote code execution critical identify critical remote vulnerabilities the d-link nas interface sc_mgr.cgi contains a command execution vulnerability that allows attackers to execute arbitrary commands on the device, potentially leading to unauthorized access or control over the system. adeljck dlink nas rce vuln cwe-78" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">D-Link NAS `sc_mgr.cgi` - Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/vulnerabilities/dlink/dlink-nas-rce.yaml" target="_blank" rel="noopener" class="nt-source-link">dlink-nas-rce.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> adeljck</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 4, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/78.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-78</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/cgi-bin/login_mgr\\.cgi&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The D-Link NAS interface sc_mgr.cgi contains a command execution vulnerability that allows attackers to execute arbitrary commands on the device, potentially leading to unauthorized access or control over the system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">To remediate this vulnerability, ensure that the device firmware is updated to the latest version provided by the manufacturer. Additionally, consider implementing network segmentation and firewall rules to restrict unauthorized access to the device.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">dlink</span><span class="nt-tag">nas</span><span class="nt-tag">rce</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="d-link network attached storage - backdoor account critical identify critical remote vulnerabilities a vulnerability, which was classified as very critical, has been found in d-link dns-320l, dns-325, dns-327l and dns-340l up to 20240403. this issue affects some unknown processing of the file /cgi-bin/nas_sharing.cgi of the component http get request handler. the manipulation of the argument user with the input messagebus leads to hard-coded credentials. cve-2024-3272 ritikchaddha cve cve2024 dlink kev nas vkev vuln cwe-77" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">D-Link Network Attached Storage - Backdoor Account</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-3272.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-3272.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 19, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/77.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-77</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-3272" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-3272</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] contains `In order to access the ShareCenter` || service[&#34;last.http.body&#34;] contains `In order to access the ShareCenter`</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A vulnerability, which was classified as very critical, has been found in D-Link DNS-320L, DNS-325, DNS-327L and DNS-340L up to 20240403. This issue affects some unknown processing of the file /cgi-bin/nas_sharing.cgi of the component HTTP GET Request Handler. The manipulation of the argument user with the input messagebus leads to hard-coded credentials.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can use hardcoded credentials to gain unauthorized access to D-Link NAS devices and execute commands.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update D-Link NAS firmware to a version that removes the backdoor account.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">dlink</span><span class="nt-tag">kev</span><span class="nt-tag">nas</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/netsecfish/dlink" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/cve-2024-3272" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="d-link network attached storage - command injection and backdoor account critical identify critical remote vulnerabilities unsupported when assigned ** a vulnerability, which was classified as critical, was found in d-link dns-320l, dns-325, dns-327l and dns-340l up to 20240403. affected is an unknown function of the file /cgi-bin/nas_sharing.cgi of the component http get request handler. the manipulation of the argument system leads to command injection. it is possible to launch the attack remotely. the exploit has been disclosed to the public and may be used. the identifier of this vulnerability is vdb-259284. note: this vulnerability only affects products that are no longer supported by the maintainer. note: vendor was contacted early and confirmed immediately that the product is end-of-life. it should be retired and replaced. cve-2024-3273 pussycat0x cve cve2024 dlink kev nas vkev vuln cwe-77" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">D-Link Network Attached Storage - Command Injection and Backdoor Account</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-3273.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-3273.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 9, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/77.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-77</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-3273" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-3273</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] contains `In order to access the ShareCenter` || service[&#34;last.http.body&#34;] contains `In order to access the ShareCenter`</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in D-Link DNS-320L, DNS-325, DNS-327L and DNS-340L up to 20240403. Affected is an unknown function of the file /cgi-bin/nas_sharing.cgi of the component HTTP GET Request Handler. The manipulation of the argument system leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-259284. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can execute arbitrary commands on D-Link NAS devices using hardcoded credentials and command injection.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Retire and replace the affected D-Link NAS devices as they are end-of-life and no longer supported.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">dlink</span><span class="nt-tag">kev</span><span class="nt-tag">nas</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/netsecfish/dlink" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.bleepingcomputer.com/news/security/over-92-000-exposed-d-link-nas-devices-have-a-backdoor-account/#google_vignette" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://news.ycombinator.com/item?id=39960107" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10383" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://vuldb.com/?ctiid.259284" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="d-link routers - remote code execution critical identify critical remote vulnerabilities d-link products such as dir-655c, dir-866l, dir-652, and dhp-1565 contain an unauthenticated remote code execution vulnerability. the issue occurs when the attacker sends an arbitrary input to a &#34;pingtest&#34; device common gateway interface that could lead to common injection. an attacker who successfully triggers the command injection could achieve full system compromise. later, it was independently found that these issues also affected; dir-855l, dap-1533, dir-862l, dir-615, dir-835, and dir-825. cve-2019-16920 dwisiswant0 cve cve2019 dlink kev rce router unauth vkev vuln cwe-78" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">D-Link Routers - Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2019/CVE-2019-16920.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2019-16920.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dwisiswant0</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/78.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-78</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2019-16920" target="_blank" rel="noopener" class="nt-cve-link">CVE-2019-16920</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;968533676&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565 contain an unauthenticated remote code execution vulnerability. The issue occurs when the attacker sends an arbitrary input to a &#34;PingTest&#34; device common gateway interface that could lead to common injection. An attacker who successfully triggers the command injection could achieve full system compromise. Later, it was independently found that these issues also affected; DIR-855L, DAP-1533, DIR-862L, DIR-615, DIR-835, and DIR-825.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability allows an attacker to execute arbitrary code on the affected router, potentially leading to complete compromise of the device and the network it is connected to.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest firmware update provided by D-Link to mitigate this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2019</span><span class="nt-tag">dlink</span><span class="nt-tag">kev</span><span class="nt-tag">rce</span><span class="nt-tag">router</span><span class="nt-tag">unauth</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2019-16920" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/pwnhacker0x18/CVE-2019-16920-MassPwn3r" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://fortiguard.com/zeroday/FG-VD-19-117" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://www.seebug.org/vuldb/ssvid-98079" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://medium.com/@80vul/determine-the-device-model-affected-by-cve-2019-16920-by-zoomeye-bf6fec7f9bb3" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="daenetip4 meto v1.25 - session hijacking high identify critical remote vulnerabilities daenetip4 meto v1.25 contains improper session management in the /login_ok.htm endpoint, letting attackers hijack sessions, exploit requires attacker to control or intercept session tokens. cve-2025-28242 0x_akoko cve cve2025 daenetip4 denkovi iot session-hijacking cwe-384" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">DAEnetIP4 METO v1.25 - Session Hijacking</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-28242.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-28242.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_Akoko</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 27, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/384.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-384</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-28242" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-28242</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)DAEnetIP4&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">DAEnetIP4 METO v1.25 contains improper session management in the /login_ok.htm endpoint, letting attackers hijack sessions, exploit requires attacker to control or intercept session tokens.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can hijack user sessions, gaining unauthorized access to user accounts and sensitive information.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Implement proper session management and secure session tokens, and update to the latest version if available.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">daenetip4</span><span class="nt-tag">denkovi</span><span class="nt-tag">iot</span><span class="nt-tag">session-hijacking</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/shiky8/my--cve-vulnerability-research/tree/main/CVE-2025-28242" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-28242" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="datagerry - improper access control high identify critical remote vulnerabilities the /rest/rights/ rest api endpoint in becon datagerry through 2.2.0 contains an incorrect access control vulnerability. an attacker can remotely access this endpoint without authentication, leading to unauthorized disclosure of sensitive information. cve-2024-50967 s4e-io,0xbytehunter auth-bypass cve cve2024 datagerry vkev vuln cwe-200" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">DATAGERRY - Improper Access Control</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-50967.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-50967.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> s4e-io,0xByteHunter</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 1, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-50967" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-50967</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)datagerry&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The /rest/rights/ REST API endpoint in Becon DATAGerry through 2.2.0 contains an Incorrect Access Control vulnerability. An attacker can remotely access this endpoint without authentication, leading to unauthorized disclosure of sensitive information.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can exploit this vulnerability to compromise system security and integrity.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches and updates to address this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">datagerry</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://medium.com/@0xbytehunter/my-first-cve-discovery-of-broken-access-control-in-the-datagerry-platform-7b0404f88a43" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/0xByteHunter/CVE-2024-50967" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-50967" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="datagerry - rest api auth bypass critical identify critical remote vulnerabilities incorrect access control in becn datagerry v2.2 allows attackers to execute arbitrary commands via crafted web requests. cve-2024-46627 gy741 auth-bypass becon cve cve2024 datagerry unauth vuln cwe-284" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">DATAGERRY - REST API Auth Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-46627.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-46627.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> gy741</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 30, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/284.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-284</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-46627" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-46627</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)datagerry&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Incorrect access control in BECN DATAGERRY v2.2 allows attackers to execute arbitrary commands via crafted web requests.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Allows unauthorized access to REST API</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches and updates from the vendor to address this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">becon</span><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">datagerry</span><span class="nt-tag">unauth</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-46627" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://daly.wtf/cve-2024-46627-incorrect-access-control-in-becn-datagerry-v2-2-allows-attackers-to-execute-arbitrary-commands-via-crafted-web-requests/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://datagerry.com/" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/DATAGerry/" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/d4lyw/CVE-2024-46627" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="dell idrac9 - default login high identify default logins in web-based control panels dell idrac9 default login credentials was discovered. kophjager007,milo2012 dell idrac default-login vuln cwe-798" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">DELL iDRAC9 - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/dell/dell-idrac9-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">dell-idrac9-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> kophjager007,milo2012</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/798.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-798</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;Integrated (?:Dell )?Remote Access Controller&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">DELL iDRAC9 default login credentials was discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">dell</span><span class="nt-tag">idrac</span><span class="nt-tag">default-login</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.dell.com/support/kbdoc/en-us/000177787/how-to-change-the-default-login-password-of-the-idrac-9" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="dplus dashboard panel - detect info identify web-based control panels dplus dashboard panel was detected. tess panel dplus exposure discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">DPLUS Dashboard Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/dplus-dashboard.yaml" target="_blank" rel="noopener" class="nt-source-link">dplus-dashboard.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> tess</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)DPLUS Dashboard&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">DPLUS Dashboard panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">dplus</span><span class="nt-tag">exposure</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="dqs superadmin login panel - detect info identify web-based control panels dqs superadmin login panel was detected. hardik-solanki panel dqs superadmin discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">DQS Superadmin Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/dqs-superadmin-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">dqs-superadmin-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Hardik-Solanki</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)DQS Superadmin&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">DQS Superadmin login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">dqs</span><span class="nt-tag">superadmin</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="dvwa default login critical identify default logins in web-based control panels damn vulnerable web app (dvwa) is a test application for security professionals. the hard coded credentials are part of a security testing scenario. pdteam default-login dvwa vuln cwe-798" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">DVWA Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/dvwa/dvwa-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">dvwa-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pdteam</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/798.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-798</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;Login :: Damn Vulnerable Web Application&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Damn Vulnerable Web App (DVWA) is a test application for security professionals. The hard coded credentials are part of a security testing scenario.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">dvwa</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://opensourcelibs.com/lib/dvwa" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="dahua ipc/vth/vto - authentication bypass critical identify critical remote vulnerabilities some dahua products contain an authentication bypass during the login process. attackers can bypass device identity authentication by constructing malicious data packets. cve-2021-33044 gy741 auth-bypass cve cve2021 dahua dahuasecurity kev seclists vkev vuln cwe-287" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Dahua IPC/VTH/VTO - Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2021/CVE-2021-33044.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2021-33044.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> gy741</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/287.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-287</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2021-33044" target="_blank" rel="noopener" class="nt-cve-link">CVE-2021-33044</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">asset[&#34;hw_vendor&#34;] == &#34;Dahua&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Some Dahua products contain an authentication bypass during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can gain unauthorized access to the device, potentially compromising the security and privacy of the system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest firmware update provided by Dahua to fix the authentication bypass vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2021</span><span class="nt-tag">dahua</span><span class="nt-tag">dahuasecurity</span><span class="nt-tag">kev</span><span class="nt-tag">seclists</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/dorkerdevil/CVE-2021-33044" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2021-33044" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://seclists.org/fulldisclosure/2021/Oct/13" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://www.dahuasecurity.com/support/cybersecurity/details/957" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/bp2008/DahuaLoginBypass" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="dahua ipc/vth/vto - authentication bypass critical identify critical remote vulnerabilities the identity authentication bypass vulnerability found in some dahua products during the login process. attackers can bypass device identity authentication by constructing malicious data packets. cve-2021-33045 phantomowl auth-bypass cve cve2021 dahua kev seclists vkev vuln cwe-287" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Dahua IPC/VTH/VTO - Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2021/CVE-2021-33045.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2021-33045.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> phantomowl</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 10, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/287.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-287</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2021-33045" target="_blank" rel="noopener" class="nt-cve-link">CVE-2021-33045</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">asset[&#34;hw_vendor&#34;] == &#34;Dahua&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can bypass device authentication by constructing malicious login packets, gaining full administrative access to Dahua IPC/VTH/VTO devices.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply firmware updates provided by Dahua to address the authentication bypass vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2021</span><span class="nt-tag">dahua</span><span class="nt-tag">kev</span><span class="nt-tag">seclists</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://seclists.org/fulldisclosure/2021/Oct/13" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.dahuasecurity.com/aboutUs/trustedCenter/details/582" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="dahua security - configuration file disclosure critical identify critical remote vulnerabilities a password in configuration file issue was discovered in dahua dh-ipc-hdbw23a0rn-zs, dh-ipc-hdbw13a0sn, dh-ipc-hdw1xxx, dh-ipc-hdw2xxx, dh-ipc-hdw4xxx, dh-ipc-hfw1xxx, dh-ipc-hfw2xxx, dh-ipc-hfw4xxx, dh-sd6cxx, dh-nvr1xxx, dh-hcvr4xxx, dh-hcvr5xxx, dhi-hcvr51a04he-s3, dhi-hcvr51a08he-s3, and dhi-hcvr58a32s-s2 devices. the password in configuration file vulnerability was identified, which could lead to a malicious user assuming the identity of a privileged user and gaining access to sensitive information. cve-2017-7925 e1a,none camera cve cve2017 dahua dahuasecurity vuln cwe-260,cwe-522" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Dahua Security - Configuration File Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2017/CVE-2017-7925.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2017-7925.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> E1A,none</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 13, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/260,CWE-522.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-260,CWE-522</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2017-7925" target="_blank" rel="noopener" class="nt-cve-link">CVE-2017-7925</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;2019488876&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A Password in Configuration File issue was discovered in Dahua DH-IPC-HDBW23A0RN-ZS, DH-IPC-HDBW13A0SN, DH-IPC-HDW1XXX, DH-IPC-HDW2XXX, DH-IPC-HDW4XXX, DH-IPC-HFW1XXX, DH-IPC-HFW2XXX, DH-IPC-HFW4XXX, DH-SD6CXX, DH-NVR1XXX, DH-HCVR4XXX, DH-HCVR5XXX, DHI-HCVR51A04HE-S3, DHI-HCVR51A08HE-S3, and DHI-HCVR58A32S-S2 devices. The password in configuration file vulnerability was identified, which could lead to a malicious user assuming the identity of a privileged user and gaining access to sensitive information.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">This vulnerability can lead to unauthorized access to sensitive information, potentially compromising the security of the system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">To remediate this vulnerability, ensure that the configuration file is properly secured and access to it is restricted to authorized personnel only.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">camera</span><span class="nt-tag">cve</span><span class="nt-tag">cve2017</span><span class="nt-tag">dahua</span><span class="nt-tag">dahuasecurity</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2017-7925" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://ics-cert.us-cert.gov/advisories/ICSA-17-124-02" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="http://us.dahuasecurity.com/en/us/Security-Bulletin_030617.php" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="dahua web service panel - detect info identify web-based control panels a dahua admin login panel was detected. dhiyaneshdk,rxerium dahua detect discovery edb panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Dahua Web Service Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/dahua-web-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">dahua-web-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDK,rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 13, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1653394551&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A Dahua admin login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">dahua</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">edb</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.exploit-db.com/ghdb/7116" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="danswer - insecure direct object reference medium identify critical remote vulnerabilities the application does not verify whether the attacker is the creator of the file, allowing the attacker to directly call the get /api/chat/file/{file_id} interface to view any user&#39;s file. cve-2024-9617 s4e-io cve cve2024 danswer idor vuln cwe-284" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Danswer - Insecure Direct Object Reference</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-9617.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-9617.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> s4e-io</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 22, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/284.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-284</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-9617" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-9617</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;484766002&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The application does not verify whether the attacker is the creator of the file, allowing the attacker to directly call the GET /api/chat/file/{file_id} interface to view any user&#39;s file.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Authenticated attackers can access and view files belonging to other users without proper authorization checks through insecure direct object references, leading to unauthorized disclosure of sensitive chat files and data.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update Danswer to a version that implements proper authorization checks to verify file ownership before allowing access through the GET /api/chat/file/{file_id} and GET /api/chat/get-chat-session endpoints.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">danswer</span><span class="nt-tag">idor</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://huntr.com/bounties/8f683ff6-3a99-41c6-b763-a8f7b73bd146" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/danswer-ai/danswer" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="dapr dashboard 0.1.0-0.10.0 - improper access control high identify critical remote vulnerabilities dapr dashboard 0.1.0 through 0.10.0 is susceptible to improper access control. an attacker can possibly obtain sensitive information, modify data, and/or execute unauthorized operations. cve-2022-38817 for3stco1d cve cve2022 dapr dashboard linuxfoundation unauth vuln cwe-306" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Dapr Dashboard 0.1.0-0.10.0 - Improper Access Control</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-38817.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-38817.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> For3stCo1d</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/306.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-306</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-38817" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-38817</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)dapr dashboard&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Dapr Dashboard 0.1.0 through 0.10.0 is susceptible to improper access control. An attacker can possibly obtain sensitive information, modify data, and/or execute unauthorized operations.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">The vulnerability allows unauthorized access to the Dapr Dashboard, potentially leading to unauthorized actions and data exposure.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade Dapr Dashboard to a version that includes the fix for CVE-2022-38817 or apply the necessary patches provided by the vendor.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">dapr</span><span class="nt-tag">dashboard</span><span class="nt-tag">linuxfoundation</span><span class="nt-tag">unauth</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/dapr/dashboard/issues/222" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-38817" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/dapr/dashboard" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-38817" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/Miraitowa70/POC-Notes" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="darktrace threat visualizer login panel - detect info identify web-based control panels darktrace threat visualizer login panel was detected. dhiyaneshdk darktrace discovery panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Darktrace Threat Visualizer Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/darktrace-threat-visualizer.yaml" target="_blank" rel="noopener" class="nt-source-link">darktrace-threat-visualizer.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)darktrace threat visualizer&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Darktrace Threat Visualizer login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">darktrace</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="dashy panel - detect info identify web-based control panels  ritikchaddha dashy detect discovery panel" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Dashy Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/dashy-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">dashy-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 9, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-1013024216&#34;</code></div>
  <div class="nt-tags"><span class="nt-tag">dashy</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://dashy.to/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="dassault systèmes delmia apriso (up to 2025) - insecure deserialization critical identify critical remote vulnerabilities a deserialization of untrusted data vulnerability affecting delmia apriso from release 2020 through release 2025 could lead to a remote code execution. cve-2025-5086 hacktronai,iamnoooob,pdresearch apriso cve cve2025 delmia kev rce serialization vkev vuln cwe-502" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Dassault Systèmes DELMIA Apriso (up to 2025) - Insecure Deserialization</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-5086.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-5086.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> hacktronai,iamnoooob,pdresearch</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 4, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/502.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-502</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-5086" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-5086</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)apriso&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A deserialization of untrusted data vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could lead to a remote code execution.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can exploit unsafe deserialization to execute arbitrary code on DELMIA Apriso servers, achieving complete system compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade DELMIA Apriso to a version later than Release 2025 that properly validates deserialized data.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">apriso</span><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">delmia</span><span class="nt-tag">kev</span><span class="nt-tag">rce</span><span class="nt-tag">serialization</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.hacktron.ai/blog/posts/dassault-delmia-apriso-rce/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.3ds.com/vulnerability/advisories" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="dataease 2.10.4-2.10.7 - remote code execution critical identify critical remote vulnerabilities dataease prior to version 2.10.8 contains a remote code execution caused by insecure backend jdbc link handling, letting authenticated users execute arbitrary code, exploit requires user authentication. cve-2025-32966 chrisjr404 cve cve2025 dataease h2 jdbc oss rce cwe-94" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">DataEase 2.10.4-2.10.7 - Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-32966.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-32966.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ChrisJr404</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 6, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/94.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-94</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-32966" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-32966</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)dataease&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">DataEase prior to version 2.10.8 contains a remote code execution caused by insecure backend JDBC link handling, letting authenticated users execute arbitrary code, exploit requires user authentication.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Authenticated users can execute arbitrary code on the server, potentially leading to full system compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to version 2.10.8 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">dataease</span><span class="nt-tag">h2</span><span class="nt-tag">jdbc</span><span class="nt-tag">oss</span><span class="nt-tag">rce</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/dataease/dataease/security/advisories/GHSA-h7hj-4j78-cvc7" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/dataease/dataease/security/advisories/GHSA-xx2m-gmwg-mf3r" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/vulhub/vulhub/tree/master/dataease/CVE-2025-32966" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="dataease &lt; 2.10.10 - jwt authentication bypass critical identify critical remote vulnerabilities dataease &lt; 2.10.10 contains a broken authentication caused by ineffective secret verification, letting users forge jwt tokens, exploit requires no special privileges. cve-2025-49001 yunseojo,aryu-ru auth-bypass cve cve2025 dataease jwt unauth cwe-287" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">DataEase &lt; 2.10.10 - JWT Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-49001.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-49001.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> YunSeoJo,aryu-ru</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 4, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/287.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-287</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-49001" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-49001</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;^DataEase&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">DataEase &lt; 2.10.10 contains a broken authentication caused by ineffective secret verification, letting users forge JWT tokens, exploit requires no special privileges.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Users can forge JWT tokens, potentially gaining unauthorized access to the system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to version 2.10.10 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">dataease</span><span class="nt-tag">jwt</span><span class="nt-tag">unauth</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/dataease/dataease/security/advisories/GHSA-xx2m-gmwg-mf3r" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/dataease/dataease" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-49001" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="dataease &lt;= 2.4.1 - sensitive information exposure medium identify critical remote vulnerabilities dataease, an open source data visualization and analysis tool, has a database configuration information exposure vulnerability prior to version 2.5.0. visiting the `/de2api/engine/getengine;.js` path via a browser reveals that the platform&#39;s database configuration is returned. cve-2024-30269 s4e-io cve cve2024 dataease exposure vkev vuln cwe-200" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">DataEase &lt;= 2.4.1 - Sensitive Information Exposure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-30269.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-30269.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> s4e-io</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 26, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-30269" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-30269</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)dataease&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">DataEase, an open source data visualization and analysis tool, has a database configuration information exposure vulnerability prior to version 2.5.0. Visiting the `/de2api/engine/getEngine;.js` path via a browser reveals that the platform&#39;s database configuration is returned.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can access sensitive configuration and credential information from the DataEase system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update DataEase to version 2.5.0 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">dataease</span><span class="nt-tag">exposure</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-30269" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/dataease/dataease/security/advisories/GHSA-8gvx-4qvj-6vv5" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/dataease/dataease" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="dataease v2.10.2 - jwt signature verification bypass critical identify critical remote vulnerabilities dataease is an open source data visualization analysis tool that helps users quickly analyze data and gain insights into business trends. in affected versions, the lack of signature verification of jwt tokens allows attackers to forge jwts, which then allow access to any interface. the vulnerability has been fixed in v2.10.2 and all users are advised to upgrade. there are no known workarounds for this vulnerability. cve-2024-47073 iamnoooob,pdresearch cve cve2024 dataease jwt vuln cwe-347" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">DataEase v2.10.2 - JWT Signature Verification Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-47073.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-47073.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> iamnoooob,pdresearch</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 12, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/347.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-347</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-47073" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-47073</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)dataease&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">DataEase is an open source data visualization analysis tool that helps users quickly analyze data and gain insights into business trends. In affected versions, the lack of signature verification of JWT tokens allows attackers to forge JWTs, which then allow access to any interface. The vulnerability has been fixed in v2.10.2 and all users are advised to upgrade. There are no known workarounds for this vulnerability.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can forge JWT tokens to bypass authentication and gain unauthorized access to any interface.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update DataEase to version 2.10.2 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">dataease</span><span class="nt-tag">jwt</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47073" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="datahub metadata - default login high identify default logins in web-based control panels datahub metadata contains a default login vulnerability.  an attacker can obtain access to user accounts and access sensitive information, modify data, and/or execute unauthorized operations. queencitycyber datahub default-login vuln cwe-522" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">DataHub Metadata - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/datahub/datahub-metadata-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">datahub-metadata-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> queencitycyber</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/522.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-522</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;DataHub&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">DataHub Metadata contains a default login vulnerability.  An attacker can obtain access to user accounts and access sensitive information, modify data, and/or execute unauthorized operations.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">datahub</span><span class="nt-tag">default-login</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/datahub-project/datahub/blob/master/docs/rfc/active/access-control/access-control.md" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="datataker dt80 dex 1.50.012 - information disclosure critical identify critical remote vulnerabilities datataker dt80 dex 1.50.012 is susceptible to information disclosure. a remote attacker can obtain sensitive credential and configuration information via a direct request for the /services/getfile.cmd?userfile=config.xml uri, thereby possibly accessing sensitive information, modifying data, and/or executing unauthorized operations. cve-2017-11165 theabhinavgaur config cve cve2017 datataker edb exposure lfr packetstorm vuln cwe-200" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">DataTaker DT80 dEX 1.50.012 - Information Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2017/CVE-2017-11165.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2017-11165.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> theabhinavgaur</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2017-11165" target="_blank" rel="noopener" class="nt-cve-link">CVE-2017-11165</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)datataker&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">DataTaker DT80 dEX 1.50.012 is susceptible to information disclosure. A remote attacker can obtain sensitive credential and configuration information via a direct request for the /services/getFile.cmd?userfile=config.xml URI, thereby possibly accessing sensitive information, modifying data, and/or executing unauthorized operations.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could lead to unauthorized access to sensitive data, potentially compromising the confidentiality of the system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest firmware update provided by the vendor to mitigate the information disclosure vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">config</span><span class="nt-tag">cve</span><span class="nt-tag">cve2017</span><span class="nt-tag">datataker</span><span class="nt-tag">edb</span><span class="nt-tag">exposure</span><span class="nt-tag">lfr</span><span class="nt-tag">packetstorm</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.exploit-db.com/exploits/45094" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://packetstormsecurity.com/files/143328/DataTaker-DT80-dEX-1.50.012-Sensitive-Configuration-Exposure.html" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.exploit-db.com/exploits/42313/" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2017-11165" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/ARPSyndicate/cvemon" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="datadog login panel - detect info identify web-based control panels datadog login panel was detected. dhiyaneshdk panel datadog discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Datadog Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/datadog-login.yaml" target="_blank" rel="noopener" class="nt-source-link">datadog-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Datadog&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Datadog login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">datadog</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="dataease - default login high identify default logins in web-based control panels dataease has a built-in account demo/dataease, and many developers forget to delete or change the account password.
as a result, many dataease can log in with this built-in account. dhiyaneshdk dataease default-login vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Dataease - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/dataease/dataease-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">dataease-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 5, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;Dataease&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Dataease has a built-in account demo/dataease, and many developers forget to delete or change the account password.
As a result, many Dataease can log in with this built-in account.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">dataease</span><span class="nt-tag">default-login</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/dataease/dataease/issues/5995" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="dataease - login panel info identify web-based control panels dataease login panel is discovered dhiyaneshdk dataease discovery login panel" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Dataease - Login Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/dataease-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">dataease-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 5, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)dataease&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Dataease Login Panel is discovered</div></div></div>
  <div class="nt-tags"><span class="nt-tag">dataease</span><span class="nt-tag">discovery</span><span class="nt-tag">login</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/dataease/dataease" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="datagerry - default login high identify default logins in web-based control panels datagerry was using default username and password was discovered. gy741 datagerry default-login vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Datagerry - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/datagerry/datagerry-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">datagerry-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> gy741</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 30, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)datagerry&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Datagerry was using default username and password was discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">datagerry</span><span class="nt-tag">default-login</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="datagerry panel - detect info identify web-based control panels datagerry panel was discovered. s4e-io panel login datagerry detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Datagerry Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/datagerry-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">datagerry-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> s4e-io</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 1, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)datagerry&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Datagerry panel was discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">login</span><span class="nt-tag">datagerry</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://datagerry.com/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="dataiku - default login high identify default logins in web-based control panels dataiku contains a default login vulnerability. an attacker can obtain access to user accounts and access sensitive information, modify data, and/or execute unauthorized operations. this vulnerability may also lead to server-side request forgery and/or remote code execution. random-robbie dataiku default-login vuln cwe-522" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Dataiku - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/dataiku/dataiku-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">dataiku-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> random-robbie</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/522.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-522</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)dataiku&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Dataiku contains a default login vulnerability. An attacker can obtain access to user accounts and access sensitive information, modify data, and/or execute unauthorized operations. This vulnerability may also lead to server-side request forgery and/or remote code execution.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">dataiku</span><span class="nt-tag">default-login</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.dataiku.com" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="dataiku panel - detect info identify web-based control panels dataiku panel was detected. dhiyaneshdk dataiku discovery panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Dataiku Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/dataiku-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">dataiku-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)dataiku&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Dataiku panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">dataiku</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="davantis video analytics panel - detect info identify web-based control panels davantis video analytics panel was detected. robotshell panel davantis discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Davantis Video Analytics Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/davantis-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">davantis-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> robotshell</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Davantis&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Davantis Video Analytics panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">davantis</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="daybydaycrm login panel - detect info identify web-based control panels daybydaycrm login panel was detected. pikpikcu,daffainfo daybyday daybydaycrm discovery panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">DaybydayCRM Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/daybyday-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">daybyday-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pikpikcu,daffainfo</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)daybyday&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">DaybydayCRM login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">daybyday</span><span class="nt-tag">daybydaycrm</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="dbgate web client management - panel detect info identify web-based control panels the dbgate web client management panel is detected on the target system. h0j3n panel dbgate oss discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">DbGate Web Client Management - Panel Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/dbgate-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">dbgate-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> h0j3n</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 18, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1198579728&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The DbGate Web Client Management Panel is detected on the target system.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">dbgate</span><span class="nt-tag">oss</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/dbgate/dbgate" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="debug endpoint pprof - exposure detection high identify critical remote vulnerabilities the debugging endpoint /debug/pprof is exposed over the unauthenticated kubelet healthz port. this debugging endpoint can potentially leak sensitive information such as internal kubelet memory addresses and configuration, or for limited denial of service. versions prior to 1.15.0, 1.14.4, 1.13.8, and 1.12.10 are affected. the issue is of medium severity, but not exposed by the default configuration. cve-2019-11248 0xceeb,ritikchaddha cve cve2019 debug devops disclosure kubelet kubernetes unauth vkev vuln cwe-419,cwe-862" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Debug Endpoint pprof - Exposure Detection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2019/CVE-2019-11248.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2019-11248.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0xceeb,ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/419,CWE-862.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-419,CWE-862</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2019-11248" target="_blank" rel="noopener" class="nt-cve-link">CVE-2019-11248</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)kubernetes web view&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The debugging endpoint /debug/pprof is exposed over the unauthenticated Kubelet healthz port. This debugging endpoint can potentially leak sensitive information such as internal Kubelet memory addresses and configuration, or for limited denial of service. Versions prior to 1.15.0, 1.14.4, 1.13.8, and 1.12.10 are affected. The issue is of medium severity, but not exposed by the default configuration.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can exploit this vulnerability to gather sensitive information, potentially leading to further attacks.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Disable or restrict access to the Debug Endpoint pprof to prevent unauthorized access.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2019</span><span class="nt-tag">debug</span><span class="nt-tag">devops</span><span class="nt-tag">disclosure</span><span class="nt-tag">kubelet</span><span class="nt-tag">kubernetes</span><span class="nt-tag">unauth</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://medium.com/bugbountywriteup/my-first-bug-bounty-21d3203ffdb0" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="http://mmcloughlin.com/posts/your-pprof-is-showing" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/kubernetes/kubernetes/issues/81023" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://groups.google.com/d/msg/kubernetes-security-announce/pKELclHIov8/BEDtRELACQAJ" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2019-11248" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="dede cms - sql injection critical identify critical remote vulnerabilities dede cms contains a sql injection vulnerability which allows remote unauthenticated users to inject arbitrary sql statements via the ajax_membergroup.php endpoint and the membergroup parameter. pikpikcu dedecms sqli vuln cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Dede CMS - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/vulnerabilities/dedecms/dedecms-membergroup-sqli.yaml" target="_blank" rel="noopener" class="nt-source-link">dedecms-membergroup-sqli.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pikpikcu</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)DedeCms&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Dede CMS contains a SQL injection vulnerability which allows remote unauthenticated users to inject arbitrary SQL statements via the ajax_membergroup.php endpoint and the membergroup parameter.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">dedecms</span><span class="nt-tag">sqli</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="http://www.dedeyuan.com/xueyuan/wenti/1244.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="dedecms 5.7 - sql injection critical identify critical remote vulnerabilities dedecms through 5.7 has sql injection via the $_files superglobal to plus/recommend.php. cve-2017-17731 j4vaovo cve cve2017 dedecms sqli vkev vuln cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">DedeCMS 5.7 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2017/CVE-2017-17731.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2017-17731.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> j4vaovo</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 5, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2017-17731" target="_blank" rel="noopener" class="nt-cve-link">CVE-2017-17731</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)dedecms&#34; || service[&#34;http.body&#34;] matches &#34;(?i)power by dedecms\&#34; \\|\\| title:\&#34;dedecms&#34; || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)dedecms\&#34; \\|\\| http\\.html:\&#34;power by dedecms&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">DedeCMS through 5.7 has SQL Injection via the $_FILES superglobal to plus/recommend.php.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized access, data leakage, or data manipulation.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patch or upgrade to a newer version of DedeCMS to mitigate the SQL Injection vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2017</span><span class="nt-tag">dedecms</span><span class="nt-tag">sqli</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-17731" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2017-17731" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://blog.csdn.net/nixawk/article/details/24982851" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/Lucifer1993/AngelSword/blob/232258e42201373fef1f323864366dc1499581fc/cms/dedecms/dedecms_recommend_sqli.py#L25" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/20142995/Goby" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="dedecms 5.7.87 - directory traversal medium identify critical remote vulnerabilities directory traversal vulnerability in dedecms 5.7.87 allows reading sensitive files via the $activepath parameter. cve-2023-2059 pussycat0x cve cve2023 dedecms lfi vkev vuln cwe-28" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">DedeCMS 5.7.87 - Directory Traversal</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-2059.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-2059.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 26, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/28.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-28</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-2059" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-2059</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)dedecms&#34; || service[&#34;http.body&#34;] matches &#34;(?i)power by dedecms\&#34; \\|\\| title:\&#34;dedecms&#34; || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)dedecms\&#34; \\|\\| http\\.html:\&#34;power by dedecms&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Directory traversal vulnerability in DedeCMS 5.7.87 allows reading sensitive files via the $activepath parameter.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can exploit directory traversal through the activepath parameter in select_templets.php to read sensitive DedeCMS configuration files and source code.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update DedeCMS to a version newer than 5.7.87 that properly validates and sanitizes the activepath parameter in select_templets.php.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">dedecms</span><span class="nt-tag">lfi</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/ATZXC-RedTeam/cve/blob/main/dedecms.md" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://vuldb.com/?ctiid.225944" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://vuldb.com/?id.225944" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="dedecms 5.7sp2 - cross-site request forgery/remote code execution high identify critical remote vulnerabilities dedecms 5.7sp2 is susceptible to cross-site request forgery with a corresponding impact of arbitrary code execution because the partcode parameter in a tag_test_action.php request can specify a runphp field in conjunction with php code. cve-2018-7700 pikpikcu cve cve2018 dedecms rce vkev vuln cwe-352" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">DedeCMS 5.7SP2 - Cross-Site Request Forgery/Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2018/CVE-2018-7700.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2018-7700.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pikpikcu</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/352.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-352</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2018-7700" target="_blank" rel="noopener" class="nt-cve-link">CVE-2018-7700</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)dedecms&#34; || service[&#34;http.body&#34;] matches &#34;(?i)power by dedecms\&#34; \\|\\| title:\&#34;dedecms&#34; || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)dedecms\&#34; \\|\\| http\\.html:\&#34;power by dedecms&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">DedeCMS 5.7SP2 is susceptible to cross-site request forgery with a corresponding impact of arbitrary code execution because the partcode parameter in a tag_test_action.php request can specify a runphp field in conjunction with PHP code.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of these vulnerabilities can lead to unauthorized actions performed on behalf of the user and execution of arbitrary code.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches and update to a newer version of DedeCMS.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2018</span><span class="nt-tag">dedecms</span><span class="nt-tag">rce</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://laworigin.github.io/2018/03/07/CVE-2018-7700-dedecms%E5%90%8E%E5%8F%B0%E4%BB%BB%E6%84%8F%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2018-7700" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/0ps/pocassistdb" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/ARPSyndicate/cvemon" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/ARPSyndicate/kenzer-templates" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="deep sea electronics dse 855 generator controller - detect info identify web-based control panels deep sea electronics dse 855 is a generator/mains automatic transfer switch (ats) controller
with a built-in http web server for remote monitoring and configuration of generator control systems.
the interface is commonly exposed on port 8090 and requires no authentication by default. rxerium detect dse energy generator ics panel scada tech" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Deep Sea Electronics DSE 855 Generator Controller - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/deep-sea-electronics-dse855-detect.yaml" target="_blank" rel="noopener" class="nt-source-link">deep-sea-electronics-dse855-detect.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 27, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;DSE 855&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Deep Sea Electronics DSE 855 is a generator/mains automatic transfer switch (ATS) controller
with a built-in HTTP web server for remote monitoring and configuration of generator control systems.
The interface is commonly exposed on port 8090 and requires no authentication by default.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">detect</span><span class="nt-tag">dse</span><span class="nt-tag">energy</span><span class="nt-tag">generator</span><span class="nt-tag">ics</span><span class="nt-tag">panel</span><span class="nt-tag">scada</span><span class="nt-tag">tech</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.deepseaelectronics.com/products/auto-mains-failure-modules/855.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="defectdojo login panel - detect info identify web-based control panels defectdojo login panel was detected. adam crosser defectdojo discovery panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">DefectDojo Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/defectdojo-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">defectdojo-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Adam Crosser</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)DefectDojo Logo&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">DefectDojo login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">defectdojo</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="defender security &lt; 4.1.0 - protection bypass (hidden login page) medium identify critical remote vulnerabilities the defender security wordpress plugin before 4.1.0 does not prevent redirects to the login page via the auth_redirect wordpress function, allowing an unauthenticated visitor to access the login page, even when the hide login page functionality of the plugin is enabled. cve-2023-5089 jpg0mez cve cve2023 defender-security redirect vuln wordpress wp-plugin wpmudev wpscan" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Defender Security &lt; 4.1.0 - Protection Bypass (Hidden Login Page)</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-5089.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-5089.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> jpg0mez</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 1, 2024</span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-5089" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-5089</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/defender-security/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The Defender Security WordPress plugin before 4.1.0 does not prevent redirects to the login page via the auth_redirect WordPress function, allowing an unauthenticated visitor to access the login page, even when the hide login page functionality of the plugin is enabled.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can bypass hidden login page protection through auth_redirect WordPress function to access the login page despite protection mechanisms.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Fixed in 4.1.0</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">defender-security</span><span class="nt-tag">redirect</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">wpmudev</span><span class="nt-tag">wpscan</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.sprocketsecurity.com/resources/discovering-wp-admin-urls-in-wordpress-with-gravityforms" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://wpscan.com/vulnerability/2b547488-187b-44bc-a57d-f876a7d4c87d/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-5089" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="dell bmc panel - detect info identify web-based control panels dell bmc web panel was detected. megamansec panel bmc dell login discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Dell BMC Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/dell-bmc-panel-detect.yaml" target="_blank" rel="noopener" class="nt-source-link">dell-bmc-panel-detect.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> megamansec</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 23, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Dell Remote Management Controller&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Dell BMC web panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">bmc</span><span class="nt-tag">dell</span><span class="nt-tag">login</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="dell emc avamar and integrated data protection appliance installation manager - invalid access control critical identify critical remote vulnerabilities avamar installation manager in dell emc avamar server 7.3.1, 7.4.1, and 7.5.0, and dell emc integrated data protection appliance 2.0 and 2.1, is affected by a missing access control check vulnerability which could potentially allow a remote unauthenticated attacker to read or change the local download service (ldls) credentials. the ldls credentials are used to connect to dell emc online support. if the ldls configuration was changed to an invalid configuration, then avamar installation manager may not be able to connect to dell emc online support web site successfully. the remote unauthenticated attacker can also read and use the credentials to login to dell emc online support, impersonating the avi service actions using those credentials. cve-2018-1217 daffainfo avamar cve cve2018 dell vkev vuln cwe-862" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Dell EMC Avamar and Integrated Data Protection Appliance Installation Manager - Invalid Access Control</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2018/CVE-2018-1217.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2018-1217.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> daffainfo</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 29, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/862.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-862</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2018-1217" target="_blank" rel="noopener" class="nt-cve-link">CVE-2018-1217</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)AVAMAR&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Avamar Installation Manager in Dell EMC Avamar Server 7.3.1, 7.4.1, and 7.5.0, and Dell EMC Integrated Data Protection Appliance 2.0 and 2.1, is affected by a missing access control check vulnerability which could potentially allow a remote unauthenticated attacker to read or change the Local Download Service (LDLS) credentials. The LDLS credentials are used to connect to Dell EMC Online Support. If the LDLS configuration was changed to an invalid configuration, then Avamar Installation Manager may not be able to connect to Dell EMC Online Support web site successfully. The remote unauthenticated attacker can also read and use the credentials to login to Dell EMC Online Support, impersonating the AVI service actions using those credentials.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can read or modify Local Download Service credentials, impersonate the service when accessing Dell EMC Online Support, or prevent legitimate connections by corrupting the configuration.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to a patched version of Dell EMC Avamar or apply vendor-provided security updates.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">avamar</span><span class="nt-tag">cve</span><span class="nt-tag">cve2018</span><span class="nt-tag">dell</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.exploit-db.com/exploits/44441" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1217" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="dell emc recoverpoint panel - detect info identify web-based control panels dell emc recoverpoint management panel was detected. rxerium panel recoverpoint dell emc login discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Dell EMC RecoverPoint Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/recoverpoint-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">recoverpoint-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 18, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-742276344&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Dell EMC RecoverPoint management panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">recoverpoint</span><span class="nt-tag">dell</span><span class="nt-tag">emc</span><span class="nt-tag">login</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.delltechnologies.com/en-us/data-protection/recoverpoint-for-virtual-machines.htm" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="dell idrac panel - detect info identify web-based control panels dell idrac panel was detected. kazet dell detect discovery idrac panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Dell IDRAC Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/dell-idrac.yaml" target="_blank" rel="noopener" class="nt-source-link">dell-idrac.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> kazet</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 21, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)thisIDRACText&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Dell IDRAC panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">dell</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">idrac</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="dell laser printer - unauthenticated detect high identify web-based control panels the dell laser printer web interface was accessible without authentication. pussycat0x dell discovery iot misconfig printer unauth vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Dell Laser Printer - Unauthenticated Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/iot/dell-laser-printer-unauth.yaml" target="_blank" rel="noopener" class="nt-source-link">dell-laser-printer-unauth.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 18, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Laser Printer&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The Dell Laser Printer web interface was accessible without authentication.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">dell</span><span class="nt-tag">discovery</span><span class="nt-tag">iot</span><span class="nt-tag">misconfig</span><span class="nt-tag">printer</span><span class="nt-tag">unauth</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="dell openmanage switch administrator login panel - detect info identify web-based control panels dell openmanage switch administrator login panel was detected. dhiyaneshdk dell discovery panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Dell OpenManage Switch Administrator Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/dell-openmanager-login.yaml" target="_blank" rel="noopener" class="nt-source-link">dell-openmanager-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Dell OpenManage Switch Administrator&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Dell OpenManage Switch Administrator login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">dell</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="dell remote web access panel - detect info identify web-based control panels dell remote web access is a secure web portal that enables remote access to files, applications, and desktops hosted on dell servers. pussycat0x dell remote-web panel login discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Dell Remote Web Access Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/dell-remote-web-access-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">dell-remote-web-access-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 17, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Dell Remote web&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Dell Remote Web Access is a secure web portal that enables remote access to files, applications, and desktops hosted on Dell servers.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">dell</span><span class="nt-tag">remote-web</span><span class="nt-tag">panel</span><span class="nt-tag">login</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="dell idrac6/7/8 default login high identify default logins in web-based control panels dell idrac6/7/8 default login information was discovered. the default idrac username and password are widely known, and any user with access to the server could change the default password. kophjager007,megamansec default-login dell idrac vuln cwe-798" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Dell iDRAC6/7/8 Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/dell/dell-idrac-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">dell-idrac-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> kophjager007,megamansec</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/798.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-798</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;Integrated (?:Dell )?Remote Access Controller&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Dell iDRAC6/7/8 default login information was discovered. The default iDRAC username and password are widely known, and any user with access to the server could change the default password.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">dell</span><span class="nt-tag">idrac</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://securityforeveryone.com/tools/dell-idrac6-7-8-default-login-scanner" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="delmia apriso - pre-authentication unsafe .net object deserialization critical identify critical remote vulnerabilities an unsafe .net object deserialization vulnerability in delmia apriso release 2019 through release 2024 could lead to pre-authentication remote code execution. cve-2024-3300 iamnoooob,rootxharsh,pdresearch apriso cve cve2024 delmia rce vuln cwe-502" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Delmia Apriso - Pre-Authentication Unsafe .NET Object Deserialization</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-3300.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-3300.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> iamnoooob,rootxharsh,pdresearch</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 8, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/502.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-502</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-3300" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-3300</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/apriso/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An unsafe .NET object deserialization vulnerability in DELMIA Apriso Release 2019 through Release 2024 could lead to pre-authentication remote code execution.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can exploit unsafe .NET object deserialization to achieve pre-authentication remote code execution.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update DELMIA Apriso to a version that addresses the unsafe deserialization vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">apriso</span><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">delmia</span><span class="nt-tag">rce</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.synacktiv.com/en/advisories/multiple-vulnerabilities-in-delmia-apriso-2019-to-2024" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.3ds.com/vulnerability/advisories" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="delta controls admin login panel - detect info identify web-based control panels delta controls admin login panel was detected. gy741 panel delta discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Delta Controls Admin Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/delta-login-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">delta-login-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> gy741</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Delta Controls ORCAview&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Delta Controls admin login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">delta</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="deluge - default login high identify default logins in web-based control panels deluge default login credentials were discovered. ritikchaddha default-login deluge vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Deluge - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/deluge/deluge-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">deluge-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 18, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;Deluge&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Deluge Default login credentials were discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">deluge</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://docs.linuxserver.io/images/docker-deluge/#:~:text=The%20admin%20interface%20is%20available,%2D%3EInterface%2D%3EPassword." target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="deluge webui login panel - detect info identify web-based control panels deluge webui login panel was detected. tess deluge deluge-torrent discovery panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Deluge WebUI Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/deluge-webui-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">deluge-webui-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> tess</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)deluge webui&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Deluge WebUI login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">deluge</span><span class="nt-tag">deluge-torrent</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="dependency-track login - panel info identify web-based control panels dependency track login panel was discovered. th3l0newolf panel login dependency track discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Dependency-Track Login - Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/dependency-track-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">dependency-track-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Th3l0newolf</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 10, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Dependency-Track&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Dependency Track login panel was discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">login</span><span class="nt-tag">dependency</span><span class="nt-tag">track</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://docs.dependencytrack.org" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="dericam login panel - detect info identify web-based control panels dericam login panel was detected. dhiyaneshdk panel dericam edb discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Dericam Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/dericam-login.yaml" target="_blank" rel="noopener" class="nt-source-link">dericam-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Dericam&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Dericam login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">dericam</span><span class="nt-tag">edb</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.exploit-db.com/ghdb/7354" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="desktop portal vmware horizon daas trade platform info identify web-based control panels  dhiyaneshdk discovery panel vmware" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Desktop Portal VMware Horizon DaaS Trade Platform</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/vmware-horizon-daas.yaml" target="_blank" rel="noopener" class="nt-source-link">vmware-horizon-daas.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)horizon daas&#34;})</code></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">vmware</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="devdojo voyager - default login high identify default logins in web-based control panels devdojo voyager contains default credentials when run with dummy data. an attacker can obtain access to user accounts and access sensitive information, modify data, and/or execute unauthorized operations. iamnoooob,rootxharsh,pdresearch default-login voyager devdojo vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">DevDojo Voyager - Default login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/devdojo/devdojo-voyager-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">devdojo-voyager-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> iamnoooob,rootxharsh,pdresearch</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 5, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;Voyager&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">DevDojo Voyager contains default credentials when run with dummy data. An attacker can obtain access to user accounts and access sensitive information, modify data, and/or execute unauthorized operations.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">voyager</span><span class="nt-tag">devdojo</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://voyager-docs.devdojo.com/getting-started/installation" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="devdojo voyager &lt;=1.8.0 - arbitrary file read high identify critical remote vulnerabilities devdojo voyager through 1.8.0 is vulnerable to path traversal at the /admin/compass. cve-2024-55415 iamnoooob,rootxharsh,pdresearch cve cve2024 devdojo lfi lfr voyager vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">DevDojo Voyager &lt;=1.8.0 - Arbitrary File Read</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-55415.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-55415.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> iamnoooob,rootxharsh,pdresearch</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 5, 2025</span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-55415" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-55415</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Voyager&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">DevDojo Voyager through 1.8.0 is vulnerable to path traversal at the /admin/compass.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Authenticated attackers can exploit path traversal to read arbitrary files from the server, potentially exposing sensitive configuration files, credentials, and application source code.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update DevDojo Voyager to version 1.8.1 or later to address the path traversal vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">devdojo</span><span class="nt-tag">lfi</span><span class="nt-tag">lfr</span><span class="nt-tag">voyager</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.sonarsource.com/blog/the-tainted-voyage-uncovering-voyagers-vulnerabilities/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/thedevdojo/voyager/blob/1.6/src/Http/Controllers/VoyagerCompassController.php#L213" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/thedevdojo/voyager/blob/1.6/src/Http/Controllers/VoyagerCompassController.php#L44" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-55415" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="device42 panel - detect info identify web-based control panels device42 was detected — a discovery, asset management and dependency mapping for data center and cloud. righettod device42 discovery login panel" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Device42 Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/device42-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">device42-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 4, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)device42&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Device42 was detected — a Discovery, Asset Management and Dependency Mapping for Data Center and Cloud.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">device42</span><span class="nt-tag">discovery</span><span class="nt-tag">login</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.device42.com/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="devika - local file inclusion high identify critical remote vulnerabilities a local file read vulnerability exists in the stitionai/devika repository, affecting the latest version. the vulnerability is due to improper handling of the &#39;snapshot_path&#39; parameter in the &#39;/api/get-browser-snapshot&#39; endpoint. an attacker can exploit this vulnerability by crafting a request with a malicious &#39;snapshot_path&#39; parameter, leading to arbitrary file read from the system. this issue impacts the security of the application by allowing unauthorized access to sensitive files on the server. cve-2024-5334 nechyo,nukunga,harksu,olfloralo,gy741 cve cve2024 devika-ai lfi vkev vuln cwe-73" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Devika - Local File Inclusion</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-5334.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-5334.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> nechyo,nukunga,harksu,olfloralo,gy741</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 7, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/73.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-73</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-5334" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-5334</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Devika AI&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A local file read vulnerability exists in the stitionai/devika repository, affecting the latest version. The vulnerability is due to improper handling of the &#39;snapshot_path&#39; parameter in the &#39;/api/get-browser-snapshot&#39; endpoint. An attacker can exploit this vulnerability by crafting a request with a malicious &#39;snapshot_path&#39; parameter, leading to arbitrary file read from the system. This issue impacts the security of the application by allowing unauthorized access to sensitive files on the server.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation could lead to unauthorized access to sensitive files and data.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Ensure input validation is implemented to prevent malicious file inclusions and use whitelists for allowed file paths.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">devika-ai</span><span class="nt-tag">lfi</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://huntr.com/bounties/7eec128b-1bf5-4922-a95c-551ad3695cf6" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/stitionai/devika/commit/6acce21fb08c3d1123ef05df6a33912bf0ee77c2" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-5334" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="devika v1 - path traversal critical identify critical remote vulnerabilities the snapshot_path parameter in the /api/get-browser-snapshot endpoint in stitionai devika v1 is susceptible to a path traversal attack. an attacker can manipulate the snapshot_path parameter to traverse directories and access sensitive files on the server. this can potentially lead to unauthorized access to critical system files and compromise the confidentiality and integrity of the system. cve-2024-40422 s4e-io,alpernae cve cve2024 devika lfi vuln cwe-22" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Devika v1 - Path Traversal</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-40422.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-40422.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> s4e-io,alpernae</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 5, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-40422" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-40422</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-1429839495&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The snapshot_path parameter in the /api/get-browser-snapshot endpoint in stitionai devika v1 is susceptible to a path traversal attack. An attacker can manipulate the snapshot_path parameter to traverse directories and access sensitive files on the server. This can potentially lead to unauthorized access to critical system files and compromise the confidentiality and integrity of the system.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can exploit path traversal to access sensitive files on the server.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update Devika to a version later than v1 that patches the path traversal vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">devika</span><span class="nt-tag">lfi</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-40422" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://cvefeed.io/vuln/detail/CVE-2024-40422" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/alpernae/CVE-2024-40422" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/stitionai/devika" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://www.exploit-db.com/exploits/52066" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="devtron panel login panel - detect info identify web-based control panels devtron panel login panel was detected. johnk3r devtron discovery panel" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Devtron Panel Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/devtron-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">devtron-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> johnk3r</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 10, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Devtron&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Devtron Panel login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">devtron</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://devtron.ai/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="dex authentication - panel info identify web-based control panels  rxerium dex sso panel login discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Dex Authentication - Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/dex-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">dex-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 25, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Log in to dex&#34;</code></div>
  <div class="nt-tags"><span class="nt-tag">dex</span><span class="nt-tag">sso</span><span class="nt-tag">panel</span><span class="nt-tag">login</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://dexidp.io" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="dialogic xms admin console - default login high identify default logins in web-based control panels dialogic xms admin console was using default credentials and it was discovered. ritikchaddha admin default-login dialogic vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Dialogic XMS Admin Console - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/dialogic/dialogic-xms-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">dialogic-xms-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 1, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;Dialogic XMS Admin Console&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Dialogic XMS Admin Console was using default credentials and it was discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">admin</span><span class="nt-tag">default-login</span><span class="nt-tag">dialogic</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="dialogic xms admin console - detect info identify web-based control panels  ritikchaddha panel dialogic admin login detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Dialogic XMS Admin Console - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/dialogic-xms-console.yaml" target="_blank" rel="noopener" class="nt-source-link">dialogic-xms-console.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 1, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Dialogic XMS Admin Console&#34;})</code></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">dialogic</span><span class="nt-tag">admin</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="diced zipline - detect info identify web-based control panels zipline panel was detected. icarot diced zipline login panel detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Diced Zipline - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/zipline-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">zipline-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> icarot</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 10, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Zipline&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Zipline panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">diced</span><span class="nt-tag">zipline</span><span class="nt-tag">login</span><span class="nt-tag">panel</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/diced/zipline" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="dify - user enumeration via &#34;account not found&#34; message medium identify critical remote vulnerabilities a user enumeration vulnerability exists in langgenius/dify, where the login api leaks information about whether a user account exists or not. when an invalid/non-existent email is used during login, the api returns a distinct error message such as &#34;account_not_found&#34; or &#34;account not found.&#34;, allowing attackers to identify valid accounts. cve-2025-11750 kazgangap cve cve2025 dify langgenius user-enum vuln cwe-544" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Dify - User Enumeration via &#34;Account not found&#34; Message</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-11750.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-11750.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Kazgangap</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 20, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/544.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-544</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-11750" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-11750</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;97378986&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A user enumeration vulnerability exists in langgenius/dify, where the login API leaks information about whether a user account exists or not. When an invalid/non-existent email is used during login, the API returns a distinct error message such as &#34;account_not_found&#34; or &#34;Account not found.&#34;, allowing attackers to identify valid accounts.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can enumerate valid user accounts through distinct error messages returned by the login API, facilitating targeted credential stuffing and phishing attacks against Dify installations.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to the patched version of Dify that implements generic error messages for authentication failures.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">dify</span><span class="nt-tag">langgenius</span><span class="nt-tag">user-enum</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://huntr.com/bounties/e7359f9f-c004-4304-9de9-753622d370a1" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/Kazgangap/cve-poc-garage/blob/main/2025/CVE-2025-11750.md" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/langgenius/dify/issues/24323" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/langgenius/dify/pull/25369" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="dify v1.9.1 - broken access control medium identify critical remote vulnerabilities dify v1.9.1 contains an insecure permissions vulnerability caused by lack of authorization checks in /console/api/system-features endpoint, letting unauthenticated attackers access sensitive system configuration data. cve-2025-63387 dhiyaneshdk auth-bypass cve cve2025 dify vkev cwe-287" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Dify v1.9.1 - Broken Access Control</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-63387.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-63387.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 19, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/287.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-287</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-63387" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-63387</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-1483370344&#34; || service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-791570210&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Dify v1.9.1 contains an insecure permissions vulnerability caused by lack of authorization checks in /console/api/system-features endpoint, letting unauthenticated attackers access sensitive system configuration data.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can access sensitive system configuration data, potentially leading to information disclosure.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest version of Dify.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">dify</span><span class="nt-tag">vkev</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-63387" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="digi international router - login panel info identify web-based control panels digi international cellular routers expose a web management interface used in industrial iot and remote connectivity applications. rxerium digi discovery ics industrial panel router" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Digi International Router - Login Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/digi-router-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">digi-router-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 27, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;Digi Router&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Digi International cellular routers expose a web management interface used in industrial IoT and remote connectivity applications.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">digi</span><span class="nt-tag">discovery</span><span class="nt-tag">ics</span><span class="nt-tag">industrial</span><span class="nt-tag">panel</span><span class="nt-tag">router</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.digi.com/products/networking/cellular-routers" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="digital watchdog - default login high identify default logins in web-based control panels digital watchdog default login credentials were discovered. omranisecurity digital-watchdog default-login dw-spectrum vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Digital Watchdog - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/digital-watchdog/digital-watchdog-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">digital-watchdog-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> omranisecurity</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 27, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;868509217&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Digital Watchdog default login credentials were discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">digital-watchdog</span><span class="nt-tag">default-login</span><span class="nt-tag">dw-Spectrum</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://digitalwatchdog.happyfox.com/kb/article/686-recorder-and-raid-default-login-list/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="digital watchdog - detect info identify web-based control panels digital watchdog panel was detected. ritikchaddha digital-watchdog panel detect login dw spectrum discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Digital Watchdog - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/digital-watchdog-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">digital-watchdog-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 28, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;868509217&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Digital Watchdog panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">digital-watchdog</span><span class="nt-tag">panel</span><span class="nt-tag">detect</span><span class="nt-tag">login</span><span class="nt-tag">dw</span><span class="nt-tag">spectrum</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="digital watchdog dw spectrum server 4.2.0.32842 - information disclosure high identify critical remote vulnerabilities digital watchdog dw spectrum server 4.2.0.32842 allows attackers to access sensitive infromation via a crafted api call. cve-2022-34534 ritikchaddha cve cve2022 digital-watchdog dw exposure spectrum vuln cwe-200" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Digital Watchdog DW Spectrum Server 4.2.0.32842 - Information Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-34534.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-34534.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 28, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-34534" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-34534</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;868509217&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Digital Watchdog DW Spectrum Server 4.2.0.32842 allows attackers to access sensitive infromation via a crafted API call.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can access sensitive system information including network configuration, remote addresses, and cloud host details through the moduleInformation API endpoint, potentially facilitating further attacks.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update Digital Watchdog DW Spectrum Server to a version newer than 4.2.0.32842 that requires authentication for the moduleInformation API endpoint.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">digital-watchdog</span><span class="nt-tag">dw</span><span class="nt-tag">exposure</span><span class="nt-tag">spectrum</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://gist.github.com/secgrant/820faeeaa0cb4889edaa1d6fef83deab" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-34534" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="directadmin login panel - detect info identify web-based control panels directadmin login panel was detected. idealphase directadmin discovery panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">DirectAdmin Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/directadmin-login-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">directadmin-login-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> idealphase</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)directadmin login&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">DirectAdmin login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">directadmin</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.directadmin.com/whats_new.php" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="directum login panel - detect info identify web-based control panels directum login panel was detected. pikpikcu directum discovery panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Directum Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/directum-login.yaml" target="_blank" rel="noopener" class="nt-source-link">directum-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pikpikcu</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Directum&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Directum login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">directum</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="discuz panel - detection info identify web-based control panels  ritikchaddha panel discuz detect login discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Discuz Panel - Detection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/discuz-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">discuz-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 7, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Discuz!&#34;})</code></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">discuz</span><span class="nt-tag">detect</span><span class="nt-tag">login</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="django queryset.order_by - sql injection critical identify critical remote vulnerabilities django 3.1.x before 3.1.13 and 3.2.x before 3.2.5 contain a sql injection caused by untrusted input in queryset.order_by. attackers can execute arbitrary sql commands if they control order_by input parameters. cve-2021-35042 0x_akoko cve cve2021 dast django sqli cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Django QuerySet.order_by - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/dast/cves/2021/CVE-2021-35042.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2021-35042.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_Akoko</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 23, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2021-35042" target="_blank" rel="noopener" class="nt-cve-link">CVE-2021-35042</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;product&#34;] contains &#39;Django&#39;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Django 3.1.x before 3.1.13 and 3.2.x before 3.2.5 contain a SQL injection caused by untrusted input in QuerySet.order_by. Attackers can execute arbitrary SQL commands if they control order_by input parameters.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can execute arbitrary SQL commands, potentially leading to data leakage, modification, or deletion.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to Django 3.1.13 or 3.2.5 or later versions.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2021</span><span class="nt-tag">dast</span><span class="nt-tag">django</span><span class="nt-tag">sqli</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2021-35042" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/zer0qs/CVE-2021-35042" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/django/django/commit/a34a5f724c5d5adb2109374ba3989ebb7b11f81f" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="django rasterfield - sql injection high identify critical remote vulnerabilities django &lt; 6.0.2, &lt; 5.2.11, and &lt; 4.2.28 contains a sql injection caused by improper sanitization of the band index parameter in rasterfield on postgis, letting remote attackers inject sql, exploit requires crafted input. cve-2026-1207 omarkurt cve cve2026 django postgis rasterfield sqli unauth vkev vuln cwe-89" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Django RasterField - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2026/CVE-2026-1207.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2026-1207.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> omarkurt</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 5, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2026-1207" target="_blank" rel="noopener" class="nt-cve-link">CVE-2026-1207</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;product&#34;] contains &#34;Django Project:Django&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Django &lt; 6.0.2, &lt; 5.2.11, and &lt; 4.2.28 contains a SQL injection caused by improper sanitization of the band index parameter in RasterField on PostGIS, letting remote attackers inject SQL, exploit requires crafted input.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Remote attackers can execute arbitrary SQL commands, potentially leading to data disclosure or modification.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to versions 6.0.2, 5.2.11, 4.2.28 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2026</span><span class="nt-tag">django</span><span class="nt-tag">postgis</span><span class="nt-tag">rasterfield</span><span class="nt-tag">sqli</span><span class="nt-tag">unauth</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1207" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.djangoproject.com/weblog/2026/feb/03/security-releases/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/django/django/commit/81aa5292967cd09319c45fe2c1a525ce7b6684d8" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="django sql injection high identify critical remote vulnerabilities django 1.11 before 1.11.29, 2.2 before 2.2.11, and 3.0 before 3.0.4 allow sql injection if untrusted data is used as a tolerance parameter in gis functions and aggregates on oracle. by passing a suitably crafted tolerance to gis functions and aggregates on oracle, it is possible to break character escaping and inject malicious sql. cve-2020-9402 geeknik,0x_akoko cve cve2020 dast django djangoproject sqli vulhub vuln cwe-89" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Django SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/dast/cves/2020/CVE-2020-9402.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2020-9402.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> geeknik,0x_Akoko</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 23, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2020-9402" target="_blank" rel="noopener" class="nt-cve-link">CVE-2020-9402</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;product&#34;] contains &#34;Django Project:Django&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Django 1.11 before 1.11.29, 2.2 before 2.2.11, and 3.0 before 3.0.4 allow SQL injection if untrusted data is used as a tolerance parameter in GIS functions and aggregates on Oracle. By passing a suitably crafted tolerance to GIS functions and aggregates on Oracle, it is possible to break character escaping and inject malicious SQL.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized access, data leakage, or data manipulation.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to the latest version.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2020</span><span class="nt-tag">dast</span><span class="nt-tag">django</span><span class="nt-tag">djangoproject</span><span class="nt-tag">sqli</span><span class="nt-tag">vulhub</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.debian.org/security/2020/dsa-4705" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/vulhub/vulhub/tree/master/django/CVE-2020-9402" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://docs.djangoproject.com/en/3.0/releases/security/" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2020-9402" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://groups.google.com/forum/#!topic/django-announce/fLUh_pOaKrY" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="docassemble - local file inclusion high identify critical remote vulnerabilities docassemble is an expert system for guided interviews and document assembly. the vulnerability allows attackers to gain unauthorized access to information on the system through url manipulation. it affects versions 1.4.53 to 1.4.96. the vulnerability has been patched in version 1.4.97 of the master branch. cve-2024-27292 johnk3r cve cve2024 docassemble lfi vkev vuln cwe-706" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Docassemble - Local File Inclusion</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-27292.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-27292.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> johnk3r</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 1, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/706.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-706</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-27292" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-27292</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)docassemble&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Docassemble is an expert system for guided interviews and document assembly. The vulnerability allows attackers to gain unauthorized access to information on the system through URL manipulation. It affects versions 1.4.53 to 1.4.96. The vulnerability has been patched in version 1.4.97 of the master branch.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can read arbitrary files on the server through URL manipulation in the Docassemble interview endpoint.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update Docassemble to version 1.4.97 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">docassemble</span><span class="nt-tag">lfi</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://tantosec.com/blog/docassemble/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/jhpyle/docassemble/security/advisories/GHSA-jq57-3w7p-vwvv" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/jhpyle/docassemble/commit/97f77dc486a26a22ba804765bfd7058aabd600c9" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="doccano - default login high identify default logins in web-based control panels detected the doccano data labeling platform was using default administrator credentials (admin:password). an attacker could have gained full administrative access. 0x_akoko doccano default-login vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Doccano - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/doccano-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">doccano-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_Akoko</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 23, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)doccano&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detected the Doccano data labeling platform was using default administrator credentials (admin:password). An attacker could have gained full administrative access.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">doccano</span><span class="nt-tag">default-login</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/doccano/doccano" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://doccano.github.io/doccano/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="docebo elearning login panel - detect info identify web-based control panels docebo elearning login panel was detected. pikpikcu discovery docebo panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Docebo eLearning Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/docebo-elearning-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">docebo-elearning-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pikpikcu</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Docebo E-learning&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Docebo eLearning login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">docebo</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="dockge panel - detect info identify web-based control panels a fancy, easy-to-use and reactive self-hosted docker compose.yaml stack-oriented manager rxerium panel dockge login discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Dockge Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/dockge-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">dockge-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 3, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Dockge&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A fancy, easy-to-use and reactive self-hosted docker compose.yaml stack-oriented manager</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">dockge</span><span class="nt-tag">login</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/louislam/dockge" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://dockge.kuma.pet/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="docuware - detect info identify web-based control panels docuware panel was detected. righettod panel docuware detect login discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">DocuWare - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/docuware-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">docuware-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 26, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Docuware&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">DocuWare panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">docuware</span><span class="nt-tag">detect</span><span class="nt-tag">login</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://start.docuware.com/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="docusaurus gists plugin &lt; 4.0.0 - github personal access token exposure high identify critical remote vulnerabilities the docusaurus gists plugin adds a page to your docusaurus instance, displaying all public gists of a github user. docusaurus-plugin-content-gists versions prior to 4.0.0 are vulnerable to exposing github personal access tokens in production build artifacts when passed through plugin configuration options. the token, intended for build-time api access only, is inadvertently included in client-side javascript bundles, making it accessible to anyone who can view the website&#39;s source code. cve-2025-53624 darses cve cve2025 docusaurus exposure vuln cwe-200" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Docusaurus Gists Plugin &lt; 4.0.0 - GitHub Personal Access Token Exposure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-53624.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-53624.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> darses</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 10, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-53624" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-53624</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Docusaurus&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The Docusaurus gists plugin adds a page to your Docusaurus instance, displaying all public gists of a GitHub user. docusaurus-plugin-content-gists versions prior to 4.0.0 are vulnerable to exposing GitHub Personal Access Tokens in production build artifacts when passed through plugin configuration options. The token, intended for build-time API access only, is inadvertently included in client-side JavaScript bundles, making it accessible to anyone who can view the website&#39;s source code.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">A GitHub personal access token exposure vulnerability can grant an attacker unauthorized access to your repositories and organization resources, potentially leading to data exfiltration, code injection, and supply chain attacks.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update docusaurus-plugin-content-gists to version 4.0.0+. Revoke access to the GitHub PAT that was used: https://github.com/settings/tokens.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">docusaurus</span><span class="nt-tag">exposure</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/webbertakken/docusaurus-plugin-content-gists/commit/8d4230b82412edb215ddfa9e609d178510a5fe31" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/webbertakken/docusaurus-plugin-content-gists/security/advisories/GHSA-qf34-qpr4-5pph" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53624" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="dokploy login panel - detect info identify web-based control panels dokploy login panel was detected. theamanrawat panel dokploy discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Dokploy Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/dokploy-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">dokploy-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> theamanrawat</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 29, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)dokploy&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Dokploy login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">dokploy</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="dokuwiki login panel - detect info identify web-based control panels dokuwiki login panel was detected. righettod panel dokuwiki login discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Dokuwiki Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/dokuwiki-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">dokuwiki-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 14, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/dokuwiki/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Dokuwiki login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">dokuwiki</span><span class="nt-tag">login</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.dokuwiki.org/dokuwiki" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="dolibarr login panel - detect info identify web-based control panels dolibarr login panel was detected. pikpikcu,daffainfo,righettod panel dolibarr discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Dolibarr Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/dolibarr-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">dolibarr-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pikpikcu,daffainfo,righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Dolibarr&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Dolibarr login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">dolibarr</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="dolibarr unauthenticated contacts database theft high identify critical remote vulnerabilities an issue in dolibarr 16 before 16.0.5 allows unauthenticated attackers to perform a database dump and access a company&#39;s entire customer file, prospects, suppliers, and employee information if a contact file exists. cve-2023-33568 dhiyaneshdk cve cve2023 dolibarr unauth vuln cwe-552" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Dolibarr Unauthenticated Contacts Database Theft</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-33568.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-33568.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 19, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/552.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-552</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-33568" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-33568</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;440258421&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An issue in Dolibarr 16 before 16.0.5 allows unauthenticated attackers to perform a database dump and access a company&#39;s entire customer file, prospects, suppliers, and employee information if a contact file exists.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">The attacker can access and steal sensitive information from the contacts database, potentially leading to data breaches and privacy violations.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patch or upgrade to a patched version of Dolibarr to mitigate the vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">dolibarr</span><span class="nt-tag">unauth</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.dsecbypass.com/en/dolibarr-pre-auth-contact-database-dump/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-33568" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/Dolibarr/dolibarr/commit/bb7b69ef43673ed403436eac05e0bc31d5033ff7" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/Dolibarr/dolibarr/commit/be82f51f68d738cce205f4ce5b469ef42ed82d9e" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://www.dolibarr.org/forum/t/dolibarr-16-0-security-breach/23471" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="doris panel - detect info identify web-based control panels doris panel detection template. ritikchaddha doris panel login detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Doris Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/doris-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">doris-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 22, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;24048806&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Doris panel detection template.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">doris</span><span class="nt-tag">panel</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="dotclear admin login panel - detect info identify web-based control panels dotclear admin login panel was detected. pikpikcu,daffainfo discovery dotclear panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Dotclear Admin Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/dotclear-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">dotclear-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pikpikcu,daffainfo</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)dotclear&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Dotclear admin login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">dotclear</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="download monitor &lt;= 4.7.60 - sensitive information exposure high identify critical remote vulnerabilities the download monitor plugin for wordpress is vulnerable to sensitive information exposure in versions up to, and including, 4.7.60 via rest api. this can allow unauthenticated attackers to extract sensitive data including user reports, download reports, and user data including email, role, id and other info (not passwords) cve-2022-45354 dhiyaneshdk cve cve2022 download-monitor vkev vuln wordpress wp wp-plugin wpchill" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Download Monitor &lt;= 4.7.60 - Sensitive Information Exposure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-45354.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-45354.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 12, 2023</span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-45354" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-45354</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/download-monitor/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The Download Monitor plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 4.7.60 via REST API. This can allow unauthenticated attackers to extract sensitive data including user reports, download reports, and user data including email, role, id and other info (not passwords)</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can exploit this vulnerability to gain access to sensitive information, potentially leading to further attacks or unauthorized access.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest version of the Download Monitor plugin (4.7.60) or apply the provided patch to fix the vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">download-monitor</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">wpchill</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/RandomRobbieBF/CVE-2022-45354" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://wordpress.org/plugins/download-monitor/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://patchstack.com/database/vulnerability/download-monitor/wordpress-download-monitor-plugin-4-7-60-sensitive-data-exposure-vulnerability?_s_id=cve" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/nomi-sec/PoC-in-GitHub" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="dradis professional edition login panel - detect info identify web-based control panels dradis professional edition login panel was detected. righettod discovery dradis panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Dradis Professional Edition Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/dradis-pro-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">dradis-pro-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Dradis Professional Edition&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Dradis Professional Edition login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">dradis</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://dradisframework.com/ce/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="dragonfly login - panel info identify web-based control panels dragonfly login panel was discovered dhiyaneshdk dragonfly panel login discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">DragonFly Login - Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/dragonfly-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">dragonfly-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 24, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)logo-dragonfly\\.png&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Dragonfly Login Panel was discovered</div></div></div>
  <div class="nt-tags"><span class="nt-tag">dragonfly</span><span class="nt-tag">panel</span><span class="nt-tag">login</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="dragonfly - default login high identify default logins in web-based control panels dragonfly was using the default username, and the password was discovered. dhiyaneshdk default-login dragonfly vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Dragonfly - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/dragonfly/dragonfly-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">dragonfly-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 24, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)logo-dragonfly\\.png&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Dragonfly was using the default username, and the password was discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">dragonfly</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="draytek - remote code execution critical identify critical remote vulnerabilities draytek vigor2960 1.3.1_beta, vigor3900 1.4.4_beta, and vigor300b 1.3.3_beta, 1.4.2.1_beta, and 1.4.4_beta devices allow remote code execution as root (without authentication) via shell metacharacters to the cgi-bin/mainfunction.cgi uri. cve-2020-8515 pikpikcu cve cve2020 draytek kev rce vkev vuln cwe-78" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">DrayTek - Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2020/CVE-2020-8515.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2020-8515.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pikpikcu</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/78.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-78</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2020-8515" target="_blank" rel="noopener" class="nt-cve-link">CVE-2020-8515</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">asset[&#34;hw_vendor&#34;] == &#34;DrayTek&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">DrayTek Vigor2960 1.3.1_Beta, Vigor3900 1.4.4_Beta, and Vigor300B 1.3.3_Beta, 1.4.2.1_Beta, and 1.4.4_Beta devices allow remote code execution as root (without authentication) via shell metacharacters to the cgi-bin/mainfunction.cgi URI.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected router, leading to complete compromise of the device and potential unauthorized access to the network.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">This issue has been fixed in Vigor3900/2960/300B v1.5.1.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2020</span><span class="nt-tag">draytek</span><span class="nt-tag">kev</span><span class="nt-tag">rce</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.draytek.com/about/security-advisory/vigor3900-/-vigor2960-/-vigor300b-router-web-management-page-vulnerability-(cve-2020-8515)" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://blog.netlab.360.com/two-zero-days-are-targeting-draytek-broadband-cpe-devices-en/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2020-8515" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://sku11army.blogspot.com/2020/01/draytek-unauthenticated-rce-in-draytek.html" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://www.draytek.com/about/security-advisory/vigor3900-/-vigor2960-/-vigor300b-router-web-management-page-vulnerability-%28cve-2020-8515%29/" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="draytek vigor - command injection critical identify critical remote vulnerabilities draytek vigor devices contain a command injection vulnerability in the cvmcfgupload functionality. the vulnerability allows remote attackers to execute arbitrary commands through specially crafted requests to the /cgi-bin/mainfunction.cgi/cvmcfgupload endpoint. cve-2020-15415 ritikchaddha cve cve2020 draytek kev rce router vkev vuln cwe-78" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">DrayTek Vigor - Command Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2020/CVE-2020-15415.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2020-15415.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 19, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/78.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-78</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2020-15415" target="_blank" rel="noopener" class="nt-cve-link">CVE-2020-15415</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] contains `&#34;excanvas.js&#34; &amp;&amp; &#34;lang == \&#34;zh-cn\&#34;&#34; &amp;&amp; &#34;detectLang&#34; &amp;&amp; server==&#34;DWS&#34;`</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">DrayTek Vigor devices contain a command injection vulnerability in the cvmcfgupload functionality. The vulnerability allows remote attackers to execute arbitrary commands through specially crafted requests to the /cgi-bin/mainfunction.cgi/cvmcfgupload endpoint.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can execute arbitrary system commands on DrayTek Vigor devices via the cvmcfgupload endpoint, leading to complete device compromise and potential network infiltration.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update the firmware to the latest version provided by DrayTek. If no update is available, consider implementing network segmentation to restrict access to the device&#39;s management interface.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2020</span><span class="nt-tag">draytek</span><span class="nt-tag">kev</span><span class="nt-tag">rce</span><span class="nt-tag">router</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/CLP-team/Vigor-Commond-Injection" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15415" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="draytek vigorconnect 1.6.0-b - local file inclusion high identify critical remote vulnerabilities draytek vigorconnect 1.6.0-b3 is susceptible to local file inclusion in the file download functionality of the downloadfileservlet endpoint. an unauthenticated attacker could leverage this vulnerability to download arbitrary files from the underlying operating system with root privileges. cve-2021-20123 0x_akoko cve cve2021 draytek kev lfi tenable vigorconnect vkev vuln cwe-22" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Draytek VigorConnect 1.6.0-B - Local File Inclusion</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2021/CVE-2021-20123.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2021-20123.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_Akoko</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2021-20123" target="_blank" rel="noopener" class="nt-cve-link">CVE-2021-20123</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)vigorconnect&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Draytek VigorConnect 1.6.0-B3 is susceptible to local file inclusion in the file download functionality of the DownloadFileServlet endpoint. An unauthenticated attacker could leverage this vulnerability to download arbitrary files from the underlying operating system with root privileges.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to read sensitive files on the server, potentially leading to unauthorized access or information disclosure.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches or updates provided by the vendor to fix the LFI vulnerability in Draytek VigorConnect 1.6.0-B.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2021</span><span class="nt-tag">draytek</span><span class="nt-tag">kev</span><span class="nt-tag">lfi</span><span class="nt-tag">tenable</span><span class="nt-tag">vigorconnect</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.tenable.com/security/research/tra-2021-42" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2021-20123" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/ARPSyndicate/kenzer-templates" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="draytek vigorconnect 6.0-b3 - local file inclusion high identify critical remote vulnerabilities draytek vigorconnect 1.6.0-b3 is susceptible to local file inclusion in the file download functionality of the webservlet endpoint. an unauthenticated attacker could leverage this vulnerability to download arbitrary files from the underlying operating system with root privileges. cve-2021-20124 0x_akoko cve cve2021 draytek kev lfi tenable vigorconnect vkev vuln cwe-22" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Draytek VigorConnect 6.0-B3 - Local File Inclusion</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2021/CVE-2021-20124.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2021-20124.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_Akoko</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2021-20124" target="_blank" rel="noopener" class="nt-cve-link">CVE-2021-20124</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)vigorconnect&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Draytek VigorConnect 1.6.0-B3 is susceptible to local file inclusion in the file download functionality of the WebServlet endpoint. An unauthenticated attacker could leverage this vulnerability to download arbitrary files from the underlying operating system with root privileges.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability can lead to unauthorized access to sensitive information, potential data leakage, and further compromise of the affected system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches or updates provided by Draytek to fix the LFI vulnerability in VigorConnect 6.0-B3.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2021</span><span class="nt-tag">draytek</span><span class="nt-tag">kev</span><span class="nt-tag">lfi</span><span class="nt-tag">tenable</span><span class="nt-tag">vigorconnect</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.tenable.com/security/research/tra-2021-42" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.draytek.com/products/vigorconnect/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2021-20124" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/ARPSyndicate/kenzer-templates" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="drone ci login panel - detect info identify web-based control panels drone ci login panel was detected. yuzhe-zhang-0 panel droneci cicd discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Drone CI Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/drone-ci-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">drone-ci-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Yuzhe-zhang-0</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1354079303&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Drone CI login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">droneci</span><span class="nt-tag">cicd</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.drone.io" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="drupal - remote code execution high identify critical remote vulnerabilities drupal 8.5.x before 8.5.11 and drupal 8.6.x before 8.6.10 v contain certain field types that do not properly sanitize data from non-form sources, which can lead to arbitrary php code execution in some cases. cve-2019-6340 madrobot cve cve2019 drupal kev rce vkev vuln cwe-502" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Drupal - Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2019/CVE-2019-6340.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2019-6340.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> madrobot</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/502.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-502</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2019-6340" target="_blank" rel="noopener" class="nt-cve-link">CVE-2019-6340</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)drupal&#34;}) || service[&#34;favicon.ico.image.md5&#34;] matches `(?i)^(b6341dfc213100c61db4fb8775878cec|cf2445dcb53a031c02f9b57e2199bc03)`</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Drupal 8.5.x before 8.5.11 and Drupal 8.6.x before 8.6.10 V contain certain field types that do not properly sanitize data from non-form sources, which can lead to arbitrary PHP code execution in some cases.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected Drupal site.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the official security patch provided by Drupal to fix the deserialization vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2019</span><span class="nt-tag">drupal</span><span class="nt-tag">kev</span><span class="nt-tag">rce</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.drupal.org/sa-core-2019-003" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.synology.com/security/advisory/Synology_SA_19_09" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2019-6340" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://www.exploit-db.com/exploits/46452/" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/CVEDB/PoC-List" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="drupal core - anonymous sql injection via postgresql entity query critical identify critical remote vulnerabilities drupal core from 8.9.0 before 10.4.10, 10.5.0 before 10.5.10, 10.6.0 before 10.6.9, 11.0.0 before 11.1.10, 11.2.0 before 11.2.12, and 11.3.0 before 11.3.10 contains an sql injection caused by improper neutralization of special elements in sql commands, letting attackers execute arbitrary sql queries, exploit requires crafted input. cve-2026-9082 slcyber,dhiyaneshdk cve cve2026 drupal kev postgresql sqli vkev cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Drupal Core - Anonymous SQL Injection via PostgreSQL Entity Query</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2026/CVE-2026-9082.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2026-9082.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> slcyber,DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 22, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2026-9082" target="_blank" rel="noopener" class="nt-cve-link">CVE-2026-9082</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches `Drupal\s+(\d{1,2})(?:\s+\(https?:\/\/(?:www\.)?drupal\.org\))?`</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Drupal core from 8.9.0 before 10.4.10, 10.5.0 before 10.5.10, 10.6.0 before 10.6.9, 11.0.0 before 11.1.10, 11.2.0 before 11.2.12, and 11.3.0 before 11.3.10 contains an SQL injection caused by improper neutralization of special elements in SQL commands, letting attackers execute arbitrary SQL queries, exploit requires crafted input.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can execute arbitrary SQL commands, potentially leading to data disclosure, modification, or full database compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to versions 10.4.10, 10.5.10, 10.6.9, 11.1.10, 11.2.12, 11.3.10 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2026</span><span class="nt-tag">drupal</span><span class="nt-tag">kev</span><span class="nt-tag">postgresql</span><span class="nt-tag">sqli</span><span class="nt-tag">vkev</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.drupal.org/sa-core-2026-004" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://slcyber.io/research-center/keys-to-the-kingdom-anonymous-sql-injection-in-drupal-core-cve-2026-9082/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="duomi cms - sql injection critical identify critical remote vulnerabilities duomi cms contains a sql injection vulnerability. an attacker can possibly obtain sensitive information from a database, modify data, and execute unauthorized administrative operations in the context of the affected site. pikpikcu duomicms sqli vuln cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Duomi CMS - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/vulnerabilities/other/duomicms-sql-injection.yaml" target="_blank" rel="noopener" class="nt-source-link">duomicms-sql-injection.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pikpikcu</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)DuomiCMS&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Duomi CMS contains a SQL injection vulnerability. An attacker can possibly obtain sensitive information from a database, modify data, and execute unauthorized administrative operations in the context of the affected site.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">duomicms</span><span class="nt-tag">sqli</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://redn3ck.github.io/2016/11/01/duomiCMS/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="dynatrace login panel - detect info identify web-based control panels dynatrace login panel was detected. ja1sh dynatrace login panel discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Dynatrace Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/dynatrace-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">dynatrace-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ja1sh</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1828614783&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Dynatrace login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">dynatrace</span><span class="nt-tag">login</span><span class="nt-tag">panel</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="dzzoffice installation panel - detect high identify web-based control panels dzzoffice installation panel was detected. ritikchaddha discovery dzzoffice install panel cwe-200" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">DzzOffice Installation Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/dzzoffice/dzzoffice-install.yaml" target="_blank" rel="noopener" class="nt-source-link">dzzoffice-install.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-1961736892&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">DzzOffice installation panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">dzzoffice</span><span class="nt-tag">install</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="dzzoffice login panel - detect info identify web-based control panels dzzoffice login panel was detected. ritikchaddha discovery dzzoffice panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">DzzOffice Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/dzzoffice/dzzoffice-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">dzzoffice-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-1961736892&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">DzzOffice login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">dzzoffice</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="e-mobile panel - detect info identify web-based control panels e-mobile panel was detected. ritikchaddha panel e-mobile discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">E-mobile Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/e-mobile-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">e-mobile-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)E-Mobile&amp;nbsp&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">E-mobile panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">e-mobile</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="ectouch v2 - sql injection critical identify critical remote vulnerabilities ectouch v2 was discovered to contain a sql injection vulnerability via the $arr[&#39;id&#39;] parameter at \default\helpers\insert.php. cve-2023-39560 s4e-io cve cve2023 ectouch sqli vuln cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">ECTouch v2 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-39560.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-39560.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> s4e-io</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 21, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-39560" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-39560</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;127711143&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">ECTouch v2 was discovered to contain a SQL injection vulnerability via the $arr[&#39;id&#39;] parameter at \default\helpers\insert.php.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can exploit SQL injection through the $arr[&#39;id&#39;] parameter to extract database contents, potentially stealing customer data, order information, and payment details from the ECTouch e-commerce system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update ECTouch to a version newer than 2.0 that uses parameterized queries or prepared statements for the id parameter in default/helpers/insert.php.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">ectouch</span><span class="nt-tag">sqli</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wiki.bachang.org/doc/2582/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-39560" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="emqx login panel - detect info identify web-based control panels emqx login panel was detected. righettod panel emqx login detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">EMQX Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/emqx-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">emqx-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 12, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)EMQX Dashboard&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">EMQX login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">emqx</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.emqx.io/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="eos http browser medium identify web-based control panels  dhiyaneshdk exposure eos httpbrowser panel discovery" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">EOS HTTP Browser</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/eos-http-browser.yaml" target="_blank" rel="noopener" class="nt-source-link">eos-http-browser.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 20, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)EOS HTTP Browser&#34;})</code></div>
  <div class="nt-tags"><span class="nt-tag">exposure</span><span class="nt-tag">eos</span><span class="nt-tag">httpbrowser</span><span class="nt-tag">panel</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.facebook.com/photo/?fbid=634930085344181&amp;set=pcb.634929508677572" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="erpnext - default login high identify default logins in web-based control panels detects erpnext installations that use the default administrator/admin login credentials. this misconfiguration grants attackers full administrative access to the system. 0x_akoko erpnext erp default-login vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">ERPNext - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/erp/erpnext-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">erpnext-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_Akoko</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 14, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Login to Frappe&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detects ERPNext installations that use the default Administrator/admin login credentials. This misconfiguration grants attackers full administrative access to the system.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">erpnext</span><span class="nt-tag">erp</span><span class="nt-tag">default-login</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/frappe/erpnext" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/frappe/erpnext/blob/develop/README.md" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="esphome - authentication bypass high identify critical remote vulnerabilities esphome 2025.8.0 contains an authentication bypass caused by improper validation of base64-encoded authorization values in the web_server component, letting attackers access functionality without valid credentials, exploit requires crafted authorization header. cve-2025-57808 sean-kim auth-bypass cve cve2025 esphome vuln cwe-303" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">ESPHome - Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-57808.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-57808.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> sean-kim</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 15, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/303.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-303</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-57808" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-57808</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)ESPHome&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">ESPHome 2025.8.0 contains an authentication bypass caused by improper validation of base64-encoded Authorization values in the web_server component, letting attackers access functionality without valid credentials, exploit requires crafted Authorization header.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can bypass authentication to access web server functions, including OTA updates, potentially compromising device control.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to version 2025.8.1 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">esphome</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://cybersecuritynews.com/esphome-web-server-authentication-bypass/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/esphome/esphome/security/advisories/GHSA-mxh2-ccgj-8635" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://esphome.io/components/web_server/" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="esphome login panel - detect info identify web-based control panels esphome login panel was detected. fabaff discovery esphome iot panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">ESPHome Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/esphome-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">esphome-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> fabaff</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)login - esphome&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">ESPHome login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">esphome</span><span class="nt-tag">iot</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="esxi system login panel - detect info identify web-based control panels esxi system login panel was detected. dhiyaneshdk discovery esxi panel vmware cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">ESXi System Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/esxi-system.yaml" target="_blank" rel="noopener" class="nt-source-link">esxi-system.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)esxuiapp&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">ESXi System login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">esxi</span><span class="nt-tag">panel</span><span class="nt-tag">vmware</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="etq reliance - authentication bypass via trailing space critical identify critical remote vulnerabilities an authentication bypass vulnerability exists in etq reliance on the cg (legacy) platform. the application allowed login as the privileged internal system user by manipulating the username field. the system account does not require a password, enabling attackers with network access to the login page to obtain elevated access. once authenticated, an attacker could achieve remote code execution by modifying jython scripts within the application. this issue was resolved by introducing stricter validation logic to exclude internal accounts from public authentication workflows in version mp-4583. cve-2025-34143 slcyber,dhiyaneshdk auth-bypass cve cve2025 etq-reliance vkev vuln cwe-287" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">ETQ Reliance - Authentication Bypass via Trailing Space</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-34143.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-34143.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> slcyber,DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 23, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/287.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-287</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-34143" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-34143</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)ETQ Reliance&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An authentication bypass vulnerability exists in ETQ Reliance on the CG (legacy) platform. The application allowed login as the privileged internal SYSTEM user by manipulating the username field. The SYSTEM account does not require a password, enabling attackers with network access to the login page to obtain elevated access. Once authenticated, an attacker could achieve remote code execution by modifying Jython scripts within the application. This issue was resolved by introducing stricter validation logic to exclude internal accounts from public authentication workflows in version MP-4583.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation allows unauthenticated attackers to bypass authentication and gain elevated SYSTEM access, potentially leading to remote code execution.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the vendor patch to version MP-4583 or later, which includes stricter validation logic to exclude internal accounts from public authentication workflows.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">etq-reliance</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-34143" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://slcyber.io/assetnote-security-research-center/how-we-accidentally-discovered-a-remote-code-execution-vulnerability-in-etq-reliance/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="etq reliance - reflected xss via sqlconverterservlet medium identify critical remote vulnerabilities a reflected cross-site scripting (xss) vulnerability exists in etq reliance cg (legacy) platform within the sqlconverterservlet component. this vulnerability requires user interaction, such as clicking a crafted link, and may result in execution of unauthorized scripts in the user&#39;s context. the affected servlet was unnecessarily exposed to authenticated users and has since been disabled in version se.2025.1. cve-2025-34141 slcyber,pdresearch cve cve2025 etq reflected-xss reliance vkev vuln xss cwe-79" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">ETQ Reliance - Reflected XSS via SQLConverterServlet</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-34141.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-34141.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> slcyber,pdresearch</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 23, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-79</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-34141" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-34141</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)ETQ Reliance&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A reflected cross-site scripting (XSS) vulnerability exists in ETQ Reliance CG (legacy) platform within the SQLConverterServlet component. This vulnerability requires user interaction, such as clicking a crafted link, and may result in execution of unauthorized scripts in the user&#39;s context. The affected servlet was unnecessarily exposed to authenticated users and has since been disabled in version SE.2025.1.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation allows attackers to execute arbitrary JavaScript in the context of an authenticated user&#39;s browser session, potentially leading to session hijacking or unauthorized actions.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to ETQ Reliance version SE.2025.1 or later where the SQLConverterServlet has been disabled.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">etq</span><span class="nt-tag">reflected-xss</span><span class="nt-tag">reliance</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">xss</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-34141" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://slcyber.io/assetnote-security-research-center/how-we-accidentally-discovered-a-remote-code-execution-vulnerability-in-etq-reliance/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="evse web interface panel - detection info identify web-based control panels  ritikchaddha detect discovery evlink evse login panel schneider-electric" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">EVSE Web Interface Panel - Detection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/evlink/evse-web-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">evse-web-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 11, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)evse web interface&#34;})</code></div>
  <div class="nt-tags"><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">evlink</span><span class="nt-tag">evse</span><span class="nt-tag">login</span><span class="nt-tag">panel</span><span class="nt-tag">schneider-electric</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="evlink city &lt; r8 v3.4.0.1 - authentication bypass critical identify critical remote vulnerabilities a cwe-798: use of hard-coded credentials vulnerability exists in evlink city (evc1s22p4 / evc1s7p4 all versions prior to r8 v3.4.0.1), evlink parking (evw2 / evf2 / ev.2 all versions prior to r8 v3.4.0.1), and evlink smart wallbox (evb1a all versions prior to r8 v3.4.0.1 ) that could allow an attacker to issue unauthorized commands to the charging station web server with administrative privileges. cve-2021-22707 ritikchaddha,dorkerdevil auth-bypass cve cve2021 evlink schneider-electric vkev vuln cwe-798" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">EVlink City &lt; R8 V3.4.0.1 - Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2021/CVE-2021-22707.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2021-22707.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha,dorkerdevil</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 10, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/798.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-798</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2021-22707" target="_blank" rel="noopener" class="nt-cve-link">CVE-2021-22707</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)evse web interface&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A CWE-798: Use of Hard-coded Credentials vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking (EVW2 / EVF2 / EV.2 all versions prior to R8 V3.4.0.1), and EVlink Smart Wallbox (EVB1A all versions prior to R8 V3.4.0.1 ) that could allow an attacker to issue unauthorized commands to the charging station web server with administrative privileges.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can bypass authentication via hardcoded credentials and issue unauthorized administrative commands to the charging station web server, potentially disrupting charging operations or stealing sensitive data.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to EVlink City R8 V3.4.0.1 or later to fix the authentication bypass vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2021</span><span class="nt-tag">evlink</span><span class="nt-tag">schneider-electric</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://codeberg.org/AmenoCat/CVE-2021-22707-PoC/raw/branch/main/exploit.sh" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2021-22707" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="http://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-194-06" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="evlink local controller - detection info identify web-based control panels  ritikchaddha panel evlink login detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">EVlink Local Controller - Detection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/evlink/evlink-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">evlink-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 11, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)EVlink Local Controller&#34;})</code></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">evlink</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="ewm manager login panel - detect info identify web-based control panels ewm manager login panel was detected. pussycat0x ewm manager login panel discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">EWM Manager Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/ewm-manager-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">ewm-manager-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)EWM Manager&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">EWM Manager login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">ewm</span><span class="nt-tag">manager</span><span class="nt-tag">login</span><span class="nt-tag">panel</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="ewww image optimizer &lt;= 7.2.0 - unauthenticated information disclosure medium identify critical remote vulnerabilities the ewww image optimizer plugin for wordpress is vulnerable to sensitive information exposure in all versions up to, and including, 7.2.0 via the debug_log function. this makes it possible for unauthenticated attackers to extract sensitive debug data when debug logging is enabled. shivam kamboj cve cve2023 ewww-image-optimizer vkev wordpress wp wp-plugin" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">EWWW Image Optimizer &lt;= 7.2.0 - Unauthenticated Information Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-40600.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-40600.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Shivam Kamboj</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 17, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] contains &#34;ewww_image_optimizer&#34; &amp;&amp; service[&#34;http.body&#34;] contains &#34;__construct()&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The EWWW Image Optimizer plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.2.0 via the debug_log function. This makes it possible for unauthenticated attackers to extract sensitive debug data when debug logging is enabled.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can access sensitive embedded data, potentially leading to information disclosure and further exploitation.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Remove debug information and update to the latest version of EWWW Image Optimizer.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">ewww-image-optimizer</span><span class="nt-tag">vkev</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-40600" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://patchstack.com/database/wordpress/plugin/ewww-image-optimizer/vulnerability/wordpress-ewww-image-optimizer-plugin-7-2-0-sensitive-data-exposure-vulnerability" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/ewww-image-optimizer/ewww-image-optimizer-720-unauthenticated-sensitive-information-exposure-via-debug-log" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="eagle for apache kakfa login - detect info identify web-based control panels efak is a visualization and management software that allows one to query, visualize, alert on, and explore their metrics wherever they were stored. irshad ahamed panel efak login detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Eagle For Apache Kakfa Login - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/efak-login-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">efak-login-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> irshad ahamed</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 4, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1693580324&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">EFAK is a visualization and management software that allows one to query, visualize, alert on, and explore their metrics wherever they were stored.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">efak</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/smartloli/efak" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.kafka-eagle.org/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="easy diffusion panel - detect info identify web-based control panels easy diffusion (formerly stable diffusion ui) was detected. easy diffusion is a one-click, self-hosted stable diffusion web application focused on accessibility and ease of use for ai image generation. exposed instances allow unauthenticated access to image generation capabilities and stored outputs. rxerium ai detect discovery easydiffusion image-generation panel stable-diffusion" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Easy Diffusion Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/easydiffusion-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">easydiffusion-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 14, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Easy Diffusion&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Easy Diffusion (formerly Stable Diffusion UI) was detected. Easy Diffusion is a one-click, self-hosted Stable Diffusion web application focused on accessibility and ease of use for AI image generation. Exposed instances allow unauthenticated access to image generation capabilities and stored outputs.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">ai</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">easydiffusion</span><span class="nt-tag">image-generation</span><span class="nt-tag">panel</span><span class="nt-tag">stable-diffusion</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/easydiffusion/easydiffusion" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://easydiffusion.github.io/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="easycvr video management - users information exposure high identify critical remote vulnerabilities easycvr video management platform has leaked user information pussycat0x unauth easycvr misconfig vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">EasyCVR video management - Users Information Exposure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/vulnerabilities/other/easycvr-info-leak.yaml" target="_blank" rel="noopener" class="nt-source-link">easycvr-info-leak.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 5, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)EasyCVR&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">EasyCVR video management platform has leaked user information</div></div></div>
  <div class="nt-tags"><span class="nt-tag">unauth</span><span class="nt-tag">easycvr</span><span class="nt-tag">misconfig</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/wy876/POC/blob/main/EasyCVR%20%E8%A7%86%E9%A2%91%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0%E5%AD%98%E5%9C%A8%E7%94%A8%E6%88%B7%E4%BF%A1%E6%81%AF%E6%B3%84%E9%9C%B2.md" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="easyjob login panel - detect info identify web-based control panels easyjob login panel was detected. righettod panel easyjob login discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">EasyJOB Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/easyjob-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">easyjob-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 7, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Log in - easyJOB&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">EasyJOB login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">easyjob</span><span class="nt-tag">login</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.en.because-software.com/software/easyjob/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="easyreport - default login high identify default logins in web-based control panels  sleepingbag945 default-login easyreport vuln cwe-798" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">EasyReport - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/easyreport/easyreport-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">easyreport-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> SleepingBag945</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 21, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/798.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-798</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)EasyReport-A Sample and Easy to Use Web Reporting System&#34;</code></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">easyreport</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="easyvista login panel - detect info identify web-based control panels easyvista login panel was detected. righettod panel easyvista login detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">EasyVista Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/easyvista-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">easyvista-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 13, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Easyvista&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">EasyVista login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">easyvista</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.easyvista.com/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="echelon i.lon smartserver - login panel info identify web-based control panels echelon (now adesto/dialog semiconductor) i.lon smartserver is a lonworks/ip-852
building automation controller used in hvac, lighting, and energy management systems.
the embedded web interface is frequently exposed on standard and non-standard ports. rxerium building-automation discovery echelon ics ilon lonworks ot panel scada" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Echelon i.LON SmartServer - Login Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/echelon-ilon-smartserver-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">echelon-ilon-smartserver-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 27, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;i\\.LON SmartServer&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Echelon (now Adesto/Dialog Semiconductor) i.LON SmartServer is a LonWorks/IP-852
building automation controller used in HVAC, lighting, and energy management systems.
The embedded web interface is frequently exposed on standard and non-standard ports.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">building-automation</span><span class="nt-tag">discovery</span><span class="nt-tag">echelon</span><span class="nt-tag">ics</span><span class="nt-tag">ilon</span><span class="nt-tag">lonworks</span><span class="nt-tag">ot</span><span class="nt-tag">panel</span><span class="nt-tag">scada</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.echelon.com/products/ilon-smartserver/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="eclipse birt panel - detect info identify web-based control panels eclipse birt (business intelligence reporting tool) detected shiva (strobes security) detect discovery eclipsebirt panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Eclipse BIRT Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/eclipse-birt-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">eclipse-birt-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Shiva (Strobes Security)</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 11, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Eclipse BIRT Home&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Eclipse BIRT (Business Intelligence Reporting Tool) detected</div></div></div>
  <div class="nt-tags"><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">eclipsebirt</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://eclipse.github.io/birt-website/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="eclipse jetty - directory listing enabled low identify critical remote vulnerabilities eclipse jetty server has directory listing enabled, which exposes the directory structure and file names to unauthenticated users. this can reveal sensitive files, backup files, configuration files, and aid attackers in reconnaissance. ritikchaddha jetty misconfig exposure listing eclipse" data-nt-sev="low">
  <div class="nt-card-header">
    <div class="nt-title">Eclipse Jetty - Directory Listing Enabled</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/misconfiguration/jetty-directory-listing.yaml" target="_blank" rel="noopener" class="nt-source-link">jetty-directory-listing.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 19, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.head.server&#34;] matches &#34;Jetty&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Eclipse Jetty server has directory listing enabled, which exposes the directory structure and file names to unauthenticated users. This can reveal sensitive files, backup files, configuration files, and aid attackers in reconnaissance.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can enumerate files and directories, discover hidden resources, backup files, configuration files, and potentially sensitive data that should not be publicly accessible.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Disable directory listing by setting dirAllowed to false in the DefaultServlet configuration or by setting allowDirectoryListing to false in WebAppContext. Add index files (index.html) to directories that should not list contents.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">jetty</span><span class="nt-tag">misconfig</span><span class="nt-tag">exposure</span><span class="nt-tag">listing</span><span class="nt-tag">eclipse</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.eclipse.org/jetty/documentation/jetty-11/operations-guide/index.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://owasp.org/www-project-web-security-testing-guide/latest/4-Web_Application_Security_Testing/02-Configuration_and_Deployment_Management_Testing/04-Review_Old_Backup_and_Unreferenced_Files_for_Sensitive_Information" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://cwe.mitre.org/data/definitions/548.html" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="eclipse theia ide panel - detect info identify web-based control panels detected eclipse theia ide panel was exposed. theia is an extensible platform for multi-language cloud and desktop ides. exposed panels may have allowed unauthenticated access to development environments and terminal. 0x_akoko theia ide panel detect tech discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Eclipse Theia IDE Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/theia-ide-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">theia-ide-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_Akoko</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 23, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Theia IDE&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detected Eclipse Theia IDE panel was exposed. Theia is an extensible platform for multi-language Cloud and Desktop IDEs. Exposed panels may have allowed unauthenticated access to development environments and terminal.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">theia</span><span class="nt-tag">ide</span><span class="nt-tag">panel</span><span class="nt-tag">detect</span><span class="nt-tag">tech</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/eclipse-theia/theia" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://theia-ide.org/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="edito cms - sensitive data leak high identify critical remote vulnerabilities web services managed by edito cms (content management system) in versions from 3.5 through 3.25 leak sensitive data as they allow downloading configuration files by an unauthorized user. cve-2024-4836 s4e-io cms cve cve2024 edito info-leak vuln cwe-552" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Edito CMS - Sensitive Data Leak</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-4836.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-4836.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> s4e-io</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 3, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/552.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-552</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-4836" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-4836</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1491301339&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Web services managed by Edito CMS (Content Management System) in versions from 3.5 through 3.25 leak sensitive data as they allow downloading configuration files by an unauthorized user.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can download configuration files containing sensitive credentials from Edito CMS installations.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update Edito CMS to a version later than 3.25 that secures configuration file access.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cms</span><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">edito</span><span class="nt-tag">info-leak</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://cert.pl/en/posts/2024/07/CVE-2024-4836/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/sleep46/CVE-2024-4836_Check" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-4836" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="efrotech timetrax v8.3 - sql injection high identify critical remote vulnerabilities efrotech timetrax v8.3 was discovered to contain an unauthenticated sql injection vulnerability via the q parameter in the search web interface. cve-2024-39250 s4e-io,efran cve cve2024 sqli timetrax vuln cwe-89" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">EfroTech Timetrax v8.3 - Sql Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-39250.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-39250.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> s4e-io,efran</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 24, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-39250" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-39250</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-661694518&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">EfroTech Timetrax v8.3 was discovered to contain an unauthenticated SQL injection vulnerability via the q parameter in the search web interface.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can execute SQL injection attacks to extract or modify sensitive timetrax database information.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update EfroTech Timetrax to a version later than v8.3 that patches the SQL injection vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">sqli</span><span class="nt-tag">timetrax</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-39250" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.tenable.com/cve/CVE-2024-39250" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/efrann/CVE-2024-39250" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://vuldb.com/?id.272268" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="eko charger management console login panel - detect info identify web-based control panels eko charger management console login panel was detected. clem9669 panel eko discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Eko Charger Management Console Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/eko-management-console-login.yaml" target="_blank" rel="noopener" class="nt-source-link">eko-management-console-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> clem9669</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Charger Management Console&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Eko Charger Management Console login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">eko</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://ekoenergetyka.com.pl/software-solutions/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="eko software update panel - detect info identify web-based control panels eko software update panel for embedded systems was detected. an attacker can possibly upload a software image or restart the system. clem9669 panel eko discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Eko Software Update Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/eko-software-update-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">eko-software-update-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> clem9669</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Ekoenergetyka-Polska Sp\\. z o\\.o - CCU3 Software Update for Embedded Systems&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Eko software update panel for embedded systems was detected. An attacker can possibly upload a software image or restart the system.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">eko</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://ekoenergetyka.com.pl/software-solutions/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="ekoapi admin panel - detect info identify web-based control panels ekoapi admin panel was detected. rxerium panel ekoapi discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">EkoAPI Admin Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/ekoapi-admin-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">ekoapi-admin-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 5, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)EkoAPI Admin&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">EkoAPI Admin panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">ekoapi</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="ektron cms login panel - detect info identify web-based control panels ektron cms login panel was detected. pikpikcu cms discovery ektron panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Ektron CMS Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/extron-cms-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">extron-cms-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pikpikcu</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)ektron&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Ektron CMS login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cms</span><span class="nt-tag">discovery</span><span class="nt-tag">ektron</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="elasticsearch - default login high identify default logins in web-based control panels elasticsearch default credentials were discovered. mohammad reza omrani | @omranisecurity default-login elasticsearch vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">ElasticSearch - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/elasticsearch/elasticsearch-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">elasticsearch-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Mohammad Reza Omrani | @omranisecurity</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 24, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;Elastic&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Elasticsearch default credentials were discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">elasticsearch</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.alibabacloud.com/blog/what-is-the-default-username-and-password-for-elasticsearch_599610" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.elastic.co/guide/en/elasticsearch/reference/current/built-in-users.html" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="elber ese dvb-s/s2 - authentication bypass critical identify critical remote vulnerabilities multiple elber products are affected by an authentication bypass vulnerability which allows unauthorized access to the password management functionality. attackers can exploit this issue by manipulating the endpoint to overwrite any user&#39;s password within the system. cve-2025-0674 dhiyaneshdk auth-bypass cve cve2025 elber vkev vuln cwe-288" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Elber ESE DVB-S/S2 - Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-0674.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-0674.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 28, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/288.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-288</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-0674" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-0674</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Elber Satellite Equipment&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Multiple Elber products are affected by an authentication bypass vulnerability which allows unauthorized access to the password management functionality. Attackers can exploit this issue by manipulating the endpoint to overwrite any user&#39;s password within the system.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">This grants them unauthorized administrative access to protected areas of the application, compromising the device&#39;s system security.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply security patches from Elber or restrict access to the password management endpoints to authorized networks only.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">elber</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.cisa.gov/news-events/ics-advisories/icsa-25-035-03" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/eeeeeeeeee-code/POC/blob/main/wpoc/wayber/Elber-Wayber%E6%A8%A1%E6%8B%9F%E6%95%B0%E5%AD%97%E9%9F%B3%E9%A2%91%E5%AF%86%E7%A0%81%E9%87%8D%E7%BD%AE%E6%BC%8F%E6%B4%9E.md?plain=1" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-0674" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="electrolink fm/dab/tv transmitter - credentials disclosure high identify critical remote vulnerabilities a credential exposure vulnerability in electrolink 500w, 1kw, 2kw medium dab transmitter web v01.09, v01.08, v01.07, and display v1.4, v1.2 allows unauthorized attackers to access credentials in plaintext. cve-2025-28228 dhiyaneshdk cve cve2025 electrolink info-leak vuln cwe-522" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Electrolink FM/DAB/TV Transmitter - Credentials Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-28228.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-28228.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 29, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/522.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-522</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-28228" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-28228</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Electrolink&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A credential exposure vulnerability in Electrolink 500W, 1kW, 2kW Medium DAB Transmitter Web v01.09, v01.08, v01.07, and Display v1.4, v1.2 allows unauthorized attackers to access credentials in plaintext.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can access plaintext credentials through the controlloLogin.js file, potentially gaining unauthorized access to Electrolink transmitter management interfaces.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Change default credentials and restrict access to the controlloLogin.js file.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">electrolink</span><span class="nt-tag">info-leak</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/shiky8/my--cve-vulnerability-research/tree/main/CVE-2025-28228" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="elemiz network manager login panel - detect info identify web-based control panels elemiz network manager login panel was detected. pussycat0x elemiz manager login panel discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Elemiz Network Manager Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/elemiz-network-manager.yaml" target="_blank" rel="noopener" class="nt-source-link">elemiz-network-manager.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Elemiz Network Manager&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Elemiz Network Manager login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">elemiz</span><span class="nt-tag">manager</span><span class="nt-tag">login</span><span class="nt-tag">panel</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="elestio memos &lt;= v0.24.0 - server-side request forgery critical identify critical remote vulnerabilities elestio memos v0.23.0 is vulnerable to server-side request forgery (ssrf) due to insufficient validation of user-supplied urls, which can be exploited to perform ssrf attacks. cve-2025-22952 iamnoooob,rootxharsh,pdresearch cve cve2025 elestio memos oast ssrf vkev vuln cwe-918" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Elestio Memos &lt;= v0.24.0 - Server-Side Request Forgery</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-22952.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-22952.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> iamnoooob,rootxharsh,pdresearch</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 4, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/918.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-918</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-22952" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-22952</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-1924700661&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">elestio memos v0.23.0 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of user-supplied URLs, which can be exploited to perform SSRF attacks.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can exploit SSRF vulnerabilities to access internal services, bypass network security controls, and potentially retrieve sensitive information from internal systems.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to Memos version 0.24.1 or later that properly validates and restricts URL access.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">elestio</span><span class="nt-tag">memos</span><span class="nt-tag">oast</span><span class="nt-tag">ssrf</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/advisories/GHSA-wfxg-v3j4-7qmj" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://elest.io/open-source/memos" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/usememos/memos" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/usememos/memos/issues/4413" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/usememos/memos/pull/4428" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="email subscribers by icegram express &lt;= 5.7.20 - unauthenticated sql injection via hash critical identify critical remote vulnerabilities email subscribers by icegram express &lt;= 5.7.20 contains an unauthenticated sql injection vulnerability via the hash parameter. cve-2024-4295 iamnoooob,rootxharsh,pdresearch cve cve2024 email-subscribers sqli time-based-sqli vkev vuln wordpress wp wp-plugin cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Email Subscribers by Icegram Express &lt;= 5.7.20 - Unauthenticated SQL Injection via Hash</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-4295.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-4295.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> iamnoooob,rootxharsh,pdresearch</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 24, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-4295" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-4295</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/email-subscribers/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Email Subscribers by Icegram Express &lt;= 5.7.20 contains an unauthenticated SQL injection vulnerability via the hash parameter.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Fixed in 5.7.21</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">email-subscribers</span><span class="nt-tag">sqli</span><span class="nt-tag">time-based-sqli</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/641123af-1ec6-4549-a58c-0a08b4678f45?source=cve" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/cve-2024/CVE-2024-4295-Poc" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/truonghuuphuc/CVE-2024-4295-Poc" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-4295" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="emby login panel - detect info identify web-based control panels emby login panel was detected. idealphase panel emby oss discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Emby Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/emby-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">emby-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> idealphase</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)emby&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Emby login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">emby</span><span class="nt-tag">oss</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/MediaBrowser/Emby" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://emby.media/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="emby server - authentication bypass critical identify critical remote vulnerabilities emby server is a user-installable home media server which stores and organizes a user&#39;s media files of virtually any format and makes them available for viewing at home and abroad on a broad range of client devices. this vulnerability may allow administrative access to an emby server system, depending on certain user account settings. by spoofing certain headers which are intended for interoperation with reverse proxy servers, it may be possible to affect the local/non-local network determination to allow logging in without password or to view a list of user accounts which may have no password configured. impacted are all emby server system which are publicly accessible and where the administrator hasn&#39;t tightened the account login configuration for administrative users. this issue has been patched in emby server beta version 4.8.31 and emby server version 4.7.12. cve-2023-33193 daffainfo auth-bypass cve cve2023 emby vkev cwe-444" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Emby Server - Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-33193.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-33193.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> daffainfo</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 21, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/444.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-444</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-33193" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-33193</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;product&#34;] contains &#34;Emby:Emby&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Emby Server is a user-installable home media server which stores and organizes a user&#39;s media files of virtually any format and makes them available for viewing at home and abroad on a broad range of client devices. This vulnerability may allow administrative access to an Emby Server system, depending on certain user account settings. By spoofing certain headers which are intended for interoperation with reverse proxy servers, it may be possible to affect the local/non-local network determination to allow logging in without password or to view a list of user accounts which may have no password configured. Impacted are all Emby Server system which are publicly accessible and where the administrator hasn&#39;t tightened the account login configuration for administrative users. This issue has been patched in Emby Server Beta version 4.8.31 and Emby Server version 4.7.12.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can gain unauthorized administrative access or view user accounts without passwords, risking full control over the server.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to Emby Server version 4.8.31 or 4.7.12.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">emby</span><span class="nt-tag">vkev</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/EmbySupport/Emby.Security/security/advisories/GHSA-fffj-6fr6-3fgf" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-33193" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="emerson network power intellislot web card panel - detect info identify web-based control panels emerson network power intellislot web card panel was detected. princechaddha panel intellislot emerson discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Emerson Network Power IntelliSlot Web Card Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/emerson-power-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">emerson-power-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> princechaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Emerson Network Power IntelliSlot Web Card&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Emerson Network Power IntelliSlot Web Card panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">intellislot</span><span class="nt-tag">emerson</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="emqx default admin login high identify default logins in web-based control panels emqx default admin credentials were discovered. for3stco1d default-login emqx vuln cwe-522" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Emqx Default Admin Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/emqx/emqx-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">emqx-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> For3stCo1d</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/522.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-522</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-670975485&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Emqx default admin credentials were discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">emqx</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="engenius enshare iot gigabit cloud service 1.4.11 root remote code execution critical identify critical remote vulnerabilities an os command injection vulnerability exists in engenius enshare cloud service version 1.4.11 and earlier.the usbinteract.cgi script fails to properly sanitize user input passed to the path parameter, allowing unauthenticated remote attackers to inject arbitrary shell commands.the injected commands are executed with root privileges, leading to full system compromise. cve-2025-34035 intelligent-ears cve cve2025 engenius enshare rce vkev vuln cwe-78" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">EnGenius EnShare IoT Gigabit Cloud Service 1.4.11 Root Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-34035.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-34035.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> intelligent-ears</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 20, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/78.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-78</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-34035" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-34035</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/web/cgi-bin/usbinfo\\.cgi&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An OS command injection vulnerability exists in EnGenius EnShare Cloud Service version 1.4.11 and earlier.The usbinteract.cgi script fails to properly sanitize user input passed to the path parameter, allowing unauthenticated remote attackers to inject arbitrary shell commands.The injected commands are executed with root privileges, leading to full system compromise.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can inject and execute arbitrary shell commands with root privileges through the path parameter in usbinteract.cgi, achieving complete system compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade EnGenius EnShare Cloud Service to version 1.4.12 or later that properly sanitizes user input in CGI scripts.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">engenius</span><span class="nt-tag">enshare</span><span class="nt-tag">rce</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://cxsecurity.com/issue/WLB-2017060050" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.exploit-db.com/exploits/42114" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.zeroscience.mk/en/vulnerabilities/ZSL-2017-5413.php" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-34035" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="enablix panel - detect info identify web-based control panels enablix panel was detected. dhiyaneshdk enablix login panel discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Enablix Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/enablix-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">enablix-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 6, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Enablix&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Enablix panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">enablix</span><span class="nt-tag">login</span><span class="nt-tag">panel</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="endpoint protector login panel - detect info identify web-based control panels endpoint protector - reporting and administration tool login panel was detected. pussycat0x panel endpoint login detect endpoint-protector discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Endpoint Protector Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/endpoint-protector-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">endpoint-protector-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 1, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Endpoint Protector&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Endpoint Protector - Reporting and Administration Tool login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">endpoint</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">endpoint-protector</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="enjoyrmis - sql injection high identify critical remote vulnerabilities enjoyrmis getoabyid has a sql injection vulnerability, through which an attacker can obtain sensitive database information and even control the server. s4e-io enjoyrmis sqli vuln cwe-89" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">EnjoyRMIS - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/vulnerabilities/other/enjoyrmis-sqli.yaml" target="_blank" rel="noopener" class="nt-source-link">enjoyrmis-sqli.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> s4e-io</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 10, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)CheckSilverlightInstalled&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">EnjoyRMIS GetOAById has a SQL injection vulnerability, through which an attacker can obtain sensitive database information and even control the server.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">enjoyrmis</span><span class="nt-tag">sqli</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/wy876/POC/blob/main/EnjoyRMIS-GetOAById%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="envoy proxy - metadata disclosure info identify critical remote vulnerabilities detected misconfigured envoy proxy instances that disclose sensitive information about the target infrastructure via the &#34;x-envoy-peer-metadata&#34; response header. theamanrawat envoy exposure misconfig disclosure" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Envoy Proxy - Metadata Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/misconfiguration/envoy-metadata-disclosure.yaml" target="_blank" rel="noopener" class="nt-source-link">envoy-metadata-disclosure.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> theamanrawat</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 20, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.head.xEnvoyPeerMetadata&#34;] != &#34;&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detected misconfigured Envoy proxy instances that disclose sensitive information about the target infrastructure via the &#34;x-envoy-peer-metadata&#34; response header.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">envoy</span><span class="nt-tag">exposure</span><span class="nt-tag">misconfig</span><span class="nt-tag">disclosure</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.acunetix.com/vulnerabilities/web/envoy-metadata-disclosure/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.envoyproxy.io/docs/envoy/latest/configuration/configuration" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="episerver login panel info identify web-based control panels episerver login panel was detected. william söderberg @ withsecure discovery episerver optimizely panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Episerver Login Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/episerver-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">episerver-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> William Söderberg @ WithSecure</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)epihash&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Episerver login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">episerver</span><span class="nt-tag">optimizely</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://docs.developers.optimizely.com/content-cloud/v12.0.0-content-cloud/docs/changing-edit-and-admin-view-urls" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="error log viewer by wp guru &lt;= 1.0.1.3 - missing authorization to arbitrary file read high identify critical remote vulnerabilities the error log viewer by wp guru plugin for wordpress is vulnerable to arbitrary file read in all versions up to, and including, 1.0.1.3 via the wp_ajax_nopriv_elvwp_log_download ajax action. this makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. cve-2024-12849 s4e-io cve cve2024 error-log-viewer-wp lfi vuln wordpress wp wp-plugin cwe-22" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Error Log Viewer By WP Guru &lt;= 1.0.1.3 - Missing Authorization to Arbitrary File Read</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-12849.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-12849.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> s4e-io</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 7, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-12849" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-12849</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)wp-content/plugins/error-log-viewer-wp&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The Error Log Viewer By WP Guru plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 1.0.1.3 via the wp_ajax_nopriv_elvwp_log_download AJAX action. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can read arbitrary files on the server including sensitive configuration files with database credentials and other sensitive data.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update Error Log Viewer By WP Guru plugin to a version newer than 1.0.1.3.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">error-log-viewer-wp</span><span class="nt-tag">lfi</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/RandomRobbieBF/CVE-2024-12849" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/57888e36-3a61-4452-b4ea-9db9e422dc2d?source=cve" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-12849" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/advisories/GHSA-899p-f2mf-g895" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="erxes &lt;0.23.0 - cross-site scripting critical identify critical remote vulnerabilities erxes before 0.23.0 contains a cross-site scripting vulnerability. the value of topicid parameter is not escaped and is triggered in the enclosing script tag. cve-2021-32853 dwisiswant0 cve cve2021 erxes oss vuln xss cwe-79" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Erxes &lt;0.23.0 - Cross-Site Scripting</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2021/CVE-2021-32853.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2021-32853.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dwisiswant0</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-79</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2021-32853" target="_blank" rel="noopener" class="nt-cve-link">CVE-2021-32853</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)erxes&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Erxes before 0.23.0 contains a cross-site scripting vulnerability. The value of topicID parameter is not escaped and is triggered in the enclosing script tag.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute malicious scripts in the context of the victim&#39;s browser, potentially leading to session hijacking, defacement, or theft of sensitive information.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to Erxes version 0.23.0 or later to mitigate the vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2021</span><span class="nt-tag">erxes</span><span class="nt-tag">oss</span><span class="nt-tag">vuln</span><span class="nt-tag">xss</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://securitylab.github.com/advisories/GHSL-2021-103-erxes/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2021-3285" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/erxes/erxes/blob/f131b49add72032650d483f044d00658908aaf4a/widgets/server/views/widget.ejs#L14" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/erxes/erxes/blob/f131b49add72032650d483f044d00658908aaf4a/widgets/server/index.ts#L54" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="esafenet cdg netsecconfigajax - sql injection high identify critical remote vulnerabilities the `state` parameter of the `netsecconfigajax` interface of the yisaitong electronic document security management system does not pre-compile and adequately verify the incoming data, resulting in a sql injection vulnerability in the interface. malicious attackers may obtain the server through this vulnerability information or directly obtain server permissions. adeljck esafenet sqli vuln cwe-89" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Esafenet CDG NetSecConfigAjax - Sql Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/vulnerabilities/esafenet/esafenet-netsecconfigajax-sqli.yaml" target="_blank" rel="noopener" class="nt-source-link">esafenet-netsecconfigajax-sqli.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> adeljck</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 24, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)电子文档安全管理系统&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The `state` parameter of the `NetSecConfigAjax` interface of the Yisaitong electronic document security management system does not pre-compile and adequately verify the incoming data, resulting in a SQL injection vulnerability in the interface. Malicious attackers may obtain the server through this vulnerability information or directly obtain server permissions.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">esafenet</span><span class="nt-tag">sqli</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="esafenet cdg noticeajax - sql injection high identify critical remote vulnerabilities cdgserver3 noticeajax interface sql injection. adeljck esafenet sqli vuln cwe-89" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Esafenet CDG NoticeAjax - Sql Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/vulnerabilities/esafenet/esafenet-noticeajax-sqli.yaml" target="_blank" rel="noopener" class="nt-source-link">esafenet-noticeajax-sqli.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> adeljck</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 24, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)电子文档安全管理系统&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">CDGServer3 NoticeAjax Interface Sql Injection.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">esafenet</span><span class="nt-tag">sqli</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="eset protect login panel - detect info identify web-based control panels login page for eset protect charles d. login eset panel detect discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Eset Protect Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/eset-protect-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">eset-protect-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Charles D.</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 8, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;751911084&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Login page for Eset Protect</div></div></div>
  <div class="nt-tags"><span class="nt-tag">login</span><span class="nt-tag">eset</span><span class="nt-tag">panel</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="eslint ignore file exposure low identify critical remote vulnerabilities eslint ignore file was exposed. dhiyaneshdk eslintignore misconfig vuln" data-nt-sev="low">
  <div class="nt-card-header">
    <div class="nt-title">Eslint Ignore File Exposure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/misconfiguration/eslint-ignore-exposure.yaml" target="_blank" rel="noopener" class="nt-source-link">eslint-ignore-exposure.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 10, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)eslintignore&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Eslint Ignore File was exposed.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">eslintignore</span><span class="nt-tag">misconfig</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://eslint.org/docs/latest/use/configure/ignore" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="espec web controller - panel info identify web-based control panels espec web controller panel was discovered. darses panel espec ics login discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Espec Web Controller - Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/espec-web-controller-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">espec-web-controller-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> darses</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 14, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;529766441&#34; || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Espec Web Controller&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Espec Web Controller panel was discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">espec</span><span class="nt-tag">ics</span><span class="nt-tag">login</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://espec.com/na/products/option_detail/web_controller/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="espocrm - detect info identify web-based control panels espocrm panel was detected. theamanrawat detect discovery espocrm panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">EspoCRM - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/espocrm-detect.yaml" target="_blank" rel="noopener" class="nt-source-link">espocrm-detect.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> theamanrawat</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 12, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-197006674&#34; || service[&#34;http.body&#34;] matches &#34;(?i)Powered by EspoCRM&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">EspoCRM panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">espocrm</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="essential blocks &lt; 4.4.3 - local file inclusion critical identify critical remote vulnerabilities wordpress essential blocks plugin prior to 4.4.3 was discovered to be vulnerable to a significant local file inclusion vulnerability that may be exploited by any attacker, regardless of whether they have an account on the site. cve-2023-6623 iamnoooob,rootxharsh,pdresearch,coldfish cve cve2023 essential-blocks lfi vkev vuln wordpress wp wp-plugin wpdeveloper wpscan cwe-22" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Essential Blocks &lt; 4.4.3 - Local File Inclusion</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-6623.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-6623.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> iamnoooob,rootxharsh,pdresearch,coldfish</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 4, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-6623" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-6623</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/essential-blocks/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Wordpress Essential Blocks plugin prior to 4.4.3 was discovered to be vulnerable to a significant Local File Inclusion vulnerability that may be exploited by any attacker, regardless of whether they have an account on the site.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can exploit this vulnerability to access sensitive information, such as configuration files, credentials, or other sensitive data stored on the server.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to the latest version of Essential Blocks 4.4.3 to fix this issue.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">essential-blocks</span><span class="nt-tag">lfi</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">wpdeveloper</span><span class="nt-tag">wpscan</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wpscan.com/blog/file-inclusion-vulnerability-fixed-in-essential-blocks-4-4-3/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://flysec-blog.blogspot.com/2024/01/cve-2023-6623-file-inclusion.html" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-6623" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="eurotel etl3100 - default login high identify default logins in web-based control panels the tv and fm transmitter uses a weak set of default administrative credentials that can be guessed in remote password attacks and gain full control of the system. r3y3r53 default-login eurotel misconfig vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">EuroTel ETL3100 - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/eurotel/etl3100-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">etl3100-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> r3Y3r53</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 17, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;ETL3100&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The TV and FM transmitter uses a weak set of default administrative credentials that can be guessed in remote password attacks and gain full control of the system.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">eurotel</span><span class="nt-tag">misconfig</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.zeroscience.mk/en/vulnerabilities/ZSL-2023-5782.php" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.exploit-db.com/exploits/51684" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="eventon (free &lt; 2.2.8, premium &lt; 4.5.5) - information disclosure medium identify critical remote vulnerabilities the eventon wordpress plugin before 4.5.5, eventon wordpress plugin before 2.2.7 do not have authorization in an ajax action, allowing unauthenticated users to retrieve email addresses of any users on the blog. cve-2024-0235 projectdiscoveryai cve cve2024 eventon exposure myeventon vkev vuln wordpress wp wp-plugin wpscan cwe-862" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">EventON (Free &lt; 2.2.8, Premium &lt; 4.5.5) - Information Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-0235.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-0235.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ProjectDiscoveryAI</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 28, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/862.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-862</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-0235" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-0235</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/eventon-lite/&#34; || service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/eventon/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not have authorization in an AJAX action, allowing unauthenticated users to retrieve email addresses of any users on the blog.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker could potentially access sensitive email information.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest version of the EventON WordPress Plugin to mitigate CVE-2024-0235.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">eventon</span><span class="nt-tag">exposure</span><span class="nt-tag">myeventon</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">wpscan</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wpscan.com/vulnerability/e370b99a-f485-42bd-96a3-60432a15a4e9/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/fkie-cad/nvd-json-data-feeds" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-0235" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="eventon &lt;= 2.1 - missing authorization medium identify critical remote vulnerabilities the eventon wordpress plugin before 2.1.2 lacks authentication and authorization in its eventon_ics_download ajax action, allowing unauthenticated visitors to access private and password protected events by guessing their numeric id. cve-2023-2796 randomrobbie bypass cve cve2023 eventon myeventon packetstorm vkev vuln wordpress wp wp-plugin wpscan cwe-862" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">EventON &lt;= 2.1 - Missing Authorization</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-2796.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-2796.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> randomrobbie</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 11, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/862.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-862</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-2796" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-2796</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/eventon/&#34; || service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/eventon-lite/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The EventON WordPress plugin before 2.1.2 lacks authentication and authorization in its eventon_ics_download ajax action, allowing unauthenticated visitors to access private and password protected Events by guessing their numeric id.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated users can perform privileged actions, potentially leading to unauthorized access or modification of events.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Fixed in version 2.1.2</div></div></div>
  <div class="nt-tags"><span class="nt-tag">bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">eventon</span><span class="nt-tag">myeventon</span><span class="nt-tag">packetstorm</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">wpscan</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/dba3f3a6-3f55-4f4e-98e4-bb98d9c94bdd" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://wpscan.com/vulnerability/e9ef793c-e5a3-4c55-beee-56b0909f7a0d" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-2796" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="http://packetstormsecurity.com/files/173984/WordPress-EventON-Calendar-4.4-Insecure-Direct-Object-Reference.html" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/nullfuzz-pentest/shodan-dorks" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="eventon lite &lt; 2.1.2 - arbitrary file download medium identify critical remote vulnerabilities the plugin does not validate that the event_id parameter in its eventon_ics_download ajax action is a valid event, allowing unauthenticated visitors
to access any post (including unpublished or protected posts) content via the ics export functionality by providing the numeric id of the post. cve-2023-3219 r3y3r53 bypass cve cve2023 eventon-lite myeventon packetstorm vuln wordpress wp wp-plugin wpscan cwe-639" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">EventON Lite &lt; 2.1.2 - Arbitrary File Download</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-3219.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-3219.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> r3Y3r53</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 17, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/639.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-639</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-3219" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-3219</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/eventon/&#34; || service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/eventon-lite/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The plugin does not validate that the event_id parameter in its eventon_ics_download ajax action is a valid Event, allowing unauthenticated visitors
to access any Post (including unpublished or protected posts) content via the ics export functionality by providing the numeric id of the post.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can exploit missing validation in the eventon_ics_download AJAX action to access any post content including unpublished or protected posts through ICS export functionality.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Fixed in version 2.1.2</div></div></div>
  <div class="nt-tags"><span class="nt-tag">bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">eventon-lite</span><span class="nt-tag">myeventon</span><span class="nt-tag">packetstorm</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">wpscan</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wpscan.com/vulnerability/72d80887-0270-4987-9739-95b1a178c1fd" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-3219" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://packetstormsecurity.com/files/173992/WordPress-EventON-Calendar-4.4-Insecure-Direct-Object-Reference.html" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://wordpress.org/plugins/eventon-lite/" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="http://packetstormsecurity.com/files/173992/WordPress-EventON-Calendar-4.4-Insecure-Direct-Object-Reference.html" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="eventum login panel - detect info identify web-based control panels eventum login panel was detected. princechaddha discovery eventum mysql panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Eventum Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/eventum-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">eventum-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> princechaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;305412257&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Eventum login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">eventum</span><span class="nt-tag">mysql</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="evertz sdvn 3080ipx-10g - unauthenticated arbitrary command injection critical identify critical remote vulnerabilities the evertz sdvn 3080ipx-10g is a high bandwidth ethernet switching fabric for video application. this device exposes a web management interface on port 80. this web management interface can be used by administrators to control product features, setup network switching, and register license among other features. the application has been developed in php with the webeasy sdk, also named ‘ewb’ by evertz.this web interface has two endpoints that are vulnerable to arbitrary command injection and the authentication mechanism has a flaw leading to authentication bypass.remote unauthenticated attackers can gain arbitrary command execution with elevated privileges ( root ) on affected devices.this level of access could lead to serious business impact such as the interruption of media streaming, modification of media being streamed, alteration of closed captions being generated, among others. cve-2025-4009 onekey,iamnoooob,pdresearch cve cve2025 evertz rce unauth vkev vuln cwe-77" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Evertz SDVN 3080ipx-10G - Unauthenticated Arbitrary Command Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-4009.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-4009.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ONEKEY,iamnoooob,pdresearch</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 12, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/77.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-77</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-4009" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-4009</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)evertz\\.min\\.css&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The Evertz SDVN 3080ipx-10G is a High Bandwidth Ethernet Switching Fabric for Video Application. This device exposes a web management interface on port 80. This web management interface can be used by administrators to control product features, setup network switching, and register license among other features. The application has been developed in PHP with the webEASY SDK, also named ‘ewb’ by Evertz.This web interface has two endpoints that are vulnerable to arbitrary command injection and the authentication mechanism has a flaw leading to authentication bypass.Remote unauthenticated attackers can gain arbitrary command execution with elevated privileges ( root ) on affected devices.This level of access could lead to serious business impact such as the interruption of media streaming, modification of media being streamed, alteration of closed captions being generated, among others.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can bypass authentication and execute arbitrary commands with root privileges, potentially disrupting media streaming or manipulating content.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the security patch from Evertz or restrict network access to the web management interface to trusted administrators only.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">evertz</span><span class="nt-tag">rce</span><span class="nt-tag">unauth</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.onekey.com/resource/security-advisory-remote-code-execution-on-evertz-svdn-cve-2025-4009" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="evidently ai panel - detect info identify web-based control panels evidently ai is an ml/llm observability platform for monitoring data drift and model performance. rxerium ai detect discovery evidently ml monitoring observability panel" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Evidently AI Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/evidently-ai-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">evidently-ai-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 27, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;Evidently&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Evidently AI is an ML/LLM observability platform for monitoring data drift and model performance.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">ai</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">evidently</span><span class="nt-tag">ml</span><span class="nt-tag">monitoring</span><span class="nt-tag">observability</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/evidentlyai/evidently" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.evidentlyai.com" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="exagrid manager login panel - detect info identify web-based control panels exagrid manager login panel was detected. pussycat0x discovery exagrid login manager panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">ExaGrid Manager Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/exagrid-manager-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">exagrid-manager-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)exagrid manager&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">ExaGrid Manager login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">exagrid</span><span class="nt-tag">login</span><span class="nt-tag">manager</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="exchange server - remote code execution critical identify critical remote vulnerabilities microsoft exchange server is vulnerable to a remote code execution vulnerability. this cve id is unique from cve-2021-31196, cve-2021-31206. cve-2021-34473 arcc,intx0x80,dwisiswant0,r3dg33k cve cve2021 exchange kev microsoft rce ssrf vkev vuln cwe-918" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Exchange Server - Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2021/CVE-2021-34473.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2021-34473.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> arcc,intx0x80,dwisiswant0,r3dg33k</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/918.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-918</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2021-34473" target="_blank" rel="noopener" class="nt-cve-link">CVE-2021-34473</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1768726119&#34; || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)outlook&#34;}) || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)outlook exchange&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Microsoft Exchange Server is vulnerable to a remote code execution vulnerability. This CVE ID is unique from CVE-2021-31196, CVE-2021-31206.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected Exchange Server, potentially leading to a complete compromise of the system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply Microsoft Exchange Server 2019 Cumulative Update 9 or upgrade to the latest version.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2021</span><span class="nt-tag">exchange</span><span class="nt-tag">kev</span><span class="nt-tag">microsoft</span><span class="nt-tag">rce</span><span class="nt-tag">ssrf</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-34473" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://blog.orange.tw/2021/08/proxylogon-a-new-attack-surface-on-ms-exchange-part-1.html" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://peterjson.medium.com/reproducing-the-proxyshell-pwn2own-exploit-49743a4ea9a1" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2021-34473" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-34473" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="exolis engage panel - detect info identify web-based control panels exolis engage panel was detected. righettod panel exolis engage discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Exolis Engage Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/exolis-engage-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">exolis-engage-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)engage - Portail soignant&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Exolis Engage panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">exolis</span><span class="nt-tag">engage</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.exolis.fr/en/solution-2/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="export wp page to static html &lt;= 4.3.4 - cookie exposure critical identify critical remote vulnerabilities export wp page to static html &amp; pdf wordpress plugin &lt;= 4.3.4 contains a sensitive information exposure caused by publicly exposed cookies.txt files with authentication cookies, letting unauthenticated attackers access sensitive authentication data, exploit requires site administrator to trigger backup with specific user role. cve-2025-11693 0x_akoko cve cve2025 export-wp-page-to-static-html exposure wordpress wp wp-plugin cwe-200" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Export WP Page to Static HTML &lt;= 4.3.4 - Cookie Exposure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-11693.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-11693.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_Akoko</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 23, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-11693" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-11693</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/export-wp-page-to-static-html/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Export WP Page to Static HTML &amp; PDF WordPress plugin &lt;= 4.3.4 contains a sensitive information exposure caused by publicly exposed cookies.txt files with authentication cookies, letting unauthenticated attackers access sensitive authentication data, exploit requires site administrator to trigger backup with specific user role.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can access authentication cookies, potentially leading to account compromise or unauthorized access.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest version beyond 4.3.4.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">export-wp-page-to-static-html</span><span class="nt-tag">exposure</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/export-wp-page-to-static-html/export-wp-page-to-static-html-pdf-434-unauthenticated-cookie-exposure-via-log-file" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-11693" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="exposed mcp json-rpc 2.0 api detection unknown identify critical remote vulnerabilities detects exposed machine control protocol (mcp) servers through json-rpc 2.0 api endpoints.
mcp servers often provide administrative access to ai tools, llm systems, or other automation infrastructure.
exposed mcp interfaces can lead to unauthorized access, information disclosure, and potential system compromise.
this template tests multiple detection methods including tools/list, rpc.discover, resources/list, and prompts/list. ivan_wallarm ai api devtools discovery exposure jsonrpc llm mcp" data-nt-sev="unknown">
  <div class="nt-card-header">
    <div class="nt-title">Exposed MCP JSON-RPC 2.0 API Detection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-unknown fd-badge-sm">Unknown</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposures/apis/exposed-mcp-server.yaml" target="_blank" rel="noopener" class="nt-source-link">exposed-mcp-server.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ivan_wallarm</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 10, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.bodies&#34;]), {# matches &#34;(?i)get requires an active session&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detects exposed Machine Control Protocol (MCP) servers through JSON-RPC 2.0 API endpoints.
MCP servers often provide administrative access to AI tools, LLM systems, or other automation infrastructure.
Exposed MCP interfaces can lead to unauthorized access, information disclosure, and potential system compromise.
This template tests multiple detection methods including tools/list, rpc.discover, resources/list, and prompts/list.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">ai</span><span class="nt-tag">api</span><span class="nt-tag">devtools</span><span class="nt-tag">discovery</span><span class="nt-tag">exposure</span><span class="nt-tag">jsonrpc</span><span class="nt-tag">llm</span><span class="nt-tag">mcp</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://jsonrpc.org/specification" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/anthropics/anthropic-tools/tree/main/mcp" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://lab.wallarm.com/wallarm-research-nuclei-template-counter-threats-targeting-llm-apps/" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="extensive vc addons for wpbakery page builder &lt; 1.9.1 - unauthenticated rce high identify critical remote vulnerabilities the plugin does not validate a parameter passed to the php extract function when loading templates, allowing an unauthenticated attacker to override the template path to read arbitrary files from the hosts file system. this may be escalated to rce using php filter chains. cve-2023-0159 c4sper0 cve cve2023 extensive-vc-addon lfi vkev vuln wordpress wp-plugin wpbakery wprealize" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Extensive VC Addons for WPBakery page builder &lt; 1.9.1 - Unauthenticated RCE</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-0159.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-0159.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> c4sper0</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 31, 2024</span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-0159" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-0159</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/extensive-vc-addon/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The plugin does not validate a parameter passed to the php extract function when loading templates, allowing an unauthenticated attacker to override the template path to read arbitrary files from the hosts file system. This may be escalated to RCE using PHP filter chains.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can exploit parameter validation flaws in the template loading mechanism to read arbitrary files including wp-config.php and escalate to remote code execution using PHP filter chains.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Fixed in 1.9.1</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">extensive-vc-addon</span><span class="nt-tag">lfi</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">wpbakery</span><span class="nt-tag">wprealize</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wpscan.com/vulnerability/239ea870-66e5-4754-952e-74d4dd60b809/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/im-hanzou/EVCer" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/nomi-sec/PoC-in-GitHub" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/xu-xiang/awesome-security-vul-llm" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://wordpress.org/plugins/extensive-vc-addon/" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="extreme netconfig ui panel - detect info identify web-based control panels extreme netconfig ui panel was detected. pussycat0x panel tech hiveos extreme discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Extreme NetConfig UI Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/extreme-netconfig-ui.yaml" target="_blank" rel="noopener" class="nt-source-link">extreme-netconfig-ui.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Extreme NetConfig UI&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Extreme NetConfig UI panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">tech</span><span class="nt-tag">hiveos</span><span class="nt-tag">extreme</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="eyesofnetwork - hardcoded api key critical identify critical remote vulnerabilities an issue was discovered in eyesofnetwork 5.3. the installation uses the same api key (hardcoded as eonapi_key in include/api_functions.php for api version 2.4.2) by default for all installations, hence allowing an attacker to calculate/guess the admin access token. cve-2020-8657 daffainfo cve cve2020 eyesofnetwork hardcoded-key kev vkev vuln cwe-798" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">EyesOfNetwork - Hardcoded API Key</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2020/CVE-2020-8657.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2020-8657.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> daffainfo</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 22, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/798.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-798</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2020-8657" target="_blank" rel="noopener" class="nt-cve-link">CVE-2020-8657</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)EyesOfNetwork&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An issue was discovered in EyesOfNetwork 5.3. The installation uses the same API key (hardcoded as EONAPI_KEY in include/api_functions.php for API version 2.4.2) by default for all installations, hence allowing an attacker to calculate/guess the admin access token.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation allows an attacker to create administrative users and gain unauthorized access to the EyesOfNetwork management system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to a newer version of EyesOfNetwork or change the default hardcoded API key in the configuration.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2020</span><span class="nt-tag">eyesofnetwork</span><span class="nt-tag">hardcoded-key</span><span class="nt-tag">kev</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.exploit-db.com/exploits/48025" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2020-8657" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="eyesofnetwork - hardcoded api key &amp; sql injection critical identify critical remote vulnerabilities an issue was discovered in eyesofnetwork 5.3. the eyesofnetwork api 2.4.2 is prone to sql injection, allowing an unauthenticated attacker to perform various tasks such as authentication bypass via the username field to getapikey in include/api_functions.php. cve-2020-8656 ritikchaddha cve cve2020 eyesofnetwork hardcoded-key sqli vkev vuln cwe-798" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">EyesOfNetwork - Hardcoded API Key &amp; SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2020/CVE-2020-8656.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2020-8656.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 24, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/798.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-798</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2020-8656" target="_blank" rel="noopener" class="nt-cve-link">CVE-2020-8656</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)EyesOfNetwork&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An issue was discovered in EyesOfNetwork 5.3. The EyesOfNetwork API 2.4.2 is prone to SQL injection, allowing an unauthenticated attacker to perform various tasks such as authentication bypass via the username field to getApiKey in include/api_functions.php.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can bypass authentication via SQL injection and gain access to the EyesOfNetwork monitoring system and all monitored infrastructure data.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply security patches or update to the latest version of EyesOfNetwork.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2020</span><span class="nt-tag">eyesofnetwork</span><span class="nt-tag">hardcoded-key</span><span class="nt-tag">sqli</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.exploit-db.com/exploits/48025" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2020-8656" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/EyesOfNetworkCommunity/eonapi/issues/17" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="eyoucms v1.6.3 - information disclosure medium identify critical remote vulnerabilities eyoucms v1.6.3 was discovered to contain an information disclosure vulnerability via the component /custom_model_path/recruit.filelist.txt. cve-2023-37645 pussycat0x cve cve2023 eyoucms info-leak vuln cwe-668" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">EyouCms v1.6.3 - Information Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-37645.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-37645.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 15, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/668.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-668</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-37645" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-37645</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)eyoucms&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">EyouCms v1.6.3 was discovered to contain an information disclosure vulnerability via the component /custom_model_path/recruit.filelist.txt.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can exploit this vulnerability to gain sensitive information.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade eYouCMS to a patched version to mitigate CVE-2023-37645.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">eyoucms</span><span class="nt-tag">info-leak</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/weng-xianhu/eyoucms/issues/50" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="f-secure policy manager server login panel - detect info identify web-based control panels f-secure policy manager server login panel was detected. dhiyaneshdk discovery login panel withsecure cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">F-Secure Policy Manager Server Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/f-secure-policy-manager.yaml" target="_blank" rel="noopener" class="nt-source-link">f-secure-policy-manager.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)f-secure policy manager server&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">F-Secure Policy Manager Server login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">login</span><span class="nt-tag">panel</span><span class="nt-tag">withsecure</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="f-logic datacube3 - sql injection high identify critical remote vulnerabilities sql injection vulnerability in f-logic datacube3 v.1.0 allows a remote attacker to obtain sensitive information via the req_id parameter. cve-2024-31750 dhiyaneshdk cve cve2024 datacube3 sqli vkev vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">F-logic DataCube3 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-31750.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-31750.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 17, 2024</span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-31750" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-31750</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)DataCube3&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">SQL injection vulnerability in f-logic datacube3 v.1.0 allows a remote attacker to obtain sensitive information via the req_id parameter.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can execute arbitrary SQL queries, potentially extracting or modifying sensitive database information.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update F-logic DataCube3 to a version that patches the SQL injection vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">datacube3</span><span class="nt-tag">sqli</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/lampSEC/semcms/blob/main/datacube3.md" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/MrWQ/vulnerability-paper/blob/master/bugs/DataCube3%20getting_index_data.php%20SQL%20%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-31750" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/wjlin0/poc-doc" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/wy876/POC" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="f5 admin interface - detect info identify web-based control panels detects f5 admin interfaces. drewvravick,righettod f5 admin detect panel login discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">F5 Admin Interface - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/f5-admin-interface.yaml" target="_blank" rel="noopener" class="nt-source-link">f5-admin-interface.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> drewvravick,righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 3, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)BIG-IP Configuration Utility&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detects F5 Admin Interfaces.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">f5</span><span class="nt-tag">admin</span><span class="nt-tag">detect</span><span class="nt-tag">panel</span><span class="nt-tag">login</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="f5 big-ip tmui - remote code execution critical identify critical remote vulnerabilities f5 big-ip versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the traffic management user interface (tmui), also referred to as the configuration utility, has a remote code execution (rce) vulnerability in undisclosed pages. cve-2020-5902 madrobot,dwisiswant0,ringo bigip cve cve2020 f5 kev packetstorm rce vkev vuln cwe-22" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">F5 BIG-IP TMUI - Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2020/CVE-2020-5902.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2020-5902.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> madrobot,dwisiswant0,ringo</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2020-5902" target="_blank" rel="noopener" class="nt-cve-link">CVE-2020-5902</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)big-ip&amp;reg;-\\+redirect\&#34; \\+\&#34;server&#34;}) || service[&#34;http.body&#34;] matches &#34;(?i)big-ip apm&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">F5 BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic Management User Interface (TMUI), also referred to as the Configuration utility, has a Remote Code Execution (RCE) vulnerability in undisclosed pages.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the necessary security patches or upgrade to a non-vulnerable version of F5 BIG-IP TMUI.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">bigip</span><span class="nt-tag">cve</span><span class="nt-tag">cve2020</span><span class="nt-tag">f5</span><span class="nt-tag">kev</span><span class="nt-tag">packetstorm</span><span class="nt-tag">rce</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="http://packetstormsecurity.com/files/158333/BIG-IP-TMUI-Remote-Code-Execution.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="http://packetstormsecurity.com/files/158334/BIG-IP-TMUI-Remote-Code-Execution.html" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="http://packetstormsecurity.com/files/158366/F5-BIG-IP-TMUI-Directory-Traversal-File-Upload-Code-Execution.html" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="http://packetstormsecurity.com/files/158414/Checker-CVE-2020-5902.html" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="http://packetstormsecurity.com/files/158581/F5-Big-IP-13.1.3-Build-0.0.6-Local-File-Inclusion.html" target="_blank" rel="noopener" class="nt-ref-link">[5]</a> <a href="https://badpackets.net/over-3000-f5-big-ip-endpoints-vulnerable-to-cve-2020-5902/" target="_blank" rel="noopener" class="nt-ref-link">[6]</a> <a href="https://github.com/Critical-Start/Team-Ares/tree/master/CVE-2020-5902" target="_blank" rel="noopener" class="nt-ref-link">[7]</a> <a href="https://support.f5.com/csp/article/K52145254" target="_blank" rel="noopener" class="nt-ref-link">[8]</a> <a href="https://swarm.ptsecurity.com/rce-in-f5-big-ip/" target="_blank" rel="noopener" class="nt-ref-link">[9]</a> <a href="https://www.criticalstart.com/f5-big-ip-remote-code-execution-exploit/" target="_blank" rel="noopener" class="nt-ref-link">[10]</a> <a href="https://www.kb.cert.org/vuls/id/290915" target="_blank" rel="noopener" class="nt-ref-link">[11]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2020-5902" target="_blank" rel="noopener" class="nt-ref-link">[12]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="f5 big-ip icontrol - rest auth bypass rce critical identify critical remote vulnerabilities f5 big-ip 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all 12.1.x and 11.6.x versions, may allow undisclosed requests to bypass icontrol rest authentication. cve-2022-1388 dwisiswant0,ph33r bigip cve cve2022 f5 kev mirai rce vkev vuln cwe-306" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">F5 BIG-IP iControl - REST Auth Bypass RCE</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-1388.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-1388.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dwisiswant0,Ph33r</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/306.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-306</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-1388" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-1388</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)big-ip&amp;reg;-\\+redirect\&#34; \\+\&#34;server&#34;}) || service[&#34;http.body&#34;] matches &#34;(?i)big-ip apm&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all 12.1.x and 11.6.x versions, may allow undisclosed requests to bypass iControl REST authentication.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to bypass authentication and execute arbitrary code on the affected system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the necessary security patches or updates provided by F5 Networks to mitigate this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">bigip</span><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">f5</span><span class="nt-tag">kev</span><span class="nt-tag">mirai</span><span class="nt-tag">rce</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://twitter.com/GossiTheDog/status/1523566937414193153" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.horizon3.ai/f5-icontrol-rest-endpoint-authentication-bypass-technical-deep-dive/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://support.f5.com/csp/article/K23605346" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1388" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://www.secpod.com/blog/critical-f5-big-ip-remote-code-execution-vulnerability-patch-now/" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="f5 big-ip icontrol rest panel - detect info identify web-based control panels f5 big-ip icontrol rest api discovered and may be vulnerable to an authentication bypass (not tested). mrcl0wnlab bigip discovery f5 panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">F5 BIG-IP iControl REST Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/bigip-rest-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">bigip-rest-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> MrCl0wnLab</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)big-ip&amp;reg;-\\+redirect&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">F5 BIG-IP iControl REST API discovered and may be vulnerable to an authentication bypass (not tested).</div></div></div>
  <div class="nt-tags"><span class="nt-tag">bigip</span><span class="nt-tag">discovery</span><span class="nt-tag">f5</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-1388" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://support.f5.com/csp/article/K23605346" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://clouddocs.f5.com/products/big-iq/mgmt-api/v5.4/ApiReferences/bigiq_api_ref/r_auth_login.html" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="f5 icontrol rest - remote command execution critical identify critical remote vulnerabilities f5 icontrol rest interface is susceptible to remote command execution. an attacker can execute malware, obtain sensitive information, modify data, and/or gain full control over a compromised system without entering necessary credentials. this affects big-ip 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3; and big-iq 7.1.0.x before 7.1.0.3 and 7.0.0.x before 7.0.0.2. cve-2021-22986 rootxharsh,iamnoooob bigip cve cve2021 f5 kev packetstorm rce vkev vuln cwe-918" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">F5 iControl REST - Remote Command Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2021/CVE-2021-22986.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2021-22986.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rootxharsh,iamnoooob</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/918.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-918</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2021-22986" target="_blank" rel="noopener" class="nt-cve-link">CVE-2021-22986</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)big-ip&amp;reg;-\\+redirect\&#34; \\+\&#34;server&#34;}) || service[&#34;http.body&#34;] matches &#34;(?i)big-ip apm&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">F5 iControl REST interface is susceptible to remote command execution. An attacker can execute malware, obtain sensitive information, modify data, and/or gain full control over a compromised system without entering necessary credentials. This affects BIG-IP 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3; and BIG-IQ 7.1.0.x before 7.1.0.3 and 7.0.0.x before 7.0.0.2.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability can lead to unauthorized access, data leakage, and potential compromise of the target system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the necessary security patches or updates provided by F5 Networks to mitigate the vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">bigip</span><span class="nt-tag">cve</span><span class="nt-tag">cve2021</span><span class="nt-tag">f5</span><span class="nt-tag">kev</span><span class="nt-tag">packetstorm</span><span class="nt-tag">rce</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://attackerkb.com/topics/J6pWeg5saG/k03009991-icontrol-rest-unauthenticated-remote-command-execution-vulnerability-cve-2021-22986" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://support.f5.com/csp/article/K03009991" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="http://packetstormsecurity.com/files/162059/F5-iControl-Server-Side-Request-Forgery-Remote-Command-Execution.html" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2021-22986" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/Miraitowa70/POC-Notes" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="fastpanel login panel - detect info identify web-based control panels fastpanel login panel was detected. pikpikcu panel fastpanel discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">FASTPANEL Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/fastpanel-hosting-control-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">fastpanel-hosting-control-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pikpikcu</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)FASTPANEL HOSTING CONTROL&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">FASTPANEL login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">fastpanel</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="fog project &lt; 1.5.10.34 - remote command execution critical identify critical remote vulnerabilities fog is a cloning/imaging/rescue suite/inventory management system. prior to 1.5.10.34, packages/web/lib/fog/reportmaker.class.php in fog was affected by a command injection via the filename parameter to /fog/management/export.php. cve-2024-39914 s4e-io cve cve2024 fog rce vkev vuln cwe-77" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">FOG Project &lt; 1.5.10.34 - Remote Command Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-39914.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-39914.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> s4e-io</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 24, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/77.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-77</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-39914" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-39914</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-1952619005&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">FOG is a cloning/imaging/rescue suite/inventory management system. Prior to 1.5.10.34, packages/web/lib/fog/reportmaker.class.php in FOG was affected by a command injection via the filename parameter to /fog/management/export.php.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can exploit command injection to achieve remote code execution on the FOG server.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update FOG Project to version 1.5.10.34 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">fog</span><span class="nt-tag">rce</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-39914" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-39914" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/FOGProject/fogproject/security/advisories/GHSA-7h44-6vq6-cq8j" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://blog.csdn.net/qq_39894062/article/details/140550009" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="fossbilling panel - detect info identify web-based control panels fossbilling panel has been detected. ritikchaddha fossbilling panel detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">FOSSBilling Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/fossbilling-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">fossbilling-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 16, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)FOSSBilling&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">FOSSBilling panel has been detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">fossbilling</span><span class="nt-tag">panel</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="freedom administration - default login critical identify critical remote vulnerabilities the web gui configuration panel of hirsch (formerly identiv and viscount) enterphone mesh through 2024 ships with default credentials (username freedom, password viscount). the administrator is not prompted to change these credentials on initial configuration, and changing the credentials requires many steps. attackers can use the credentials over the internet via mesh.webadmin.meshadminservlet to gain access to dozens of canadian and u.s. apartment buildings and obtain building residents&#39; pii. note- the supplier&#39;s perspective is that the &#34;vulnerable systems are not following manufacturers&#39; recommendations to change the default password.&#34; cve-2025-26793 eric daigle,dhiyaneshdk admin cve cve2025 freedom mesh vkev vuln cwe-1393" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">FREEDOM Administration - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-26793.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-26793.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Eric Daigle,DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 5, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/1393.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-1393</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-26793" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-26793</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)FREEDOM Administration&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The Web GUI configuration panel of Hirsch (formerly Identiv and Viscount) Enterphone MESH through 2024 ships with default credentials (username freedom, password viscount). The administrator is not prompted to change these credentials on initial configuration, and changing the credentials requires many steps. Attackers can use the credentials over the Internet via mesh.webadmin.MESHAdminServlet to gain access to dozens of Canadian and U.S. apartment buildings and obtain building residents&#39; PII. NOTE- the Supplier&#39;s perspective is that the &#34;vulnerable systems are not following manufacturers&#39; recommendations to change the default password.&#34;</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can gain unauthorized access to building management systems using default credentials, potentially exposing residents&#39; personally identifiable information and controlling access to apartment buildings.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Change default credentials immediately to strong, unique passwords as recommended in the manufacturer&#39;s security guidelines.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">admin</span><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">freedom</span><span class="nt-tag">mesh</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.ericdaigle.ca/posts/breaking-into-dozens-of-apartments-in-five-minutes/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://news.ycombinator.com/item?id=43160884" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://support.identiv.com/products/physical-access/hirsch/" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="fuel cms 1.4.1 - remote code execution critical identify critical remote vulnerabilities fuel cms 1.4.1 allows php code evaluation via the pages/select/ filter parameter or the preview/ data parameter. cve-2018-16763 pikpikcu cve cve2018 edb fuelcms rce thedaylightstudio vkev vuln cwe-74" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">FUEL CMS 1.4.1 - Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2018/CVE-2018-16763.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2018-16763.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pikpikcu</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/74.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-74</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2018-16763" target="_blank" rel="noopener" class="nt-cve-link">CVE-2018-16763</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)fuel cms&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability allows an attacker to execute arbitrary code on the target system, leading to complete compromise of the application and potentially the underlying server.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to FUEL CMS version 1.4.2 or later, which includes a patch for this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2018</span><span class="nt-tag">edb</span><span class="nt-tag">fuelcms</span><span class="nt-tag">rce</span><span class="nt-tag">thedaylightstudio</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.exploit-db.com/exploits/47138" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.getfuelcms.com/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/daylightstudio/FUEL-CMS/releases/tag/1.4.1" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2018-16763" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/daylightstudio/FUEL-CMS/issues/478" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="fuxa - scada/hmi panel info identify web-based control panels fuxa is an open-source web-based scada/hmi platform built on node.js.
it supports modbus, opc-ua, bacnet, mqtt, and siemens s7 protocols and
is widely self-hosted for small industrial deployments. instances are
frequently exposed to the internet without authentication. rxerium discovery fuxa hmi ics modbus nodejs opc-ua open-source panel scada" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">FUXA - SCADA/HMI Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/fuxa-scada-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">fuxa-scada-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 27, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches `(?i)powered by (?:frangoteam|&lt;span&gt;&lt;b&gt;frango&lt;/b&gt;team&lt;/span&gt;)`</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">FUXA is an open-source web-based SCADA/HMI platform built on Node.js.
It supports Modbus, OPC-UA, BACnet, MQTT, and Siemens S7 protocols and
is widely self-hosted for small industrial deployments. Instances are
frequently exposed to the internet without authentication.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">fuxa</span><span class="nt-tag">hmi</span><span class="nt-tag">ics</span><span class="nt-tag">modbus</span><span class="nt-tag">nodejs</span><span class="nt-tag">opc-ua</span><span class="nt-tag">open-source</span><span class="nt-tag">panel</span><span class="nt-tag">scada</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/frangoteam/FUXA" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="fuxa &lt;= 1.2.7 - hardcoded jwt secret authentication bypass critical identify critical remote vulnerabilities fuxa v1.2.7 contains a hardcoded credentials vulnerability caused by use of a hard-coded secret key in server/api/jwt-helper.js, letting remote attackers forge admin tokens and bypass authentication, exploit requires no special conditions. cve-2025-69971 trader642 auth-bypass cve cve2025 frangoteam fuxa hardcoded-credentials jwt scada vuln cwe-321" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">FUXA &lt;= 1.2.7 - Hardcoded JWT Secret Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-69971.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-69971.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> trader642</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 16, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/321.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-321</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-69971" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-69971</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)FUXA&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">FUXA v1.2.7 contains a hardcoded credentials vulnerability caused by use of a hard-coded secret key in server/api/jwt-helper.js, letting remote attackers forge admin tokens and bypass authentication, exploit requires no special conditions.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Remote attackers can bypass authentication and gain full administrative access.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest version that removes hard-coded credentials.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">frangoteam</span><span class="nt-tag">fuxa</span><span class="nt-tag">hardcoded-credentials</span><span class="nt-tag">jwt</span><span class="nt-tag">scada</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/frangoteam/FUXA/security/advisories/GHSA-32cc-x95p-fxcg" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-69971" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/frangoteam/FUXA/blob/master/server/api/jwt-helper.js" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="facefusion panel - detect info identify web-based control panels facefusion panel was detected. facefusion is a next-generation face swapper and enhancer. rxerium ai deepfake detect discovery face-swap facefusion panel" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">FaceFusion Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/facefusion-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">facefusion-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 27, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;FaceFusion&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">FaceFusion panel was detected. FaceFusion is a next-generation face swapper and enhancer.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">ai</span><span class="nt-tag">deepfake</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">face-swap</span><span class="nt-tag">facefusion</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/facefusion/facefusion" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://facefusion.io" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="falcosidekick ui login panel - detect info identify web-based control panels falcosidekick ui login panel was detected. righettod panel falco detect login discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Falcosidekick UI Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/falcosidekick-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">falcosidekick-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 14, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Falcosidekick&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Falcosidekick UI login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">falco</span><span class="nt-tag">detect</span><span class="nt-tag">login</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/falcosecurity/falcosidekick-ui" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="faraday login panel - detect info identify web-based control panels faraday login panel was detected. dhiyaneshdk discovery faraday panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Faraday Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/faraday-login.yaml" target="_blank" rel="noopener" class="nt-source-link">faraday-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)faradayApp&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Faraday login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">faraday</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="fastadmin &lt; v1.3.4.20220530 - path traversal medium identify critical remote vulnerabilities a vulnerability, which was classified as problematic, has been found in fastadmin up to 1.3.3.20220121. affected by this issue is some unknown functionality of the file /index/ajax/lang. the manipulation of the argument lang leads to path traversal. the attack may be launched remotely. the exploit has been disclosed to the public and may be used. upgrading to version 1.3.4.20220530 is able to address this issue. it is recommended to upgrade the affected component. cve-2024-7928 s4e-io,hel10-web cve cve2024 fastadmin lfi vkev vuln cwe-22" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">FastAdmin &lt; V1.3.4.20220530 - Path Traversal</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-7928.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-7928.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> s4e-io,Hel10-Web</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 20, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-7928" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-7928</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-1036943727&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A vulnerability, which was classified as problematic, has been found in FastAdmin up to 1.3.3.20220121. Affected by this issue is some unknown functionality of the file /index/ajax/lang. The manipulation of the argument lang leads to path traversal. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.3.4.20220530 is able to address this issue. It is recommended to upgrade the affected component.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Authenticated attackers can exploit path traversal to read sensitive files including database configuration files containing credentials, usernames, passwords, and other critical system information.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update FastAdmin to version 1.3.4.20220530 or later to address the path traversal vulnerability in the lang parameter.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">fastadmin</span><span class="nt-tag">lfi</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wiki.shikangsi.com/post/share/da0292b8-0f92-4e6e-bdb7-73f47b901acd" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/bigb0x/CVE-2024-7928" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-7928" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="fastgpt panel - detect info identify web-based control panels fastgpt is a knowledge-based platform built on the llm, offering out-of-the-box
data processing and model invocation capabilities. rxerium ai detect discovery fastgpt llm panel rag" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">FastGPT Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/fastgpt-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">fastgpt-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 27, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)FastGPT 是一个&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">FastGPT is a knowledge-based platform built on the LLM, offering out-of-the-box
data processing and model invocation capabilities.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">ai</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">fastgpt</span><span class="nt-tag">llm</span><span class="nt-tag">panel</span><span class="nt-tag">rag</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/labring/FastGPT" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://fastgpt.in" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="fastmile 5g gateway panel - detect info identify web-based control panels fastmile 5g gateway web interface was discovered. th3l0newolf 5g detect discovery login panel router cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">FastMile 5G Gateway Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/fastmile-5g-gateway-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">fastmile-5g-gateway-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Th3l0newolf</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 19, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)FastMile 5G Gateway&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">FastMile 5G Gateway web interface was discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">5g</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">login</span><span class="nt-tag">panel</span><span class="nt-tag">router</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="fastify swagger-ui - information disclosure medium identify critical remote vulnerabilities fastify-swagger-ui is a fastify plugin for serving swagger ui.  prior to 2.1.0, the default configuration of `@fastify/swagger-ui` without `basedir` set will lead to all files in the module&#39;s directory being exposed via http routes served by the module.  the vulnerability is fixed in v2.1.0. setting the `basedir` option can also work around this vulnerability. cve-2024-22207 dhiyaneshdk,iamnoooob cve cve2024 exposure swagger-ui vuln cwe-1188" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Fastify Swagger-UI - Information Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-22207.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-22207.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK,iamnoooob</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 23, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/1188.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-1188</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-22207" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-22207</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-1180440057&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">fastify-swagger-ui is a Fastify plugin for serving Swagger UI.  Prior to 2.1.0, the default configuration of `@fastify/swagger-ui` without `baseDir` set will lead to all files in the module&#39;s directory being exposed via http routes served by the module.  The vulnerability is fixed in v2.1.0. Setting the `baseDir` option can also work around this vulnerability.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can access sensitive files in the Fastify Swagger-UI module directory, potentially exposing source code or configuration files.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update @fastify/swagger-ui to version 2.1.0 or later, or configure the baseDir option.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">exposure</span><span class="nt-tag">swagger-ui</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://security.netapp.com/advisory/ntap-20240216-0002/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-22207" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="fastly backend server information disclosure low identify critical remote vulnerabilities detected fastly cdn misconfigured and exposing backend/origin server ip addresses or hostnames in http response headers. 0x_akoko exposure fastly cdn misconfig cwe-200" data-nt-sev="low">
  <div class="nt-card-header">
    <div class="nt-title">Fastly Backend Server Information Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/misconfiguration/fastly-backend-info-disclosure.yaml" target="_blank" rel="noopener" class="nt-source-link">fastly-backend-info-disclosure.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_Akoko</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 21, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.head.xBackendServer&#34;] != &#34;&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detected Fastly CDN misconfigured and exposing backend/origin server IP addresses or hostnames in HTTP response headers.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">exposure</span><span class="nt-tag">fastly</span><span class="nt-tag">cdn</span><span class="nt-tag">misconfig</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://developer.fastly.com/reference/http/http-headers/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="feiyuxing enterprise-level management system - default login high identify default logins in web-based control panels attackers can log in through admin:admin, check the system status, and configure the device. sleepingbag945 default-login feiyuxing iot vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Feiyuxing Enterprise-Level Management System - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/feiyuxing/feiyuxing-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">feiyuxing-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> SleepingBag945</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 21, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)飞鱼星企业级智能上网行为管理系统&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Attackers can log in through admin:admin, check the system status, and configure the device.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">feiyuxing</span><span class="nt-tag">iot</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/wushigudan/poc/blob/main/%E9%A3%9E%E9%B1%BC%E6%98%9F%E9%BB%98%E8%AE%A4%E5%AF%86%E7%A0%81.py" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="femtocell access point panel - detect info identify web-based control panels femtocell access point panel was discovered. dhiyaneshdk femtocell network panel login discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Femtocell Access Point Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/femtocell-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">femtocell-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 23, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Femtocell Access Point&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Femtocell Access Point panel was discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">femtocell</span><span class="nt-tag">network</span><span class="nt-tag">panel</span><span class="nt-tag">login</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://en.wikipedia.org/wiki/Femtocell" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.facebook.com/photo/?fbid=844447314392456&amp;set=a.467014098802448" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="fides privacy center ≤ 2.39.1 - server-side url disclosure medium identify critical remote vulnerabilities fides versions 2.19.0 to before 2.39.2rc0 contain an information disclosure caused by unauthenticated http get request to the privacy center, letting attackers access the server_side_fides_api_url, which may reveal server configuration details, exploit requires no authentication. cve-2024-31223 hnd3884 cve cve2024 disclosure ethyca fides vkev vuln cwe-497" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Fides Privacy Center ≤ 2.39.1 - Server-Side URL Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-31223.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-31223.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> hnd3884</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 4, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/497.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-497</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-31223" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-31223</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)SERVER_SIDE_FIDES_API_URL&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Fides versions 2.19.0 to before 2.39.2rc0 contain an information disclosure caused by unauthenticated HTTP GET request to the Privacy Center, letting attackers access the SERVER_SIDE_FIDES_API_URL, which may reveal server configuration details, exploit requires no authentication.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can obtain server-side URLs, revealing private IPs, ports, and domain names, potentially aiding further targeted attacks.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to version 2.39.2rc0 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">disclosure</span><span class="nt-tag">ethyca</span><span class="nt-tag">fides</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/ethyca/fides/commit/0555080541f18a5aacff452c590ac9a1b56d7097" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/ethyca/fides/security/advisories/GHSA-53q7-4874-24qg" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-31223" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="file browser login panel - detect info identify web-based control panels  ritikchaddha detect discovery filebrowser panel" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">File Browser Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/filebrowser-login-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">filebrowser-login-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 9, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1052926265&#34;</code></div>
  <div class="nt-tags"><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">filebrowser</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://filebrowser.org/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="filecatalyst file transfer solution - detect info identify web-based control panels detects the presence of filecatalyst file transfer solution login panel dhiyaneshdk panel login filecatalyst detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">FileCatalyst File Transfer Solution - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/filecatalyst-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">filecatalyst-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 18, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)FileCatalyst file transfer solution&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detects the presence of FileCatalyst file transfer solution login panel</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">login</span><span class="nt-tag">filecatalyst</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="filegator panel - detect info identify web-based control panels  ritikchaddha filegator panel login detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">FileGator Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/filegator-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">filegator-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 23, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)FileGator&#34;})</code></div>
  <div class="nt-tags"><span class="nt-tag">filegator</span><span class="nt-tag">panel</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://serverpilot.io/docs/how-to-install-a-file-manager-on-your-server/#:~:text=You%20should%20see%20the%20FileGator,Password%3A%20admin123" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="filemage gateway - directory traversal high identify critical remote vulnerabilities directory traversal vulnerability in filemage gateway windows deployments v.1.10.8 and before allows a remote attacker to obtain sensitive information via a crafted request to the /mgmt/ component. cve-2023-39026 dhiyaneshdk cve cve2023 filemage lfi microsoft packetstorm vkev vuln cwe-22" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">FileMage Gateway - Directory Traversal</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-39026.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-39026.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 24, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-39026" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-39026</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)filemage&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Directory Traversal vulnerability in FileMage Gateway Windows Deployments v.1.10.8 and before allows a remote attacker to obtain sensitive information via a crafted request to the /mgmt/ component.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can view, modify, or delete sensitive files on the system, potentially leading to unauthorized access, data leakage, or system compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches or updates provided by the vendor to fix the directory traversal vulnerability in FileMage Gateway.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">filemage</span><span class="nt-tag">lfi</span><span class="nt-tag">microsoft</span><span class="nt-tag">packetstorm</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://raindayzz.com/technicalblog/2023/08/20/FileMage-Vulnerability.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://securityonline.info/cve-2023-39026-filemage-gateway-directory-traversal-vulnerability/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-39026" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://www.filemage.io/docs/updates.html#change-log" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="http://packetstormsecurity.com/files/174491/FileMage-Gateway-1.10.9-Local-File-Inclusion.html" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="filegator - default-login high identify default logins in web-based control panels  ritikchaddha default-login filegator misconfig vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Filegator - Default-Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/filegator/filegator-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">filegator-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 24, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;FileGator&#34;})</code></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">filegator</span><span class="nt-tag">misconfig</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://serverpilot.io/docs/how-to-install-a-file-manager-on-your-server/#:~:text=You%20should%20see%20the%20FileGator,Password%3A%20admin123" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="financial transaction manager login panel - detect info identify web-based control panels financial transaction manager login panel was detected. idealphase discovery ftm ibm panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Financial Transaction Manager Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/ftm-manager-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">ftm-manager-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> idealphase</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)ftm manager&#34; || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)ftm manager&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Financial Transaction Manager login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">ftm</span><span class="nt-tag">ibm</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="fireware xtm login panel - detect info identify web-based control panels fireware xtm login panel was detected. dhiyaneshdk discovery panel watchguard cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Fireware XTM Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/fireware-xtm-user-authentication.yaml" target="_blank" rel="noopener" class="nt-source-link">fireware-xtm-user-authentication.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)fireware xtm user authentication&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Fireware XTM login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">watchguard</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="flahscookie superadmin login panel - detect info identify web-based control panels flahscookie superadmin login panel was detected. hardik-solanki panel flahscookie superadmin discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Flahscookie Superadmin Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/flahscookie-superadmin-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">flahscookie-superadmin-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Hardik-Solanki</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Flahscookie Superadmin&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Flahscookie Superadmin login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">flahscookie</span><span class="nt-tag">superadmin</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="flatpress &lt; 1.3 - path traversal critical identify critical remote vulnerabilities path traversal in github repository flatpressblog/flatpress prior to 1.3. cve-2023-0947 r3y3r53 cve cve2023 flatpress huntr lfi listing vuln cwe-22" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Flatpress &lt; 1.3 - Path Traversal</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-0947.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-0947.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> r3Y3r53</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 17, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-0947" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-0947</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-1189292869&#34; || service[&#34;http.body&#34;] matches &#34;(?i)flatpress&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Path Traversal in GitHub repository flatpressblog/flatpress prior to 1.3.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can exploit path traversal to access and list sensitive directories and files in the FlatPress blogging system, potentially exposing configuration files and user data.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update FlatPress to version 1.3 or later that properly validates directory paths and prevents unauthorized directory listing in fp-content.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">flatpress</span><span class="nt-tag">huntr</span><span class="nt-tag">lfi</span><span class="nt-tag">listing</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://huntr.dev/bounties/7379d702-72ff-4a5d-bc68-007290015496/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-0947" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/flatpressblog/flatpress/commit/9c4e5d6567e446c472f3adae3b2fe612f66871c7" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="fleetcart 4.1.1 - information disclosure medium identify critical remote vulnerabilities issues with information disclosure in redirect responses. accessing the majority of the website&#39;s pages exposes sensitive data, including the &#34;razorpay&#34; &#34;razorpaykeyid&#34;. cve-2024-5230 s4e-io cms cve cve2024 fleetcart info-leak packetstorm vuln cwe-200" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">FleetCart 4.1.1 - Information Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-5230.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-5230.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> s4e-io</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 24, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-5230" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-5230</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)FleetCart&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Issues with information disclosure in redirect responses. Accessing the majority of the website&#39;s pages exposes sensitive data, including the &#34;Razorpay&#34; &#34;razorpayKeyId&#34;.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can access sensitive configuration data including Razorpay payment gateway API keys through information disclosure in redirect responses.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update FleetCart to a version later than 4.1.1 that addresses this information disclosure vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cms</span><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">fleetcart</span><span class="nt-tag">info-leak</span><span class="nt-tag">packetstorm</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-5230" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://packetstormsecurity.com/files/178770/FleetCart-4.1.1-Information-Disclosure.html" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://codecanyon.net/item/fleetcart-laravel-ecommerce-system/23014826" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://vuldb.com/?ctiid.265981" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://vuldb.com/?id.265981" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="flexnet operations panel - detect info identify web-based control panels flexnet operations was detected — a software monetization platform. righettod panel flexnet login detect" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">FlexNet Operations Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/flexnet-operations-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">flexnet-operations-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 26, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)FlexNet Login&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">FlexNet Operations was detected — a software monetization platform.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">flexnet</span><span class="nt-tag">login</span><span class="nt-tag">detect</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://resources.flexera.com/web/media/documents/Datasheet-FNO-Overview.pdf" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.flexera.com" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="flexible checkout fields for woocommerce &lt;= 2.3.1 - unauthenticated arbitrary plugin settings update high identify critical remote vulnerabilities the flexible checkout fields for woocommerce  plugin for wordpress is vulnerable to unauthenticated arbitrary plugin settings update, in addition to stored cross-site scripting in versions up to, and including, 2.3.1. this is due to missing authorization checks on the updatesettingsaction() function which is called via an admin_init hook, along with missing sanitization and escaping on the settings that are stored. cve-2020-36731 popcorn94 cve cve2020 flexible-checkout-fields vkev vuln wordpress wp wp-plugin xss cwe-79" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Flexible Checkout Fields for WooCommerce &lt;= 2.3.1 - Unauthenticated Arbitrary Plugin Settings Update</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2020/CVE-2020-36731.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2020-36731.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> popcorn94</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 23, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-79</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2020-36731" target="_blank" rel="noopener" class="nt-cve-link">CVE-2020-36731</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/flexible-checkout-fields/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The Flexible Checkout Fields for WooCommerce  plugin for WordPress is vulnerable to Unauthenticated Arbitrary Plugin Settings update, in addition to Stored Cross-Site Scripting in versions up to, and including, 2.3.1. This is due to missing authorization checks on the updateSettingsAction() function which is called via an admin_init hook, along with missing sanitization and escaping on the settings that are stored.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can arbitrarily update plugin settings and inject stored XSS payloads, potentially taking over the WordPress site or stealing administrator credentials.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Fixed in 2.3.2.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2020</span><span class="nt-tag">flexible-checkout-fields</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">xss</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-11972" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.wordfence.com/blog/2020/02/site-takeover-campaign-exploits-multiple-zero-day-vulnerabilities/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/fd12a952-2e99-41f7-b74c-55c2b7d8deed?source=cve" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="flightpath - local file inclusion medium identify critical remote vulnerabilities flightpath versions prior to 4.8.2 and 5.0-rc2 are vulnerable to local file inclusion. cve-2019-13396 0x_akoko,daffainfo cve cve2019 edb flightpath getflightpath lfi vkev vuln cwe-22" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">FlightPath - Local File Inclusion</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2019/CVE-2019-13396.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2019-13396.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_Akoko,daffainfo</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2019-13396" target="_blank" rel="noopener" class="nt-cve-link">CVE-2019-13396</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1560589236&#34; || service[&#34;http.body&#34;] matches `(?i)FlightPath\.settings`</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">FlightPath versions prior to 4.8.2 and 5.0-rc2 are vulnerable to local file inclusion.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">This vulnerability can lead to unauthorized access, data leakage, and remote code execution.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to the latest version to mitigate this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2019</span><span class="nt-tag">edb</span><span class="nt-tag">flightpath</span><span class="nt-tag">getflightpath</span><span class="nt-tag">lfi</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.exploit-db.com/exploits/47121" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="http://getflightpath.com/node/2650" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2019-13396" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/ARPSyndicate/kenzer-templates" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/d4n-sec/d4n-sec.github.io" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="flightpath login panel - detect info identify web-based control panels flightpath login panel was detected. princechaddha panel flightpath discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">FlightPath Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/flightpath-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">flightpath-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> princechaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)flightpath&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">FlightPath login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">flightpath</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="flock safety camera admin panel - detect info identify web-based control panels detected the flock safety camera admin panel. inokii panel iot camera flock-safety discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Flock Safety Camera Admin Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/iot/flock-safety-camera-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">flock-safety-camera-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> inokii</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 25, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Flock Admin&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detected the Flock Safety camera admin panel.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">iot</span><span class="nt-tag">camera</span><span class="nt-tag">flock-safety</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.flocksafety.com/products/video-cameras" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="flowise 1.6.5 - authentication bypass high identify critical remote vulnerabilities the flowise version &lt;= 1.6.5 is vulnerable to authentication bypass vulnerability. cve-2024-31621 dhiyaneshdk ai auth-bypass cve cve2024 flowise vuln cwe-94" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Flowise 1.6.5 - Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-31621.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-31621.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 23, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/94.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-94</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-31621" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-31621</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-2051052918&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The flowise version &lt;= 1.6.5 is vulnerable to authentication bypass vulnerability.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can bypass authentication and gain unauthorized access to the Flowise application and its data.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update Flowise to version 1.6.6 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">ai</span><span class="nt-tag">auth-bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">flowise</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.exploit-db.com/exploits/52001" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/FlowiseAI/Flowise/releases" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://flowiseai.com/" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="flowise &lt;= 1.8.2 authentication bypass high identify critical remote vulnerabilities an authentication bypass vulnerability exists in flowise version 1.8.2. this could allow a remote, unauthenticated attacker to access api endpoints as an administrator and allow them to access restricted functionality. cve-2024-8181 iamnoooob,rootxharsh,pdresearch ai auth-bypass cve cve2024 flowise tenable vkev vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Flowise &lt;= 1.8.2 Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-8181.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-8181.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> iamnoooob,rootxharsh,pdresearch</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 29, 2024</span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-8181" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-8181</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-2051052918&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An Authentication Bypass vulnerability exists in Flowise version 1.8.2. This could allow a remote, unauthenticated attacker to access API endpoints as an administrator and allow them to access restricted functionality.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can bypass authentication to access administrative API endpoints, gaining unauthorized access to restricted functionality, API keys, and administrative operations.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update Flowise to a version later than 1.8.2 to address the authentication bypass vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">ai</span><span class="nt-tag">auth-bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">flowise</span><span class="nt-tag">tenable</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.tenable.com/security/research/tra-2024-33" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://tenable.com/security/research/tra-2024-22-0" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-8181" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="flowise &lt;= 3.0.5 - account takeover critical identify critical remote vulnerabilities flowise versions 3.0.5 and earlier had a vulnerability in the forgot-password endpoint, which returned valid reset tokens without authentication—allowing attackers to reset passwords and take over accounts. cve-2025-58434 nukunga[seunghyeonjeon] ai ato cve cve2025 flowise rce unauth vuln cwe-306" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Flowise &lt;= 3.0.5 - Account Takeover</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-58434.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-58434.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> nukunga[seunghyeonJeon]</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 13, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/306.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-306</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-58434" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-58434</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Flowise - Build AI Agents, Visually&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Flowise versions 3.0.5 and earlier had a vulnerability in the forgot-password endpoint, which returned valid reset tokens without authentication—allowing attackers to reset passwords and take over accounts.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can obtain valid password reset tokens without authentication, enabling account takeover of any user including administrators through password reset attacks.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade Flowise to version 3.0.6 or later that properly protects password reset token generation.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">ai</span><span class="nt-tag">ato</span><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">flowise</span><span class="nt-tag">rce</span><span class="nt-tag">unauth</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/advisories/GHSA-wgpv-6j63-x5ph" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58434" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="flowise panel - detect info identify web-based control panels flowise panel was detected. flowise is an open-source drag-and-drop llm flow builderand ai agent platform. exposed instances may reveal ai workflow configurations, api keys, and connected data sources. rxerium ai detect discovery flowise llm panel" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Flowise Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/flowise-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">flowise-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 14, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Flowise - Build AI Agents, Visually&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Flowise panel was detected. Flowise is an open-source drag-and-drop LLM flow builderand AI agent platform. Exposed instances may reveal AI workflow configurations, API keys, and connected data sources.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">ai</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">flowise</span><span class="nt-tag">llm</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/FlowiseAI/Flowise" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://flowiseai.com/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="flureedb admin console login panel - detect info identify web-based control panels flureedb admin console login panel was detected. dhiyaneshdk panel flureedb discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">FlureeDB Admin Console Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/flureedb-admin-console.yaml" target="_blank" rel="noopener" class="nt-source-link">flureedb-admin-console.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)FlureeDB Admin Console&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">FlureeDB Admin Console login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">flureedb</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/fluree/fluree-admin-ui" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="footprints service core login panel - detect info identify web-based control panels footprints service core login panel was detected. tess discovery footprints panel tech cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">FootPrints Service Core Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/footprints-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">footprints-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> tess</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)FootPrints Service Core Login&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">FootPrints Service Core login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">footprints</span><span class="nt-tag">panel</span><span class="nt-tag">tech</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="forcepoint appliance info identify web-based control panels  dhiyaneshdk panel forcepoint discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Forcepoint Appliance</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/forcepoint-applicance.yaml" target="_blank" rel="noopener" class="nt-source-link">forcepoint-applicance.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Forcepoint Appliance&#34;})</code></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">forcepoint</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="forgerock openam &lt;7.0 - remote code execution critical identify critical remote vulnerabilities forgerock am server before 7.0 has a java deserialization vulnerability in the jato.pagesession parameter on multiple pages.
the exploitation does not require authentication, and remote code execution can be triggered by sending a single crafted
/ccversion/* request to the server. the vulnerability exists due to the usage of sun one application framework (jato)
found in versions of java 8 or earlier. cve-2021-35464 madrobot cve cve2021 forgerock java kev openam packetstorm rce vkev vuln cwe-502" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">ForgeRock OpenAM &lt;7.0 - Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2021/CVE-2021-35464.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2021-35464.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> madrobot</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/502.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-502</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2021-35464" target="_blank" rel="noopener" class="nt-cve-link">CVE-2021-35464</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)openam&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pages.
The exploitation does not require authentication, and remote code execution can be triggered by sending a single crafted
/ccversion/* request to the server. The vulnerability exists due to the usage of Sun ONE Application Framework (JATO)
found in versions of Java 8 or earlier.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade ForgeRock OpenAM to version 7.0 or later to mitigate this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2021</span><span class="nt-tag">forgerock</span><span class="nt-tag">java</span><span class="nt-tag">kev</span><span class="nt-tag">openam</span><span class="nt-tag">packetstorm</span><span class="nt-tag">rce</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://portswigger.net/research/pre-auth-rce-in-forgerock-openam-cve-2021-35464" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-35464" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="http://packetstormsecurity.com/files/163486/ForgeRock-OpenAM-Jato-Java-Deserialization.html" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="http://packetstormsecurity.com/files/163525/ForgeRock-Access-Manager-OpenAM-14.6.3-Remote-Code-Execution.html" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://bugster.forgerock.org" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="fork cms - installer critical identify critical remote vulnerabilities fork cms installer page was detected. dhiyaneshdk misconfig exposure fork cms install vuln" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Fork CMS - Installer</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/misconfiguration/installer/fork-installer.yaml" target="_blank" rel="noopener" class="nt-source-link">fork-installer.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 12, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Install Fork CMS&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Fork CMS installer page was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">misconfig</span><span class="nt-tag">exposure</span><span class="nt-tag">fork</span><span class="nt-tag">cms</span><span class="nt-tag">install</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="form-maker &lt; 1.15.20 - unauthenticated arbitrary file upload critical identify critical remote vulnerabilities the plugin does not validate signatures when creating them on the server from user input, allowing unauthenticated users to create arbitrary files and lead to rce. cve-2023-4666 pussycat0x cve cve2023 form-maker passive vkev vuln wordpress wp-plugin wpscan" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Form-Maker &lt; 1.15.20 - Unauthenticated Arbitrary File Upload</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-4666.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-4666.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 24, 2025</span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-4666" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-4666</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/form-maker/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The plugin does not validate signatures when creating them on the server from user input, allowing unauthenticated users to create arbitrary files and lead to RCE.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can exploit missing signature validation to upload arbitrary files and achieve remote code execution on WordPress installations running vulnerable Form-Maker plugins.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Fixed in 1.15.20</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">form-maker</span><span class="nt-tag">passive</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">wpscan</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wpscan.com/vulnerability/c6597e36-02d6-46b4-89db-52c160f418be/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="formlift for infusionsoft web forms &lt;= 7.5.17 - sql injection critical identify critical remote vulnerabilities the formlift for infusionsoft web forms plugin for wordpress is vulnerable to sql injection via the &#39;form_id&#39; parameter in versions up to, and including, 7.5.17 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing sql query. this makes it possible for unauthenticated attackers to append additional sql queries into already existing queries that can be used to extract sensitive information from the database. cve-2024-38773 shivam kamboj cve cve2024 formlift sqli wordpress wp wp-plugin cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">FormLift for Infusionsoft Web Forms &lt;= 7.5.17 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-38773.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-38773.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Shivam Kamboj</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 4, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-38773" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-38773</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/formlift/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The FormLift for Infusionsoft Web Forms plugin for WordPress is vulnerable to SQL Injection via the &#39;form_id&#39; parameter in versions up to, and including, 7.5.17 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can execute arbitrary SQL commands, potentially leading to data disclosure or manipulation.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest version of FormLift for Infusionsoft Web Forms.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">formlift</span><span class="nt-tag">sqli</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/formlift/formlift-for-infusionsoft-web-forms-7517-unauthenticated-sql-injection" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://patchstack.com/database/wordpress/plugin/formlift/vulnerability/wordpress-formlift-plugin-7-5-17-unauthenticated-blind-sql-injection-vulnerability" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://plugins.trac.wordpress.org/changeset?old_path=/formlift/tags/7.5.17&amp;new_path=/formlift/tags/7.5.18&amp;sfp_email=&amp;sfph_mail=" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-38773" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="formidable forms &lt; 2.05.02 - cross-site scripting medium identify critical remote vulnerabilities formidable form builder for wordpress versions before 2.05.03 contains a stored cross-site scripting caused by insufficient input sanitization and output escaping in form parameters like &#39;after_html&#39;, letting unauthenticated attackers inject and execute arbitrary scripts in victims&#39; browsers cve-2017-20192 0xanis cve cve2017 formidable reflected vkev wordpress wp-plugin xss cwe-79" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Formidable Forms &lt; 2.05.02 - Cross-Site Scripting</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2017/CVE-2017-20192.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2017-20192.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0xanis</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 24, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-79</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2017-20192" target="_blank" rel="noopener" class="nt-cve-link">CVE-2017-20192</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)formidable&#34; &amp;&amp; service[&#34;http.body&#34;] matches &#34;wp-content/plugins&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Formidable Form Builder for WordPress versions before 2.05.03 contains a stored cross-site scripting caused by insufficient input sanitization and output escaping in form parameters like &#39;after_html&#39;, letting unauthenticated attackers inject and execute arbitrary scripts in victims&#39; browsers</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can execute arbitrary scripts in users&#39; browsers, potentially leading to session hijacking, defacement, or redirection.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to version 2.05.03 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2017</span><span class="nt-tag">formidable</span><span class="nt-tag">reflected</span><span class="nt-tag">vkev</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">xss</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://klikki.fi/formidable-forms-vulnerabilities/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://wordpress.org/plugins/formidable/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2017-20192" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="fortiadc login panel - detect info identify web-based control panels fortiadc login panel was detected. dhiyaneshdk discovery fortinet panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">FortiADC Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/forti/fortiadc-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">fortiadc-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)fortiadc&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">FortiADC login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">fortinet</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.fortinet.com/products/application-delivery-controller/fortiadc" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="fortiap login panel - detect info identify web-based control panels fortiap login panel was detected. dhiyaneshdk discovery fortiap fortinet panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">FortiAP Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/fortinet/fortiap-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">fortiap-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)fortiap&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">FortiAP login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">fortiap</span><span class="nt-tag">fortinet</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.fortinet.com/products/wireless-access-points" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="fortiauthenticator - detect info identify web-based control panels the fortiauthenticator panel was detected. johnk3r detect discovery fortiauthenticator fortinet panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">FortiAuthenticator - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/fortinet/fortiauthenticator-detect.yaml" target="_blank" rel="noopener" class="nt-source-link">fortiauthenticator-detect.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> johnk3r</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 19, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-1653412201&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The FortiAuthenticator panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">fortiauthenticator</span><span class="nt-tag">fortinet</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="forticlient ems - authentication bypass high identify critical remote vulnerabilities detects whether fortinet hotfix fg-ir-26-099 for cve-2026-35616 is missing by comparing behavioral responses from a certificate-authenticated endpoint. the template sends x-ssl-client-verify: success without certificate material and checks whether this spoofed header changes server behavior. cve-2026-35616 ritikchaddha auth-bypass cve cve2026 ems forticlient fortinet kev vkev cwe-284" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">FortiClient EMS - Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2026/CVE-2026-35616.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2026-35616.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 9, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/284.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-284</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2026-35616" target="_blank" rel="noopener" class="nt-cve-link">CVE-2026-35616</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;product&#34;] contains &#34;Fortinet:FortiClient Endpoint Management Server&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detects whether Fortinet hotfix FG-IR-26-099 for CVE-2026-35616 is missing by comparing behavioral responses from a certificate-authenticated endpoint. The template sends X-SSL-CLIENT-VERIFY: SUCCESS without certificate material and checks whether this spoofed header changes server behavior.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">If spoofing X-SSL-CLIENT-VERIFY changes backend behavior, Apache is likely not stripping the header before Django, indicating the target is still vulnerable.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply Fortinet hotfix FG-IR-26-099 or upgrade to FortiClient EMS 7.4.7+.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2026</span><span class="nt-tag">ems</span><span class="nt-tag">forticlient</span><span class="nt-tag">fortinet</span><span class="nt-tag">kev</span><span class="nt-tag">vkev</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://bishopfox.com/blog/api-authentication-bypass-in-forticlient-ems-7-4-5-7-4-6-cve-2026-35616" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35616" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="forticlient endpoint management server panel - detect info identify web-based control panels  h4sh5 panel fortinet forticlient ems login detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">FortiClient Endpoint Management Server Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/fortinet/forticlientems-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">forticlientems-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> h4sh5</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 18, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-800551065&#34;</code></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">fortinet</span><span class="nt-tag">forticlient</span><span class="nt-tag">ems</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="fortios admin login panel - detect info identify web-based control panels fortios admin login panel was detected. canberbamber,jna1 discovery fortinet fortios panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">FortiOS Admin Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/fortinet/fortios-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">fortios-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> canberbamber,Jna1</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;945408572&#34; || service[&#34;http.body&#34;] matches &#34;(?i)/remote/login&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">FortiOS admin login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">fortinet</span><span class="nt-tag">fortios</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.horizon3.ai/fortinet-iocs-cve-2022-40684/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="fortirecorder panel - detect info identify web-based control panels fortirecorder panel was discovered. rxerium fortinet fortirecorder login panel discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">FortiRecorder Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/fortirecorder-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">fortirecorder-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 4, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)FortiRecorder&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">FortiRecorder Panel was discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">fortinet</span><span class="nt-tag">fortirecorder</span><span class="nt-tag">login</span><span class="nt-tag">panel</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.fortinet.com/content/dam/fortinet/assets/data-sheets/FortiRecorder.pdf" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="fortiwlm - directory traversal critical identify critical remote vulnerabilities a relative path traversal in fortinet fortiwlm version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specially crafted web requests. cve-2023-34990 dhiyaneshdk cisa cve cve2023 fortiwlm lfi vuln cwe-23,cwe-94" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">FortiWLM - Directory Traversal</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-34990.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-34990.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 4, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/23,CWE-94.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-23,CWE-94</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-34990" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-34990</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)FortiWLM Login&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A relative path traversal in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specially crafted web requests.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can exploit path traversal through the imagename parameter in ezrf_lighttpd.cgi to read arbitrary files and potentially execute unauthorized code, compromising the entire Fortinet FortiWLM wireless LAN management system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update Fortinet FortiWLM to version 8.6.6 or 8.5.5 or later that validates file paths in ezrf_lighttpd.cgi and prevents directory traversal attacks.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cisa</span><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">fortiwlm</span><span class="nt-tag">lfi</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://fortiguard.com/psirt/FG-IR-23-144" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="fortiweb - cross site scripting medium identify critical remote vulnerabilities fortiweb 6.3.0 through 6.3.7 and versions before 6.2.4 contain an unauthenticated cross-site scripting vulnerability. improper neutralization of input during web page generation can allow a remote attacker to inject malicious payload in vulnerable api end-points. cve-2021-22122 dwisiswant0 cve cve2021 fortinet fortiweb vkev vuln xss cwe-79" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">FortiWeb - Cross Site Scripting</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2021/CVE-2021-22122.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2021-22122.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dwisiswant0</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-79</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2021-22122" target="_blank" rel="noopener" class="nt-cve-link">CVE-2021-22122</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)fortiweb - &#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">FortiWeb 6.3.0 through 6.3.7 and versions before 6.2.4 contain an unauthenticated cross-site scripting vulnerability. Improper neutralization of input during web page generation can allow a remote attacker to inject malicious payload in vulnerable API end-points.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability can result in the compromise of sensitive user information, session hijacking.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches or updates provided by Fortinet to fix the XSS vulnerability in FortiWeb.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2021</span><span class="nt-tag">fortinet</span><span class="nt-tag">fortiweb</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">xss</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.fortiguard.com/psirt/FG-IR-20-122" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://twitter.com/ptswarm/status/1357316793753362433" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://fortiguard.com/advisory/FG-IR-20-122" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2021-22122" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/Elsfa7-110/kenzer-templates" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="fortinet forticlientems 7.4.4 - sql injection critical identify critical remote vulnerabilities fortinet forticlientems version 7.4.4 and earlier contains an unauthenticated sql injection vulnerability in the /api/v1/init_consts endpoint. the &#39;site&#39; http header value is passed directly into the postgresql search_path without sanitization, allowing remote unauthenticated attackers to inject arbitrary sql commands. this can lead to information disclosure, database manipulation, or os command execution when chained with postgresql functions. cve-2026-21643 ritikchaddha cve cve2026 ems forticlient fortinet kev sqli vkev cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Fortinet FortiClientEMS 7.4.4 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2026/CVE-2026-21643.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2026-21643.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 9, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2026-21643" target="_blank" rel="noopener" class="nt-cve-link">CVE-2026-21643</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;product&#34;] contains &#34;Fortinet:FortiClient Endpoint Management Server&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Fortinet FortiClientEMS version 7.4.4 and earlier contains an unauthenticated SQL injection vulnerability in the /api/v1/init_consts endpoint. The &#39;Site&#39; HTTP header value is passed directly into the PostgreSQL search_path without sanitization, allowing remote unauthenticated attackers to inject arbitrary SQL commands. This can lead to information disclosure, database manipulation, or OS command execution when chained with PostgreSQL functions.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An unauthenticated remote attacker can execute arbitrary SQL queries against the backend PostgreSQL database, potentially extracting sensitive data, modifying database contents, or achieving remote code execution through PostgreSQL-specific functions (e.g., COPY, lo_import, pg_read_file).</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade FortiClientEMS to a patched version as recommended by Fortinet. As a workaround, restrict network access to the FortiClientEMS management interface and apply WAF rules to filter malicious Site header values.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2026</span><span class="nt-tag">ems</span><span class="nt-tag">forticlient</span><span class="nt-tag">fortinet</span><span class="nt-tag">kev</span><span class="nt-tag">sqli</span><span class="nt-tag">vkev</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.fortiguard.com/psirt/FG-IR-2026-21643" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21643" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="fortinet fortiddos panel info identify web-based control panels fortinet fortiddos panel was detected. johnk3r discovery fortiddos fortinet login panel" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Fortinet FortiDDoS Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/fortinet/fortinet-fortiddos-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">fortinet-fortiddos-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> johnk3r</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 26, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)fortiddos&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Fortinet FortiDDoS panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">fortiddos</span><span class="nt-tag">fortinet</span><span class="nt-tag">login</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.fortinet.com/products/ddos/fortiddos" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="fortinet fortimail login panel - detect info identify web-based control panels fortinet fortimail login panel was detected. johnk3r discovery fortimail fortinet login panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Fortinet FortiMail Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/fortinet/fortimail-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">fortimail-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> johnk3r</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)fortimail&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Fortinet FortiMail login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">fortimail</span><span class="nt-tag">fortinet</span><span class="nt-tag">login</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="fortinet fortinac login panel - detect info identify web-based control panels fortinet fortinac login panel was detected. johnk3r discovery fortinac fortinet login panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Fortinet FortiNAC Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/fortinet/fortinet-fortinac-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">fortinet-fortinac-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> johnk3r</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)fortinac&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Fortinet FortiNAC login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">fortinac</span><span class="nt-tag">fortinet</span><span class="nt-tag">login</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="fortinet fortios - credentials disclosure critical identify critical remote vulnerabilities fortinet fortios 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4.6 to 5.4.12 and fortiproxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 under ssl vpn web portal allows an unauthenticated attacker to download system files via special crafted http resource requests due to improper limitation of a pathname to a restricted directory (path traversal). cve-2018-13379 organiccrap cve cve2018 fortinet fortios kev lfi vkev vuln cwe-22" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Fortinet FortiOS - Credentials Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2018/CVE-2018-13379.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2018-13379.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> organiccrap</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2018-13379" target="_blank" rel="noopener" class="nt-cve-link">CVE-2018-13379</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/remote/login\&#34; \&#34;xxxxxxxx&#34; || service[&#34;favicon.ico.image.mmh3&#34;] == &#34;945408572&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4.6 to 5.4.12 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 under SSL VPN web portal allows an unauthenticated attacker to download system files via special crafted HTTP resource requests due to improper limitation of a pathname to a restricted directory (path traversal).</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can obtain sensitive information such as usernames and passwords.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the necessary patches or updates provided by Fortinet to fix the vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2018</span><span class="nt-tag">fortinet</span><span class="nt-tag">fortios</span><span class="nt-tag">kev</span><span class="nt-tag">lfi</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://fortiguard.com/advisory/FG-IR-18-384" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.fortiguard.com/psirt/FG-IR-20-233" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-13379" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="fortinet fortios management interface panel - detect info identify web-based control panels fortinet fortios management interface panel was detected. mbmy discovery fortiap fortigate fortinet fortios fortiproxy panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Fortinet FortiOS Management Interface Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/fortinet/fortios-management-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">fortios-management-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> mbmy</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;945408572&#34; || service[&#34;http.body&#34;] matches &#34;(?i)/remote/login&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Fortinet FortiOS Management interface panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">fortiap</span><span class="nt-tag">fortigate</span><span class="nt-tag">fortinet</span><span class="nt-tag">fortios</span><span class="nt-tag">fortiproxy</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="fortinet fortisiem - os command injection critical identify critical remote vulnerabilities fortisiem versions 6.4.0 through 7.1.1 contain an os command injection vulnerability in the phoenix monitor service. the vulnerability exists in the xml parsing of test_storage elements where the mount_point field is not properly sanitized before being passed to shell commands, allowing unauthenticated remote code execution. cve-2024-23108 0x_akoko cve cve2024 fortinet fortisiem injection unauth vkev cwe-78" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Fortinet FortiSIEM - OS Command Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/network/cves/2024/CVE-2024-23108.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-23108.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_Akoko</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 30, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/78.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-78</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-23108" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-23108</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-1341442175&#34; and service[&#34;http.body&#34;] matches &#34;(?i)var hst = location\\.hostname&#34; and service[&#34;protocol&#34;] contains &#34;http&#34; and service[&#34;service.transport&#34;] contains &#34;tcp&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">FortiSIEM versions 6.4.0 through 7.1.1 contain an OS command injection vulnerability in the Phoenix Monitor service. The vulnerability exists in the XML parsing of TEST_STORAGE elements where the mount_point field is not properly sanitized before being passed to shell commands, allowing unauthenticated remote code execution.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can execute arbitrary commands on the FortiSIEM system, potentially leading to full system compromise, data exfilteration, lateral movement, and complete bypass of security monitoring capabilities.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update FortiSIEM to versions newer than 7.1.1. Implement network segmentation to restrict access to Phoenix Monitor service (TCP/7900) and monitor for suspicious connections to this port.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">fortinet</span><span class="nt-tag">fortisiem</span><span class="nt-tag">injection</span><span class="nt-tag">unauth</span><span class="nt-tag">vkev</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.horizon3.ai/attack-research/disclosures/cve-2024-23108-fortinet-fortisiem-2nd-order-command-injection-deep-dive/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://fortiguard.com/psirt/FG-IR-23-130" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-23108" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/horizon3ai/CVE-2024-23108" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/nomi-sec/PoC-in-GitHub" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="fortinet fortisiem - os command injection critical identify critical remote vulnerabilities fortinet fortisiem 6.7.9 &lt; version &lt;= 7.3.1 contains an os command injection caused by improper neutralization of special elements in cli requests, letting unauthenticated attackers execute unauthorized commands remotely. cve-2025-25256 watchtowr,darses cve cve2025 fortinet network rce tcp vkev vuln cwe-78" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Fortinet FortiSIEM - OS Command Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/network/cves/2025/CVE-2025-25256.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-25256.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> watchtowr,darses</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 18, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/78.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-78</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-25256" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-25256</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-1341442175&#34; and service[&#34;http.body&#34;] matches &#34;(?i)var hst = location\\.hostname&#34; and service[&#34;service.transport&#34;] contains &#34;tcp&#34; and service[&#34;protocol&#34;] contains &#34;http&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Fortinet FortiSIEM 6.7.9 &lt; version &lt;= 7.3.1 contains an OS command injection caused by improper neutralization of special elements in CLI requests, letting unauthenticated attackers execute unauthorized commands remotely.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can execute arbitrary commands, potentially leading to full system compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest version beyond 7.3.1.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">fortinet</span><span class="nt-tag">network</span><span class="nt-tag">rce</span><span class="nt-tag">tcp</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.fortiguard.com/psirt/FG-IR-25-152" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/watchtowrlabs/watchTowr-vs-FortiSIEM-CVE-2025-25256" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://labs.watchtowr.com/should-security-solutions-be-secure-maybe-were-all-wrong-fortinet-fortisiem-pre-auth-command-injection-cve-2025-25256/" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="fortinet fortisandbox panel - detect info identify web-based control panels fortinet fortisandbox login panel was discovered. umut özen,rxerium discovery fortinet fortisandbox login panel tech" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Fortinet FortiSandbox Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/fortinet/fortisandbox-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">fortisandbox-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Umut ÖZEN,rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 23, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)FortiSandbox&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Fortinet FortiSandbox login panel was discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">fortinet</span><span class="nt-tag">fortisandbox</span><span class="nt-tag">login</span><span class="nt-tag">panel</span><span class="nt-tag">tech</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.fortinet.com/products/sandbox/fortisandbox" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.fortinet.com/content/dam/fortinet/assets/data-sheets/FortiSandbox.pdf" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="fortinet fortitester login panel - detect info identify web-based control panels fortinet fortitester login panel was detected. dhiyaneshdk discovery fortinet panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Fortinet FortiTester Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/fortinet/fortitester-login-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">fortitester-login-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)fortitester&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Fortinet FortiTester login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">fortinet</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.fortinet.com/products/fortitester" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="fortinet fortiwlm login panel - detect info identify web-based control panels fortinet fortiwlm login panel was detected. egemenkochisarli discovery fortinet fortiwlm login panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Fortinet FortiWLM Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/fortinet/fortiwlm-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">fortiwlm-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> EgemenKochisarli</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 15, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)fortiwlm&#34; || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)fortiwlm&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Fortinet FortiWLM login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">fortinet</span><span class="nt-tag">fortiwlm</span><span class="nt-tag">login</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://docs.fortinet.com/product/fortiwlm/8.6" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="fortinet fortiweb - sql injection critical identify critical remote vulnerabilities an improper neutralization of special elements used in an sql command (&#39;sql injection&#39;) vulnerability [cwe-89] in fortiweb may allow an unauthenticated attacker to execute unauthorized sql code or commands via crafted http or https requests. cve-2025-25257 watchtowr,johnk3r cve cve2025 fortinet fortiweb kev sqli unauth vkev vuln cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Fortinet FortiWeb - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-25257.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-25257.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> watchtowr,johnk3r</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 11, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-25257" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-25257</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)FortiWeb - &#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An improper neutralization of special elements used in an SQL command (&#39;SQL Injection&#39;) vulnerability [CWE-89] in FortiWeb may allow an unauthenticated attacker to execute unauthorized SQL code or commands via crafted HTTP or HTTPS requests.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can exploit this vulnerability to execute unauthorized SQL commands, potentially leading to data exposure, data manipulation, or system compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches provided by Fortinet to fix the SQL injection vulnerability in FortiWeb.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">fortinet</span><span class="nt-tag">fortiweb</span><span class="nt-tag">kev</span><span class="nt-tag">sqli</span><span class="nt-tag">unauth</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://labs.watchtowr.com/pre-auth-sql-injection-to-rce-fortinet-fortiweb-fabric-connector-cve-2025-25257/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://fortiguard.fortinet.com/psirt/FG-IR-25-151" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="fortinet fortiweb login panel - detect info identify web-based control panels fortinet fortiweb login panel was detected. pr3r00t,daffainfo discovery fortinet fortiweb login panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Fortinet FortiWeb Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/fortinet/fortiweb-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">fortiweb-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> PR3R00T,daffainfo</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)fortiweb - &#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Fortinet FortiWeb login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">fortinet</span><span class="nt-tag">fortiweb</span><span class="nt-tag">login</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="fortinet forticlient endpoint management server - sql injection critical identify critical remote vulnerabilities a improper neutralization of special elements used in an sql command (&#39;sql injection&#39;) in fortinet forticlientems version 7.2.0 through 7.2.2, forticlientems 7.0.1 through 7.0.10 allows attacker to execute unauthorized code or commands via specially crafted packets. cve-2023-48788 james horseman,itshmoh cve cve2023 fortinet kev sqli vkev vuln cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Fortinet Forticlient Endpoint Management Server - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/network/cves/2023/CVE-2023-48788.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-48788.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> James Horseman,ItshMoh</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 26, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-48788" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-48788</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;service.transport&#34;] == &#34;tcp&#34; and service[&#34;service.port&#34;] == &#34;8013&#34; and asset[&#34;hw_vendor&#34;] matches `(?i)Fortinet`</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A improper neutralization of special elements used in an sql command (&#39;sql injection&#39;) in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, FortiClientEMS 7.0.1 through 7.0.10 allows attacker to execute unauthorized code or commands via specially crafted packets.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can execute arbitrary SQL commands through specially crafted network packets to the FortiClient Endpoint Management Server, potentially compromising the database, accessing sensitive endpoint data, and executing unauthorized code.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade FortiClient EMS to version 7.2.3 or later for the 7.2.x series, or version 7.0.11 or later for the 7.0.x series.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">fortinet</span><span class="nt-tag">kev</span><span class="nt-tag">sqli</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="fortinet login panel - detect info identify web-based control panels fortinet login panel was detected. pikpikcu,daffainfo detect discovery fortinet login panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Fortinet Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/fortinet/fortinet-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">fortinet-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pikpikcu,daffainfo</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)FORTINET LOGIN&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Fortinet login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">fortinet</span><span class="nt-tag">login</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="fortra filecatalyst workflow &lt;= v5.1.6 - sql injection critical identify critical remote vulnerabilities a sql injection vulnerability in fortra filecatalyst workflow allows an attacker to modify application data.  likely impacts include creation of administrative users and deletion or modification of data in the application database. data exfiltration via sql injection is not possible using this vulnerability. successful unauthenticated exploitation requires a workflow system with anonymous access enabled, otherwise an authenticated user is required. this issue affects all versions of filecatalyst workflow from 5.1.6 build 135 and earlier. cve-2024-5276 iamnoooob,rootxharsh,pdresearch auth-bypass cve cve2024 filecatalyst fortra instrusive sqli sqli vkev vuln cwe-20" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Fortra FileCatalyst Workflow &lt;= v5.1.6 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-5276.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-5276.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> iamnoooob,rootxharsh,pdresearch</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 18, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/20.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-20</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-5276" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-5276</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)FileCatalyst file transfer solution, easily transfer large files&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A SQL Injection vulnerability in Fortra FileCatalyst Workflow allows an attacker to modify application data.  Likely impacts include creation of administrative users and deletion or modification of data in the application database. Data exfiltration via SQL injection is not possible using this vulnerability. Successful unauthenticated exploitation requires a Workflow system with anonymous access enabled, otherwise an authenticated user is required. This issue affects all versions of FileCatalyst Workflow from 5.1.6 Build 135 and earlier.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can execute SQL injection to create administrative users, delete or modify application database content. Unauthenticated exploitation is possible if anonymous access is enabled.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update Fortra FileCatalyst Workflow to version 5.1.7 Build 136 or later to address the SQL injection vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">filecatalyst</span><span class="nt-tag">fortra</span><span class="nt-tag">instrusive</span><span class="nt-tag">sqli</span><span class="nt-tag">sqli</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.tenable.com/security/research/tra-2024-25" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://support.fortra.com/filecatalyst/kb-articles/advisory-6-24-2024-filecatalyst-workflow-sql-injection-vulnerability-YmYwYWY4OTYtNTUzMi1lZjExLTg0MGEtNjA0NWJkMDg3MDA0" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.fortra.com/security/advisory/fi-2024-008" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-5276" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="fortra goanywhere mft - authentication bypass critical identify critical remote vulnerabilities authentication bypass in fortra&#39;s goanywhere mft prior to 7.4.1 allows an unauthorized user to create an admin user via the administration portal. cve-2024-0204 dhiyaneshdk auth-bypass cve cve2024 fortra goanywhere packetstorm vkev vuln cwe-425" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Fortra GoAnywhere MFT - Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-0204.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-0204.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 24, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/425.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-425</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-0204" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-0204</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1484947000,1828756398,1170495932&#34; || service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1484947000&#34; || service[&#34;http.body&#34;] matches &#34;(?i)goanywhere managed file transfer&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Authentication bypass in Fortra&#39;s GoAnywhere MFT prior to 7.4.1 allows an unauthorized user to create an admin user via the administration portal.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can bypass authentication to create administrator accounts, leading to complete control over the GoAnywhere MFT system and access to all managed file transfers and sensitive data.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to Fortra GoAnywhere MFT version 7.4.1 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">fortra</span><span class="nt-tag">goanywhere</span><span class="nt-tag">packetstorm</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://my.goanywhere.com/webclient/ViewSecurityAdvisories.xhtml" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.fortra.com/security/advisory/fi-2024-001" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/horizon3ai/CVE-2024-0204/blob/main/CVE-2024-0204.py" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://www.horizon3.ai/cve-2024-0204-fortra-goanywhere-mft-authentication-bypass-deep-dive/" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="http://packetstormsecurity.com/files/176683/GoAnywhere-MFT-Authentication-Bypass.html" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="four-faith f3x36 - authentication bypass critical identify critical remote vulnerabilities four-faith f3x36 router with firmware v2.0.0 contains an authentication bypass caused by hard-coded credentials in the administrative web server, letting attackers with knowledge of credentials gain administrative access via crafted http requests. cve-2024-9643 trader642 auth-bypass cve cve2024 default-login four-faith iot router vkev cwe-798" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Four-Faith F3x36 - Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-9643.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-9643.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> trader642</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 16, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/798.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-798</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-9643" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-9643</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Four-Faith&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Four-Faith F3x36 router with firmware v2.0.0 contains an authentication bypass caused by hard-coded credentials in the administrative web server, letting attackers with knowledge of credentials gain administrative access via crafted HTTP requests.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can gain unauthorized administrative access, potentially leading to full control over the device.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest firmware version provided by the vendor to fix hard-coded credential issues.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">default-login</span><span class="nt-tag">four-faith</span><span class="nt-tag">iot</span><span class="nt-tag">router</span><span class="nt-tag">vkev</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://vulncheck.com/advisories/four-faith-hard-coded-creds" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://talosintelligence.com/vulnerability_reports/TALOS-2023-1752" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="foxcms v.1.2.5 - remote code execution critical identify critical remote vulnerabilities an issue in foxcms v.1.2.5 allows a remote attacker to execute arbitrary code via the case display page in the index.html component. cve-2025-29306 ritikchaddha cve cve2025 foxcms oast rce unauth vkev vuln cwe-94" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">FoxCMS v.1.2.5 - Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-29306.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-29306.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 23, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/94.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-94</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-29306" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-29306</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)foxcms-(logo|container)&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An issue in FoxCMS v.1.2.5 allows a remote attacker to execute arbitrary code via the case display page in the index.html component.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can execute arbitrary code through the id parameter in the index.html component, leading to complete server compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest version of FOXCMS if available. If no patch is available,implement WAF rules to block malicious requests to the /images/index.html endpoint with suspicious &#39;id&#39; parameter values.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">foxcms</span><span class="nt-tag">oast</span><span class="nt-tag">rce</span><span class="nt-tag">unauth</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/verylazytech/CVE-2025-29306/blob/main/CVE-2025-29306.sh" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://medium.com/@verylazytech" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-29306" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="franklin fueling systems colibri controller module 1.8.19.8580 - local file inclusion high identify critical remote vulnerabilities franklin fueling systems colibri controller module 1.8.19.8580 is susceptible to local file inclusion because of insecure handling of a download function that leads to disclosure of internal files due to path traversal with root privileges. cve-2021-46417 for3stco1d cve cve2021 franklinfueling lfi packetstorm vkev vuln cwe-22" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Franklin Fueling Systems Colibri Controller Module 1.8.19.8580 - Local File Inclusion</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2021/CVE-2021-46417.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2021-46417.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> For3stCo1d</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2021-46417" target="_blank" rel="noopener" class="nt-cve-link">CVE-2021-46417</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Franklin Fueling Systems&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Franklin Fueling Systems Colibri Controller Module 1.8.19.8580 is susceptible to local file inclusion because of insecure handling of a download function that leads to disclosure of internal files due to path traversal with root privileges.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could lead to unauthorized access to sensitive information, including configuration files, credentials, and other sensitive data.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patch or update provided by Franklin Fueling Systems to fix the LFI vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2021</span><span class="nt-tag">franklinfueling</span><span class="nt-tag">lfi</span><span class="nt-tag">packetstorm</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://packetstormsecurity.com/files/166671/Franklin-Fueling-Systems-Colibri-Controller-Module-1.8.19.8580-Local-File-Inclusion.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://drive.google.com/drive/folders/1Yu4aVDdrgvs-F9jP3R8Cw7qo_TC7VB-R" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="http://packetstormsecurity.com/files/166610/FFS-Colibri-Controller-Module-1.8.19.8580-Directory-Traversal.html" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2021-46417" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/KayCHENvip/vulnerability-poc" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="frappe framework - default login credentials high identify default logins in web-based control panels frappe framework (and erpnext) is accessible using the default credentials administrator:admin. successful login exposes full administrative access to the erp/crm system and underlying data. dhiyaneshdk default-login erpnext frappe" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Frappe Framework - Default Login Credentials</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/frappe/frappe-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">frappe-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 27, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches `(?i)Login to Frappe|frappe(?:\.(?:csrf_token|boot)|-web\.bundle)`</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Frappe Framework (and ERPNext) is accessible using the default credentials Administrator:admin. Successful login exposes full administrative access to the ERP/CRM system and underlying data.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">erpnext</span><span class="nt-tag">frappe</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://frappeframework.com" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://docs.erpnext.com" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="frappe helpdesk login panel - detect info identify web-based control panels frappe helpdesk products was detected. righettod panel frappe login discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Frappe Helpdesk Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/frappe-helpdesk-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">frappe-helpdesk-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 19, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)window\\.frappe_version&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Frappe Helpdesk products was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">frappe</span><span class="nt-tag">login</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://frappe.io/helpdesk" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/frappe/helpdesk" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="frappe panel - detect info identify web-based control panels frappe erpnext login panel was discovered. th3l0newolf frappe login web erp detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Frappe Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/frappe-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">frappe-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Th3l0newolf</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 3, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Login to Frappe&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Frappe ERPNext Login Panel was discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">frappe</span><span class="nt-tag">login</span><span class="nt-tag">web</span><span class="nt-tag">erp</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://frappeframework.com/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="free5gc 3.2.1 - information disclosure high identify critical remote vulnerabilities free5gc 3.2.1 is susceptible to information disclosure. an attacker can possibly obtain sensitive information, modify data, and/or execute unauthorized operations. cve-2022-38870 for3stco1d cve cve2022 exposure free5gc vuln cwe-306" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Free5gc 3.2.1 - Information Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-38870.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-38870.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> For3stCo1d</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/306.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-306</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-38870" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-38870</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)free5gc web console&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Free5gc 3.2.1 is susceptible to information disclosure. An attacker can possibly obtain sensitive information, modify data, and/or execute unauthorized operations.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could result in unauthorized access to sensitive information.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest patch or upgrade to a patched version of Free5gc 3.2.1 to mitigate the vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">exposure</span><span class="nt-tag">free5gc</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/free5gc/free5gc/issues/387" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-38870" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/ARPSyndicate/cvemon" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/ARPSyndicate/kenzer-templates" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/Henry4E36/POCS" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="freeipa - xml entity injection high identify critical remote vulnerabilities access to external entities when parsing xml documents can lead to xml external entity (xxe) attacks. this flaw allows a remote attacker to potentially retrieve the content of arbitrary files by sending specially crafted http requests. cve-2022-2414 dhiyaneshdk cve cve2022 dogtag dogtagpki freeipa vkev vuln xxe cwe-611" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">FreeIPA - XML Entity Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-2414.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-2414.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 5, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/611.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-611</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-2414" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-2414</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Identity Management\&#34; html:\&#34;FreeIPA&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Access to external entities when parsing XML documents can lead to XML external entity (XXE) attacks. This flaw allows a remote attacker to potentially retrieve the content of arbitrary files by sending specially crafted HTTP requests.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can exploit this vulnerability to gain unauthorized access to sensitive information stored on the server.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches and updates provided by the vendor to fix the XML Entity Injection vulnerability in FreeIPA.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">dogtag</span><span class="nt-tag">dogtagpki</span><span class="nt-tag">freeipa</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">xxe</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/PeiQi0/PeiQi-WIKI-Book/blob/main/docs/wiki/webapp/Dogtag/Dogtag%20PKI%20XML%E5%AE%9E%E4%BD%93%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E%20CVE-2022-2414.md" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-2414" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/dogtagpki/pki/pull/4021" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="freeipa identity management login panel - detect info identify web-based control panels freeipa identity management login panel was detected. dhiyaneshdk discovery freeipa login panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">FreeIPA Identity Management Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/freeipa-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">freeipa-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)freeipa&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">FreeIPA Identity Management login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">freeipa</span><span class="nt-tag">login</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="freepbx - cve-2025-57819 backdoor high identify critical remote vulnerabilities freepbx backdoor cleanup script used in 0-day exploitation of cve-2025-57819 was detected. darses backdoor sangoma freepbx vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">FreePBX - CVE-2025-57819 Backdoor</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/vulnerabilities/backdoor/freepbx-cleanup-backdoor.yaml" target="_blank" rel="noopener" class="nt-source-link">freepbx-cleanup-backdoor.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> darses</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 28, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)FreePBX&#34;}) || service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-1908328911&#34; || service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1574423538&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">FreePBX backdoor cleanup script used in 0-day exploitation of CVE-2025-57819 was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">backdoor</span><span class="nt-tag">sangoma</span><span class="nt-tag">freepbx</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://community.freepbx.org/t/security-advisory-please-lock-down-your-administrator-access/107203" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="freepbx - default admin credentials high identify default logins in web-based control panels detected freepbx administration panel was using default admin credentials (admin:admin). an attacker could gain full administrative access to the pbx system, manage extensions, trunks, and call routing. 0x_akoko auth default-login freepbx misconfig" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">FreePBX - Default Admin Credentials</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/freepbx-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">freepbx-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_Akoko</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 8, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1574423538&#34; || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)FreePBX&#34;}) || service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-1908328911&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detected FreePBX administration panel was using default admin credentials (admin:admin). An attacker could gain full administrative access to the PBX system, manage extensions, trunks, and call routing.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth</span><span class="nt-tag">default-login</span><span class="nt-tag">freepbx</span><span class="nt-tag">misconfig</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.freepbx.org/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://community.freepbx.org/t/freepbx-default-admin-passwords/9221" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="freepbx admin panel - detect info identify web-based control panels freepbx admin panel was detected. tess,darses freepbx panel sangoma discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">FreePBX Admin Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/freepbx-administration-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">freepbx-administration-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> tess,darses</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1574423538&#34; || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)FreePBX&#34;}) || service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-1908328911&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">FreePBX admin panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">freepbx</span><span class="nt-tag">panel</span><span class="nt-tag">sangoma</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="freshrss fever api - exposure low identify critical remote vulnerabilities detected an exposed freshrss instance with the fever api enabled, which could allow unauthorized access to rss feed data and user-related information via accessible fever-compatible api endpoints. ritikchaddha exposure freshrss fever api" data-nt-sev="low">
  <div class="nt-card-header">
    <div class="nt-title">FreshRSS Fever API - Exposure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposures/apis/freshrss-fever-api.yaml" target="_blank" rel="noopener" class="nt-source-link">freshrss-fever-api.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 29, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)FreshRSS&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detected an exposed FreshRSS instance with the Fever API enabled, which could allow unauthorized access to RSS feed data and user-related information via accessible Fever-compatible API endpoints.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">exposure</span><span class="nt-tag">freshrss</span><span class="nt-tag">fever</span><span class="nt-tag">api</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://freshrss.github.io/FreshRSS/en/developers/06_Fever_API.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="freshrss google reader api exposure low identify critical remote vulnerabilities detected an exposed freshrss instance with the google reader api enabled, which could have allowed unauthorized access to rss feeds and user-related data via accessible api endpoints. dhiyaneshdk exposure freshrss google api" data-nt-sev="low">
  <div class="nt-card-header">
    <div class="nt-title">FreshRSS Google Reader API Exposure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposures/apis/freshrss-api.yaml" target="_blank" rel="noopener" class="nt-source-link">freshrss-api.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 21, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)FreshRSS&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detected an exposed FreshRSS instance with the Google Reader API enabled, which could have allowed unauthorized access to RSS feeds and user-related data via accessible API endpoints.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">exposure</span><span class="nt-tag">freshrss</span><span class="nt-tag">google</span><span class="nt-tag">api</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://freshrss.github.io/FreshRSS/en/developers/06_GoogleReader_API.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="freshrss panel - detect info identify web-based control panels freshrss panel has been detected. ritikchaddha freshrss panel detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Freshrss Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/freshrss-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">freshrss-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 18, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Freshrss&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Freshrss panel has been detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">freshrss</span><span class="nt-tag">panel</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="friendica panel - detect info identify web-based control panels friendica login panel was detected. righettod detect discovery friendica login panel" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Friendica Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/friendica-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">friendica-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 28, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)friendica&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Friendica Login Panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">friendica</span><span class="nt-tag">login</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://friendi.ca" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="fronius datalogger web - login panel info identify web-based control panels fronius datalogger web is a web interface for fronius solar inverter data loggers, providing real-time monitoring and configuration of photovoltaic systems. rxerium discovery fronius ics panel scada solar" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Fronius Datalogger Web - Login Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/fronius-datalogger-web-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">fronius-datalogger-web-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 27, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches `(?i)Fronius Datalogger Web`</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Fronius Datalogger Web is a web interface for Fronius solar inverter data loggers, providing real-time monitoring and configuration of photovoltaic systems.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">fronius</span><span class="nt-tag">ics</span><span class="nt-tag">panel</span><span class="nt-tag">scada</span><span class="nt-tag">solar</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.fronius.com/en/solar-energy/installers-partners/technical-data/all-products/system-monitoring/hardware/fronius-datamanager-2-0" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="fronius inverter - login panel info identify web-based control panels fronius inverter is the web interface for fronius gen24 and symo series solar inverters, providing real-time monitoring, configuration, and energy management for photovoltaic systems. rxerium discovery fronius ics panel scada solar" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Fronius Inverter - Login Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/fronius-inverter-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">fronius-inverter-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 27, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;^Fronius Inverter&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Fronius Inverter is the web interface for Fronius GEN24 and Symo series solar inverters, providing real-time monitoring, configuration, and energy management for photovoltaic systems.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">fronius</span><span class="nt-tag">ics</span><span class="nt-tag">panel</span><span class="nt-tag">scada</span><span class="nt-tag">solar</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.fronius.com/en/solar-energy/private-customers/products-solutions/solar-inverters" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="froxlor server management login panel - detect info identify web-based control panels froxlor server management login panel was detected. dhiyaneshdk discovery froxlor panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Froxlor Server Management Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/froxlor-management-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">froxlor-management-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)froxlor server management panel&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Froxlor Server Management login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">froxlor</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="fuel cms 1.4.7 - sql injection critical identify critical remote vulnerabilities fuel cms 1.4.7 allows sql injection via the col parameter to /pages/items, /permissions/items, or /navigation/items. cve-2020-17463 thirukrishnan cve cve2020 fuel-cms kev packetstorm sqli thedaylightstudio time-based-sqli vkev vuln cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Fuel CMS 1.4.7 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2020/CVE-2020-17463.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2020-17463.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Thirukrishnan</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 16, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2020-17463" target="_blank" rel="noopener" class="nt-cve-link">CVE-2020-17463</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)fuel cms&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">FUEL CMS 1.4.7 allows SQL Injection via the col parameter to /pages/items, /permissions/items, or /navigation/items.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability allows an attacker to execute arbitrary SQL queries, potentially leading to unauthorized access, data manipulation, or data leakage.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Fixed in version 115</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2020</span><span class="nt-tag">fuel-cms</span><span class="nt-tag">kev</span><span class="nt-tag">packetstorm</span><span class="nt-tag">sqli</span><span class="nt-tag">thedaylightstudio</span><span class="nt-tag">time-based-sqli</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.exploit-db.com/exploits/48741" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2020-17463" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="http://packetstormsecurity.com/files/158840/Fuel-CMS-1.4.7-SQL-Injection.html" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://getfuelcms.com/" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="fuel cms login panel - detect info identify web-based control panels fuel cms login panel was detected. adam crosser panel fuelcms oss daylightstudio discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Fuel CMS Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/fuelcms-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">fuelcms-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Adam Crosser</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)fuel cms&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Fuel CMS login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">fuelcms</span><span class="nt-tag">oss</span><span class="nt-tag">daylightstudio</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="fuji xerox printer panel - detect info identify web-based control panels fuji xerox printer panel was detected. gy741 iot panel fuji printer discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Fuji Xerox Printer Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/fuji-xerox-printer-detect.yaml" target="_blank" rel="noopener" class="nt-source-link">fuji-xerox-printer-detect.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> gy741</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Fuji Xerox Co\\., Ltd&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Fuji Xerox printer panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">iot</span><span class="nt-tag">panel</span><span class="nt-tag">fuji</span><span class="nt-tag">printer</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="fujian kelixin communication - command injection medium identify critical remote vulnerabilities a vulnerability was found in fujian kelixin communication command and dispatch platform up to 20240318 and classified as critical. affected by this issue is some unknown functionality of the file api/client/user/pwd_update.php. cve-2024-2621 dhiyaneshdk cve cve2024 fujian rce sqli time-based-sqli vuln cwe-89" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Fujian Kelixin Communication - Command Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-2621.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-2621.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 17, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-2621" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-2621</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)app/structure/departments\\.php&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A vulnerability was found in Fujian Kelixin Communication Command and Dispatch Platform up to 20240318 and classified as critical. Affected by this issue is some unknown functionality of the file api/client/user/pwd_update.php.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Authenticated attackers can extract sensitive database information via time-based SQL injection in the usr_number parameter.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update Fujian Kelixin Communication Command and Dispatch Platform to a version newer than 20240318.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">fujian</span><span class="nt-tag">rce</span><span class="nt-tag">sqli</span><span class="nt-tag">time-based-sqli</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://h0e4a0r1t.github.io/2024/vulns/Fujian%20Kelixin%20Communication%20Co.,%20Ltd.%20Command%20and%20Dispatch%20Platform%20SQL%20Injection%20Vulnerability-pwd_update.php.pdf" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://vuldb.com/?ctiid.257198" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://vuldb.com/?id.257198" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/NaInSec/CVE-LIST" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/fkie-cad/nvd-json-data-feeds" target="_blank" rel="noopener" class="nt-ref-link">[5]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-2621" target="_blank" rel="noopener" class="nt-ref-link">[6]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="fujitsu ip series - hardcoded credentials high identify critical remote vulnerabilities fujitsu real-time video transmission gear “ip series” use hard-coded credentials, which may allow a remote unauthenticated attacker to initialize or reboot the products, and as a result, terminate the video transmission. the credentials cannot be changed by the end-user and provide administrative access to the devices. cve-2023-38433 adnanekhan cve cve2023 fujitsu ip-series vkev vuln cwe-798" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Fujitsu IP Series - Hardcoded Credentials</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-38433.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-38433.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> AdnaneKhan</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 10, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/798.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-798</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-38433" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-38433</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.head.server&#34;] matches &#34;thttpd/2.25b 29dec2003\&#34; content-length:1133&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Fujitsu Real-time Video Transmission Gear “IP series” use hard-coded credentials, which may allow a remote unauthenticated attacker to initialize or reboot the products, and as a result, terminate the video transmission. The credentials cannot be changed by the end-user and provide administrative access to the devices.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could lead to unauthorized access to the device, potentially resulting in further compromise of the network.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches and updates from the vendor to address this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">fujitsu</span><span class="nt-tag">ip-series</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.praetorian.com/blog/fujitsu-ip-series-hard-coded-credentials" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-38433" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.cisa.gov/news-events/ics-advisories/icsa-23-248-01" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://www.fujitsu.com/global/products/computing/peripheral/video/download" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://jvn.jp/en/jp/JVN95727578" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="fumasoft cloud - sql injection critical identify critical remote vulnerabilities there is a sql injection vulnerability in the ajaxmethod.ashx file of fumasoft cloud. attackers can obtain server permissions through the vulnerability ritikchaddha fumasoft sqli vuln cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Fumasoft Cloud - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/vulnerabilities/other/fumasoft-sqli.yaml" target="_blank" rel="noopener" class="nt-source-link">fumasoft-sqli.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 10, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Fumeng Cloud&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">There is a SQL injection vulnerability in the AjaxMethod.ashx file of Fumasoft Cloud. Attackers can obtain server permissions through the vulnerability</div></div></div>
  <div class="nt-tags"><span class="nt-tag">fumasoft</span><span class="nt-tag">sqli</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="fumeng - sql injection critical identify critical remote vulnerabilities the fumeng ajaxmethod.ashx file has an sql injection vulnerability. attackers can use this vulnerability to obtain server data. ritikchaddha time-based-sqli fumasoft sqli vuln cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Fumeng - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/vulnerabilities/other/fumengyun-sqli.yaml" target="_blank" rel="noopener" class="nt-source-link">fumengyun-sqli.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 11, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)孚盟云 &#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The Fumeng AjaxMethod.ashx file has an SQL injection vulnerability. Attackers can use this vulnerability to obtain server data.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation could lead to unauthorized access to sensitive data.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Implement input validation and use parameterized queries to prevent SQL Injection attacks.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">time-based-sqli</span><span class="nt-tag">fumasoft</span><span class="nt-tag">sqli</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/emadshanab/goby-poc/blob/main/fumengyun%20%20AjaxMethod.ashx%20SQL%20injection.json" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="fusionauth admin panel - detect info identify web-based control panels  ritikchaddha detect discovery fusionauth login panel" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">FusionAuth Admin Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/fusionauth-admin-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">fusionauth-admin-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 6, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)fusionauth&#34;})</code></div>
  <div class="nt-tags"><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">fusionauth</span><span class="nt-tag">login</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="ge proficy webspace - login panel info identify web-based control panels ge proficy webspace is a thin-client delivery platform for ge proficy
hmi/scada (ifix, cimplicity) applications over the web. it exposes
industrial hmi screens via browser on tcp/491 by default. the server
header &#34;websocket++/0.7.0&#34; is a unique indicator. rxerium cimplicity discovery ge hmi ics ifix panel proficy scada webspace" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">GE Proficy WebSpace - Login Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/ge-proficy-webspace-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">ge-proficy-webspace-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 27, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Proficy WebSpace&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">GE Proficy WebSpace is a thin-client delivery platform for GE Proficy
HMI/SCADA (iFIX, CIMPLICITY) applications over the web. It exposes
industrial HMI screens via browser on TCP/491 by default. The Server
header &#34;WebSocket++/0.7.0&#34; is a unique indicator.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cimplicity</span><span class="nt-tag">discovery</span><span class="nt-tag">ge</span><span class="nt-tag">hmi</span><span class="nt-tag">ics</span><span class="nt-tag">ifix</span><span class="nt-tag">panel</span><span class="nt-tag">proficy</span><span class="nt-tag">scada</span><span class="nt-tag">webspace</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.ge.com/digital/applications/hmi-scada/proficy-webspace" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="gl.inet ssid key disclosure high identify critical remote vulnerabilities an issue was discovered on gl.inet devices before 3.216. an api endpoint reveals information about the wi-fi configuration, including the ssid and key. cve-2023-31478 dhiyaneshdk cve cve2023 disclosure gl-inet vkev vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">GL.iNET SSID Key Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-31478.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-31478.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 25, 2025</span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-31478" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-31478</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)GL\\.iNet Admin Panel&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An issue was discovered on GL.iNet devices before 3.216. An API endpoint reveals information about the Wi-Fi configuration, including the SSID and key.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can retrieve Wi-Fi SSID and password information through the mesh status API endpoint, potentially allowing unauthorized access to the wireless network and intercepting network traffic.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update GL.iNET firmware to version 3.216 or later that requires authentication for the /api/router/mesh/status endpoint and protects Wi-Fi credentials.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">disclosure</span><span class="nt-tag">gl-inet</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.gl-inet.com" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="glpi 9.2/&lt;9.5.6 - information disclosure medium identify critical remote vulnerabilities glpi 9.2 and prior to 9.5.6 is susceptible to information disclosure via the telemetry endpoint, which discloses glpi and server information. an attacker can possibly obtain sensitive information, modify data, and/or execute unauthorized operations. cve-2021-39211 dogasantos,noraj cve cve2021 exposure glpi glpi-project vkev vuln cwe-200,nvd-cwe-noinfo" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">GLPI 9.2/&lt;9.5.6 - Information Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2021/CVE-2021-39211.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2021-39211.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dogasantos,noraj</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200,NVD-CWE-NOINFO.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200,NVD-CWE-NOINFO</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2021-39211" target="_blank" rel="noopener" class="nt-cve-link">CVE-2021-39211</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)setup glpi&#34; || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)glpi&#34;}) || service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-1474875778&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">GLPI 9.2 and prior to 9.5.6 is susceptible to information disclosure via the telemetry endpoint, which discloses GLPI and server information. An attacker can possibly obtain sensitive information, modify data, and/or execute unauthorized operations.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Information disclosure vulnerability in GLPI versions 9.2 to &lt;9.5.6 allows an attacker to access sensitive information.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">This issue is fixed in version 9.5.6. As a workaround, remove the file ajax/telemetry.php, which is not needed for usual GLPI functions.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2021</span><span class="nt-tag">exposure</span><span class="nt-tag">glpi</span><span class="nt-tag">glpi-project</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/glpi-project/glpi/security/advisories/GHSA-xx66-v3g5-w825" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/glpi-project/glpi/releases/tag/9.5.6" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2021-39211" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/ARPSyndicate/kenzer-templates" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/StarCrossPortal/scalpel" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="glpi &lt; 10.0.17 - pre-auth sql injection critical identify critical remote vulnerabilities a pre-authentication sql injection vulnerability exists in the inventory feature of glpi. the vulnerability is caused by insufficient sanitization of user input in the handleagent function when processing xml requests. the issue occurs because simplexmlelement objects can bypass the dbescaperecursive function, allowing an attacker to inject sql queries. this can lead to unauthorized access to sensitive information in the database, including user credentials and potential authentication bypass. cve-2025-24799 ritikchaddha cve cve2025 glpi sqli vkev vuln cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">GLPI &lt; 10.0.17 - Pre-Auth SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-24799.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-24799.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 31, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-24799" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-24799</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)GLPI&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A pre-authentication SQL injection vulnerability exists in the Inventory feature of GLPI. The vulnerability is caused by insufficient sanitization of user input in the handleAgent function when processing XML requests. The issue occurs because SimpleXMLElement objects can bypass the dbEscapeRecursive function, allowing an attacker to inject SQL queries. This can lead to unauthorized access to sensitive information in the database, including user credentials and potential authentication bypass.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can execute arbitrary SQL queries through XML requests to the Inventory feature, potentially extracting user credentials, bypassing authentication, and accessing sensitive database information.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to GLPI version 10.0.18 or later. If upgrading is not immediately possible, consider disabling the Inventory feature or restricting access to it.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">glpi</span><span class="nt-tag">sqli</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://blog.lexfo.fr/glpi-sql-to-rce.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/glpi-project/glpi/security/advisories/GHSA-p626-hph9-p6fj" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24799" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="glpi &lt;=10.0.2 - remote command execution critical identify critical remote vulnerabilities glpi through 10.0.2 is susceptible to remote command execution injection in /vendor/htmlawed/htmlawed/htmlawedtest.php in the htmlawed module. cve-2022-35914 for3stco1d,allendemoura cve cve2022 glpi glpi-project kev rce vkev vuln cwe-74" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">GLPI &lt;=10.0.2 - Remote Command Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-35914.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-35914.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> For3stCo1d,allendemoura</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/74.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-74</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-35914" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-35914</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-1474875778&#34; || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)glpi&#34;}) || service[&#34;http.body&#34;] matches &#34;(?i)setup glpi&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">GLPI through 10.0.2 is susceptible to remote command execution injection in /vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute arbitrary commands on the target system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade GLPI to a version higher than 10.0.2 to mitigate this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">glpi</span><span class="nt-tag">glpi-project</span><span class="nt-tag">kev</span><span class="nt-tag">rce</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://mayfly277.github.io/posts/GLPI-htmlawed-CVE-2022-35914" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/cosad3s/CVE-2022-35914-poc" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="http://www.bioinformatics.org/phplabware/sourceer/sourceer.php?&amp;Sfs=htmLawedTest.php&amp;Sl=.%2Finternal_utilities%2FhtmLawed" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-35914" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/glpi-project/glpi/releases" target="_blank" rel="noopener" class="nt-ref-link">[5]</a> <a href="https://senderend.medium.com/pg-practice-box-deep-dive-glpi-c3a1cf1520f8" target="_blank" rel="noopener" class="nt-ref-link">[6]</a> <a href="https://github.com/allendemoura/CVE-2022-35914" target="_blank" rel="noopener" class="nt-ref-link">[7]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="glpi panel - detect info identify web-based control panels glpi panel was detected. dogasantos,daffainfo,ricardomaia,dhiyaneshdk discovery edb glpi glpi-project panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">GLPI Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/glpi-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">glpi-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dogasantos,daffainfo,ricardomaia,dhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)glpi&#34;}) || service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-1474875778&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">GLPI panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">edb</span><span class="nt-tag">glpi</span><span class="nt-tag">glpi-project</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://glpi-project.org/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.exploit-db.com/ghdb/7002" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="gnu mailman panel - detect info identify web-based control panels gnu mailman panel was detected. panel exposes all public mailing lists on server. matt galligan discovery exposure gnu mailman panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">GNU Mailman Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/gnu-mailman.yaml" target="_blank" rel="noopener" class="nt-source-link">gnu-mailman.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Matt Galligan</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)mailing lists&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">GNU Mailman panel was detected. Panel exposes all public mailing lists on server.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">exposure</span><span class="nt-tag">gnu</span><span class="nt-tag">mailman</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="gude - default login high identify default logins in web-based control panels gude 2301 and 2302 default administrator login credentials (admin:admin) were detected. bretss gude default-login cwe-522" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">GUDE - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/gude/gude-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">gude-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Bretss</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 3, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/522.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-522</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Expert Net Control&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">GUDE 2301 and 2302 default administrator login credentials (admin:admin) were detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">gude</span><span class="nt-tag">default-login</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://media.distrelec.com/Web/Downloads/_m/an/Gude_2302-1_ger_man.pdf" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="gxd5 pacs connexion login panel - detect info identify web-based control panels gxd5 pacs connexion panel was detected. dhiyaneshdk panel login discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">GXD5 Pacs Connexion Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/pacs-connexion-utilisateur.yaml" target="_blank" rel="noopener" class="nt-source-link">pacs-connexion-utilisateur.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)GXD5 Pacs Connexion utilisateur&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">GXD5 Pacs Connexion panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">login</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="gyra master admin login panel - detect info identify web-based control panels gyra master admin login panel was detected. hardik-solanki panel master admin gyra discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">GYRA Master Admin Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/gyra-master-admin.yaml" target="_blank" rel="noopener" class="nt-source-link">gyra-master-admin.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Hardik-Solanki</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Login \\| GYRA Master Admin&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">GYRA Master Admin login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">master</span><span class="nt-tag">admin</span><span class="nt-tag">gyra</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="ganglia web interface (v3.7.3 - v3.7.5) - cross-site scripting medium identify critical remote vulnerabilities a cross-site scripting (xss) vulnerability in the component /graph_all_periods.php of ganglia-web v3.73 to v3.75 allows attackers to execute arbitrary web scripts or html via a crafted payload injected into the &#34;g&#34; parameter. cve-2024-52763 dhiyaneshdk cve cve2024 ganglia vkev vuln xss cwe-79" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Ganglia Web Interface (v3.7.3 - v3.7.5) - Cross-Site Scripting</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-52763.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-52763.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 11, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-79</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-52763" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-52763</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)ganglia_form\\.submit\\(\\)&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A cross-site scripting (XSS) vulnerability in the component /graph_all_periods.php of Ganglia-web v3.73 to v3.75 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the &#34;g&#34; parameter.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Authenticated attackers can execute arbitrary JavaScript or HTML in victim browsers by injecting malicious payloads into the g parameter.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update Ganglia-web to version 3.7.6 or later to address the XSS vulnerability in the graph parameter.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">ganglia</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">xss</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/ganglia/ganglia-web/issues/382" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="gargoyle router management utility admin login panel - detect info identify web-based control panels gargoyle router management utility admin login panel was detected. dhiyaneshdk discovery edb gargoyle iot panel router cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Gargoyle Router Management Utility Admin Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/gargoyle-router.yaml" target="_blank" rel="noopener" class="nt-source-link">gargoyle-router.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Gargoyle Router Management Utility&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Gargoyle Router Management Utility admin login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">edb</span><span class="nt-tag">gargoyle</span><span class="nt-tag">iot</span><span class="nt-tag">panel</span><span class="nt-tag">router</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.exploit-db.com/ghdb/8004" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="genieacs =&gt; 1.2.8 - os command injection critical identify critical remote vulnerabilities in genieacs 1.2.x before 1.2.8, the ui interface api is vulnerable to unauthenticated os command injection via the ping host argument (lib/ui/api.ts and lib/ping.ts). the vulnerability arises from insufficient input validation combined with a missing authorization check. cve-2021-46704 dhiyaneshdk cve cve2021 genieacs rce vuln cwe-78" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">GenieACS =&gt; 1.2.8 - OS Command Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2021/CVE-2021-46704.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2021-46704.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 22, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/78.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-78</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2021-46704" target="_blank" rel="noopener" class="nt-cve-link">CVE-2021-46704</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)genieacs&#34; || service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-2098066288&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">In GenieACS 1.2.x before 1.2.8, the UI interface API is vulnerable to unauthenticated OS command injection via the ping host argument (lib/ui/api.ts and lib/ping.ts). The vulnerability arises from insufficient input validation combined with a missing authorization check.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute arbitrary commands on the target system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to a patched version of GenieACS or apply the necessary security patches to mitigate the vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2021</span><span class="nt-tag">genieacs</span><span class="nt-tag">rce</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://twitter.com/shaybt12/status/1671598239835906058" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/advisories/GHSA-2877-693q-pj33" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2021-46704" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/genieacs/genieacs/commit/7f295beeecc1c1f14308a93c82413bb334045af6" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/genieacs/genieacs/releases/tag/v1.2.8" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="geoserver - missing authorization on rest api index medium identify critical remote vulnerabilities geoserver contains a missing authorization vulnerability that allows unauthorized access to the rest api index page, potentially exposing sensitive configuration information. cve-2025-27505 securitytaters cve cve2025 geoserver misconfig osgeo vkev vuln cwe-862" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">GeoServer - Missing Authorization on REST API Index</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-27505.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-27505.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> securitytaters</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 10, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/862.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-862</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-27505" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-27505</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)geoserver&#34;}) || service[&#34;favicon.ico.image.mmh3&#34;] == &#34;97540678&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">GeoServer contains a missing authorization vulnerability that allows unauthorized access to the REST API Index page, potentially exposing sensitive configuration information.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated users can access the GeoServer REST API Index page, potentially exposing sensitive configuration information and available API endpoints.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to the latest GeoServer version that implements proper authorization checks for the REST API Index page.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">geoserver</span><span class="nt-tag">misconfig</span><span class="nt-tag">osgeo</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="http://geoserver.org/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://geoserver.org/vulnerability/2025/06/10/cve-disclosure.html" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-27505" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="geoserver - xml external entity injection high identify critical remote vulnerabilities geoserver 2.26.0 to 2.26.2 and 2.25.6 contains an xml external entity (xxe) injection caused by insufficient sanitization of xml input in /geoserver/wms getmap operation, letting attackers disclose files or cause dos, exploit requires crafted xml input. cve-2025-58360 lbb,xbow,darses cve cve2025 geoserver kev vkev wms xxe cwe-611" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">GeoServer - XML External Entity Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-58360.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-58360.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> lbb,xbow,darses</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 27, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/611.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-611</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-58360" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-58360</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)geoserver&#34;}) || service[&#34;http.body.mmh3&#34;] == &#34;1093634893&#34; || service[&#34;favicon.ico.image.mmh3&#34;] == &#34;97540678&#34; || service[&#34;http.body&#34;] matches &#34;(?i)/geoserver/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">GeoServer 2.26.0 to 2.26.2 and 2.25.6 contains an XML External Entity (XXE) injection caused by insufficient sanitization of XML input in /geoserver/wms GetMap operation, letting attackers disclose files or cause DoS, exploit requires crafted XML input.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can disclose sensitive files or cause denial of service by exploiting XML external entity processing.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to GeoServer 2.25.6, 2.26.3, 2.27.0 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">geoserver</span><span class="nt-tag">kev</span><span class="nt-tag">vkev</span><span class="nt-tag">wms</span><span class="nt-tag">xxe</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/geoserver/geoserver/security/advisories/GHSA-fjf5-xgmq-5525" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58360" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="geoserver &lt;1.2.2 - remote code execution critical identify critical remote vulnerabilities programs run on geoserver before 1.2.2 which use jt-jiffle and allow jiffle script to be provided via network request are susceptible to remote code execution. the jiffle script is compiled into java code via janino, and executed. in particular, this affects downstream geoserver 1.1.22. cve-2022-24816 mukundbhuva cve cve2022 geoserver geosolutionsgroup kev rce vkev vuln cwe-94" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">GeoServer &lt;1.2.2 - Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-24816.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-24816.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> mukundbhuva</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/94.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-94</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-24816" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-24816</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)geoserver&#34;}) || service[&#34;favicon.ico.image.mmh3&#34;] == &#34;97540678&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Programs run on GeoServer before 1.2.2 which use jt-jiffle and allow Jiffle script to be provided via network request are susceptible to remote code execution. The Jiffle script is compiled into Java code via Janino, and executed. In particular, this affects downstream GeoServer 1.1.22.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability allows an attacker to execute arbitrary code on the target system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">1.2.22 contains a patch that disables the ability to inject malicious code into the resulting script. Users unable to upgrade may negate the ability to compile Jiffle scripts from the final application by removing janino-x.y.z.jar from the classpath.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">geoserver</span><span class="nt-tag">geosolutionsgroup</span><span class="nt-tag">kev</span><span class="nt-tag">rce</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.synacktiv.com/en/publications/exploiting-cve-2022-24816-a-code-injection-in-the-jt-jiffle-extension-of-geoserver.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/geosolutions-it/jai-ext/security/advisories/GHSA-v92f-jx6p-73rx" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/geosolutions-it/jai-ext/commit/cb1d6565d38954676b0a366da4f965fef38da1cb" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-24816" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/tanjiti/sec_profile" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="geoserver login panel - detect info identify web-based control panels geoserver login panel was detected. ritikchaddha discovery geoserver osgeo panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">GeoServer Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/geoserver-login-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">geoserver-login-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)geoserver&#34;}) || service[&#34;favicon.ico.image.mmh3&#34;] == &#34;97540678&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">GeoServer login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">geoserver</span><span class="nt-tag">osgeo</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="geoserver admin - default login high identify default logins in web-based control panels geoserver default admin credentials were discovered. for3stco1d,professorabhay,ritikchaddha default-login geoserver vuln cwe-522" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Geoserver Admin - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/geoserver/geoserver-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">geoserver-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> For3stCo1d,professorabhay,ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/522.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-522</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;GeoServer: Welcome&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Geoserver default admin credentials were discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">geoserver</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="http://geoserver.org/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="ghost cms content api - sql injection critical identify critical remote vulnerabilities ghost cms before 6.19.1 is vulnerable to a blind sql injection in the /ghost/api/content/tags/ endpoint via the filter parameter. this template checks for the vulnerability by sending a boolean-based payload. cve-2026-26980 domwhewell-sage cve cve2026 ghost ghostcms sqli vkev vuln cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Ghost CMS Content API - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2026/CVE-2026-26980.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2026-26980.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> domwhewell-sage</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 8, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2026-26980" target="_blank" rel="noopener" class="nt-cve-link">CVE-2026-26980</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;product&#34;] contains &#34;Ghost:Ghost&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Ghost CMS before 6.19.1 is vulnerable to a blind SQL injection in the /ghost/api/content/tags/ endpoint via the filter parameter. This template checks for the vulnerability by sending a boolean-based payload.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An unauthenticated attacker can extract arbitrary data from the Ghost database including user credentials, API keys, and all content, potentially leading to full compromise of the CMS.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade Ghost CMS to version 6.19.1 or later which uses parameterized queries for slug filter ordering.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2026</span><span class="nt-tag">ghost</span><span class="nt-tag">ghostcms</span><span class="nt-tag">sqli</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/TryGhost/Ghost/security/advisories/GHSA-w52v-v783-gw97" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/TryGhost/Ghost/commit/30868d632b2252b638bc8a4c8ebf73964592ed91" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-26980" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="ghost cms installation setup - exposure high identify critical remote vulnerabilities detected ghost cms installation setup wizard accessible without authentication. an unauthenticated remote attacker can navigate to
/ghost/#/setup and complete the installation to gain full owner-level administrative control of the site. 0x_akoko ghost cms exposure setup takeover unauth" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Ghost CMS Installation Setup - Exposure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/misconfiguration/installer/ghost-cms-installer.yaml" target="_blank" rel="noopener" class="nt-source-link">ghost-cms-installer.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_Akoko</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 20, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;product&#34;] contains &#34;Ghost:Ghost&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detected Ghost CMS installation setup wizard accessible without authentication. An unauthenticated remote attacker can navigate to
/ghost/#/setup and complete the installation to gain full owner-level administrative control of the site.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">ghost</span><span class="nt-tag">cms</span><span class="nt-tag">exposure</span><span class="nt-tag">setup</span><span class="nt-tag">takeover</span><span class="nt-tag">unauth</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://ghost.org/docs/install/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://ghost.org/docs/config/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/TryGhost/Ghost" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="gibbon v25.0.0 - local file inclusion critical identify critical remote vulnerabilities gibbon v25.0.0 is vulnerable to a local file inclusion (lfi) vulnerability where it&#39;s possible to include the content of several files present in the installation folder in the server&#39;s response. cve-2023-34598 dhiyaneshdk cve cve2023 gibbon gibbonedu lfi vkev vuln cwe-22" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Gibbon v25.0.0 - Local File Inclusion</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-34598.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-34598.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 26, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-34598" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-34598</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-165631681&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Gibbon v25.0.0 is vulnerable to a Local File Inclusion (LFI) vulnerability where it&#39;s possible to include the content of several files present in the installation folder in the server&#39;s response.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">The LFI vulnerability can lead to unauthorized access to sensitive files, potentially exposing sensitive information or allowing for further exploitation.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to a patched version of Gibbon or apply the necessary security patches to mitigate the LFI vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">gibbon</span><span class="nt-tag">gibbonedu</span><span class="nt-tag">lfi</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/maddsec/CVE-2023-34598" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://twitter.com/shaybt12/status/1673612503547355137?s=20" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-34598" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/izj007/wechat" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/komodoooo/Some-things" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="gira homeserver 4 login panel - detect info identify web-based control panels gira homeserver 4 login panel was detected. tess discovery gira panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Gira HomeServer 4 Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/gira-homeserver-homepage.yaml" target="_blank" rel="noopener" class="nt-source-link">gira-homeserver-homepage.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> tess</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Gira HomeServer 4&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Gira HomeServer 4 login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">gira</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="github enterprise - encrypted saml info identify web-based control panels this template checks if encrypted saml (security assertion markup language) is enabled on a github enterprise instance. rootxharsh,iamnoooob,pdresearch github ghe saml discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">GitHub Enterprise - Encrypted SAML</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/ghe-encrypt-saml.yaml" target="_blank" rel="noopener" class="nt-source-link">ghe-encrypt-saml.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rootxharsh,iamnoooob,pdresearch</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 13, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)GitHub Enterprise&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">This template checks if Encrypted SAML (Security Assertion Markup Language) is enabled on a GitHub Enterprise instance.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">github</span><span class="nt-tag">ghe</span><span class="nt-tag">saml</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://docs.github.com/en/enterprise-server@3.10/admin/managing-iam/using-saml-for-enterprise-iam/enabling-encrypted-assertions" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="gitlab ce/ee - hard-coded credentials critical identify critical remote vulnerabilities gitlab ce/ee contains a hard-coded credentials vulnerability. a hardcoded password was set for accounts registered using an omniauth provider (e.g. oauth, ldap, saml), allowing attackers to potentially take over accounts. this template attempts to passively identify vulnerable versions of gitlab without the need for an exploit by matching unique hashes for the application-&lt;hash&gt;.css file in the header for unauthenticated requests. positive matches do not guarantee exploitability. affected versions are 14.7 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2. cve-2022-1162 gitlab red team cve cve2022 gitlab packetstorm vuln cwe-798" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">GitLab CE/EE - Hard-Coded Credentials</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-1162.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-1162.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> GitLab Red Team</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/798.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-798</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-1162" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-1162</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)GitLab&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">GitLab CE/EE contains a hard-coded credentials vulnerability. A hardcoded password was set for accounts registered using an OmniAuth provider (e.g. OAuth, LDAP, SAML), allowing attackers to potentially take over accounts. This template attempts to passively identify vulnerable versions of GitLab without the need for an exploit by matching unique hashes for the application-&lt;hash&gt;.css file in the header for unauthenticated requests. Positive matches do not guarantee exploitability. Affected versions are 14.7 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability can lead to unauthorized access to sensitive information or unauthorized actions within the GitLab application.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Tooling to find relevant hashes based on the semantic version ranges specified in the CVE is linked in the reference section below.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">gitlab</span><span class="nt-tag">packetstorm</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://gitlab.com/gitlab-com/gl-security/threatmanagement/redteam/redteam-public/cve-hash-harvester" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1162.json" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1162" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="http://packetstormsecurity.com/files/166828/Gitlab-14.9-Authentication-Bypass.html" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://nvd.nist.gov/vuln/detail/cve-2022-1162" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="gitlab ce/ee - information disclosure critical identify critical remote vulnerabilities gitlab ce/ee is susceptible to information disclosure. an attacker can access runner registration tokens using quick actions commands, thereby making it possible to obtain sensitive information, modify data, and/or execute unauthorized operations. affected versions are from 12.10 before 14.6.5, from 14.7 before 14.7.4, and from 14.8 before 14.8.2. cve-2022-0735 gitlab red team cve cve2022 gitlab vuln cwe-863" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">GitLab CE/EE - Information Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-0735.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-0735.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> GitLab Red Team</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/863.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-863</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-0735" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-0735</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)GitLab&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">GitLab CE/EE is susceptible to information disclosure. An attacker can access runner registration tokens using quick actions commands, thereby making it possible to obtain sensitive information, modify data, and/or execute unauthorized operations. Affected versions are from 12.10 before 14.6.5, from 14.7 before 14.7.4, and from 14.8 before 14.8.2.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can gain access to sensitive information stored in GitLab.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the necessary patches or updates provided by GitLab to fix the vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">gitlab</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://gitlab.com/gitlab-com/gl-security/threatmanagement/redteam/redteam-public/cve-hash-harvester" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0735.json" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0735" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/cve-2022-0735" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://gitlab.com/gitlab-org/gitlab/-/issues/353529" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="gitlab ce/ee - remote code execution critical identify critical remote vulnerabilities gitlab ce/ee starting from 11.9 does not properly validate image files that were passed to a file parser, resulting in a remote command execution vulnerability. this template attempts to passively identify vulnerable versions of gitlab without the need for an exploit by matching unique hashes for the application-&lt;hash&gt;.css file in the header for unauthenticated requests. positive matches do not guarantee exploitability. tooling to find relevant hashes based on the semantic version ranges specified in the cve is linked in the references section below. cve-2021-22205 gitlab red team cve cve2021 gitlab hackerone kev rce vkev vuln cwe-94" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">GitLab CE/EE - Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2021/CVE-2021-22205.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2021-22205.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> GitLab Red Team</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/94.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-94</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2021-22205" target="_blank" rel="noopener" class="nt-cve-link">CVE-2021-22205</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)gitlab-ci\\.yml&#34; || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)gitlab&#34;}) || service[&#34;http.body&#34;] matches &#34;(?i)gitlab enterprise edition&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">GitLab CE/EE starting from 11.9 does not properly validate image files that were passed to a file parser, resulting in a remote command execution vulnerability. This template attempts to passively identify vulnerable versions of GitLab without the need for an exploit by matching unique hashes for the application-&lt;hash&gt;.css file in the header for unauthenticated requests. Positive matches do not guarantee exploitability. Tooling to find relevant hashes based on the semantic version ranges specified in the CVE is linked in the references section below.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected GitLab instance.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to GitLab CE/EE version 13.10.3 or 13.11.1 to mitigate this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2021</span><span class="nt-tag">gitlab</span><span class="nt-tag">hackerone</span><span class="nt-tag">kev</span><span class="nt-tag">rce</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://gitlab.com/gitlab-com/gl-security/security-operations/gl-redteam/red-team-research/cve-2021-22205-hash-generator" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://gitlab.com/gitlab-com/gl-security/security-operations/gl-redteam/red-team-operations/-/issues/196" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22205.json" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://censys.io/blog/cve-2021-22205-it-was-a-gitlab-smash/" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://security.humanativaspa.it/gitlab-ce-cve-2021-22205-in-the-wild/" target="_blank" rel="noopener" class="nt-ref-link">[5]</a> <a href="https://hackerone.com/reports/1154542" target="_blank" rel="noopener" class="nt-ref-link">[6]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2021-22205" target="_blank" rel="noopener" class="nt-ref-link">[7]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="gitlab graphql api user enumeration medium identify critical remote vulnerabilities an unauthenticated remote attacker can leverage this vulnerability to collect registered gitlab usernames, names, and email addresses. cve-2021-4191 zsusac api cve cve2021 enum gitlab graphql unauth vkev vuln cwe-287" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">GitLab GraphQL API User Enumeration</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2021/CVE-2021-4191.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2021-4191.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> zsusac</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/287.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-287</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2021-4191" target="_blank" rel="noopener" class="nt-cve-link">CVE-2021-4191</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)gitlab&#34;}) || service[&#34;http.body&#34;] matches &#34;(?i)gitlab enterprise edition&#34; || service[&#34;http.body&#34;] matches &#34;(?i)gitlab-ci\\.yml&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An unauthenticated remote attacker can leverage this vulnerability to collect registered GitLab usernames, names, and email addresses.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can enumerate valid usernames, which can be used for further attacks such as brute-forcing passwords or launching targeted phishing campaigns.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Implement rate limiting or CAPTCHA on the GraphQL API to prevent user enumeration.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">api</span><span class="nt-tag">cve</span><span class="nt-tag">cve2021</span><span class="nt-tag">enum</span><span class="nt-tag">gitlab</span><span class="nt-tag">graphql</span><span class="nt-tag">unauth</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.rapid7.com/blog/post/2022/03/03/cve-2021-4191-gitlab-graphql-api-user-enumeration-fixed/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://thehackernews.com/2022/03/new-security-vulnerability-affects.html" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=2021-4191" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://gitlab.com/gitlab-org/gitlab/-/issues/343898" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-4191.json" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="gitlab instance explore - detect info identify web-based control panels this template checks for gitlab instances by verifying if /explore and /api/v4/projects endpoints are accessible with a 200 response. sujal tuladhar gitlab explore panel detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">GitLab Instance Explore - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/gitlab-explore.yaml" target="_blank" rel="noopener" class="nt-source-link">gitlab-explore.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Sujal Tuladhar</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 7, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)GitLab&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">This template checks for GitLab instances by verifying if /explore and /api/v4/projects endpoints are accessible with a 200 response.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">gitlab</span><span class="nt-tag">explore</span><span class="nt-tag">panel</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="gitblit - default login high identify default logins in web-based control panels gitblit default login credentials were discovered. ritikchaddha gitblit default-login vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Gitblit - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/gitblit/gitblit-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">gitblit-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 18, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;Gitblit&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Gitblit Default login credentials were discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">gitblit</span><span class="nt-tag">default-login</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.gitblit.com/administration.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="gitblit login panel - detect info identify web-based control panels gitblit login panel was detected — a pure java stack for managing, viewing, and serving git repositories. tess,righettod discovery gitblit panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Gitblit Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/gitblit-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">gitblit-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> tess,righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)gitblit&#34;}) || service[&#34;http.body&#34;] matches &#34;(?i)gitblit&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Gitblit login panel was detected — a pure Java stack for managing, viewing, and serving Git repositories.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">gitblit</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.gitblit.com/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/gitblit-org/gitblit" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="gitea 1.4.0 - remote code execution critical identify critical remote vulnerabilities gitea 1.4.0 is vulnerable to remote code execution. theamanrawat gitea rce unauth edb vuln" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Gitea 1.4.0 - Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/vulnerabilities/gitea/gitea-rce.yaml" target="_blank" rel="noopener" class="nt-source-link">gitea-rce.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> theamanrawat</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Installation -  Gitea: Git with a cup of tea&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Gitea 1.4.0 is vulnerable to remote code execution.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">gitea</span><span class="nt-tag">rce</span><span class="nt-tag">unauth</span><span class="nt-tag">edb</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.exploit-db.com/exploits/44996" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/kacperszurek/exploits/blob/master/Gitea/gitea_lfs_rce.py" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="gitea login panel - detect info identify web-based control panels gitea login panel was detected. dhiyaneshdk discovery gitea panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Gitea Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/gitea-login.yaml" target="_blank" rel="noopener" class="nt-source-link">gitea-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)powered by gitea version&#34; || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)gitea&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Gitea login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">gitea</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="gitea public repository - exposure low identify critical remote vulnerabilities detected publicly accessible gitea instances exposing repository listings and user information without authentication. theamanrawat gitea exposure misconfig git" data-nt-sev="low">
  <div class="nt-card-header">
    <div class="nt-title">Gitea Public Repository - Exposure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/misconfiguration/gitea-public-repo-exposure.yaml" target="_blank" rel="noopener" class="nt-source-link">gitea-public-repo-exposure.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> theamanrawat</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 20, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;product&#34;] contains &#34;Gitea:Gitea&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detected publicly accessible Gitea instances exposing repository listings and user information without authentication.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">gitea</span><span class="nt-tag">exposure</span><span class="nt-tag">misconfig</span><span class="nt-tag">git</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://gitea.io/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://docs.gitea.io/en-us/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="github enterprise login panel - detect info identify web-based control panels github enterprise login panel was detected. ehsahil discovery github panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Github Enterprise Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/github-enterprise-detect.yaml" target="_blank" rel="noopener" class="nt-source-link">github-enterprise-detect.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ehsahil</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Setup GitHub Enterprise&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Github Enterprise login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">github</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="gitlab ce/ee 10.5 - server-side request forgery high identify critical remote vulnerabilities gitlab ce/ee versions starting from 10.5 are susceptible to a server-side request forgery vulnerability when requests to the internal network for webhooks are enabled, even on a gitlab instance where registration is limited. the same vulnerability actually spans multiple cves, due to similar reports that were fixed across separate patches. these cves are:
- cve-2021-39935
- cve-2021-22214
- cve-2021-22175 cve-2021-22214 suman_kar,gitlab red team cve cve2021 gitlab ssrf vkev vuln cwe-918" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Gitlab CE/EE 10.5 - Server-Side Request Forgery</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2021/CVE-2021-22214.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2021-22214.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Suman_Kar,GitLab Red Team</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/918.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-918</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2021-22214" target="_blank" rel="noopener" class="nt-cve-link">CVE-2021-22214</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;product&#34;] contains &#34;GitLab:GitLab&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">GitLab CE/EE versions starting from 10.5 are susceptible to a server-side request forgery vulnerability when requests to the internal network for webhooks are enabled, even on a GitLab instance where registration is limited. The same vulnerability actually spans multiple CVEs, due to similar reports that were fixed across separate patches. These CVEs are:
- CVE-2021-39935
- CVE-2021-22214
- CVE-2021-22175</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability can lead to unauthorized access to internal resources, potential data leakage, and further attacks on the system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade Gitlab CE/EE to a version that is not affected by the vulnerability (10.6 or higher).</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2021</span><span class="nt-tag">gitlab</span><span class="nt-tag">ssrf</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2021-22214" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2021-39935" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2021-22175" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://vin01.github.io/piptagole/gitlab/ssrf/security/2021/06/15/gitlab-ssrf.html" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://docs.gitlab.com/ee/api/lint.html" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="gitlab ce/ee 13.4 - 13.6.2 - information disclosure medium identify critical remote vulnerabilities gitlab ce and ee 13.4 through 13.6.2 is susceptible to information disclosure via graphql. user email is visible. an attacker can possibly obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site. cve-2020-26413 _0xf4n9x_,pikpikcu cve cve2020 enum exposure gitlab graphql hackerone vuln cwe-200" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Gitlab CE/EE 13.4 - 13.6.2 - Information Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2020/CVE-2020-26413.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2020-26413.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> _0xf4n9x_,pikpikcu</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2020-26413" target="_blank" rel="noopener" class="nt-cve-link">CVE-2020-26413</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)gitlab&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">GitLab CE and EE 13.4 through 13.6.2 is susceptible to Information disclosure via GraphQL. User email is visible. An attacker can possibly obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can gain unauthorized access to sensitive information.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade Gitlab CE/EE to version 13.6.3 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2020</span><span class="nt-tag">enum</span><span class="nt-tag">exposure</span><span class="nt-tag">gitlab</span><span class="nt-tag">graphql</span><span class="nt-tag">hackerone</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://gitlab.com/gitlab-org/gitlab/-/issues/244275" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-26413.json" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2020-26413" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://hackerone.com/reports/972355" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/ARPSyndicate/cvemon" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="gitlab default login high identify default logins in web-based control panels gitlab default login credentials were discovered. suman_kar,dwisiswant0 default-login gitlab vuln cwe-798" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Gitlab Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/gitlab/gitlab-weak-login.yaml" target="_blank" rel="noopener" class="nt-source-link">gitlab-weak-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Suman_Kar,dwisiswant0</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/798.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-798</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;GitLab&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Gitlab default login credentials were discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">gitlab</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://twitter.com/0xmahmoudJo0/status/1467394090685943809" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://git-scm.com/book/en/v2/Git-on-the-Server-GitLab" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="gitlab login panel - detect info identify web-based control panels gitlab login panel was detected. ehsahil discovery gitlab panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Gitlab Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/gitlab-detect.yaml" target="_blank" rel="noopener" class="nt-source-link">gitlab-detect.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ehsahil</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)gitlab&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Gitlab login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">gitlab</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="gitlab saml - detection info identify web-based control panels the presence of saml-based authentication on gitlab instances. saml is commonly used for single sign-on (sso) integrations, which allows users to authenticate with gitlab using an external identity provider (idp). rootxharsh,iamnoooob,pdresearch discovery gitlab panel saml" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Gitlab SAML - Detection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/gitlab-saml.yaml" target="_blank" rel="noopener" class="nt-source-link">gitlab-saml.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rootxharsh,iamnoooob,pdresearch</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 5, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)gitlab&#34;}) || service[&#34;http.body&#34;] matches &#34;(?i)gitlab enterprise edition&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The presence of SAML-based authentication on GitLab instances. SAML is commonly used for Single Sign-On (SSO) integrations, which allows users to authenticate with GitLab using an external Identity Provider (IdP).</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">gitlab</span><span class="nt-tag">panel</span><span class="nt-tag">saml</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="gitness - default login high identify default logins in web-based control panels detected gitness instance was found using default admin credentials (admin/changeit). 0x_akoko gitness default-login" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Gitness - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/gitness-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">gitness-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_Akoko</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 23, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Gitness&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detected Gitness instance was found using default admin credentials (admin/changeit).</div></div></div>
  <div class="nt-tags"><span class="nt-tag">gitness</span><span class="nt-tag">default-login</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://docs.gitness.com/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="gladinet centrestack &amp; triofox - local file inclusion medium identify critical remote vulnerabilities in the default installation and configuration of gladinet centrestack and triofox, there is an unauthenticated local file inclusion flaw that allows unintended disclosure of system files. exploitation of this vulnerability has been observed in the wild.  this issue impacts gladinet centrestack and triofox: all versions prior to and including 16.7.10368.56560 cve-2025-11371 kazgangap centrestack cve cve2025 gladinet kev lfi vkev vuln cwe-552" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Gladinet CentreStack &amp; TrioFox - Local File Inclusion</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-11371.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-11371.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Kazgangap</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 17, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/552.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-552</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-11371" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-11371</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)CentreStack&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">In the default installation and configuration of Gladinet CentreStack and TrioFox, there is an unauthenticated Local File Inclusion Flaw that allows unintended disclosure of system files. Exploitation of this vulnerability has been observed in the wild.  This issue impacts Gladinet CentreStack and Triofox: All versions prior to and including 16.7.10368.56560</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can disclose sensitive system files, potentially leading to information leakage.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to a version later than 16.7.10368.56560 or the latest available version.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">centrestack</span><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">gladinet</span><span class="nt-tag">kev</span><span class="nt-tag">lfi</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.huntress.com/blog/gladinet-centrestack-triofox-local-file-inclusion-flaw" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/Kazgangap/cve-poc-garage/blob/main/2025/CVE-2025-11371.md" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://thehackernews.com/2025/10/from-lfi-to-rce-active-exploitation.html" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-11371" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="gladinet centrestack &amp; triofox - hardcoded credentials critical identify critical remote vulnerabilities gladinet centrestack and triofox &lt; 16.12.10420.56791 contain a hardcoded credentials vulnerability caused by use of hardcoded aes cryptoscheme values, letting attackers perform arbitrary local file inclusion without authentication, potentially leading to full system compromise. cve-2025-14611 0xanis centrestack cve cve2025 gladinet kev triofox vkev cwe-321" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Gladinet CentreStack &amp; Triofox - Hardcoded Credentials</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-14611.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-14611.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0xanis</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 17, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/321.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-321</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-14611" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-14611</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)CentreStack|Triofox&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Gladinet CentreStack and Triofox &lt; 16.12.10420.56791 contain a hardcoded credentials vulnerability caused by use of hardcoded AES cryptoscheme values, letting attackers perform arbitrary local file inclusion without authentication, potentially leading to full system compromise.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can exploit hardcoded AES keys to perform arbitrary local file inclusion, potentially leading to full system compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to version 16.12.10420.56791 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">centrestack</span><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">gladinet</span><span class="nt-tag">kev</span><span class="nt-tag">triofox</span><span class="nt-tag">vkev</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.huntress.com/blog/active-exploitation-gladinet-centrestack-triofox-insecure-cryptography-vulnerability" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-14611" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="gladinet centrestack &lt; 16.4.10315.56368 use of hard-coded key leads to unauthenticated rce critical identify critical remote vulnerabilities gladinet centrestack through 16.1.10296.56315 (fixed in 16.4.10315.56368) has a deserialization vulnerability due to the centrestack portal&#39;s hardcoded machinekey use, as exploited in the wild in march 2025. this enables threat actors (who know the machinekey) to serialize a payload for server-side deserialization to achieve remote code execution. cve-2025-30406 iamnoooob,rootxharsh,pdresearch centrestack cve cve2025 deserialization gladinet kev rce vkev vuln cwe-321,cwe-502,cwe-798" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Gladinet CentreStack &lt; 16.4.10315.56368 Use of Hard-coded Key Leads to Unauthenticated RCE</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-30406.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-30406.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> iamnoooob,rootxharsh,pdresearch</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 15, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/321,CWE-502,CWE-798.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-321,CWE-502,CWE-798</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-30406" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-30406</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1163764264&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Gladinet CentreStack through 16.1.10296.56315 (fixed in 16.4.10315.56368) has a deserialization vulnerability due to the CentreStack portal&#39;s hardcoded machineKey use, as exploited in the wild in March 2025. This enables threat actors (who know the machineKey) to serialize a payload for server-side deserialization to achieve remote code execution.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can exploit hard-coded machineKey values to deserialize malicious payloads, achieving remote code execution and complete server compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to Gladinet CentreStack version 16.4.10315.56368 or later that uses secure, randomly generated machineKeys.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">centrestack</span><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">deserialization</span><span class="nt-tag">gladinet</span><span class="nt-tag">kev</span><span class="nt-tag">rce</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-30406" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://gladinetsupport.s3.us-east-1.amazonaws.com/gladinet/securityadvisory-cve-2005.pdf" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.centrestack.com/p/gce_latest_release.html" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="glances - information disclosure high identify critical remote vulnerabilities glances &lt; 4.5.2 contains an information disclosure vulnerability caused by the web server running without authentication by default, letting remote attackers access sensitive system information including credentials, exploit requires no special privileges. cve-2026-32596 theamanrawat cve cve2026 exposure glances unauth vuln cwe-200" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Glances - Information Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2026/CVE-2026-32596.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2026-32596.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> theamanrawat</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 19, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2026-32596" target="_blank" rel="noopener" class="nt-cve-link">CVE-2026-32596</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;840398323&#34; || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Glances&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Glances &lt; 4.5.2 contains an information disclosure vulnerability caused by the web server running without authentication by default, letting remote attackers access sensitive system information including credentials, exploit requires no special privileges.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Remote attackers can access sensitive system information including credentials, risking data exposure and system compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to version 4.5.2 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2026</span><span class="nt-tag">exposure</span><span class="nt-tag">glances</span><span class="nt-tag">unauth</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/nicolargo/glances/security/advisories/GHSA-wvxv-4j8q-4wjq" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32596" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="glimpse diagnostics - sensitive data exposure high identify critical remote vulnerabilities detected glimpse diagnostics endpoint. glimpse is a .net diagnostics tool that reveals detailed request information, server configuration, sql queries, connection strings, and session data. 0x_akoko exposure misconfig dotnet glimpse debug cwe-200" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Glimpse Diagnostics - Sensitive Data Exposure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposures/configs/glimpse-data-exposure.yaml" target="_blank" rel="noopener" class="nt-source-link">glimpse-data-exposure.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_Akoko</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 16, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Glimpse\\.axd&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detected Glimpse diagnostics endpoint. Glimpse is a .NET diagnostics tool that reveals detailed request information, server configuration, SQL queries, connection strings, and session data.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">exposure</span><span class="nt-tag">misconfig</span><span class="nt-tag">dotnet</span><span class="nt-tag">glimpse</span><span class="nt-tag">debug</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://getglimpse.com/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/Glimpse/Glimpse" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="glowroot - panel info identify web-based control panels  dhiyaneshdk panel login glowroot discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Glowroot - Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/glowroot-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">glowroot-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 20, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Glowroot&#34;})</code></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">login</span><span class="nt-tag">glowroot</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.facebook.com/photo?fbid=618105097026680&amp;set=a.467014098802448" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="gnuboard5 5.5.16 - open redirect medium identify critical remote vulnerabilities gnuboard5 5.5.16 contains an open redirect vulnerability caused by insufficient url parameter verification in bbs/logout.php, letting remote attackers redirect users to arbitrary urls, exploit requires crafted url parameter. cve-2024-37656 0x_akoko cve cve2024 gnuboard5 redirect vkev cwe-601" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">GnuBoard5 5.5.16 - Open Redirect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-37656.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-37656.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_Akoko</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 17, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/601.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-601</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-37656" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-37656</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)GnuBoard5&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Gnuboard5 5.5.16 contains an open redirect vulnerability caused by insufficient URL parameter verification in bbs/logout.php, letting remote attackers redirect users to arbitrary URLs, exploit requires crafted URL parameter.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Remote attackers can redirect users to malicious sites, potentially leading to phishing or information theft.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest version of Gnuboard5.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">gnuboard5</span><span class="nt-tag">redirect</span><span class="nt-tag">vkev</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/gnuboard/gnuboard5/issues/318" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-37656" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="go.control event administration panel - detect info identify web-based control panels detects the presence of the go.control event administration login panel. mys7ic panel gocontrol login detect discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Go.Control Event Administration Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/gocontrol-admin-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">gocontrol-admin-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Mys7ic</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 1, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Go\\.Control&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detects the presence of the Go.Control Event Administration login panel.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">gocontrol</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.go-control.de/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="goanywhere - authentication bypass critical identify critical remote vulnerabilities fortra goanywhere mft contains an insecure deserialization vulnerability in the license servlet caused by deserializing attacker-controlled objects with a valid forged license response signature, letting attackers perform command injection, exploit requires valid forged license signature. cve-2025-10035 dhiyaneshdk,watchtowr auth-bypass cve cve2025 goanywhere kev vkev vuln cwe-502" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">GoAnywhere - Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-10035.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-10035.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk,watchtowr</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 24, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/502.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-502</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-10035" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-10035</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)GoAnywhere&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Fortra GoAnywhere MFT contains an insecure deserialization vulnerability in the License Servlet caused by deserializing attacker-controlled objects with a valid forged license response signature, letting attackers perform command injection, exploit requires valid forged license signature.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can execute arbitrary commands remotely, potentially leading to full system compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest version with the deserialization fix.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">goanywhere</span><span class="nt-tag">kev</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://labs.watchtowr.com/is-this-bad-this-feels-bad-goanywhere-cve-2025-10035/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://attackerkb.com/topics/LbA9ANjcdz/cve-2025-10035/rapid7-analysis" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.fortra.com/security/advisories/product-security/fi-2025-011" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="goanywhere managed file transfer login panel - detect info identify web-based control panels goanywhere managed file transfer login panel was detected. ritikchaddha,righettod discovery filetransfer goanywhere login panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">GoAnywhere Managed File Transfer Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/goanywhere-mft-login.yaml" target="_blank" rel="noopener" class="nt-source-link">goanywhere-mft-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha,righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)GoAnywhere Managed File Transfer&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">GoAnywhere Managed File Transfer login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">filetransfer</span><span class="nt-tag">goanywhere</span><span class="nt-tag">login</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="gocd login panel - detect info identify web-based control panels gocd login panel was detected. dhiyaneshdk discovery go gocd panel thoughtworks cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">GoCD Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/gocd-login.yaml" target="_blank" rel="noopener" class="nt-source-link">gocd-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)create a pipeline - go&#34;}) || service[&#34;http.body&#34;] matches &#34;(?i)gocd version&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">GoCD login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">go</span><span class="nt-tag">gocd</span><span class="nt-tag">panel</span><span class="nt-tag">thoughtworks</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="gogs (go git service) - sql injection high identify critical remote vulnerabilities multiple sql injection vulnerabilities in gogs (aka go git service) 0.3.1-9 through 0.5.x before 0.5.6.1105 beta allow remote attackers to execute arbitrary sql commands via the q parameter to (1) api/v1/repos/search, which is not properly handled in models/repo.go, or (2) api/v1/users/search, which is not properly handled in models/user.go. cve-2014-8682 dhiyaneshdk,daffainfo cve cve2014 edb gogits gogs packetstorm seclists sqli vuln cwe-89" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Gogs (Go Git Service) - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2014/CVE-2014-8682.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2014-8682.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDK,daffainfo</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2014-8682" target="_blank" rel="noopener" class="nt-cve-link">CVE-2014-8682</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)sign in - gogs&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Multiple SQL injection vulnerabilities in Gogs (aka Go Git Service) 0.3.1-9 through 0.5.x before 0.5.6.1105 Beta allow remote attackers to execute arbitrary SQL commands via the q parameter to (1) api/v1/repos/search, which is not properly handled in models/repo.go, or (2) api/v1/users/search, which is not properly handled in models/user.go.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could lead to unauthorized access, data leakage, and potential compromise of the entire system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches and updates provided by the Gogs project to mitigate the SQL Injection vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2014</span><span class="nt-tag">edb</span><span class="nt-tag">gogits</span><span class="nt-tag">gogs</span><span class="nt-tag">packetstorm</span><span class="nt-tag">seclists</span><span class="nt-tag">sqli</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2014-8682" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="http://seclists.org/fulldisclosure/2014/Nov/33" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="http://packetstormsecurity.com/files/129117/Gogs-Repository-Search-SQL-Injection.html" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/gogits/gogs/commit/0c5ba4573aecc9eaed669e9431a70a5d9f184b8d" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://www.exploit-db.com/exploits/35238" target="_blank" rel="noopener" class="nt-ref-link">[5]</a> <a href="https://exchange.xforce.ibmcloud.com/vulnerabilities/98694" target="_blank" rel="noopener" class="nt-ref-link">[6]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="gogs (go git service) 0.11.66 - remote code execution critical identify critical remote vulnerabilities gogs 0.11.66 allows remote code execution because it does not properly validate session ids, as demonstrated by a &#34;..&#34; session-file forgery in the file session provider in file.go. this is related to session id handling in the go-macaron/session code for macaron. cve-2018-18925 princechaddha cve cve2018 gogs lfi rce vulhub vuln cwe-384" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Gogs (Go Git Service) 0.11.66 - Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2018/CVE-2018-18925.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2018-18925.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> princechaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/384.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-384</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2018-18925" target="_blank" rel="noopener" class="nt-cve-link">CVE-2018-18925</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)sign in - gogs&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Gogs 0.11.66 allows remote code execution because it does not properly validate session IDs, as demonstrated by a &#34;..&#34; session-file forgery in the file session provider in file.go. This is related to session ID handling in the go-macaron/session code for Macaron.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the target system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">This issue will be fixed by updating to the latest version of Gogs.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2018</span><span class="nt-tag">gogs</span><span class="nt-tag">lfi</span><span class="nt-tag">rce</span><span class="nt-tag">vulhub</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.anquanke.com/post/id/163575" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/vulhub/vulhub/tree/master/gogs/CVE-2018-18925" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/cve-2018-18925" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/gogs/gogs/issues/5469" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/j4k0m/CVE-2018-18925" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="gogs &lt;= 0.13.3 - remote code execution high identify critical remote vulnerabilities gogs self-hosted git service versions 0.13.3 and earlier contain a critical symlink bypass vulnerability that circumvents the fix for cve-2024-55947. authenticated users can exploit improper symbolic link handling in the putcontents api to overwrite files outside the repository by committing a symlink pointing to sensitive targets, leading to remote code execution. as of december 2025, this remains an unpatched zero-day with active exploitation ongoing. approximately 1,400 exposed gogs instances exist, with over 700 showing signs of compromise. the vulnerability stems from the api writing to file paths without checking if targets are symlinks pointing outside the repository. gogs maintainers are working on a fix. cve-2025-8110 rxerium cve cve2025 git gogs kev passive rce symlink vkev cwe-22" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Gogs &lt;= 0.13.3 - Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-8110.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-8110.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 13, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-8110" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-8110</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;product&#34;] contains &#34;Gogs:Gogs&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Gogs self-hosted Git service versions 0.13.3 and earlier contain a critical symlink bypass vulnerability that circumvents the fix for CVE-2024-55947. Authenticated users can exploit improper symbolic link handling in the PutContents API to overwrite files outside the repository by committing a symlink pointing to sensitive targets, leading to remote code execution. As of December 2025, this remains an unpatched zero-day with active exploitation ongoing. Approximately 1,400 exposed Gogs instances exist, with over 700 showing signs of compromise. The vulnerability stems from the API writing to file paths without checking if targets are symlinks pointing outside the repository. Gogs maintainers are working on a fix.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Local attackers can execute arbitrary code, potentially leading to full system compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest version of Gogs.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">git</span><span class="nt-tag">gogs</span><span class="nt-tag">kev</span><span class="nt-tag">passive</span><span class="nt-tag">rce</span><span class="nt-tag">symlink</span><span class="nt-tag">vkev</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.wiz.io/blog/wiz-research-gogs-cve-2025-8110-rce-exploit" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://thehackernews.com/2025/12/unpatched-gogs-zero-day-exploited.html" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/advisories/ghsa-mq8m-42gh-wq7r" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-8110" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="gogs login panel - detect info identify web-based control panels gogs login panel was detected. dhiyaneshdk,daffainfo discovery gogs panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Gogs Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/gogs-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">gogs-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk,daffainfo</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;917966895&#34; || service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1935513730&#34; || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)sign in - gogs&#34;}) || service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-449283196&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Gogs login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">gogs</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://gogs.io/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="google earth enterprise default login high identify default logins in web-based control panels google earth enterprise default login credentials were discovered. orpheus,johnjhacking default-login google-earth vuln cwe-522" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Google Earth Enterprise Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/google/google-earth-dlogin.yaml" target="_blank" rel="noopener" class="nt-source-link">google-earth-dlogin.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> orpheus,johnjhacking</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/522.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-522</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;GEE Server&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Google Earth Enterprise default login credentials were discovered.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">To reset the username and password:

sudo /opt/google/gehttpd/bin/htpasswd -c
/opt/google/gehttpd/conf.d/.htpasswd geapacheuse&#34;</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">google-earth</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://johnjhacking.com/blog/gee-exploitation/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.opengee.org/geedocs/5.2.2/answer/3470759.html" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="gophish login panel - detect info identify web-based control panels gophish login panel was detected. dhiyaneshdk discovery gophish panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Gophish Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/gophish-login.yaml" target="_blank" rel="noopener" class="nt-source-link">gophish-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Gophish - Login&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Gophish login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">gophish</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="gotify login panel - detect info identify web-based control panels gotify login panel was detected. righettod detect discovery gotify login panel" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Gotify Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/gotify-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">gotify-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 15, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)gotify&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Gotify login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">gotify</span><span class="nt-tag">login</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/gotify/server" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="gradio - absolute path traversal high identify critical remote vulnerabilities gradio &lt; 6.7 on windows with python 3.13+ contains an absolute path traversal caused by incorrect path validation in path joining logic, letting unauthenticated attackers read arbitrary files from the server. cve-2026-28414 0x_akoko cve cve2026 gradio lfi traversal unauth vkev windows cwe-36" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Gradio - Absolute Path Traversal</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2026/CVE-2026-28414.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2026-28414.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_Akoko</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 8, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/36.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-36</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2026-28414" target="_blank" rel="noopener" class="nt-cve-link">CVE-2026-28414</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;Gradio&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Gradio &lt; 6.7 on Windows with Python 3.13+ contains an absolute path traversal caused by incorrect path validation in path joining logic, letting unauthenticated attackers read arbitrary files from the server.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can read arbitrary files on the server, potentially exposing sensitive information.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to version 6.7 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2026</span><span class="nt-tag">gradio</span><span class="nt-tag">lfi</span><span class="nt-tag">traversal</span><span class="nt-tag">unauth</span><span class="nt-tag">vkev</span><span class="nt-tag">windows</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/gradio-app/gradio/security/advisories/GHSA-39mp-8hj3-5c49" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28414" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="gradio - local file inclusion critical identify critical remote vulnerabilities gradio&#39;s dropdown component is vulnerable to local file inclusion (lfi) when the value is a dictionary controlled by an attacker. in the postprocess of components, if the value type is a dict, it flows to the async_move_files_to_cache function. when the dictionary is crafted with a &#34;path&#34; key, it causes local file inclusion allowing attackers to read arbitrary files. ritikchaddha file-inclusion gradio lfi cwe-20,cwe-22,cwe-73" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Gradio - Local File Inclusion</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/vulnerabilities/gradio-lfi.yaml" target="_blank" rel="noopener" class="nt-source-link">gradio-lfi.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 6, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/20,CWE-22,CWE-73.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-20,CWE-22,CWE-73</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)__gradio_mode__&#34; || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)gradio&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Gradio&#39;s Dropdown component is vulnerable to Local File Inclusion (LFI) when the value is a dictionary controlled by an attacker. In the postprocess of components, if the value type is a dict, it flows to the async_move_files_to_cache function. When the dictionary is crafted with a &#34;path&#34; key, it causes local file inclusion allowing attackers to read arbitrary files.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">file-inclusion</span><span class="nt-tag">gradio</span><span class="nt-tag">lfi</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://huntr.com/bounties/936ef084-45e1-4dc5-a419-bca071189565" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="gradle develocity build cache node login panel - detect info identify web-based control panels gradle develocity build cache node login panel was detected. righettod panel gradle detect login discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Gradle Develocity Build Cache Node Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/gradle/gradle-develocity-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">gradle-develocity-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 11, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Develocity Build Cache Node&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Gradle Develocity Build Cache Node login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">gradle</span><span class="nt-tag">detect</span><span class="nt-tag">login</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://gradle.com/gradle-enterprise-solutions/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="gradle enterprise build cache node login panel - detect info identify web-based control panels gradle enterprise build cache node login panel was detected. adam crosser,righettod panel gradle detect discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Gradle Enterprise Build Cache Node Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/gradle/gradle-cache-node-detect.yaml" target="_blank" rel="noopener" class="nt-source-link">gradle-cache-node-detect.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Adam Crosser,righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Gradle Enterprise Build Cache Node&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Gradle Enterprise Build Cache Node login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">gradle</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://gradle.com/gradle-enterprise-solutions/build-cache/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="grafana &amp; zabbix integration - credentials disclosure critical identify critical remote vulnerabilities grafana through 7.3.4, when integrated with zabbix, contains a credential disclosure vulnerability. the zabbix password can be found in the api_jsonrpc.php html source code. when the user logs in and allows the user to register, one can right click to view the source code and use ctrl-f to search for password in api_jsonrpc.php to discover the zabbix account password and url address. cve-2022-26148 geekby cve cve2022 exposure grafana vuln zabbix cwe-312" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Grafana &amp; Zabbix Integration - Credentials Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-26148.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-26148.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Geekby</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/312.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-312</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-26148" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-26148</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)grafana&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Grafana through 7.3.4, when integrated with Zabbix, contains a credential disclosure vulnerability. The Zabbix password can be found in the api_jsonrpc.php HTML source code. When the user logs in and allows the user to register, one can right click to view the source code and use Ctrl-F to search for password in api_jsonrpc.php to discover the Zabbix account password and URL address.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can obtain sensitive credentials, leading to unauthorized access and potential data breaches.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest version of the Grafana &amp; Zabbix Integration plugin to fix the vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">exposure</span><span class="nt-tag">grafana</span><span class="nt-tag">vuln</span><span class="nt-tag">zabbix</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://2k8.org/post-319.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://security.netapp.com/advisory/ntap-20220425-0005/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-26148" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/HimmelAward/Goby_POC" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/Z0fhack/Goby_POC" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="grafana - exposes dingding api keys medium identify critical remote vulnerabilities an incident occurred where the dingding alerting integration url was inadvertently exposed to viewers due to a setting oversight in versions below or equals to 12.0.1. cve-2025-3415 lucasribolli apikey cve cve2025 dingding dingtalk grafana vkev vuln cwe-200" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Grafana - Exposes DingDing API Keys</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-3415.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-3415.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> lucasribolli</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 18, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-3415" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-3415</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)grafana&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An incident occurred where the DingDing alerting integration URL was inadvertently exposed to viewers due to a setting oversight in versions below or equals to 12.0.1.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Viewers can access DingDing alerting integration URLs containing access tokens through the alertmanager API, potentially enabling unauthorized message delivery and notification manipulation.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to Grafana version 12.0.2 or later that properly restricts access to DingDing integration settings.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">apikey</span><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">dingding</span><span class="nt-tag">dingtalk</span><span class="nt-tag">grafana</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://grafana.com/blog/2025/06/13/grafana-security-update-medium-severity-security-release-for-cve-2025-3415/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="grafana 3.0.1-7.0.1 - server-side request forgery high identify critical remote vulnerabilities grafana 3.0.1 through 7.0.1 is susceptible to server-side request forgery via the avatar feature, which can lead to remote code execution. any unauthenticated user/client can make grafana send http requests to any url and return its result. this can be used to gain information about the network grafana is running on, thereby potentially enabling an attacker to obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site. cve-2020-13379 joshua rogers cve cve2020 grafana ssrf vkev vuln cwe-918" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Grafana 3.0.1-7.0.1 - Server-Side Request Forgery</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2020/CVE-2020-13379.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2020-13379.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Joshua Rogers</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/918.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-918</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2020-13379" target="_blank" rel="noopener" class="nt-cve-link">CVE-2020-13379</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Grafana&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Grafana 3.0.1 through 7.0.1 is susceptible to server-side request forgery via the avatar feature, which can lead to remote code execution. Any unauthenticated user/client can make Grafana send HTTP requests to any URL and return its result. This can be used to gain information about the network Grafana is running on, thereby potentially enabling an attacker to obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can exploit this vulnerability to bypass security controls, access internal resources, and potentially perform further attacks.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to 6.3.4 or higher.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2020</span><span class="nt-tag">grafana</span><span class="nt-tag">ssrf</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/advisories/GHSA-wc9w-wvq2-ffm9" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/grafana/grafana/commit/ba953be95f0302c2ea80d23f1e5f2c1847365192" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="http://www.openwall.com/lists/oss-security/2020/06/03/4" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2020-13379" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00060.html" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="grafana 8.0.0 &lt;= v.8.2.2 - angularjs rendering cross-site scripting medium identify critical remote vulnerabilities grafana is an open-source platform for monitoring and observability. in affected versions if an attacker is able to convince a victim to visit a url referencing a vulnerable page, arbitrary javascript content may be executed within the context of the victim&#39;s browser. the user visiting the malicious link must be unauthenticated and the link must be for a page that contains the login button in the menu bar. the url has to be crafted to exploit angularjs rendering and contain the interpolation binding for angularjs expressions. cve-2021-41174 pdteam cve cve2021 grafana vkev vuln xss cwe-79" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Grafana 8.0.0 &lt;= v.8.2.2 - Angularjs Rendering Cross-Site Scripting</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2021/CVE-2021-41174.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2021-41174.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pdteam</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-79</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2021-41174" target="_blank" rel="noopener" class="nt-cve-link">CVE-2021-41174</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Grafana&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Grafana is an open-source platform for monitoring and observability. In affected versions if an attacker is able to convince a victim to visit a URL referencing a vulnerable page, arbitrary JavaScript content may be executed within the context of the victim&#39;s browser. The user visiting the malicious link must be unauthenticated and the link must be for a page that contains the login button in the menu bar. The url has to be crafted to exploit AngularJS rendering and contain the interpolation binding for AngularJS expressions.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute arbitrary JavaScript code in the context of the victim&#39;s browser, leading to potential data theft, session hijacking, or defacement of the Grafana application.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to 8.2.3 or higher.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2021</span><span class="nt-tag">grafana</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">xss</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/grafana/grafana/security/advisories/GHSA-3j9m-hcv9-rpj8" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2021-41174" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/grafana/grafana/commit/3cb5214fa45eb5a571fd70d6c6edf0d729983f82" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/grafana/grafana/commit/31b78d51c693d828720a5b285107a50e6024c912" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/grafana/grafana/commit/fb85ed691290d211a5baa44d9a641ab137f0de88" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="grafana default login high identify default logins in web-based control panels grafana default admin login credentials were detected. pdteam default-login grafana vuln cwe-522" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Grafana Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/grafana/grafana-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">grafana-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pdteam</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/522.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-522</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;Grafana&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Grafana default admin login credentials were detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">grafana</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://grafana.com/docs/grafana/latest/administration/configuration/#disable_brute_force_login_protection" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://stackoverflow.com/questions/54039604/what-is-the-default-username-and-password-for-grafana-login-page" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/grafana/grafana/issues/14755" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="grafana login check critical http-credential-stuffing checks for a valid login on self hosted grafana instance. parthmalhotra,pdresearch creds-stuffing grafana login-check self-hosted vuln" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Grafana Login Check</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/credential-stuffing/self-hosted/grafana-login-check.yaml" target="_blank" rel="noopener" class="nt-source-link">grafana-login-check.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> parthmalhotra,pdresearch</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 5, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Grafana&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Checks for a valid login on self hosted Grafana instance.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">creds-stuffing</span><span class="nt-tag">grafana</span><span class="nt-tag">login-check</span><span class="nt-tag">self-hosted</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://owasp.org/www-community/attacks/Credential_stuffing" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">http-credential-stuffing</span></span></div>
</div>
<div class="nt-card" data-nt-search="grafana login panel - detect info identify web-based control panels grafana login panel was detected. organiccrap,adamcrosser,bhutch detect discovery grafana panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Grafana Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/grafana-detect.yaml" target="_blank" rel="noopener" class="nt-source-link">grafana-detect.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> organiccrap,AdamCrosser,bhutch</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)grafana&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Grafana login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">grafana</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="grafana snapshot - authentication bypass high identify critical remote vulnerabilities grafana instances up to 7.5.11 and 8.1.5 allow remote unauthenticated users to view the snapshot associated with the lowest database key by accessing the literal paths /api/snapshot/:key or /dashboard/snapshot/:key. if the snapshot is in public mode, unauthenticated users can delete snapshots by accessing the endpoint /api/snapshots-delete/:deletekey. authenticated users can also delete snapshots by accessing the endpoints /api/snapshots-delete/:deletekey, or sending a delete request to /api/snapshot/:key, regardless of whether or not the snapshot is set to public mode (disabled by default). cve-2021-39226 evan rubinstein,matejsmycka cve cve2021 grafana kev vkev vuln cwe-287" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Grafana Snapshot - Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2021/CVE-2021-39226.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2021-39226.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Evan Rubinstein,matejsmycka</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/287.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-287</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2021-39226" target="_blank" rel="noopener" class="nt-cve-link">CVE-2021-39226</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)grafana&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Grafana instances up to 7.5.11 and 8.1.5 allow remote unauthenticated users to view the snapshot associated with the lowest database key by accessing the literal paths /api/snapshot/:key or /dashboard/snapshot/:key. If the snapshot is in public mode, unauthenticated users can delete snapshots by accessing the endpoint /api/snapshots-delete/:deleteKey. Authenticated users can also delete snapshots by accessing the endpoints /api/snapshots-delete/:deleteKey, or sending a delete request to /api/snapshot/:key, regardless of whether or not the snapshot is set to public mode (disabled by default).</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can bypass authentication and gain unauthorized access to Grafana Snapshot feature.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">This issue has been resolved in versions 8.1.6 and 7.5.11. If you cannot upgrade you can block access to the literal paths: /api/snapshots/:key, /api/snapshots-delete/:deleteKey, /dashboard/snapshot/:key, and /api/snapshots/:key. They have no normal function and can be disabled without side effects.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2021</span><span class="nt-tag">grafana</span><span class="nt-tag">kev</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/advisories/GHSA-69j6-29vr-p3j9" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2021-39226" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/grafana/grafana/commit/2d456a6375855364d098ede379438bf7f0667269" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://grafana.com/docs/grafana/latest/release-notes/release-notes-8-1-6/" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="http://www.openwall.com/lists/oss-security/2021/10/05/4" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="grafana v8.x - arbitrary file read high identify critical remote vulnerabilities grafana versions 8.0.0-beta1 through 8.3.0 are vulnerable to a local directory traversal, allowing access to local files. the vulnerable url path is `&lt;grafana_host_url&gt;/public/plugins/name/`, where name is the plugin id for any installed plugin. cve-2021-43798 z0ne,dhiyaneshdk,j4vaovo cve cve2021 grafana kev lfi packetstorm vkev vuln cwe-22" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Grafana v8.x - Arbitrary File Read</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2021/CVE-2021-43798.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2021-43798.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> z0ne,dhiyaneshDk,j4vaovo</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2021-43798" target="_blank" rel="noopener" class="nt-cve-link">CVE-2021-43798</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)grafana&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Grafana versions 8.0.0-beta1 through 8.3.0 are vulnerable to a local directory traversal, allowing access to local files. The vulnerable URL path is `&lt;grafana_host_url&gt;/public/plugins/NAME/`, where NAME is the plugin ID for any installed plugin.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can read sensitive files on the server, potentially leading to unauthorized access, data leakage, or further exploitation.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to patched versions 8.0.7, 8.1.8, 8.2.7, or 8.3.1.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2021</span><span class="nt-tag">grafana</span><span class="nt-tag">kev</span><span class="nt-tag">lfi</span><span class="nt-tag">packetstorm</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/grafana/grafana/security/advisories/GHSA-8pjx-jj86-j47p" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nosec.org/home/detail/4914.html" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/jas502n/Grafana-VulnTips" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2021-43798" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="http://packetstormsecurity.com/files/165198/Grafana-Arbitrary-File-Reading.html" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="grandstream grp - default login high identify default logins in web-based control panels grandstream grp series devices use default credentials (admin/admin). the web ui login sends a sha-256 hash of the password to /cgi-bin/access. successful authentication returns a json response with a session token, indicating full admin access to the device management interface. dhiyaneshdk default-login grandstream grp iot vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Grandstream GRP - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/grandstream/grandstream-grp-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">grandstream-grp-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 21, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)tl\\.account\\.ucm\\.js&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Grandstream GRP series devices use default credentials (admin/admin). The web UI login sends a SHA-256 hash of the password to /cgi-bin/access. Successful authentication returns a JSON response with a session token, indicating full admin access to the device management interface.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Change the default administrator password immediately. Update firmware to the latest version which generates random passwords on factory reset.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">grandstream</span><span class="nt-tag">grp</span><span class="nt-tag">iot</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="grandstream grp panel - detect info identify web-based control panels detected the presence of a grandstream grp web management login panel. the react-based spa loads characteristic javascript modules including tl.account.ucm.js and webpack chunks for ucm modules. dhiyaneshdk detect grandstream grp iot panel" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Grandstream GRP Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/iot/grandstream-grp-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">grandstream-grp-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 27, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)tl\\.account\\.ucm\\.js&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detected the presence of a Grandstream GRP web management login panel. The React-based SPA loads characteristic JavaScript modules including tl.account.ucm.js and webpack chunks for UCM modules.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">detect</span><span class="nt-tag">grandstream</span><span class="nt-tag">grp</span><span class="nt-tag">iot</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="graphiql - exposure low identify critical remote vulnerabilities detected publicly exposed graphiql consoles. vincent olagbemide misconfig graphql graphiql exposure" data-nt-sev="low">
  <div class="nt-card-header">
    <div class="nt-title">GraphiQL - Exposure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/misconfiguration/graphql/graphiql-exposure.yaml" target="_blank" rel="noopener" class="nt-source-link">graphiql-exposure.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Vincent Olagbemide</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 17, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)GraphiQL&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detected publicly exposed GraphiQL consoles.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">misconfig</span><span class="nt-tag">graphql</span><span class="nt-tag">graphiql</span><span class="nt-tag">exposure</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/graphql/graphiql" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="graphite browser login panel - detect info identify web-based control panels graphite browser login panel was detected. 0x_akoko discovery graphite panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Graphite Browser Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/graphite-browser.yaml" target="_blank" rel="noopener" class="nt-source-link">graphite-browser.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_Akoko</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Graphite Browser&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Graphite Browser login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">graphite</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://graphiteapp.org/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="gravity smtp wordpress plugin - sensitive information exposure high identify critical remote vulnerabilities gravity smtp wordpress plugin &lt;= 2.1.4 contains a sensitive information exposure caused by an unrestricted rest api endpoint at /wp-json/gravitysmtp/v1/tests/mock-data, letting unauthenticated attackers retrieve detailed system configuration data, exploit requires no authentication. cve-2026-4020 theamanrawat cve cve2026 exposure gravitysmtp unauthenticated vkev wordpress wp wp-plugin cwe-200" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Gravity SMTP WordPress Plugin - Sensitive Information Exposure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2026/CVE-2026-4020.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2026-4020.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> theamanrawat</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 8, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2026-4020" target="_blank" rel="noopener" class="nt-cve-link">CVE-2026-4020</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/gravity(?:smtp|forms)&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Gravity SMTP WordPress plugin &lt;= 2.1.4 contains a sensitive information exposure caused by an unrestricted REST API endpoint at /wp-json/gravitysmtp/v1/tests/mock-data, letting unauthenticated attackers retrieve detailed system configuration data, exploit requires no authentication.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can access detailed system and configuration data, potentially aiding further attacks or information leakage.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest version beyond 2.1.4.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2026</span><span class="nt-tag">exposure</span><span class="nt-tag">gravitysmtp</span><span class="nt-tag">unauthenticated</span><span class="nt-tag">vkev</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://patchstack.com/database/vulnerability/wordpress-gravity-smtp-plugin-2-1-4-unauthenticated-sensitive-information-exposure-via-rest-api-vulnerability" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/12a296db-ecc0-409b-8718-0c208504053a?source=cve" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4020" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="graylog - default login high identify default logins in web-based control panels graylog instance is accessible with default admin credentials (admin/admin). this provides full administrative access to the log management platform, including the ability to read all ingested logs, create inputs, configure pipelines, and manage users. 0x_akoko,0xbassia default-login graylog logging cwe-798" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Graylog - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/graylog/graylog-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">graylog-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_Akoko,0xBassia</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 8, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/798.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-798</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;product&#34;] contains &#34;Graylog:Graylog&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Graylog instance is accessible with default admin credentials (admin/admin). This provides full administrative access to the log management platform, including the ability to read all ingested logs, create inputs, configure pipelines, and manage users.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker with admin access to Graylog can read all collected log data which may contain credentials, API keys, internal IPs, and sensitive business information. They can also create new inputs to intercept future log data or modify pipelines to redirect/suppress logs.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Change the default root_password_sha2 in the Graylog server.conf configuration file. Use a strong, unique password for the admin account.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">graylog</span><span class="nt-tag">logging</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://go2docs.graylog.org/current/setting_up_graylog/rest_api.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://archivedocs.graylog.org/en/2.5/pages/installation/virtual_machine_appliances.html" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://docs.graylog.org/docs/authentication" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://docs.graylog.org/docs/server-conf" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="graylog login panel - detect info identify web-based control panels graylog login panel was detected. righettod panel graylog login detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Graylog Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/graylog-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">graylog-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 8, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Graylog Web Interface&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Graylog login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">graylog</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://graylog.org/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="greenbone security assistant panel - detect info identify web-based control panels greenbone security assistant web panel is detected pbuff07 discovery greenbone login panel" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Greenbone Security Assistant Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/greenbone-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">greenbone-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pbuff07</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 24, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)greenbone security assistant&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Greenbone Security Assistant Web Panel is detected</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">greenbone</span><span class="nt-tag">login</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="grocy - default admin credentials high identify default logins in web-based control panels detected grocy was found using default credentials admin:admin.successful authentication grants full access to the household management platform including all stock data, chores, recipes, and user settings. 0x_akoko auth default-login grocy" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Grocy - Default Admin Credentials</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/grocy/grocy-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">grocy-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_Akoko</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 8, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)grocy&#34;}) &amp;&amp; service[&#34;http.body&#34;] contains &#34;grocy-version&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detected Grocy was found using default credentials admin:admin.Successful authentication grants full access to the household management platform including all stock data, chores, recipes, and user settings.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth</span><span class="nt-tag">default-login</span><span class="nt-tag">grocy</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/grocy/grocy" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://docs.linuxserver.io/images/docker-grocy/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="group-ib managed xdr login panel - detect info identify web-based control panels group-ib managed xdr login panel was detected. dhiyaneshdk panel groupib discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Group-IB Managed XDR Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/group-ib-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">group-ib-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Group-IB Managed XDR&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Group-IB Managed XDR login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">groupib</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.facebook.com/photo/?fbid=566951735475350&amp;set=a.467014098802448" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="growatt shinelink - login panel info identify web-based control panels growatt shinelink is a web-based data logger and monitoring interface for growatt solar inverters, providing real-time solar energy production data and system configuration. rxerium discovery growatt ics panel scada solar" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Growatt Shinelink - Login Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/growatt-shinelink-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">growatt-shinelink-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 27, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;Growatt Shinelink&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Growatt Shinelink is a web-based data logger and monitoring interface for Growatt solar inverters, providing real-time solar energy production data and system configuration.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">growatt</span><span class="nt-tag">ics</span><span class="nt-tag">panel</span><span class="nt-tag">scada</span><span class="nt-tag">solar</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.ginverter.com/en/product/monitor/shinelink-x.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="gryphon panel - detect info identify web-based control panels gryphon router panel was detected. pdteam panel gryphon router discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Gryphon Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/gryphon-login.yaml" target="_blank" rel="noopener" class="nt-source-link">gryphon-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pdteam</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Gryphon&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Gryphon router panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">gryphon</span><span class="nt-tag">router</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="gurock testrail application files.md5 exposure high identify critical remote vulnerabilities improper access control in gurock testrail versions &lt; 7.2.0.3014 resulted in sensitive information exposure. a threat actor can access the /files.md5 file on the client side of a gurock testrail application, disclosing a full list of application files and the corresponding file paths which can then be tested, and in some cases result in the disclosure of hardcoded credentials, api keys, or other sensitive data. cve-2021-40875 oscarintherocks cve cve2021 exposure gurock testrail vkev vuln cwe-425" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Gurock TestRail Application files.md5 Exposure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2021/CVE-2021-40875.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2021-40875.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> oscarintherocks</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/425.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-425</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2021-40875" target="_blank" rel="noopener" class="nt-cve-link">CVE-2021-40875</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)testrail&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Improper access control in Gurock TestRail versions &lt; 7.2.0.3014 resulted in sensitive information exposure. A threat actor can access the /files.md5 file on the client side of a Gurock TestRail application, disclosing a full list of application files and the corresponding file paths which can then be tested, and in some cases result in the disclosure of hardcoded credentials, API keys, or other sensitive data.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker could use the exposed files.md5 to gain insight into the application&#39;s file structure and potentially identify vulnerabilities or sensitive information.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Securely restrict access to the files.md5 file and ensure that it is not accessible to unauthorized users.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2021</span><span class="nt-tag">exposure</span><span class="nt-tag">gurock</span><span class="nt-tag">testrail</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="htttps://github.com/SakuraSamuraii/derailed" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://johnjhacking.com/blog/cve-2021-40875/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.gurock.com/testrail/tour/enterprise-edition" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-40875" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/SakuraSamuraii/derailed" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="güralp systems fmus series - unauthenticated access critical identify critical remote vulnerabilities güralp systems fmus series seismic monitoring devices expose an unauthenticated telnet-based command line interface that allows attackers to modify hardware configurations, manipulate data, or factory reset the device. cve-2025-8286 darses cve cve2025 guralp ics network tcp telnet vuln cwe-306" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Güralp Systems FMUS Series - Unauthenticated Access</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/network/cves/2025/CVE-2025-8286.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-8286.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> darses</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 4, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/306.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-306</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-8286" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-8286</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;service.port&#34;] == &#34;4244&#34; and service[&#34;service.transport&#34;] contains &#34;tcp&#34; and service[&#34;banner&#34;] matches `(?i)\s*Welcome\s+to\s+(FMUS|MINP?)-[A-Fa-f0-9]{4}[^,]+,\s*type\s+&#34;help&#34;\s+for\s+a\s+list\s+of\s+available\s+commands`</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Güralp Systems FMUS Series Seismic Monitoring Devices expose an unauthenticated Telnet-based command line interface that allows attackers to modify hardware configurations, manipulate data, or factory reset the device.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to modify hardware configurations, manipulate data, or factory reset the device.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest firmware version or apply vendor recommended patches to secure Telnet access.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">guralp</span><span class="nt-tag">ics</span><span class="nt-tag">network</span><span class="nt-tag">tcp</span><span class="nt-tag">telnet</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.cisa.gov/news-events/ics-advisories/icsa-25-212-01" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.cve.org/CVERecord?id=CVE-2025-8286" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="h2 console web login panel - detect info identify web-based control panels h2 console web login panel was detected. righettod console discovery h2 h2database panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">H2 Console Web Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/h2console-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">h2console-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)h2 console&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">H2 Console Web login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">console</span><span class="nt-tag">discovery</span><span class="nt-tag">h2</span><span class="nt-tag">h2database</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://mp.weixin.qq.com/s/Yn5U8WHGJZbTJsxwUU3UiQ" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://jfrog.com/blog/the-jndi-strikes-back-unauthenticated-rce-in-h2-database-console" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="h2o importfiles - local file inclusion high identify critical remote vulnerabilities an attacker is able to read any file on the server hosting the h2o dashboard without any authentication. cve-2023-6038 danmcinerney,byt3bl33d3r cve cve2023 h2o h2o-3 ml vkev vuln cwe-862" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">H2O ImportFiles - Local File Inclusion</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-6038.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-6038.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> danmcinerney,byt3bl33d3r</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 20, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/862.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-862</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-6038" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-6038</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)h2o flow&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An attacker is able to read any file on the server hosting the H2O dashboard without any authentication.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can read any file on the server via the ImportFiles endpoint, potentially exposing sensitive data including database contents and application code.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update H2O to a version that implements proper authentication and authorization controls for the ImportFiles endpoint.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">h2o</span><span class="nt-tag">h2o-3</span><span class="nt-tag">ml</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://huntr.com/bounties/380fce33-fec5-49d9-a101-12c972125d8c/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-6038" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/h2o/h2o" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="h2o wave ml application server - detect info identify web-based control panels h2o wave was detected. h2o wave was an open-source python development framework for building real-time interactive ai and ml web applications. the wave server hosted applications built on the platform. rxerium ai detect discovery h2o h2o-wave ml panel" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">H2O Wave ML Application Server - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/h2o-wave-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">h2o-wave-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 14, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)H2O Wave&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">H2O Wave was detected. H2O Wave was an open-source Python development framework for building real-time interactive AI and ML web applications. The Wave server hosted applications built on the platform.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">ai</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">h2o</span><span class="nt-tag">h2o-wave</span><span class="nt-tag">ml</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/h2oai/wave" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://wave.h2o.ai/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="h3c er8300g2-x - password disclosure critical identify critical remote vulnerabilities h3c er8300g2-x is vulnerable to incorrect access control. the password for the router&#39;s management system can be accessed via the management system page login interface. cve-2024-32238 s4e-io,adeljck cve cve2024 h3c info-leak router vkev vuln cwe-522" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">H3C ER8300G2-X - Password Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-32238.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-32238.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> s4e-io,adeljck</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 17, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/522.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-522</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-32238" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-32238</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)icg_helpScript\\.js&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">H3C ER8300G2-X is vulnerable to Incorrect Access Control. The password for the router&#39;s management system can be accessed via the management system page login interface.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can access the router&#39;s administrative password via the management system interface.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update H3C ER8300G2-X router firmware to a version that addresses the password disclosure vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">h3c</span><span class="nt-tag">info-leak</span><span class="nt-tag">router</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/wy876/POC/blob/main/H3C/H3C%E8%B7%AF%E7%94%B1%E5%99%A8userLogin.asp%E4%BF%A1%E6%81%AF%E6%B3%84%E6%BC%8F%E6%BC%8F%E6%B4%9E.md" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/asdfjkl11/CVE-2024-32238/issues/1" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.h3c.com/cn/Products_And_Solution/InterConnect/Products/Routers/Products/Enterprise/ER/ER8300G2-X/" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/20142995/nuclei-templates" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/FuBoLuSec/CVE-2024-32238" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="h3c imc - remote code execution critical identify critical remote vulnerabilities h3c imc allows remote unauthenticated attackers to cause the remote web application to execute arbitrary commands via the &#39;dynamiccontent.properties.xhtml&#39; endpoint. pikpikcu h3c-imc rce vuln cwe-77,cwe-78" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">H3c IMC - Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/vulnerabilities/other/h3c-imc-rce.yaml" target="_blank" rel="noopener" class="nt-source-link">h3c-imc-rce.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pikpikcu</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/77,CWE-78.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-77,CWE-78</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/imc/javax\\.faces\\.resource/images/login_help\\.png\\.jsf\\?ln=primefaces-imc-new-webui&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">H3c IMC allows remote unauthenticated attackers to cause the remote web application to execute arbitrary commands via the &#39;dynamiccontent.properties.xhtml&#39; endpoint.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">h3c-imc</span><span class="nt-tag">rce</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://mp.weixin.qq.com/s/BP9_H3lpluqIwL5OMIJlIw" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="hal management console panel info identify web-based control panels hal management console login panel was discovered. dhiyaneshdk panel login hal discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">HAL Management Console Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/hal-management-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">hal-management-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 18, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)HAL Management Console&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">HAL Management Console login panel was discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">login</span><span class="nt-tag">hal</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="hcl bigfix login panel - detect info identify web-based control panels hcl bigfix login panel was detected. idealphase bigfix discovery panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">HCL BigFix Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/bigfix-login.yaml" target="_blank" rel="noopener" class="nt-source-link">bigfix-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> idealphase</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)BigFix&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">HCL BigFix login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">bigfix</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.hcltechsw.com/bigfix" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="hoobs panel - detect info identify web-based control panels hoobs is a home automation platform that bridges homekit and non-homekit devices. rxerium panel iot homekit hoobs discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">HOOBS Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/hoobs-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">hoobs-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 8, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)HOOBS&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">HOOBS is a home automation platform that bridges HomeKit and non-HomeKit devices.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">iot</span><span class="nt-tag">homekit</span><span class="nt-tag">hoobs</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://hoobs.com" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="hp 1820-8g switch j9979a default login high identify default logins in web-based control panels hp 1820-8g switch j9979a default admin login credentials were discovered. pussycat0x default-login hp vuln cwe-522" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">HP 1820-8G Switch J9979A Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/hp/hp-switch-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">hp-switch-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/522.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-522</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;J9979A&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">HP 1820-8G Switch J9979A default admin login credentials were discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">hp</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://support.hpe.com/hpesc/public/docDisplay?docId=a00077779en_us&amp;docLocale=en_US" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="hp service manager login panel - detect info identify web-based control panels hp service manager login panel was detected. dhiyaneshdk discovery hp panel service cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">HP Service Manager Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/hp-service-manager.yaml" target="_blank" rel="noopener" class="nt-source-link">hp-service-manager.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)hp service manager&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">HP Service Manager login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">hp</span><span class="nt-tag">panel</span><span class="nt-tag">service</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="hp virtual connect manager login panel - detect info identify web-based control panels hp virtual connect manager login panel was detected. dhiyaneshdk panel hp discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">HP Virtual Connect Manager Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/hp-virtual-connect-manager.yaml" target="_blank" rel="noopener" class="nt-source-link">hp-virtual-connect-manager.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)HP Virtual Connect Manager&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">HP Virtual Connect Manager login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">hp</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="hpe officeconnect switch - panel detect info identify web-based control panels the hpe officeconnect switch was a network switch series built for small and medium businesses.it provided reliable connectivity, simple management, and poe options to support growing networks. pussycat0x panel hp hpe officeconnect login discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">HPE OfficeConnect Switch - Panel Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/hpe-officeconnect-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">hpe-officeconnect-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 18, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)HPE OfficeConnect&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The HPE OfficeConnect Switch was a network switch series built for small and medium businesses.It provided reliable connectivity, simple management, and PoE options to support growing networks.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">hp</span><span class="nt-tag">hpe</span><span class="nt-tag">officeconnect</span><span class="nt-tag">login</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="hpe oneview - panel detect info identify web-based control panels hpe oneview is an infrastructure management platform that provides automated management, monitoring, and updates for hpe servers, storage, and networking resources through a unified interface. rxerium panel hpe hp oneview login" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">HPE OneView - Panel Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/hpe-oneview-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">hpe-oneview-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 18, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-1569311459&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">HPE OneView is an infrastructure management platform that provides automated management, monitoring, and updates for HPE servers, storage, and networking resources through a unified interface.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">hpe</span><span class="nt-tag">hp</span><span class="nt-tag">oneview</span><span class="nt-tag">login</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.hpe.com/us/en/integrated-systems/software.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="http file server &lt;2.3c - remote command execution critical identify critical remote vulnerabilities http file server before 2.3c is susceptible to remote command execution. the findmacromarker function in parserlib.pas allows an attacker to execute arbitrary programs via a %00 sequence in a search action. therefore, an attacker can obtain sensitive information, modify data, and/or gain full control over a compromised system without entering necessary credentials. cve-2014-6287 j4vaovo cve cve2014 hfs kev msf packetstorm rce rejetto vkev vuln cwe-94" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">HTTP File Server &lt;2.3c - Remote Command Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2014/CVE-2014-6287.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2014-6287.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> j4vaovo</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/94.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-94</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2014-6287" target="_blank" rel="noopener" class="nt-cve-link">CVE-2014-6287</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;2124459909&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">HTTP File Server before 2.3c is susceptible to remote command execution. The findMacroMarker function in parserLib.pas allows an attacker to execute arbitrary programs via a %00 sequence in a search action. Therefore, an attacker can obtain sensitive information, modify data, and/or gain full control over a compromised system without entering necessary credentials.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability allows remote attackers to execute arbitrary commands on the target system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to the latest version of HTTP File Server (&gt;=2.3c) to mitigate this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2014</span><span class="nt-tag">hfs</span><span class="nt-tag">kev</span><span class="nt-tag">msf</span><span class="nt-tag">packetstorm</span><span class="nt-tag">rce</span><span class="nt-tag">rejetto</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6287" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="http://www.kb.cert.org/vuls/id/251276" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="http://packetstormsecurity.com/files/128243/HttpFileServer-2.3.x-Remote-Command-Execution.html" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/rapid7/metasploit-framework/pull/3793" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2014-6287" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="httpbin login panel - detect info identify web-based control panels httpbin login panel was detected. adam crosser panel httpbin oss discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">HTTPBin Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/httpbin-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">httpbin-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Adam Crosser</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)httpbin\\.org&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">HTTPBin login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">httpbin</span><span class="nt-tag">oss</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/postmanlabs/httpbin" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="hyperplanning login panel - detect info identify web-based control panels hyperplanning products was detected. righettod panel hyperplanning login detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">HYPERPLANNING Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/hyperplanning-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">hyperplanning-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 4, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)HYPERPLANNING&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">HYPERPLANNING products was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">hyperplanning</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.index-education.com/fr/presentation-hyperplanning.php" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="haivision gateway login panel - detect info identify web-based control panels haivision gateway login panel was detected. righettod panel haivision login detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Haivision Gateway Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/haivision-gateway-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">haivision-gateway-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 14, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Haivision Gateway&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Haivision Gateway login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">haivision</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.haivision.com/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="haivision media platform login panel - detect info identify web-based control panels haivision media platform login panel was detected. righettod panel haivision login detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Haivision Media Platform Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/haivision-media-platform-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">haivision-media-platform-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 15, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Haivision Media Platform&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Haivision Media Platform login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">haivision</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.haivision.com/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="halo itsm - pre-authentication sql injection critical identify critical remote vulnerabilities a time-based sql injection vulnerability in halo itsm allows unauthenticated attackers to execute malicious sql queries by leveraging time delays, potentially leading to data exfiltration, privilege escalation, or full system compromise. rootxharsh,iamnoooob,pdresearch halo itsm sqli time-based-sqli vuln cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Halo ITSM - Pre-Authentication SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/vulnerabilities/other/halo-tism-sqli.yaml" target="_blank" rel="noopener" class="nt-source-link">halo-tism-sqli.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rootxharsh,iamnoooob,pdresearch</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 2, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;489905671&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A Time-Based SQL Injection vulnerability in Halo ITSM allows unauthenticated attackers to execute malicious SQL queries by leveraging time delays, potentially leading to data exfiltration, privilege escalation, or full system compromise.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">halo</span><span class="nt-tag">itsm</span><span class="nt-tag">sqli</span><span class="nt-tag">time-based-sqli</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://slcyber.io/assetnote-security-research-center/loose-types-sink-ships-pre-authentication-sql-injection-in-halo-itsm/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="hangfire dashboard panel - detect info identify web-based control panels hangfire dashboard panel was detected. dhiyaneshdk,righettod discovery hangfire panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Hangfire Dashboard Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/hangfire-dashboard.yaml" target="_blank" rel="noopener" class="nt-source-link">hangfire-dashboard.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk,righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)overview – hangfire dashboard&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Hangfire Dashboard panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">hangfire</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="harbor login panel - detect info identify web-based control panels harbor login panel was detected. daffainfo,righettod detect discovery harbor linuxfoundation login panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Harbor Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/harbor-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">harbor-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> daffainfo,righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;657337228&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Harbor login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">harbor</span><span class="nt-tag">linuxfoundation</span><span class="nt-tag">login</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/goharbor/harbor" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="harbor registry - default admin credentials high identify default logins in web-based control panels detected: the harbor container registry was found to be using default administrator credentials (admin:harbor12345). an attacker could have gained full administrative access to manage registries, projects, users, and stored container images. 0x_akoko harbor default-login auth registry vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Harbor Registry - Default Admin Credentials</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/harbor-registry-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">harbor-registry-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_Akoko</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 24, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Harbor&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detected: The Harbor container registry was found to be using default administrator credentials (admin:Harbor12345). An attacker could have gained full administrative access to manage registries, projects, users, and stored container images.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">harbor</span><span class="nt-tag">default-login</span><span class="nt-tag">auth</span><span class="nt-tag">registry</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://goharbor.io/docs/1.10/install-config/run-installer-script/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://goharbor.io/docs/latest/administration/managing-users/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="hashicorp consul web ui login panel - detect info identify web-based control panels hashicorp consul web ui login panel was detected, c-sh0 consul discovery hashicorp panel webserver cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">HashiCorp Consul Web UI Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/hashicorp-consul-webgui.yaml" target="_blank" rel="noopener" class="nt-source-link">hashicorp-consul-webgui.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> c-sh0</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)consul by hashicorp&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">HashiCorp Consul Web UI login panel was detected,</div></div></div>
  <div class="nt-tags"><span class="nt-tag">consul</span><span class="nt-tag">discovery</span><span class="nt-tag">hashicorp</span><span class="nt-tag">panel</span><span class="nt-tag">webserver</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="hashicorp consul agent - detect info identify web-based control panels hashicorp consul agent was detected. c-sh0 tech consul api panel hashicorp discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Hashicorp Consul Agent - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/hashicorp-consul-agent.yaml" target="_blank" rel="noopener" class="nt-source-link">hashicorp-consul-agent.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> c-sh0</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)consul by hashicorp&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Hashicorp Consul Agent was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">tech</span><span class="nt-tag">consul</span><span class="nt-tag">api</span><span class="nt-tag">panel</span><span class="nt-tag">hashicorp</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="headlamp kubernetes ui panel - detect medium identify web-based control panels detected headlamp kubernetes web ui panel exposed, which could lead to unauthorized access to kubernetes cluster management if not properly secured. shamo0 panel headlamp kubernetes exposure cwe-200" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Headlamp Kubernetes UI Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/headlamp-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">headlamp-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> shamo0</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 12, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)headlampBaseUrl&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detected Headlamp Kubernetes Web UI panel exposed, which could lead to unauthorized access to Kubernetes cluster management if not properly secured.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">headlamp</span><span class="nt-tag">kubernetes</span><span class="nt-tag">exposure</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://headlamp.dev/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/kubernetes-sigs/headlamp" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="hestia control panel login - detect info identify web-based control panels hestia control panel login was detected. justaacat detect discovery hestia hestiacp panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Hestia Control Panel Login - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/hestia-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">hestia-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> JustaAcat</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)hestia control panel&#34;}) || service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-476299640&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Hestia Control Panel login was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">hestia</span><span class="nt-tag">hestiacp</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://hestiacp.com/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="hide my wp ghost &lt; 5.2.02 - hidden login page disclosure high identify critical remote vulnerabilities the hide my wp ghost plugin does not prevent redirects to the login page via the auth_redirect wordpress function, allowing an unauthenticated visitor to access the hidden login page. cve-2024-6420 jpg0mez bypass cve cve2024 hide-my-wp vuln wordpress wp wp-plugin wpscan" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Hide My WP Ghost &lt; 5.2.02 - Hidden Login Page Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-6420.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-6420.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> jpg0mez</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 30, 2024</span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-6420" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-6420</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/hide-my-wp&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The Hide My WP Ghost plugin does not prevent redirects to the login page via the auth_redirect WordPress function, allowing an unauthenticated visitor to access the hidden login page.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can discover and access the hidden WordPress login page through auth_redirect exploitation, bypassing the plugin&#39;s security obfuscation.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update Hide My WP Ghost plugin to version 5.2.02 or later to address the login page disclosure vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">hide-my-wp</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">wpscan</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wpscan.com/vulnerability/dfda6577-81aa-4397-a2d6-1d736f9ebd44/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.sprocketsecurity.com/resources/discovering-wp-admin-urls-in-wordpress-with-gravityforms/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-6420" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="highmail admin login panel - detect info identify web-based control panels highmail admin login panel was detected. ritikchaddha aryanic discovery highmail panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">HighMail Admin Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/highmail-admin-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">highmail-admin-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)highmail&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">HighMail admin login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">aryanic</span><span class="nt-tag">discovery</span><span class="nt-tag">highmail</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="hikvision ip ping.php - command execution critical identify critical remote vulnerabilities a vulnerability was found in hikvision intercom broadcasting system 3.0.3_20201113_release(hik). it has been declared as critical. this vulnerability affects unknown code of the file /php/ping.php. the manipulation of the argument jsondata[ip] with the input netstat -ano leads to os command injection. the exploit has been disclosed to the public and may be used. upgrading to version 4.1.0 is able to address this issue. it is recommended to upgrade the affected component. vdb-248254 is the identifier assigned to this vulnerability. cve-2023-6895 dhiyaneshdk,archer cve cve2023 hikvision rce vkev vuln cwe-78" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Hikvision IP ping.php - Command Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-6895.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-6895.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk,archer</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 29, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/78.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-78</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-6895" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-6895</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-1830859634&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A vulnerability was found in Hikvision Intercom Broadcasting System 3.0.3_20201113_RELEASE(HIK). It has been declared as critical. This vulnerability affects unknown code of the file /php/ping.php. The manipulation of the argument jsondata[ip] with the input netstat -ano leads to os command injection. The exploit has been disclosed to the public and may be used. Upgrading to version 4.1.0 is able to address this issue. It is recommended to upgrade the affected component. VDB-248254 is the identifier assigned to this vulnerability.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can execute arbitrary operating system commands via the jsondata[ip] parameter, potentially gaining complete control over the Hikvision Intercom Broadcasting System.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to Hikvision Intercom Broadcasting System version 4.1.0 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">hikvision</span><span class="nt-tag">rce</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://vuldb.com/?ctiid.248254" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://vuldb.com/?id.248254" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/tanjiti/sec_profile" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/wy876/POC" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/xingchennb/POC-" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="hitachi pentaho business analytics server - bypass authorization high identify critical remote vulnerabilities hitachi vantara pentaho business analytics server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x contain security restrictions using non-canonical urls which can be circumvented. cve-2022-43939 daffainfo auth-bypass cve cve2022 hitachi kev pentaho vkev vuln cwe-647" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Hitachi Pentaho Business Analytics Server - Bypass Authorization</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-43939.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-43939.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> daffainfo</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 24, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/647.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-647</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-43939" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-43939</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1749354953&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x contain security restrictions using non-canonical URLs which can be circumvented.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can bypass authorization restrictions using non-canonical URL paths to access protected administrative endpoints in Hitachi Pentaho Business Analytics Server, potentially gaining unauthorized access to sensitive analytics data and configurations.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to Hitachi Vantara Pentaho Business Analytics Server version 9.4.0.1, 9.3.0.2 or later that properly validates canonical URL paths.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">hitachi</span><span class="nt-tag">kev</span><span class="nt-tag">pentaho</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://support.pentaho.com/hc/en-us/articles/14455394120333--Resolved-Pentaho-BA-Server-Use-of-Non-Canonical-URL-Paths-for-Authorization-Decisions-Versions-before-9-4-0-1-and-9-3-0-2-including-8-3-x-Impacted-CVE-2022-43939-" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-43769" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://research.aurainfosec.io/pentest/pentah0wnage/" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="hivemanager login panel - detect info identify web-based control panels hivemanager login panel was detected. binaryfigments,daffainfo aerohive discovery hivemanager panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">HiveManager Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/hivemanager-login-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">hivemanager-login-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> binaryfigments,daffainfo</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1604363273&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">HiveManager login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">aerohive</span><span class="nt-tag">discovery</span><span class="nt-tag">hivemanager</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="home assistant panel info identify web-based control panels  fabaff,daffainfo,lum8rjack discovery homeassistant iot panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Home Assistant Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/home-assistant-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">home-assistant-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> fabaff,daffainfo,lum8rjack</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Home Assistant&#34;})</code></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">homeassistant</span><span class="nt-tag">iot</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.home-assistant.io/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="home assistant supervisor - authentication bypass critical identify critical remote vulnerabilities home assistant supervisor is an open source home automation tool. a remotely exploitable vulnerability bypassing authentication for accessing the supervisor api through home assistant has been discovered.this impacts all home assistant installation types that use the supervisor 2023.01.1 or older. installation types, like home assistant container (for example docker), or home assistant core manually in a python environment, are not affected. cve-2023-27482 dhiyaneshdk auth-bypass cve cve2023 home-assistant homeassistant rce vkev vuln cwe-287" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Home Assistant Supervisor - Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-27482.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-27482.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 1, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/287.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-287</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-27482" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-27482</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)home assistant&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Home Assistant Supervisor is an open source home automation tool. A remotely exploitable vulnerability bypassing authentication for accessing the Supervisor API through Home Assistant has been discovered.This impacts all Home Assistant installation types that use the Supervisor 2023.01.1 or older. Installation types, like Home Assistant Container (for example Docker), or Home Assistant Core manually in a Python environment, are not affected.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can bypass authentication and gain unauthorized access to the Home Assistant Supervisor, potentially leading to further compromise of the system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">The issue has been mitigated and closed in Supervisor version 2023.03.1, which has been rolled out to all affected installations via the auto-update feature of the Supervisor. This rollout has been completed at the time of publication of this advisory. Home Assistant Core 2023.3.0 included mitigation for this vulnerability. Upgrading to at least that version is thus advised. In case one is not able to upgrade the Home Assistant Supervisor or the Home Assistant Core application at this time, it is advised to not expose your Home Assistant instance to the internet.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">home-assistant</span><span class="nt-tag">homeassistant</span><span class="nt-tag">rce</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.elttam.com/blog/pwnassistant/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/elttam/publications/blob/master/writeups/home-assistant/supervisor-authentication-bypass-advisory.md" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.home-assistant.io/blog/2023/03/08/supervisor-security-disclosure/" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-27482" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/home-assistant/core/security/advisories/GHSA-2j8f-h4mr-qr25" target="_blank" rel="noopener" class="nt-ref-link">[5]</a> <a href="https://xz.aliyun.com/t/12572" target="_blank" rel="noopener" class="nt-ref-link">[6]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="homebridge - default admin credentials high identify default logins in web-based control panels detected homebridge ui was found using default administrator credentials (admin:admin). an attacker could have gained full access to manage homekit accessories, plugins, and server configuration. 0x_akoko default-login homebridge iot vuln cwe-798" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Homebridge - Default Admin Credentials</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/homebridge-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">homebridge-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_Akoko</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 8, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/798.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-798</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Homebridge&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detected Homebridge UI was found using default administrator credentials (admin:admin). An attacker could have gained full access to manage HomeKit accessories, plugins, and server configuration.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">homebridge</span><span class="nt-tag">iot</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/homebridge/homebridge" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/homebridge/homebridge-config-ui-x" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="homebridge - unfinished installation high identify critical remote vulnerabilities homebridge instance with incomplete installation detected. the setup wizard is exposed, allowing anyone to create the first admin account and gain full control over the homebridge instance. this can lead to unauthorized access to smart home devices and potential network compromise. theamanrawat homebridge misconfig exposure iot smart-home unauth cwe-284" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Homebridge - Unfinished Installation</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/misconfiguration/homebridge-unfinished-install.yaml" target="_blank" rel="noopener" class="nt-source-link">homebridge-unfinished-install.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> theamanrawat</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 21, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/284.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-284</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Homebridge&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Homebridge instance with incomplete installation detected. The setup wizard is exposed, allowing anyone to create the first admin account and gain full control over the Homebridge instance. This can lead to unauthorized access to smart home devices and potential network compromise.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">homebridge</span><span class="nt-tag">misconfig</span><span class="nt-tag">exposure</span><span class="nt-tag">iot</span><span class="nt-tag">smart-home</span><span class="nt-tag">unauth</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://homebridge.io/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/homebridge/homebridge-config-ui-x" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="homebridge panel - detect info identify web-based control panels homebridge allows you to integrate with smart home devices that do not natively support homekit. rxerium panel homebridge detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Homebridge Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/homebridge-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">homebridge-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 27, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Homebridge&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Homebridge allows you to integrate with smart home devices that do not natively support HomeKit.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">homebridge</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://homebridge.io/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/homebridge" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="homematic panel - detect info identify web-based control panels homematic panel was deetcted. princechaddha discovery eq-3 homematic iot panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Homematic Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/homematic-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">homematic-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> princechaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)homematic&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Homematic panel was deetcted.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">eq-3</span><span class="nt-tag">homematic</span><span class="nt-tag">iot</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="homer panel - detect info identify web-based control panels a simple static homepage was discovered rxerium panel homer detect login discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Homer Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/homer-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">homer-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 4, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-417785140&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A simple static homepage was discovered</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">homer</span><span class="nt-tag">detect</span><span class="nt-tag">login</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/bastienwirtz/homer" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://homer-demo.netlify.app/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="honeywell excel web control login panel - detect info identify web-based control panels honeywell excel web control login panel was detected. dhiyaneshdk panel honeywell edb discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Honeywell Excel Web Control Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/honeywell-xl-web-controller.yaml" target="_blank" rel="noopener" class="nt-source-link">honeywell-xl-web-controller.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Honeywell XL Web Controller&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Honeywell Excel Web Control login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">honeywell</span><span class="nt-tag">edb</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.exploit-db.com/ghdb/7130" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="honeywell pm43 printers - command injection critical identify critical remote vulnerabilities improper input validation vulnerability in honeywell pm43 on 32 bit, arm (printer web page modules) allows command injection.this issue affects pm43 versions prior to p10.19.050004. update to the latest available firmware version of the respective printers to version mr19.5 (e.g. p10.19.050006) cve-2023-3710 win3zz cve cve2023 honeywell iot pm43 printer rce vkev vuln cwe-20,cwe-77" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Honeywell PM43 Printers - Command Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-3710.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-3710.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> win3zz</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 15, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/20,CWE-77.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-20,CWE-77</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-3710" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-3710</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/main/login\\.lua\\?pageid=&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Improper Input Validation vulnerability in Honeywell PM43 on 32 bit, ARM (Printer web page modules) allows Command Injection.This issue affects PM43 versions prior to P10.19.050004. Update to the latest available firmware version of the respective printers to version MR19.5 (e.g. P10.19.050006)</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can execute arbitrary operating system commands through the username parameter in loadfile.lp, potentially gaining full control of Honeywell PM43 printers and intercepting print jobs containing sensitive documents.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update Honeywell PM43 printer firmware to version P10.19.050004 (MR19.5) or later that properly sanitizes input in loadfile.lp and prevents command injection attacks.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">honeywell</span><span class="nt-tag">iot</span><span class="nt-tag">pm43</span><span class="nt-tag">printer</span><span class="nt-tag">rce</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-3710" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/vpxuser/CVE-2023-3710-POC" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://twitter.com/win3zz/status/1713451282344853634" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://hsmftp.honeywell.com:443/en/Software/Printers/Industrial/PM23-PM23c-PM43-PM43c/Current/Firmware/firmwaresignedP1019050004" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://hsmftp.honeywell.com:443/en/Software/Printers/Industrial/PM23-PM23c-PM43-PM43c/Current/Firmware/firmwarexasignedP1019050004A" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="hongjing e-hr 2020 - sql injection high identify critical remote vulnerabilities a vulnerability, which was classified as critical, has been found in hongjing e-hr 2020. affected by this issue is some unknown functionality of the file /w_selfservice/oauthservlet/%2e./.%2e/general/inform/org/loadhistroyorgtree of the component login interface. the manipulation of the argument parentid leads to sql injection. the attack may be launched remotely. the exploit has been disclosed to the public and may be used. vdb-247358 is the identifier assigned to this vulnerability. cve-2023-6655 pussycat0x cve cve2023 hjsoft management-system sqli vkev vuln cwe-89" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Hongjing e-HR 2020 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-6655.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-6655.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 16, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-6655" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-6655</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)人力资源信息管理系统&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A vulnerability, which was classified as critical, has been found in Hongjing e-HR 2020. Affected by this issue is some unknown functionality of the file /w_selfservice/oauthservlet/%2e./.%2e/general/inform/org/loadhistroyorgtree of the component Login Interface. The manipulation of the argument parentid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-247358 is the identifier assigned to this vulnerability.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can execute arbitrary SQL queries via the parentid parameter, potentially extracting sensitive database information including user credentials.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update Hongjing e-HR to a version newer than 2020 that addresses this SQL injection vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">hjsoft</span><span class="nt-tag">management-system</span><span class="nt-tag">sqli</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-6655" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/Gent5698/vulnerability/blob/main/%E5%AE%8F%E6%99%AF/CVE-2023-6655/README.md" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="hookbot rat panel - detect info identify web-based control panels hookbot panel were detected. pussycat0x tech rat hookbot c2 panel detect vuln" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Hookbot Rat Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/c2/hookbot-rat.yaml" target="_blank" rel="noopener" class="nt-source-link">hookbot-rat.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 6, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)hookbot&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Hookbot panel were detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">tech</span><span class="nt-tag">rat</span><span class="nt-tag">hookbot</span><span class="nt-tag">c2</span><span class="nt-tag">panel</span><span class="nt-tag">detect</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="horde login panel - detect info identify web-based control panels horde login panel was detected. ritikchaddha horde panel discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Horde Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/horde-login-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">horde-login-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-741491222&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Horde login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">horde</span><span class="nt-tag">panel</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="horde webmail login panel - detect info identify web-based control panels horde webmail login panel was detected. ritikchaddha horde webmail panel discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Horde Webmail Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/horde-webmail-login.yaml" target="_blank" rel="noopener" class="nt-source-link">horde-webmail-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;2104916232&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Horde Webmail login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">horde</span><span class="nt-tag">webmail</span><span class="nt-tag">panel</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="hospital management system 1.0 - sql injection critical identify critical remote vulnerabilities hospital management system 1.0 contains a sql injection vulnerability via the editid parameter in /hms/user-login.php.  an attacker can possibly obtain sensitive information from a database, modify data, and execute unauthorized administrative operations in the context of the affected site. cve-2022-38637 arafatansari auth-bypass cms cve cve2022 hms hospital_management_system_project sqli vuln cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Hospital Management System 1.0 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-38637.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-38637.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> arafatansari</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-38637" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-38637</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)hospital management system&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Hospital Management System 1.0 contains a SQL injection vulnerability via the editid parameter in /HMS/user-login.php.  An attacker can possibly obtain sensitive information from a database, modify data, and execute unauthorized administrative operations in the context of the affected site.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized access, data leakage, or data manipulation.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to the latest version to mitigate this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">cms</span><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">hms</span><span class="nt-tag">hospital_management_system_project</span><span class="nt-tag">sqli</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.youtube.com/watch?v=m8nW0p69UHU" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://owasp.org/www-community/attacks/SQL_Injection" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-38637" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/Henry4E36/POCS" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/ARPSyndicate/cvemon" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="hospital management system 1.0 - sql injection critical identify critical remote vulnerabilities hospital management system 1.0 contains a sql injection vulnerability via the editid parameter in /hms/doctor.php. an attacker can possibly obtain sensitive information from a database, modify data, and execute unauthorized administrative operations in the context of the affected site. cve-2022-32094 arafatansari auth-bypass cms cve cve2022 hms hospital_management_system_project sqli vuln cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Hospital Management System 1.0 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-32094.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-32094.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> arafatansari</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-32094" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-32094</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)hospital management system&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Hospital Management System 1.0 contains a SQL injection vulnerability via the editid parameter in /HMS/doctor.php. An attacker can possibly obtain sensitive information from a database, modify data, and execute unauthorized administrative operations in the context of the affected site.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized access, data leakage, or data manipulation.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to the latest version to mitigate this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">cms</span><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">hms</span><span class="nt-tag">hospital_management_system_project</span><span class="nt-tag">sqli</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/Danie1233/Hospital-Management-System-v1.0-SQLi-3/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-32094" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/ARPSyndicate/cvemon" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/ARPSyndicate/kenzer-templates" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="hospital management system 1.0 - sql injection high identify critical remote vulnerabilities hospital management system 1.0 contains a sql injection vulnerability via the editid parameter in /hms/admin.php. an attacker can possibly obtain sensitive information from a database, modify data, and execute unauthorized administrative operations in the context of the affected site. cve-2022-34590 arafatansari cms cve cve2022 hms hospital_management_system_project sqli vuln cwe-89" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Hospital Management System 1.0 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-34590.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-34590.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> arafatansari</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-34590" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-34590</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)hospital management system&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Hospital Management System 1.0 contains a SQL injection vulnerability via the editid parameter in /HMS/admin.php. An attacker can possibly obtain sensitive information from a database, modify data, and execute unauthorized administrative operations in the context of the affected site.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized access, data leakage, or data manipulation.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to the latest version to mitigate this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cms</span><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">hms</span><span class="nt-tag">hospital_management_system_project</span><span class="nt-tag">sqli</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/Renrao/bug_report/blob/master/blob/main/vendors/itsourcecode.com/hospital-management-system/sql_injection.md" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-34590" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/ARPSyndicate/cvemon" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/ARPSyndicate/kenzer-templates" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/StarCrossPortal/scalpel" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="hospital management system login panel - detect info identify web-based control panels hospital management system login panel was detected. arafatansari cms discovery hms hospital_management_system_project panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Hospital Management System Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/hospital-management-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">hospital-management-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> arafatansari</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)hospital management system&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Hospital Management System login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cms</span><span class="nt-tag">discovery</span><span class="nt-tag">hms</span><span class="nt-tag">hospital_management_system_project</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="hotel booking lite &lt; 4.8.5 - arbitrary file download &amp; deletion critical identify critical remote vulnerabilities the hotel booking lite wordpress plugin before 4.8.5 does not validate file paths provided via user input, as well as does not have proper csrf and authorisation checks, allowing unauthenticated users to download and delete arbitrary files on the server cve-2023-5991 s4e-io cve cve2023 lfi motopress motopress-hotel-booking vuln wordpress wp wp-plugin wpscan cwe-22" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Hotel Booking Lite &lt; 4.8.5 - Arbitrary File Download &amp; Deletion</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-5991.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-5991.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> s4e-io</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 14, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-5991" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-5991</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/motopress-hotel-booking&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The Hotel Booking Lite WordPress plugin before 4.8.5 does not validate file paths provided via user input, as well as does not have proper CSRF and authorisation checks, allowing unauthenticated users to download and delete arbitrary files on the server</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can exploit missing validation and authorization checks to download and delete arbitrary files on WordPress servers running Hotel Booking Lite.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Fixed in 4.8.5</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">lfi</span><span class="nt-tag">motopress</span><span class="nt-tag">motopress-hotel-booking</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">wpscan</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wpscan.com/vulnerability/e9d35e36-1e60-4483-b8b3-5cbf08fcd49e/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-5991" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="hoteldruid v3.0.5 - sql injection critical identify critical remote vulnerabilities hoteldruid v3.0.5 was discovered to contain a sql injection vulnerability via the id_utente_log parameter at /hoteldruid/personalizza.php. cve-2023-43374 ritikchaddha cms cve cve2023 digitaldruid hoteldruid sqli time-based-sqli vuln cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Hoteldruid v3.0.5 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-43374.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-43374.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 9, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-43374" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-43374</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)hoteldruid&#34;}) || service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-1521640213&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Hoteldruid v3.0.5 was discovered to contain a SQL injection vulnerability via the id_utente_log parameter at /hoteldruid/personalizza.php.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation could lead to unauthorized access to sensitive data or complete takeover of the affected system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade Hoteldruid to a patched version that addresses the SQL Injection vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cms</span><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">digitaldruid</span><span class="nt-tag">hoteldruid</span><span class="nt-tag">sqli</span><span class="nt-tag">time-based-sqli</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://flashy-lemonade-192.notion.site/SQL-injection-in-hoteldruid-version-3-0-5-via-id_utente_log-parameter-8b89f014004947e7bd2ecdacf1610cf9" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-43374" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="hoteldruid v3.0.5 - sql injection critical identify critical remote vulnerabilities hoteldruid v3.0.5 was discovered to contain a sql injection vulnerability via the n_utente_agg parameter at /hoteldruid/interconnessioni.php. cve-2023-43373 ritikchaddha cve cve2023 hoteldruid sqli vuln cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Hoteldruid v3.0.5 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-43373.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-43373.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 22, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-43373" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-43373</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)hoteldruid&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Hoteldruid v3.0.5 was discovered to contain a SQL injection vulnerability via the n_utente_agg parameter at /hoteldruid/interconnessioni.php.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Allows attackers to execute arbitrary SQL queries and potentially gain unauthorized access to the database.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update Hoteldruid to a patched version or apply vendor-supplied fixes to mitigate the SQL Injection vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">hoteldruid</span><span class="nt-tag">sqli</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://flashy-lemonade-192.notion.site/SQL-injection-in-hoteldruid-version-3-0-5-via-n_utente_agg-parameter-948a6d724b5348f3867ee6d780f98f1a" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-43373" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="huangdou utcms v9 - os command injection high identify critical remote vulnerabilities a vulnerability, which was classified as critical, has been found in huangdou utcms v9. affected by this issue is some unknown functionality of the file app/modules/ut-cac/admin/cli.php. the manipulation of the argument o leads to os command injection.the attack may be launched remotely. the exploit has been disclosed to the public and may be used.the vendor was contacted early about this disclosure but did not respond in any way. cve-2024-9916 iamnoooob,pdresearch cve cve2024 huangdou php rce utc vkev vuln cwe-78" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">HuangDou UTCMS V9 - OS Command Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-9916.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-9916.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> iamnoooob,pdresearch</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 28, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/78.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-78</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-9916" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-9916</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)usualtool&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A vulnerability, which was classified as critical, has been found in HuangDou UTCMS V9. Affected by this issue is some unknown functionality of the file app/modules/ut-cac/admin/cli.php. The manipulation of the argument o leads to os command injection.The attack may be launched remotely. The exploit has been disclosed to the public and may be used.The vendor was contacted early about this disclosure but did not respond in any way.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can execute arbitrary OS commands on the server through command injection in the cli.php file, achieving complete system compromise and potential access to sensitive data.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply security patches from HuangDou for UTCMS V9 to address the OS command injection vulnerability in app/modules/ut-cac/admin/cli.php.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">huangdou</span><span class="nt-tag">php</span><span class="nt-tag">rce</span><span class="nt-tag">utc</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://vuldb.com/?ctiid.280244" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-9916" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="huawei hg532e default credential high identify default logins in web-based control panels huawei hg532e default admin credentials were discovered. pussycat0x default-login huawei vuln cwe-522" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Huawei HG532e Default Credential</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/huawei/huawei-HG532e-default-router-login.yaml" target="_blank" rel="noopener" class="nt-source-link">huawei-HG532e-default-router-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/522.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-522</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;HG532e&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Huawei HG532e default admin credentials were discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">huawei</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="huawei hg532e router panel - detect info identify web-based control panels huawei hg532e router login panel was detected. after installation, both the default username and default password are user. idealphase discovery huawei panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Huawei HG532e Router Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/huawei-hg532e-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">huawei-hg532e-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> idealphase</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)HG532e&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Huawei HG532e router login panel was detected. After installation, both the default username and default password are user.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">huawei</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://setuprouter.com/router/huawei/hg532e/1194.pdf" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.192-168-1-1-ip.co/router/huawei/hg532e/2186/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="huawei holosens sdc - panel info identify web-based control panels huawei holosens sdc panel was discovered. darses detect discovery holosens huawei iot panel" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Huawei HoloSens SDC - Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/huawei-holosense-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">huawei-holosense-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> darses</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 14, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.head.server&#34;] matches &#34;SDC Server&#34; || service[&#34;http.body.mmh3&#34;] == &#34;-968212412&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Huawei HoloSens SDC Panel was discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">holosens</span><span class="nt-tag">huawei</span><span class="nt-tag">iot</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.huawei.com/en/products/intelligent-devices/holosens-sdc" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="hue magic 3.0.0 - local file inclusion high identify critical remote vulnerabilities hue magic 3.0.0 is susceptible to local file inclusion via the res.sendfile api. cve-2021-25864 0x_akoko cve cve2021 dgtl huemagic lfi node.js vkev vuln cwe-22" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Hue Magic 3.0.0 - Local File Inclusion</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2021/CVE-2021-25864.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2021-25864.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_Akoko</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2021-25864" target="_blank" rel="noopener" class="nt-cve-link">CVE-2021-25864</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)NODE-RED&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Hue Magic 3.0.0 is susceptible to local file inclusion via the res.sendFile API.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">The LFI vulnerability can lead to unauthorized access to sensitive files, potentially exposing sensitive information or allowing for further exploitation.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patch or update to a non-vulnerable version of Hue Magic.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2021</span><span class="nt-tag">dgtl</span><span class="nt-tag">huemagic</span><span class="nt-tag">lfi</span><span class="nt-tag">node.js</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/Foddy/node-red-contrib-huemagic/issues/217" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2021-25864" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/ARPSyndicate/cvemon" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/ARPSyndicate/kenzer-templates" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="huginn login panel - detect info identify web-based control panels huginn products was detected. righettod panel huginn login discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Huginn Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/huginn-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">huginn-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 10, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-1951475503&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Huginn products was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">huginn</span><span class="nt-tag">login</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/huginn/huginn" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="huly login panel - detect info identify web-based control panels huly products was detected. righettod panel huly login discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Huly Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/huly-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">huly-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 14, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Huly&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Huly products was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">huly</span><span class="nt-tag">login</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://huly.io/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="hunk companion &lt; 1.9.0 - unauthenticated plugin installation critical identify critical remote vulnerabilities the plugin does not correctly authorize some rest api endpoints, allowing unauthenticated requests to install and activate arbitrary plugins from the wordpress.org repo, including vulnerable plugins that have been closed. cve-2024-11972 s4e-io cve cve2024 hunk-companion vkev vuln wordpress wp wp-plugin" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Hunk Companion &lt; 1.9.0 - Unauthenticated Plugin Installation</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-11972.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-11972.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> s4e-io</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 29, 2025</span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-11972" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-11972</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/hunk-companion/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The plugin does not correctly authorize some REST API endpoints, allowing unauthenticated requests to install and activate arbitrary plugins from the WordPress.org repo, including vulnerable plugins that have been closed.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can install and activate arbitrary WordPress plugins including vulnerable or malicious ones, leading to potential site compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update Hunk Companion plugin to version 1.9.0 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">hunk-companion</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wpscan.com/vulnerability/4963560b-e4ae-451d-8f94-482779c415e4/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/JunTakemura/exploit-CVE-2024-11972" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/Nxploited/CVE-2024-11972-PoC" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/RonF98/CVE-2024-11972-POC" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="hybris - default login high identify default logins in web-based control panels hybris contains a default login vulnerability. an attacker can obtain access to user accounts and access sensitive information, modify data, and/or execute unauthorized operations. princechaddha default-login hybris vuln cwe-522" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Hybris - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/hybris/hybris-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">hybris-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> princechaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/522.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-522</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;Hybris&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Hybris contains a default login vulnerability. An attacker can obtain access to user accounts and access sensitive information, modify data, and/or execute unauthorized operations.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">hybris</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="hybris administration console login panel - detect info identify web-based control panels hybris administration console login panel was detected. princechaddha discovery hybris panel sap cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Hybris Administration Console Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/hybris-administration-console.yaml" target="_blank" rel="noopener" class="nt-source-link">hybris-administration-console.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> princechaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)hybris&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Hybris Administration Console login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">hybris</span><span class="nt-tag">panel</span><span class="nt-tag">sap</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="hybris management console login panel - detect info identify web-based control panels hybris management console login panel was detected. dogasantos panel sap discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Hybris Management Console Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/hmc-hybris-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">hmc-hybris-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dogasantos</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)hybris&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Hybris Management Console login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">sap</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="hydra router dashboard - detect info identify web-based control panels hydra router dashboard was detected. tess discovery exposure hydra hydra_project panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Hydra Router Dashboard - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/hydra-dashboard.yaml" target="_blank" rel="noopener" class="nt-source-link">hydra-dashboard.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> tess</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)hydra router dashboard&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Hydra router dashboard was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">exposure</span><span class="nt-tag">hydra</span><span class="nt-tag">hydra_project</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="hyperdx panel - detect info identify web-based control panels hyperdx panel was discovered. righettod panel hyperdx detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">HyperDX Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/hyperdx-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">hyperdx-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 8, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)hyperdx&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">HyperDX panel was discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">hyperdx</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/hyperdxio/hyperdx" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.hyperdx.io/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="hypertest common dashboard - detect info identify web-based control panels hypertest common dashboard was detected. dhiyaneshdk panel exposure hypertest discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">HyperTest Common Dashboard - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/hypertest-dashboard.yaml" target="_blank" rel="noopener" class="nt-source-link">hypertest-dashboard.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)HyperTest&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">HyperTest Common Dashboard was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">exposure</span><span class="nt-tag">hypertest</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.facebook.com/photo?fbid=487809593389565&amp;set=a.467014098802448" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.hypertest.co" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="hytec inter hwl-2511-ss - remote command execution critical identify critical remote vulnerabilities hytec inter hwl-2511-ss v1.05 and below was discovered to contain a command injection vulnerability via the component /www/cgi-bin/popen.cgi. cve-2022-36553 huta0 cve cve2022 hytec rce vkev vuln cwe-77" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Hytec Inter HWL-2511-SS - Remote Command Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-36553.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-36553.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> HuTa0</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 25, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/77.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-77</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-36553" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-36553</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)index&#34;}) &amp;&amp; service[&#34;http.head.server&#34;] contains &#34;lighttpd/1.4.30&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Hytec Inter HWL-2511-SS v1.05 and below was discovered to contain a command injection vulnerability via the component /www/cgi-bin/popen.cgi.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can execute arbitrary commands on the Hytec Inter HWL-2511-SS cellular router through command injection in the popen.cgi endpoint, potentially gaining complete control over the device and connected network infrastructure.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update Hytec Inter HWL-2511-SS firmware to a version later than 1.05 that properly sanitizes command parameters in popen.cgi.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">hytec</span><span class="nt-tag">rce</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-36553" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/zan8in/afrog/blob/main/v2/pocs/afrog-pocs/vulnerability/cellular-router-rce.yaml" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://gist.github.com/Nwqda/b27418ab801eb0b9cdbe8d042cb0249b" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://hytec.co.jp/eng/products/our-brand/hwl-2511-ss.html" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://hytec.co.jp/eng/wordpress/wp-content/uploads/2019/09/hwl-2511-ss-ds.3.0.pdf" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="ibm advanced system management panel - detect info identify web-based control panels ibm advanced system management panel was detected. dhiyaneshdk,righettod panel ibm login detect discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">IBM Advanced System Management Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/ibm/ibm-advanced-system-management.yaml" target="_blank" rel="noopener" class="nt-source-link">ibm-advanced-system-management.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDK,righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Advanced System Management&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">IBM Advanced System Management panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">ibm</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.ibm.com/docs/en/power8/9080-MME?topic=operations-advanced-system-management" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="ibm bigfix platform - information disclosure medium identify critical remote vulnerabilities ibm bigfix platform 9.2 and 9.5 contains an information disclosure vulnerability caused by not enabling authenticated access in relay, letting remote attackers query and gather update and fixlet information, exploit requires no authentication. cve-2019-4061 daffainfo bigfix cve cve2019 disclosure ibm vkev cwe-200" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">IBM BigFix Platform - Information Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2019/CVE-2019-4061.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2019-4061.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> daffainfo</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 8, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2019-4061" target="_blank" rel="noopener" class="nt-cve-link">CVE-2019-4061</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.head.server&#34;] matches &#34;^BigFixHTTPServer&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">IBM BigFix Platform 9.2 and 9.5 contains an information disclosure vulnerability caused by not enabling authenticated access in relay, letting remote attackers query and gather update and fixlet information, exploit requires no authentication.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can remotely gather sensitive update and fixlet deployment information, potentially aiding targeted attacks.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Enable authenticated access for relay to prevent unauthorized information queries.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">bigfix</span><span class="nt-tag">cve</span><span class="nt-tag">cve2019</span><span class="nt-tag">disclosure</span><span class="nt-tag">ibm</span><span class="nt-tag">vkev</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.atredis.com/blog/2019/3/18/harvesting-data-from-bigfix-relay-servers" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/rapid7/metasploit-framework/blob/0fd8f0984e10a135c000d1fb8797d76d62fb24f7/modules/auxiliary/gather/ibm_bigfix_sites_packages_enum.rb" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2019-4061" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="ibm data risk manager - authentication bypass via saml critical identify critical remote vulnerabilities ibm data risk manager versions 2.0.1 through 2.0.6 are vulnerable to authentication bypass when configured with saml authentication. a remote attacker can bypass security restrictions by sending a specially crafted http request to the saml idpselection endpoint, allowing them to bypass the authentication process and gain full administrative access to the system. cve-2020-4427 ritikchaddha auth-bypass cve cve2020 ibm kev saml vkev vuln cwe-287" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">IBM Data Risk Manager - Authentication Bypass via SAML</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2020/CVE-2020-4427.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2020-4427.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 10, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/287.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-287</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2020-4427" target="_blank" rel="noopener" class="nt-cve-link">CVE-2020-4427</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)IBM Data Risk Manager&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">IBM Data Risk Manager versions 2.0.1 through 2.0.6 are vulnerable to authentication bypass when configured with SAML authentication. A remote attacker can bypass security restrictions by sending a specially crafted HTTP request to the SAML idpSelection endpoint, allowing them to bypass the authentication process and gain full administrative access to the system.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can bypass authentication via SAML endpoint and gain full administrative access to IBM Data Risk Manager, compromising all managed data risk information.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security updates and patches provided by Cisco for HyperFlex HX.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2020</span><span class="nt-tag">ibm</span><span class="nt-tag">kev</span><span class="nt-tag">saml</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/ibm_drm_rce.rb" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://seclists.org/fulldisclosure/2020/Apr/33" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.ibm.com/support/pages/node/6206875" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2020-4427" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="ibm decision center business console - default login high identify default logins in web-based control panels  dhiyaneshdk decision-center default-login ibm vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">IBM Decision Center Business Console - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/ibm/ibm-dcbc-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">ibm-dcbc-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 22, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;Decision Center \\| Business Console&#34;})</code></div>
  <div class="nt-tags"><span class="nt-tag">decision-center</span><span class="nt-tag">default-login</span><span class="nt-tag">ibm</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.ibm.com/docs/en/odm/8.0.1?topic=users-tutorial-getting-started-decision-center-business-console" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="ibm decision center enterprise console - default login high identify default logins in web-based control panels  dhiyaneshdk decision-center default-login ibm vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">IBM Decision Center Enterprise Console - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/ibm/ibm-dcec-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">ibm-dcec-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 22, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;Decision Center Enterprise console&#34;</code></div>
  <div class="nt-tags"><span class="nt-tag">decision-center</span><span class="nt-tag">default-login</span><span class="nt-tag">ibm</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.ibm.com/docs/en/odm/8.5.1?topic=console-tutorial-getting-started-decision-center-enterprise" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="ibm decision center enterprise console - panel detection info identify web-based control panels ibm decision center enterprise console panel was detected. dhiyaneshdk panel ibm login detect decision-center discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">IBM Decision Center Enterprise Console - Panel Detection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/ibm/ibm-dcec-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">ibm-dcec-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 22, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Decision Center Enterprise console&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">IBM Decision Center Enterprise Console panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">ibm</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">decision-center</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.ibm.com/docs/en/odm/8.5.1?topic=console-tutorial-getting-started-decision-center-enterprise" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="ibm decision server console - default login high identify default logins in web-based control panels  dhiyaneshdk decision-server default-login ibm vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">IBM Decision Server Console - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/ibm/ibm-dsc-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">ibm-dsc-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 22, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;Rule Execution Server&#34;})</code></div>
  <div class="nt-tags"><span class="nt-tag">decision-server</span><span class="nt-tag">default-login</span><span class="nt-tag">ibm</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.ibm.com/docs/en/odm/8.8.0?topic=center-overview-decision" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="ibm decision server console panel - detect info identify web-based control panels ibm decision server console panel was detected. dhiyaneshdk panel ibm login detect decision-server discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">IBM Decision Server Console Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/ibm/ibm-decision-server-console.yaml" target="_blank" rel="noopener" class="nt-source-link">ibm-decision-server-console.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 22, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Rule Execution Server&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">IBM Decision Server Console panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">ibm</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">decision-server</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.ibm.com/docs/en/odm/8.12.0?topic=overview-introducing-rule-execution-server" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="ibm maximo asset management information disclosure - xml external entity injection high identify critical remote vulnerabilities ibm maximo asset management is vulnerable to an
xml external entity injection (xxe) attack when processing xml data.
a remote attacker could exploit this vulnerability to expose
sensitive information or consume memory resources. cve-2020-4463 dwisiswant0 cve cve2020 disclosure ibm vkev vuln xxe cwe-611" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">IBM Maximo Asset Management Information Disclosure - XML External Entity Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2020/CVE-2020-4463.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2020-4463.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dwisiswant0</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/611.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-611</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2020-4463" target="_blank" rel="noopener" class="nt-cve-link">CVE-2020-4463</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-399298961&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">IBM Maximo Asset Management is vulnerable to an
XML external entity injection (XXE) attack when processing XML data.
A remote attacker could exploit this vulnerability to expose
sensitive information or consume memory resources.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">The vulnerability can lead to unauthorized access to sensitive information or a denial of service.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches or updates provided by IBM to mitigate the vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2020</span><span class="nt-tag">disclosure</span><span class="nt-tag">ibm</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">xxe</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.ibm.com/support/pages/security-bulletin-ibm-maximo-asset-management-vulnerable-information-disclosure-cve-2020-4463" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/Ibonok/CVE-2020-4463" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://exchange.xforce.ibmcloud.com/vulnerabilities/181484" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://www.ibm.com/support/pages/node/6253953" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2020-4463" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="ibm maximo login panel - detect info identify web-based control panels ibm maximo login panel was detected. ritikchaddha,righettod detect discovery ibm login maximo panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">IBM Maximo Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/ibm/ibm-maximo-login.yaml" target="_blank" rel="noopener" class="nt-source-link">ibm-maximo-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha,righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-399298961&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">IBM Maximo login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">ibm</span><span class="nt-tag">login</span><span class="nt-tag">maximo</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.ibm.com/support/pages/what-default-username-and-password-websphere-application-server-community-edition-and-how-add-users-admin-group" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.ibm.com/products/maximo" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="ibm mobilefirst foundation - default credentials critical identify default logins in web-based control panels detected ibm mobilefirst foundation operations console was found using default credentials. the administration rest api exposes full control over mobile application backends including adapter management, push notification infrastructure, oauth security configuration, and application authenticity enforcement. vishal vishwakarma default-login ibm mobilefirst cwe-798" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">IBM MobileFirst Foundation - Default Credentials</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/ibm/ibm-mfp-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">ibm-mfp-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Vishal Vishwakarma</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 8, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/798.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-798</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)MobileFirst Operations Console&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detected IBM MobileFirst Foundation Operations Console was found using default credentials. The administration REST API exposes full control over mobile application backends including adapter management, push notification infrastructure, OAuth security configuration, and application authenticity enforcement.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">ibm</span><span class="nt-tag">mobilefirst</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.ibm.com/docs/en/mfp/8.0?topic=console-mobilefirst-operations" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://mobilefirstplatform.ibmcloud.com/tutorials/en/foundation/8.0/installation-configuration/production/server-configuration/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="ibm openadmin tool - panel info identify web-based control panels  dhiyaneshdk openadmin login panel discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">IBM OpenAdmin Tool - Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/ibm-openadmin-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">ibm-openadmin-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 20, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;965982073&#34;</code></div>
  <div class="nt-tags"><span class="nt-tag">openadmin</span><span class="nt-tag">login</span><span class="nt-tag">panel</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="ibm operational decision manager panel - detect info identify web-based control panels ibm operational decision manager panel was detected. dhiyaneshdk,righettod panel ibm login detect decision-center discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">IBM Operational Decision Manager Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/ibm/ibm-odm-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">ibm-odm-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK,righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 22, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Decision Center \\| Business Console&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">IBM Operational Decision Manager panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">ibm</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">decision-center</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.ibm.com/docs/en/odm/8.12.0" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.ibm.com/products/operational-decision-manager" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="ibm planning analytics - authentication bypass &amp; remote code execution version detection critical identify critical remote vulnerabilities ibm planning analytics versions 2.0.0 through 2.0.8 are vulnerable to a configuration overwrite that allows an unauthenticated user to login as &#34;admin&#34;, and then execute code as root or system via tm1 scripting. cve-2019-4716 0x_akoko cve cve2019 ibm kev passive planning_analytics vkev cwe-94" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">IBM Planning Analytics - Authentication Bypass &amp; Remote Code Execution Version Detection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2019/CVE-2019-4716.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2019-4716.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_Akoko</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 23, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/94.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-94</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2019-4716" target="_blank" rel="noopener" class="nt-cve-link">CVE-2019-4716</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Arc for TM1&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">IBM Planning Analytics versions 2.0.0 through 2.0.8 are vulnerable to a configuration overwrite that allows an unauthenticated user to login as &#34;admin&#34;, and then execute code as root or SYSTEM via TM1 scripting.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can gain admin access and execute arbitrary code with SYSTEM privileges, leading to full system compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest version or 2.0.9 or apply the security patches provided by IBM.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2019</span><span class="nt-tag">ibm</span><span class="nt-tag">kev</span><span class="nt-tag">passive</span><span class="nt-tag">planning_analytics</span><span class="nt-tag">vkev</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.ibm.com/support/pages/node/1127781" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2019-4716" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="http://packetstormsecurity.com/files/156953/IBM-Cognos-TM1-IBM-Planning-Analytics-Server-Configuration-Overwrite-Code-Execution.html" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="ibm power hmc - default login high identify default logins in web-based control panels ibm hmc default admin login credentials were discovered. r3s ost default-login hmc ibm vuln cwe-522" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">IBM Power HMC - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/ibm/ibm-hmc-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">ibm-hmc-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> R3S OST</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 23, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/522.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-522</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;262502857&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">IBM HMC default admin login credentials were discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">hmc</span><span class="nt-tag">ibm</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.ibm.com/docs/en/power8?topic=tools-hardware-management-console" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="ibm security access manager login panel - detect info identify web-based control panels ibm security access manager login panel was detected. geeknik,righettod detect discovery ibm login panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">IBM Security Access Manager Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/ibm/ibm-security-access-manager.yaml" target="_blank" rel="noopener" class="nt-source-link">ibm-security-access-manager.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> geeknik,righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)IBM Security Access Manager&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">IBM Security Access Manager login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">ibm</span><span class="nt-tag">login</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.ibm.com/docs/en/sva/9.0.7?topic=overview-introduction-security-access-manager" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="ibm security verify access login - panel info identify web-based control panels ibm security verify access login panel was detected. johnk3r panel ibm login detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">IBM Security Verify Access Login - Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/ibm/ibm-security-verify-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">ibm-security-verify-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> johnk3r</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 16, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)IBM Security Verify Access&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">IBM Security Verify Access login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">ibm</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.ibm.com/docs/en/sva/10.0.8?topic=overview-introduction-security-verify-access" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="ibm service assistant login panel - detect info identify web-based control panels ibm service assistant login panel was detected. dhiyaneshdk,righettod panel ibm service login detect discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">IBM Service Assistant Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/ibm/ibm-service-assistant.yaml" target="_blank" rel="noopener" class="nt-source-link">ibm-service-assistant.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDK,righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Welcome to Service Assistant&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">IBM Service Assistant login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">ibm</span><span class="nt-tag">service</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://mediacenter.ibm.com/media/Using+the+IBM+Support+Assistant/0_ffe9o5w1" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="ibm websphere application server community edition admin login panel - detect info identify web-based control panels ibm websphere application server community edition admin login panel was detected. ritikchaddha discovery ibm panel websphere cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">IBM WebSphere Application Server Community Edition Admin Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/ibm/ibm-websphere-admin-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">ibm-websphere-admin-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1337147129&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">IBM WebSphere Application Server Community Edition admin login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">ibm</span><span class="nt-tag">panel</span><span class="nt-tag">websphere</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.ibm.com/support/pages/what-default-username-and-password-websphere-application-server-community-edition-and-how-add-users-admin-group" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="ibm websphere portal login panel - detect info identify web-based control panels ibm websphere portal login panel was detected. pdteam discovery ibm panel websphere cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">IBM WebSphere Portal Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/ibm/ibm-websphere-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">ibm-websphere-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pdteam</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)ibm websphere portal&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">IBM WebSphere Portal login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">ibm</span><span class="nt-tag">panel</span><span class="nt-tag">websphere</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="ibm inotes login panel - detect info identify web-based control panels ibm inotes login panel was detected. dhiyaneshdk,righettod detect discovery edb ibm login panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">IBM iNotes Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/ibm/ibm-note-login.yaml" target="_blank" rel="noopener" class="nt-source-link">ibm-note-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDK,righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)IBM iNotes Login&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">IBM iNotes login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">edb</span><span class="nt-tag">ibm</span><span class="nt-tag">login</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.exploit-db.com/ghdb/7122" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="icc pro login panel - detect info identify web-based control panels icc pro login panel was detected. dhiyaneshdk panel icc-pro edb discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">ICC PRO Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/icc-pro-login.yaml" target="_blank" rel="noopener" class="nt-source-link">icc-pro-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Login to ICC PRO system&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">ICC PRO login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">icc-pro</span><span class="nt-tag">edb</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.exploit-db.com/ghdb/7980" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="ice hrm login - detect info identify web-based control panels the ice hrm login panel was discovered. th3l0newolf icehrm login hrm panel web detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">ICE HRM Login - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/ice-hrm-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">ice-hrm-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Th3l0newolf</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 18, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Ice Hrm Login&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The ICE HRM login panel was discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">icehrm</span><span class="nt-tag">login</span><span class="nt-tag">hrm</span><span class="nt-tag">panel</span><span class="nt-tag">web</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://icehrm.com" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="ict protege wx login panel - detect info identify web-based control panels  ritikchaddha discovery ict ictprotege panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">ICT Protege WX Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/ictprotege-login-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">ictprotege-login-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)ict protege wx&amp;reg;&#34;})</code></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">ict</span><span class="nt-tag">ictprotege</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="ictbroadcast login panel - detect info identify web-based control panels ictbroadcast login panel was detected. rxerium panel ictbroadcast login discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">ICTBroadcast Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/ictbroadcast-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">ictbroadcast-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 21, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-60395993&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">ICTBroadcast login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">ictbroadcast</span><span class="nt-tag">login</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.ictbroadcast.com/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="idemia biometrics - default login medium identify default logins in web-based control panels idemia biometrics application  default login credentials were discovered. techryptic (@tech) biometrics default-login idemia vuln cwe-522" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">IDEMIA BIOMetrics - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/idemia/idemia-biometrics-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">idemia-biometrics-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Techryptic (@Tech)</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/522.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-522</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;IDEMIA&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">IDEMIA BIOMetrics application  default login credentials were discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">biometrics</span><span class="nt-tag">default-login</span><span class="nt-tag">idemia</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.google.com/search?q=idemia+password%3D+&#34;12345&#34;" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="ilias lms - default admin credentials high identify default logins in web-based control panels the ilias learning management system was found to be using default administrator credentials (root:homer). an attacker was able to gain full administrative access to manage courses, users, and system configuration. 0x_akoko ilias default-login auth lms" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">ILIAS LMS - Default Admin Credentials</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/ilias/ilias-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">ilias-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_Akoko</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 25, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Login to ILIAS&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The ILIAS learning management system was found to be using default administrator credentials (root:homer). An attacker was able to gain full administrative access to manage courses, users, and system configuration.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">ilias</span><span class="nt-tag">default-login</span><span class="nt-tag">auth</span><span class="nt-tag">lms</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.ilias.de/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.securityspace.com/smysecure/catid.html?id=1.3.6.1.4.1.25623.1.0.107313" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="ilias login panel - detect info identify web-based control panels ilias login panel was detected. arafatansari panel ilias discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">ILIAS Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/ilias-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">ilias-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> arafatansari</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)ilias&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">ILIAS login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">ilias</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="intelbras telefone ip tip200 60.61.75.22 - local file inclusion high identify critical remote vulnerabilities intelbras telefone ip tip200 version 60.61.75.22 is vulnerable to information disclosure, allowing unauthenticated attackers to access sensitive device information and configuration data via a direct request to the /cgi-bin/export_settings.sh endpoint. cve-2020-24285 ritikchaddha cve cve2020 exposure intelbras lfi telefone tip200 vuln cwe-200" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">INTELBRAS TELEFONE IP TIP200 60.61.75.22 - Local File Inclusion</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2020/CVE-2020-24285.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2020-24285.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 28, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2020-24285" target="_blank" rel="noopener" class="nt-cve-link">CVE-2020-24285</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/cgi-bin/cgiServer\\.exx&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">INTELBRAS TELEFONE IP TIP200 version 60.61.75.22 is vulnerable to information disclosure, allowing unauthenticated attackers to access sensitive device information and configuration data via a direct request to the /cgi-bin/export_settings.sh endpoint.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Authenticated attackers can read arbitrary files from the device including configuration files and credentials, potentially leading to complete device compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update the device firmware to the latest version provided by INTELBRAS.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2020</span><span class="nt-tag">exposure</span><span class="nt-tag">intelbras</span><span class="nt-tag">lfi</span><span class="nt-tag">telefone</span><span class="nt-tag">tip200</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/SecLoop/CVE/blob/main/telefone_ip_tip200.md" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2020-24285" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="ips community suite - unauthenticated sql injection critical identify critical remote vulnerabilities ips community suite is vulnerable to unauthenticated sql injection via the filter[] parameter in the /index.php?/store/ endpoint, allowing attackers to extract sensitive information from the database. cve-2024-30163 ritikchaddha cve cve2024 invision-community ips sqli vuln cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">IPS Community Suite - Unauthenticated SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-30163.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-30163.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 28, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-30163" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-30163</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)invision community&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">IPS Community Suite is vulnerable to unauthenticated SQL injection via the filter[] parameter in the /index.php?/store/ endpoint, allowing attackers to extract sensitive information from the database.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can execute arbitrary SQL queries, potentially extracting or modifying sensitive database information.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update IPS Community Suite to a version that patches CVE-2024-30163.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">invision-community</span><span class="nt-tag">ips</span><span class="nt-tag">sqli</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://karmainsecurity.com/pocs/CVE-2024-30163.php" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-30163" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="ipdiva mediation login panel - detect info identify web-based control panels ipdiva mediation login panel was detected. ritikchaddha panel ipdiva mediation discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">IPdiva Mediation Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/ipdiva-mediation-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">ipdiva-mediation-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)IPdiva&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">IPdiva Mediation login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">ipdiva</span><span class="nt-tag">mediation</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="ipeakcms 3.5 - sql injection critical identify critical remote vulnerabilities ipeak infosystems ibexwebcms 3.5 contains an unauthenticated boolean-based sql injection caused by unsanitized &#39;id&#39; parameter in /cms/print.php, letting attackers execute arbitrary sql commands, exploit requires no authentication. cve-2021-3018 theamanrawat cms cve cve2021 ipeakcms sqli unauth vkev vuln cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">IPeakCMS 3.5 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2021/CVE-2021-3018.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2021-3018.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> theamanrawat</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 15, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2021-3018" target="_blank" rel="noopener" class="nt-cve-link">CVE-2021-3018</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)ipeak&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">ipeak Infosystems ibexwebCMS 3.5 contains an unauthenticated Boolean-based SQL injection caused by unsanitized &#39;id&#39; parameter in /cms/print.php, letting attackers execute arbitrary SQL commands, exploit requires no authentication.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can execute arbitrary SQL commands, potentially leading to data disclosure, data tampering, or full database compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches or update to a version that fixes this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cms</span><span class="nt-tag">cve</span><span class="nt-tag">cve2021</span><span class="nt-tag">ipeakcms</span><span class="nt-tag">sqli</span><span class="nt-tag">unauth</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/M4DM0e/m4dm0e.github.io/blob/gh-pages/_posts/2020-12-07-ipeak-cms-sqli.md" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://m4dm0e.github.io/2020/12/07/ipeak-cms-sqli.html" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2021-3018" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="irisnext login panel - detect info identify web-based control panels irisnext products was detected. righettod panel irisnext login discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">IRISNext Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/irisnext-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">irisnext-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 26, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)irisnext&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">IRISNext products was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">irisnext</span><span class="nt-tag">login</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.irislink.com/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="ispconfig admin - default password high identify default logins in web-based control panels ispconfig admin default password vulnerability exposes systems to unauthorized access, compromising data integrity and security. pussycat0x default-login ispconfig vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">ISPConfig Admin - Default Password</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/ispconfig/ispconfig-admin-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">ispconfig-admin-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 25, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)ispconfig&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">ISPConfig Admin Default Password Vulnerability exposes systems to unauthorized access, compromising data integrity and security.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">ispconfig</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="ispconfig hosting control panel - default login high identify default logins in web-based control panels ispconfig hosting control panel default password vulnerability exposes systems to unauthorized access, compromising data integrity and security. ritikchaddha default-login hsp ispconfig vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">ISPConfig Hosting Control Panel - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/ispconfig/ispconfig-hcp-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">ispconfig-hcp-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 25, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;ISPConfig&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">ISPConfig Hosting Control Panel Default Password Vulnerability exposes systems to unauthorized access, compromising data integrity and security.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">hsp</span><span class="nt-tag">ispconfig</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="itflow unfinished installation high identify critical remote vulnerabilities detected itflow setup wizard was exposed with an unfinished installation, allowing attackers to configure the database and create an admin account. 0x_akoko itflow misconfig install exposure" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">ITFlow Unfinished Installation</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/misconfiguration/installer/itflow-unfinished-installation.yaml" target="_blank" rel="noopener" class="nt-source-link">itflow-unfinished-installation.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_Akoko</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 20, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)ITFlow&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detected ITFlow setup wizard was exposed with an unfinished installation, allowing attackers to configure the database and create an admin account.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">itflow</span><span class="nt-tag">misconfig</span><span class="nt-tag">install</span><span class="nt-tag">exposure</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/itflow-org/itflow" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://docs.itflow.org/installation" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="icewarp email client - cross site scripting medium identify critical remote vulnerabilities cross site scripting vulnerability in icewarp corporation webclient v.10.2.1 allows a remote attacker to execute arbitrary code via a crafted payload to the mid parameter. cve-2023-39598 imjust0 cve cve2023 icewarp vuln xss cwe-79" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">IceWarp Email Client - Cross Site Scripting</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-39598.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-39598.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Imjust0</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 10, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-79</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-39598" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-39598</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)icewarp&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Cross Site Scripting vulnerability in IceWarp Corporation WebClient v.10.2.1 allows a remote attacker to execute arbitrary code via a crafted payload to the mid parameter.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute arbitrary script code in the context of the victim&#39;s browser, potentially leading to session hijacking, defacement, or theft of sensitive information.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches and updates from the vendor to address this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">icewarp</span><span class="nt-tag">vuln</span><span class="nt-tag">xss</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://medium.com/@muthumohanprasath.r/reflected-cross-site-scripting-on-icewarp-webclient-product-cve-2023-39598-9598b92da49c" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-39598" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-39598" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://medium.com/%40muthumohanprasath.r/reflected-cross-site-scripting-on-icewarp-webclient-product-cve-2023-39598-9598b92da49c" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="icewarp login panel - detect info identify web-based control panels icewarp login panel was detected. ritikchaddha discovery icewarp panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">IceWarp Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/icewarp-panel-detect.yaml" target="_blank" rel="noopener" class="nt-source-link">icewarp-panel-detect.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)icewarp&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">IceWarp login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">icewarp</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="icewarp mail server &lt;=10.4.4 - local file inclusion high identify critical remote vulnerabilities icewarp mail server through 10.4.4 is prone to a local file inclusion vulnerability via webmail/calendar/minimizer/index.php?style=..%5c directory traversal. cve-2019-12593 pikpikcu cve cve2019 icewarp lfi packetstorm vkev vuln cwe-22" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">IceWarp Mail Server &lt;=10.4.4 - Local File Inclusion</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2019/CVE-2019-12593.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2019-12593.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pikpikcu</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2019-12593" target="_blank" rel="noopener" class="nt-cve-link">CVE-2019-12593</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)icewarp&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">IceWarp Mail Server through 10.4.4 is prone to a local file inclusion vulnerability via webmail/calendar/minimizer/index.php?style=..%5c directory traversal.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can read sensitive files on the server, potentially leading to unauthorized access, data leakage, or further exploitation.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade IceWarp Mail Server to a version higher than 10.4.4 or apply the vendor-provided patch to fix the LFI vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2019</span><span class="nt-tag">icewarp</span><span class="nt-tag">lfi</span><span class="nt-tag">packetstorm</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/JameelNabbo/exploits/blob/master/IceWarp%20%3C%3D10.4.4%20local%20file%20include.txt" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="http://www.icewarp.com" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2019-12593" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="http://packetstormsecurity.com/files/153161/IceWarp-10.4.4-Local-File-Inclusion.html" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/sobinge/nuclei-templates" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="icewarp webclient - remote code execution critical identify critical remote vulnerabilities icewarp webclient is susceptible to remote code execution. gy741 icewarp rce vuln cwe-77" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">IceWarp WebClient - Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/vulnerabilities/other/icewarp-webclient-rce.yaml" target="_blank" rel="noopener" class="nt-source-link">icewarp-webclient-rce.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> gy741</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/77.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-77</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)icewarp&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">IceWarp WebClient is susceptible to remote code execution.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">icewarp</span><span class="nt-tag">rce</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="icewarp webmail 11.4.5.0 - cross-site scripting medium identify critical remote vulnerabilities icewarp webmail 11.4.5.0 is vulnerable to cross-site scripting via the language parameter. cve-2020-27982 madrobot cve cve2020 icewarp packetstorm vkev vuln xss cwe-79" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">IceWarp WebMail 11.4.5.0 - Cross-Site Scripting</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2020/CVE-2020-27982.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2020-27982.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> madrobot</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-79</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2020-27982" target="_blank" rel="noopener" class="nt-cve-link">CVE-2020-27982</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)icewarp&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">IceWarp WebMail 11.4.5.0 is vulnerable to cross-site scripting via the language parameter.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute arbitrary JavaScript code in the context of the victim&#39;s browser, leading to session hijacking, defacement, or theft of sensitive information.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patch or upgrade to a non-vulnerable version of IceWarp WebMail.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2020</span><span class="nt-tag">icewarp</span><span class="nt-tag">packetstorm</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">xss</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://packetstormsecurity.com/files/159763/Icewarp-WebMail-11.4.5.0-Cross-Site-Scripting.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://cxsecurity.com/issue/WLB-2020100161" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2020-27982" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="http://packetstormsecurity.com/files/159763/Icewarp-WebMail-11.4.5.0-Cross-Site-Scripting.html" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/ARPSyndicate/cvemon" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="icewarp webmail server v10.2.1 - cross site scripting medium identify critical remote vulnerabilities icewarp icearp v10.2.1 was discovered to contain a cross-site scripting (xss) vulnerability via the color parameter. cve-2023-37728 technicaljunkie,r3y3r53 cve cve2023 icearp icewarp vuln xss cwe-79" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">IceWarp Webmail Server v10.2.1 - Cross Site Scripting</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-37728.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-37728.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> technicaljunkie,r3Y3r53</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 16, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-79</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-37728" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-37728</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;2144485375&#34; || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)icewarp&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Icewarp Icearp v10.2.1 was discovered to contain a cross-site scripting (XSS) vulnerability via the color parameter.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can inject malicious JavaScript through the color parameter to steal webmail user session cookies and access email communications.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update IceWarp to a version newer than 10.2.1 that properly sanitizes the color parameter and encodes output in the webmail interface.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">icearp</span><span class="nt-tag">icewarp</span><span class="nt-tag">vuln</span><span class="nt-tag">xss</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://medium.com/@ayush.engr29/cve-2023-37728-6dfb7586311" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-37728" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="http://icearp.com" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="http://icewarp.com" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://medium.com/%40ayush.engr29/cve-2023-37728-6dfb7586311" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="icinga exposed dashboard medium identify critical remote vulnerabilities icinga dashboard was exposed. dhiyaneshdk exposure icinga statistics oos" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Icinga Exposed Dashboard</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/misconfiguration/icinga-dashboard-exposure.yaml" target="_blank" rel="noopener" class="nt-source-link">icinga-dashboard-exposure.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 9, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)icinga\&#34; html:\&#34;Statistics&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Icinga Dashboard was exposed.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">exposure</span><span class="nt-tag">icinga</span><span class="nt-tag">statistics</span><span class="nt-tag">oos</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://icinga.com/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="icinga web 2 - arbitrary file disclosure high identify critical remote vulnerabilities icinga web 2 is an open source monitoring web interface, framework and command-line interface. unauthenticated users can leak the contents of files of the local system accessible to the web-server user, including `icingaweb2` configuration files with database credentials. cve-2022-24716 dhiyaneshdk cve cve2022 icinga lfi packetstorm vkev vuln cwe-22" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Icinga Web 2 - Arbitrary File Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-24716.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-24716.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 8, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-24716" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-24716</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Icinga&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. Unauthenticated users can leak the contents of files of the local system accessible to the web-server user, including `icingaweb2` configuration files with database credentials.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">The vulnerability can lead to unauthorized access to sensitive information, potentially exposing credentials, configuration files, and other sensitive data.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">This issue has been resolved in versions 2.9.6 and 2.10 of Icinga Web 2. Database credentials should be rotated.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">icinga</span><span class="nt-tag">lfi</span><span class="nt-tag">packetstorm</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/JacobEbben/CVE-2022-24716/blob/main/exploit.py" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="http://packetstormsecurity.com/files/171774/Icinga-Web-2.10-Arbitrary-File-Disclosure.html" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/Icinga/icingaweb2/commit/9931ed799650f5b8d5e1dc58ea3415a4cdc5773d" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/Icinga/icingaweb2/security/advisories/GHSA-5p3f-rh28-8frw" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://security.gentoo.org/glsa/202208-05" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="icinga web 2 login panel - detect info identify web-based control panels icinga web 2 login panel was detected. dhiyaneshdk discovery icinga panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Icinga Web 2 Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/icinga-web-login.yaml" target="_blank" rel="noopener" class="nt-source-link">icinga-web-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)icinga web 2 login&#34;}) || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)icinga&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Icinga Web 2 login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">icinga</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="ideacms &lt;= 1.7 - sql injection critical identify critical remote vulnerabilities ideacms up to 1.7 is vulnerable to sql injection via the field parameter in article and product query interfaces. this template uses a time-based payload to safely detect the vulnerability. cve-2025-5569 ritikchaddha cve cve2025 ideacms sqli vuln cwe-74,cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">IdeaCMS &lt;= 1.7 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-5569.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-5569.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 18, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/74,CWE-89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-74,CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-5569" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-5569</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-1033616879&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">IdeaCMS up to 1.7 is vulnerable to SQL injection via the field parameter in article and product query interfaces. This template uses a time-based payload to safely detect the vulnerability.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can extract sensitive data from the database through SQL injection in the field parameter, potentially compromising user information and system credentials.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade IdeaCMS to a version later than 1.7 that properly sanitizes SQL parameters in article and product query interfaces.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">ideacms</span><span class="nt-tag">sqli</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://gitee.com/ideacms/ideacms/issues/ICBVWE#note_42016626_link" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-5569" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="ignite realtime openfire &lt;4.42 - local file inclusion medium identify critical remote vulnerabilities ignite realtime openfire through 4.4.2 is vulnerable to local file inclusion via pluginservlet.java. it does not ensure that retrieved files are located under the openfire home directory. cve-2019-18393 pikpikcu cve cve2019 igniterealtime lfi openfire vkev vuln cwe-22" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Ignite Realtime Openfire &lt;4.42 - Local File Inclusion</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2019/CVE-2019-18393.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2019-18393.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pikpikcu</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2019-18393" target="_blank" rel="noopener" class="nt-cve-link">CVE-2019-18393</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)openfire admin console&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Ignite Realtime Openfire through 4.4.2 is vulnerable to local file inclusion via PluginServlet.java. It does not ensure that retrieved files are located under the Openfire home directory.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability can lead to unauthorized access to sensitive information, remote code execution, and potential compromise of the affected system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade Ignite Realtime Openfire to version 4.42 or later to mitigate this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2019</span><span class="nt-tag">igniterealtime</span><span class="nt-tag">lfi</span><span class="nt-tag">openfire</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/igniterealtime/Openfire/pull/1498" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://swarm.ptsecurity.com/openfire-admin-console/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2019-18393" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/ARPSyndicate/kenzer-templates" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/Elsfa7-110/kenzer-templates" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="ilch cms admin login panel - detect info identify web-based control panels ilch cms admin login panel was detected. ritikchaddha cms discovery ilch panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Ilch CMS Admin Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/ilch-admin-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">ilch-admin-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)ilch&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Ilch CMS admin login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cms</span><span class="nt-tag">discovery</span><span class="nt-tag">ilch</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="imageresizer debug - information exposure low identify critical remote vulnerabilities the imageresizer debug endpoint exposes sensitive server configuration and path information. ritikchaddha exposure debug imageresizer config" data-nt-sev="low">
  <div class="nt-card-header">
    <div class="nt-title">ImageResizer Debug - Information Exposure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/misconfiguration/imageresizer-debug-exposure.yaml" target="_blank" rel="noopener" class="nt-source-link">imageresizer-debug-exposure.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 23, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)ImageResizer&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The ImageResizer debug endpoint exposes sensitive server configuration and path information.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">exposure</span><span class="nt-tag">debug</span><span class="nt-tag">imageresizer</span><span class="nt-tag">config</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://world.optimizely.com/blogs/Eric-Pettersson/Dates/2016/4/hide-resizer-debug-ashx-from-your-website/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="immich panel - detect info identify web-based control panels immich is a self-hosted photo and video backup solution rxerium panel immich detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Immich Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/immich-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">immich-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 27, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-43504595&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Immich is a self-hosted photo and video backup solution</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">immich</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://immich.app/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/immich-app/immich" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="impresscms &lt; 1.4.3 - sql injection high identify critical remote vulnerabilities impresscms before 1.4.3 is vulnerable to sql injection via the groups parameter in include/findusers.php, allowing unauthenticated attackers to execute arbitrary sql queries. cve-2021-26599 ritikchaddha cve cve2021 impresscms sqli time-based-sqli vuln cwe-89" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">ImpressCMS &lt; 1.4.3 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2021/CVE-2021-26599.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2021-26599.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 3, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2021-26599" target="_blank" rel="noopener" class="nt-cve-link">CVE-2021-26599</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)ImpressCMS&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">ImpressCMS before 1.4.3 is vulnerable to SQL injection via the groups parameter in include/findusers.php, allowing unauthenticated attackers to execute arbitrary SQL queries.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can execute arbitrary SQL queries via SQL injection, potentially extracting sensitive database contents or modifying data.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update ImpressCMS to version 1.4.3 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2021</span><span class="nt-tag">impresscms</span><span class="nt-tag">sqli</span><span class="nt-tag">time-based-sqli</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://hackerone.com/reports/1081145" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="http://karmainsecurity.com/KIS-2022-04" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2021-26599" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="impresscms &lt;1.4.3 - incorrect authorization medium identify critical remote vulnerabilities impresscms before 1.4.3 is susceptible to incorrect authorization via include/findusers.php. an attacker can provide a security token and potentially obtain sensitive information, modify data, and/or execute unauthorized operations. cve-2021-26598 gy741,pdteam cms cve cve2021 hackerone impresscms unauth vuln cwe-287" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">ImpressCMS &lt;1.4.3 - Incorrect Authorization</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2021/CVE-2021-26598.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2021-26598.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> gy741,pdteam</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/287.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-287</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2021-26598" target="_blank" rel="noopener" class="nt-cve-link">CVE-2021-26598</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)impresscms&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">ImpressCMS before 1.4.3 is susceptible to incorrect authorization via include/findusers.php. An attacker can provide a security token and potentially obtain sensitive information, modify data, and/or execute unauthorized operations.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can bypass authorization and gain unauthorized access to sensitive information or perform unauthorized actions.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to ImpressCMS version 1.4.3 or later to fix the vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cms</span><span class="nt-tag">cve</span><span class="nt-tag">cve2021</span><span class="nt-tag">hackerone</span><span class="nt-tag">impresscms</span><span class="nt-tag">unauth</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://hackerone.com/reports/1081137" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="http://karmainsecurity.com/KIS-2022-03" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/ImpressCMS" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2021-26598" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/ARPSyndicate/cvemon" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="indusoft web studio ntwebserver directory traversal vulnerability critical identify critical remote vulnerabilities directory traversal vulnerability in ntwebserver in indusoft web studio 7.1 before sp2 patch 4 allows remote attackers to read administrative passwords in app files. cve-2014-0780 n3integration cve cve2014 kev vuln cwe-22" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">InduSoft Web Studio NTWebServer Directory Traversal Vulnerability</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2014/CVE-2014-0780.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2014-0780.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> n3integration</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 20, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2014-0780" target="_blank" rel="noopener" class="nt-cve-link">CVE-2014-0780</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;product&#34;] contains &#34;InduSoft:Web Studio&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Directory traversal vulnerability in NTWebServer in InduSoft Web Studio 7.1 before SP2 Patch 4 allows remote attackers to read administrative passwords in APP files.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply updates per vendor instructions.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2014</span><span class="nt-tag">kev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://ics-cert.us-cert.gov/advisories/ICSA-14-107-02" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.cisa.gov/news-events/ics-advisories/icsa-14-107-02" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.exploit-db.com/exploits/42699" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="inductive automation ignition - gateway panel info identify web-based control panels inductive automation ignition is a widely-deployed industrial scada/hmi
platform used in manufacturing, utilities, and process industries. the
ignition gateway web interface provides access to project management,
opc-ua tag browsing, and system configuration. exposed gateways may
allow unauthenticated access to project lists and system information. rxerium discovery hmi ics ignition inductive-automation opc-ua panel scada" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Inductive Automation Ignition - Gateway Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/inductive-automation-ignition-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">inductive-automation-ignition-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 27, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;^Ignition Gateway&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Inductive Automation Ignition is a widely-deployed industrial SCADA/HMI
platform used in manufacturing, utilities, and process industries. The
Ignition Gateway web interface provides access to project management,
OPC-UA tag browsing, and system configuration. Exposed gateways may
allow unauthenticated access to project lists and system information.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">hmi</span><span class="nt-tag">ics</span><span class="nt-tag">ignition</span><span class="nt-tag">inductive-automation</span><span class="nt-tag">opc-ua</span><span class="nt-tag">panel</span><span class="nt-tag">scada</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://inductiveautomation.com/ignition/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://docs.inductiveautomation.com/docs/8.1/ignition-gateway-interface" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="infinispan - default admin login high identify default logins in web-based control panels the infinispan rest api was found exposed with the default administrator credentials `admin:password`. an unauthenticated network attacker can authenticate via http digest and gain full read/write access to all cache managers, caches, and server administration endpoints. dhiyanesdk config default-login infinispan redhat" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Infinispan - Default Admin Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/infinispan/infinispan-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">infinispan-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyanesDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 14, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;647951307&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The Infinispan REST API was found exposed with the default administrator credentials `admin:password`. An unauthenticated network attacker can authenticate via HTTP Digest and gain full read/write access to all cache managers, caches, and server administration endpoints.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">config</span><span class="nt-tag">default-login</span><span class="nt-tag">infinispan</span><span class="nt-tag">redhat</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://infinispan.org/docs/stable/titles/security/security.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://infinispan.org/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="influxdb &lt;1.7.6 - authentication bypass critical identify critical remote vulnerabilities influxdb before 1.7.6 contains an authentication bypass vulnerability via the authenticate function in services/httpd/handler.go. a jwt token may have an empty sharedsecret (aka shared secret). an attacker can possibly obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site. cve-2019-20933 pussycat0x,c-sh0 cve cve2019 db influxdata influxdb misconfig unauth vkev vuln cwe-287" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">InfluxDB &lt;1.7.6 - Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2019/CVE-2019-20933.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2019-20933.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x,c-sh0</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/287.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-287</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2019-20933" target="_blank" rel="noopener" class="nt-cve-link">CVE-2019-20933</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)influxdb - admin interface&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">InfluxDB before 1.7.6 contains an authentication bypass vulnerability via the authenticate function in services/httpd/handler.go. A JWT token may have an empty SharedSecret (aka shared secret). An attacker can possibly obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can bypass authentication and gain unauthorized access to the InfluxDB database.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update Influxdb to version 1.7.6~rc0-1 or higher.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2019</span><span class="nt-tag">db</span><span class="nt-tag">influxdata</span><span class="nt-tag">influxdb</span><span class="nt-tag">misconfig</span><span class="nt-tag">unauth</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/LorenzoTullini/InfluxDB-Exploit-CVE-2019-20933" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-20933" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/influxdata/influxdb/compare/v1.7.5...v1.7.6" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2019-20933" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/influxdata/influxdb/commit/761b557315ff9c1642cf3b0e5797cd3d983a24c0" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="influxdb admin interface panel - detect info identify web-based control panels influxdb admin interface panel was detected. pikpikcu,idealphase discovery influxdata influxdb panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">InfluxDB Admin Interface Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/influxdb-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">influxdb-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pikpikcu,idealphase</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)influxdb - admin interface&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">InfluxDB admin interface panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">influxdata</span><span class="nt-tag">influxdb</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.influxdata.com/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="infoblox nios login panel - detect info identify web-based control panels infoblox nios login panel was detected. egemenkochisarli panel infoblox nios login detect discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Infoblox NIOS Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/infoblox-nios-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">infoblox-nios-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> EgemenKochisarli</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 24, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Infoblox&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Infoblox NIOS login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">infoblox</span><span class="nt-tag">nios</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.infoblox.com/glossary/network-identity-operating-system-nios/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="inspur clusterengine 4 - default admin login high identify default logins in web-based control panels inspur clusterengine version 4 default admin login credentials were successful. ritikchaddha clusterengine default-login inspur vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Inspur Clusterengine 4 - Default Admin Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/others/inspur-clusterengine-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">inspur-clusterengine-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)TSCEV4\\.0&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Inspur Clusterengine version 4 default admin login credentials were successful.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">clusterengine</span><span class="nt-tag">default-login</span><span class="nt-tag">inspur</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://blog.csdn.net/qq_36197704/article/details/115665793" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="inspur clusterengine v4 sysshell - remote command execution critical identify critical remote vulnerabilities inspur clusterengine v4 sysshell was found and allows remote command execution by design. cve-2020-21224 ritikchaddha clusterengine inspur rce vuln cwe-88" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Inspur Clusterengine V4 SYSshell - Remote Command Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/vulnerabilities/other/inspur-clusterengine-rce.yaml" target="_blank" rel="noopener" class="nt-source-link">inspur-clusterengine-rce.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/88.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-88</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2020-21224" target="_blank" rel="noopener" class="nt-cve-link">CVE-2020-21224</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)TSCEV4\\.0&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Inspur Clusterengine V4 SYSshell was found and allows remote command execution by design.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">clusterengine</span><span class="nt-tag">inspur</span><span class="nt-tag">rce</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.inspursystems.com/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/MzzdToT/ClusterEngineV4.0sysShell_rce" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2020-21224" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/NS-Sp4ce/Inspur/tree/master/ClusterEngineV4.0%20Vul" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="instawp connect &lt; 0.1.0.86 - local php file inclusion high identify critical remote vulnerabilities the instawp connect - 1-click wp staging &amp; migration plugin for wordpress is vulnerable to local file inclusion in all versions up to, and including, 0.1.0.85 via the &#39;instawp-database-manager&#39; parameter. this makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any php code in those files. cve-2025-2636 iamnoooob,pdresearch cve cve2025 instawp-connect lfi vkev vuln wordpress wp wp-plugin cwe-22" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">InstaWP Connect &lt; 0.1.0.86 - Local PHP File Inclusion</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-2636.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-2636.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> iamnoooob,pdresearch</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 26, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-2636" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-2636</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/instawp-connect&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The InstaWP Connect - 1-click WP Staging &amp; Migration plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 0.1.0.85 via the &#39;instawp-database-manager&#39; parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can include and execute arbitrary PHP files through the instawp-database-manager parameter, allowing arbitrary code execution and potential complete server compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update InstaWP Connect plugin to version 0.1.0.86 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">instawp-connect</span><span class="nt-tag">lfi</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wpscan.com/vulnerability/d1b64725-d4ae-4d73-950a-b772a877022b/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/4c8f2c6f-c231-477c-895b-df892569ef95" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-2636" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="integrate google drive &lt;= 1.5.3 - information disclosure high identify critical remote vulnerabilities file manager for google drive - integrate google drive with wordpress plugin for wordpress &lt;= 1.5.3 contains sensitive information exposure caused by improper protection of the get_localize_data function, letting unauthenticated attackers extract google oauth credentials and account email addresses, exploit requires no authentication. cve-2025-12139 meysam bal-afkan cve cve2025 exposure google-drive token wordpress wp-plugin" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Integrate Google Drive &lt;= 1.5.3 - Information Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-12139.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-12139.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Meysam Bal-afkan</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 21, 2025</span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-12139" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-12139</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/integrate-google-drive&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">File Manager for Google Drive - Integrate Google Drive with WordPress plugin for WordPress &lt;= 1.5.3 contains sensitive information exposure caused by improper protection of the get_localize_data function, letting unauthenticated attackers extract Google OAuth credentials and account email addresses, exploit requires no authentication.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can extract sensitive Google OAuth credentials and email addresses, risking account compromise and data theft.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to a version later than 1.5.3 or the latest available version.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">exposure</span><span class="nt-tag">google-drive</span><span class="nt-tag">token</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp-plugin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wordpress.org/plugins/integrate-google-drive/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/Galaxy-sc/CVE-2025-12139-WordPress-Integrate-Google-Drive-Exploit" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="integrated management module - default login high identify default logins in web-based control panels integrated management module default login credentials were discovered. jpg0mez default-login ibm imm vuln cwe-798" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Integrated Management Module - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/ibm/imm-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">imm-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> jpg0mez</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 4, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/798.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-798</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)ibmdojo&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Integrated Management Module default login credentials were discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">ibm</span><span class="nt-tag">imm</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://pubs.lenovo.com/x3650-m4/t_logging_web_interface" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.ibm.com/docs/en/tcs-service?topic=oip-logging-imm-web-interface" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="intel active management - authentication bypass critical identify critical remote vulnerabilities intel active management platforms are susceptible to authentication bypass. a non-privileged network attacker can gain system privileges to provisioned intel manageability skus: intel active management technology (amt) and intel standard manageability. a non-privileged local attacker can provision manageability features, gaining unprivileged network or local system privileges on intel manageability skus: intel active management technology, intel standard manageability, and intel small business technology. the issue has been observed in versions 6.x, 7.x, 8.x 9.x, 10.x, 11.0, 11.5, and 11.6 for all three platforms. versions before 6 and after 11.6 are not impacted. cve-2017-5689 pdteam amt cve cve2017 intel kev tenable vkev vuln" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Intel Active Management - Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2017/CVE-2017-5689.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2017-5689.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pdteam</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2017-5689" target="_blank" rel="noopener" class="nt-cve-link">CVE-2017-5689</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)active management technology&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Intel Active Management platforms are susceptible to authentication bypass. A non-privileged network attacker can gain system privileges to provisioned Intel manageability SKUs: Intel Active Management Technology (AMT) and Intel Standard Manageability. A non-privileged local attacker can provision manageability features, gaining unprivileged network or local system privileges on Intel manageability SKUs: Intel Active Management Technology, Intel Standard Manageability, and Intel Small Business Technology. The issue has been observed in versions 6.x, 7.x, 8.x 9.x, 10.x, 11.0, 11.5, and 11.6 for all three platforms. Versions before 6 and after 11.6 are not impacted.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can bypass authentication and gain unauthorized access to the Intel Active Management firmware, potentially leading to unauthorized control of the affected system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update the Intel Active Management firmware to version 11.6.55, 11.7.55, 11.11.55, 11.0.25, 8.1.71, or 7.1.91 to mitigate the vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">amt</span><span class="nt-tag">cve</span><span class="nt-tag">cve2017</span><span class="nt-tag">intel</span><span class="nt-tag">kev</span><span class="nt-tag">tenable</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00075&amp;languageid=en-fr" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.tenable.com/blog/rediscovering-the-intel-amt-vulnerability" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.embedi.com/news/mythbusters-cve-2017-5689" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://www.embedi.com/files/white-papers/Silent-Bob-is-Silent.pdf" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://nvd.nist.gov/vuln/detail/cve-2017-5689" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="intelbras nplug 1.0.0.14 - authentication bypass critical identify critical remote vulnerabilities intelbras nplug 1.0.0.14 is vulnerable to authentication bypass through cookie manipulation. an attacker can bypass authentication by simply setting a cookie named &#34;admin:&#34;. cve-2018-12455 ritikchaddha auth-bypass cve cve2018 intelbras iot vuln cwe-287" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Intelbras NPLUG 1.0.0.14 - Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2018/CVE-2018-12455.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2018-12455.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 3, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/287.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-287</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2018-12455" target="_blank" rel="noopener" class="nt-cve-link">CVE-2018-12455</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)NPLUG&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Intelbras NPLUG 1.0.0.14 is vulnerable to authentication bypass through cookie manipulation. An attacker can bypass authentication by simply setting a cookie named &#34;admin:&#34;.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can bypass authentication and download the router configuration file containing credentials, network settings, and sensitive information.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update the device firmware to the latest version.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2018</span><span class="nt-tag">intelbras</span><span class="nt-tag">iot</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://seclists.org/fulldisclosure/2018/Oct/18" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2018-12455" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="intelbras router login panel - detect info identify web-based control panels intelbras router logjn panel was detected. dhiyaneshdk discovery edb panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Intelbras Router Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/intelbras-login.yaml" target="_blank" rel="noopener" class="nt-source-link">intelbras-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Intelbras&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Intelbras router logjn panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">edb</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.exploit-db.com/ghdb/7272" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="intelbras router panel - detect info identify web-based control panels intelbras router panel was detected. pikpikcu discovery intelbras panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Intelbras Router Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/intelbras-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">intelbras-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pikpikcu</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)intelbras&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Intelbras router panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">intelbras</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="intelbras switch - information disclosure high identify critical remote vulnerabilities an authentication bypass in intelbras switch sg 2404 mr in firmware 1.00.54 allows an unauthenticated attacker to download the backup file of the device, exposing critical information about the device configuration. cve-2023-36144 gy741 cve cve2023 exposure intelbras switch vkev vuln cwe-862" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Intelbras Switch - Information Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-36144.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-36144.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> gy741</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 23, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/862.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-862</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-36144" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-36144</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)intelbras&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An authentication bypass in Intelbras Switch SG 2404 MR in firmware 1.00.54 allows an unauthenticated attacker to download the backup file of the device, exposing critical information about the device configuration.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can exploit authentication bypass to download backup configuration files containing critical device information including credentials and network configuration from Intelbras Switch devices.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches or updates provided by the vendor to mitigate this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">exposure</span><span class="nt-tag">intelbras</span><span class="nt-tag">switch</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-36144" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/leonardobg/CVE-2023-36144" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="http://intelbras.com" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/nomi-sec/PoC-in-GitHub" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="intelbras wrn 150 - authentication bypass critical identify critical remote vulnerabilities intelbras wrn 150 router is vulnerable to authentication bypass through cookie manipulation. an attacker can bypass authentication and download the router configuration file by manipulating the admin:language cookie. cve-2017-14942 ritikchaddha auth-bypass cve cve2017 intelbras router vuln cwe-552" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Intelbras WRN 150 - Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2017/CVE-2017-14942.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2017-14942.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 3, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/552.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-552</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2017-14942" target="_blank" rel="noopener" class="nt-cve-link">CVE-2017-14942</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)WRN150&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Intelbras WRN 150 router is vulnerable to authentication bypass through cookie manipulation. An attacker can bypass authentication and download the router configuration file by manipulating the admin:language cookie.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can bypass authentication and download the router configuration file containing credentials, network settings, and sensitive information, potentially leading to complete network compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update the router firmware to the latest version.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2017</span><span class="nt-tag">intelbras</span><span class="nt-tag">router</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.exploit-db.com/exploits/42916" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2017-14942" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="intellian aptus web login panel - detect info identify web-based control panels intelllian aptus web login panel was detected. princechaddha aptus discovery intellian intelliantech panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Intellian Aptus Web Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/intellian-aptus-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">intellian-aptus-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> princechaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)intellian aptus web&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Intelllian Aptus Web login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">aptus</span><span class="nt-tag">discovery</span><span class="nt-tag">intellian</span><span class="nt-tag">intelliantech</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="internet multi server control panel - detect info identify web-based control panels internet multi server control panel was detected. justaacat panel i-mscp detect discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Internet Multi Server Control Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/i-mscp-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">i-mscp-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> JustaAcat</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)i-MSCP - Multi Server Control Panel&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Internet Multi Server Control Panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">i-mscp</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://i-mscp.net/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="invision community &lt;=5.0.6 unauthenticated rce via template injection critical identify critical remote vulnerabilities invision community 5.0.0 before 5.0.7 allows remote code execution via crafted template strings to themeeditor.php. the issue lies within the themeeditor controller (/applications/core/modules/front/system/themeeditor.php), where a protected method named customcss can be invoked by unauthenticated users. this method passes the value of the content parameter to the theme::makeprocessfunction() method, which is evaluated by the template engine. accordingly, unauthenticated attackers can inject and execute arbitrary php code by providing crafted template strings. cve-2025-47916 egix,iamnoooob,pdresearch cve cve2025 invision rce seclists ssti unauth vkev vuln cwe-1336" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Invision Community &lt;=5.0.6 Unauthenticated RCE via Template Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-47916.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-47916.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> EgiX,iamnoooob,pdresearch</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 26, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/1336.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-1336</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-47916" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-47916</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Invision&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Invision Community 5.0.0 before 5.0.7 allows remote code execution via crafted template strings to themeeditor.php. The issue lies within the themeeditor controller (/applications/core/modules/front/system/themeeditor.php), where a protected method named customCss can be invoked by unauthenticated users. This method passes the value of the content parameter to the Theme::makeProcessFunction() method, which is evaluated by the template engine. Accordingly, unauthenticated attackers can inject and execute arbitrary PHP code by providing crafted template strings.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can inject and execute arbitrary PHP code through the content parameter in themeeditor.php, achieving complete server compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade Invision Community to version 5.0.7 or later that properly sanitizes template strings before evaluation.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">invision</span><span class="nt-tag">rce</span><span class="nt-tag">seclists</span><span class="nt-tag">ssti</span><span class="nt-tag">unauth</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-47916" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://karmainsecurity.com/pocs/CVE-2025-47916.php" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://invisioncommunity.com/release-notes-v5/507-r41/" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://karmainsecurity.com/KIS-2025-02" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="http://seclists.org/fulldisclosure/2025/May/4" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="issabel login panel - detect info identify web-based control panels issabel login panel was detected. pikpikcu discovery issabel panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Issabel Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/issabel-login.yaml" target="_blank" rel="noopener" class="nt-source-link">issabel-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pikpikcu</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Issabel&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Issabel login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">issabel</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="issabel pbx 4.0.0-6 - directory listing high identify critical remote vulnerabilities an issue in issabel-pbx v.4.0.0-6 allows a remote attacker to obtain sensitive information via the modules directory cve-2023-37599 ritikchaddha cve cve2023 directory-listing issabel issabel-pbx vuln cwe-668" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Issabel PBX 4.0.0-6 - Directory Listing</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-37599.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-37599.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 9, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/668.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-668</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-37599" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-37599</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)issabel&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An issue in issabel-pbx v.4.0.0-6 allows a remote attacker to obtain sensitive information via the modules directory</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Exploiting this vulnerability could lead to unauthorized access to sensitive directories and files, compromising the confidentiality of the system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">It is recommended to update to a patched version of issabel-pbx or apply necessary configuration changes to prevent directory listing.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">directory-listing</span><span class="nt-tag">issabel</span><span class="nt-tag">issabel-pbx</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/sahiloj/CVE-2023-37599" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-37599" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="ivanti cloud services appliance - path traversal critical identify critical remote vulnerabilities path traversal in the ivanti csa before 4.6 patch 519 allows a remote unauthenticated attacker to access restricted functionality. cve-2024-8963 johnk3r cve cve2024 ivanti kev vkev vuln cwe-22" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Ivanti Cloud Services Appliance - Path Traversal</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-8963.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-8963.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> johnk3r</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 6, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-8963" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-8963</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)cloud services appliance&#34;}) || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)landesk\\(r\\) cloud services appliance&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted functionality.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can exploit path traversal to access restricted administrative functionality, potentially gaining unauthorized control of the Ivanti Cloud Services Appliance and accessing sensitive user management features.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update Ivanti Cloud Services Appliance to version 4.6 Patch 519 or later to address the path traversal vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">ivanti</span><span class="nt-tag">kev</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.fortinet.com/blog/threat-research/burning-zero-days-suspected-nation-state-adversary-targets-ivanti-csa" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-CSA-4-6-Cloud-Services-Appliance-CVE-2024-8963?language=en_US" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-8963" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="ivanti connect secure - stack-based buffer overflow critical identify critical remote vulnerabilities ivanti connect secure &lt; 22.7r2.5, ivanti policy secure &lt; 22.7r1.2, and ivanti neurons for zta gateways &lt; 22.7r2.3 contain a stack-based buffer overflow in the clientcapabilities parameter handling. this vulnerability allows remote unauthenticated attackers to execute arbitrary code through if-t tls requests. cve-2025-0282 ritikchaddha buffer-overflow cve cve2025 ivanti kev passive rce vkev vuln cwe-121,cwe-787" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Ivanti Connect Secure - Stack-based Buffer Overflow</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-0282.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-0282.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 4, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/121,CWE-787.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-121,CWE-787</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-0282" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-0282</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)ivanti connect secure&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Ivanti Connect Secure &lt; 22.7R2.5, Ivanti Policy Secure &lt; 22.7R1.2, and Ivanti Neurons for ZTA gateways &lt; 22.7R2.3 contain a stack-based buffer overflow in the clientCapabilities parameter handling. This vulnerability allows remote unauthenticated attackers to execute arbitrary code through IF-T TLS requests.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can exploit a stack-based buffer overflow to execute arbitrary code remotely on Ivanti Connect Secure devices, potentially compromising VPN infrastructure and accessing all connected networks.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to Ivanti Connect Secure version 22.7R2.5, Ivanti Policy Secure version 22.7R1.2, or Ivanti Neurons for ZTA version 22.7R2.3 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">buffer-overflow</span><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">ivanti</span><span class="nt-tag">kev</span><span class="nt-tag">passive</span><span class="nt-tag">rce</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Connect-Secure-Policy-Secure-ZTA-Gateways-CVE-2025-0282-CVE-2025-0283" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://labs.watchtowr.com/exploitation-walkthrough-and-techniques-ivanti-connect-secure-rce-cve-2025-0282/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://cloud.google.com/blog/topics/threat-intelligence/ivanti-connect-secure-vpn-zero-day" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-0282" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="ivanti connect secure panel - detect info identify web-based control panels ivanti connect secure provides a seamless, cost-effective ssl vpn solution for remote and mobile users from any web-enabled device to corporate resources— anytime, anywhere. rxerium connectsecure discovery ivanti login panel" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Ivanti Connect Secure Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/ivanti-connect-secure-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">ivanti-connect-secure-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 3, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)welcome\\.cgi\\?p=logo&#34; || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)ivanti connect secure&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Ivanti Connect Secure provides a seamless, cost-effective SSL VPN solution for remote and mobile users from any web-enabled device to corporate resources— anytime, anywhere.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">connectsecure</span><span class="nt-tag">discovery</span><span class="nt-tag">ivanti</span><span class="nt-tag">login</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.ivanti.com/products/connect-secure-vpn" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="ivanti epm cloud services appliance code injection critical identify critical remote vulnerabilities ivanti epm cloud services appliance (csa) before version 4.6.0-512 is susceptible to a code injection vulnerability because it allows an unauthenticated user to execute arbitrary code with limited permissions (nobody). cve-2021-44529 duty_1g,phyr3wall,tirtha csa cve cve2021 epm injection ivanti kev packetstorm vkev vuln cwe-94" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Ivanti EPM Cloud Services Appliance Code Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2021/CVE-2021-44529.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2021-44529.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> duty_1g,phyr3wall,Tirtha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/94.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-94</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2021-44529" target="_blank" rel="noopener" class="nt-cve-link">CVE-2021-44529</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)landesk\\(r\\) cloud services appliance&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Ivanti EPM Cloud Services Appliance (CSA) before version 4.6.0-512 is susceptible to a code injection vulnerability because it allows an unauthenticated user to execute arbitrary code with limited permissions (nobody).</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could lead to remote code execution and compromise of the affected system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches provided by Ivanti to mitigate this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">csa</span><span class="nt-tag">cve</span><span class="nt-tag">cve2021</span><span class="nt-tag">epm</span><span class="nt-tag">injection</span><span class="nt-tag">ivanti</span><span class="nt-tag">kev</span><span class="nt-tag">packetstorm</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://forums.ivanti.com/s/article/SA-2021-12-02" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://twitter.com/Dinosn/status/1505273954478530569" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2021-44529" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="http://packetstormsecurity.com/files/166383/Ivanti-Endpoint-Manager-CSA-4.5-4.6-Remote-Code-Execution.html" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/SYRTI/POC_to_review" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="ivanti endpoint manager - authentication bypass high identify critical remote vulnerabilities ivanti endpoint manager &lt; 2024 su5 contains an authentication bypass caused by improper access control, letting remote unauthenticated attackers leak stored credential data, exploit requires no special privileges. cve-2026-1603 dhiyaneshdk,watchtowrlabs api auth authbypass cve cve2026 epmm ivanti kev vkev cwe-288" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Ivanti Endpoint Manager - Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2026/CVE-2026-1603.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2026-1603.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk,watchtowrlabs</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 13, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/288.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-288</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2026-1603" target="_blank" rel="noopener" class="nt-cve-link">CVE-2026-1603</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;362091310&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Ivanti Endpoint Manager &lt; 2024 SU5 contains an authentication bypass caused by improper access control, letting remote unauthenticated attackers leak stored credential data, exploit requires no special privileges.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Remote attackers can leak stored credential data, potentially compromising sensitive information.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to version 2024 SU5 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">api</span><span class="nt-tag">auth</span><span class="nt-tag">authbypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2026</span><span class="nt-tag">epmm</span><span class="nt-tag">ivanti</span><span class="nt-tag">kev</span><span class="nt-tag">vkev</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://x.com/watchtowrcyber/status/2022305033086235108/photo/1" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://hub.ivanti.com/s/article/Security-Advisory-EPM-February-2026-for-EPM-2024" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1603" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="ivanti endpoint manager mobile (epmm) - authentication bypass critical identify critical remote vulnerabilities ivanti endpoint manager mobile (epmm), formerly mobileiron core, through 11.10 allows remote attackers to obtain pii, add an administrative account, and change the configuration because of an authentication bypass, as exploited in the wild in july 2023. a patch is available. cve-2023-35078 parth,pdresearch cve cve2023 epmm ivanti kev mobileiron vkev vuln cwe-287" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Ivanti Endpoint Manager Mobile (EPMM) - Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-35078.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-35078.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> parth,pdresearch</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 29, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/287.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-287</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-35078" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-35078</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;362091310&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Ivanti Endpoint Manager Mobile (EPMM), formerly MobileIron Core, through 11.10 allows remote attackers to obtain PII, add an administrative account, and change the configuration because of an authentication bypass, as exploited in the wild in July 2023. A patch is available.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to bypass authentication and gain unauthorized access to the affected system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches or updates provided by Ivanti to fix the authentication bypass vulnerability in Endpoint Manager Mobile (EPMM).</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">epmm</span><span class="nt-tag">ivanti</span><span class="nt-tag">kev</span><span class="nt-tag">mobileiron</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://forums.ivanti.com/s/article/CVE-2023-35078-Remote-unauthenticated-API-access-vulnerability" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://forums.ivanti.com/s/article/KB-Remote-unauthenticated-API-access-vulnerability-CVE-2023-35078" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.cisa.gov/news-events/alerts/2023/07/24/ivanti-releases-security-updates-endpoint-manager-mobile-epmm-cve-2023-35078" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://www.ivanti.com/blog/cve-2023-35078-new-ivanti-epmm-vulnerability" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://help.ivanti.com/mi/help/en_us/CORE/11.2.0.0/dmgw/DMGfiles/Join_Azure_and_MobileIro.htm" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="ivanti ics - authentication bypass high identify critical remote vulnerabilities an authentication bypass vulnerability in the web component of ivanti ics 9.x, 22.x and ivanti policy secure allows a remote attacker to access restricted resources by bypassing control checks. cve-2023-46805 dhiyaneshdk,daffainfo,geeknik auth-bypass cve cve2023 ivanti kev packetstorm vkev vuln cwe-287" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Ivanti ICS - Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-46805.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-46805.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK,daffainfo,geeknik</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 17, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/287.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-287</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-46805" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-46805</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)welcome\\.cgi\\?p=logo&#34; || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)ivanti connect secure&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restricted resources by bypassing control checks.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can bypass authentication controls and access restricted administrative resources, potentially exposing sensitive configuration data.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade Ivanti Connect Secure and Policy Secure to the latest patched versions as provided in the vendor advisory.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">ivanti</span><span class="nt-tag">kev</span><span class="nt-tag">packetstorm</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://forums.ivanti.com/s/article/CVE-2023-46805-Authentication-Bypass-CVE-2024-21887-Command-Injection-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure-Gateways?language=en_US" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-46805" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="http://packetstormsecurity.com/files/176668/Ivanti-Connect-Secure-Unauthenticated-Remote-Code-Execution.html" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/H4lo/awesome-IoT-security-article" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/inguardians/ivanti-VPN-issues-2024-research" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="ivanti incapptic connect panel - detect info identify web-based control panels ivanti incapptic connect panel was detected. righettod discovery incapptic-connect ivanti panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Ivanti Incapptic Connect Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/incapptic-connect-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">incapptic-connect-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)incapptic&#34;}) || service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-1067582922&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Ivanti Incapptic Connect panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">incapptic-connect</span><span class="nt-tag">ivanti</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.ivanti.com/products/incapptic-connect" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="ivanti traffic manager panel - detect info identify web-based control panels an ivanti traffic manager login panel was detected. rxerium detect traffic-manager panel login discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Ivanti Traffic Manager Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/ivanti-traffic-manager-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">ivanti-traffic-manager-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 25, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Login \\(Virtual Traffic Manager&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An Ivanti Traffic Manager Login Panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">detect</span><span class="nt-tag">traffic-manager</span><span class="nt-tag">panel</span><span class="nt-tag">login</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.ivanti.com/resources/v/doc/ivi/2528/2ef03e8ed03d" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="ivanti(r) cloud services appliance - panel info identify web-based control panels an ivanti cloud services appliance panel was detected. rxerium ivanti csa panel login discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Ivanti(R) Cloud Services Appliance - Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/ivanti-csa-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">ivanti-csa-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 24, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Cloud Services Appliance&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An Ivanti Cloud Services Appliance panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">ivanti</span><span class="nt-tag">csa</span><span class="nt-tag">panel</span><span class="nt-tag">login</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://help.ivanti.com/ld/help/en_US/LDMS/10.0/Windows/csa-h-help.htm" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="jboss soa platform login panel - detect info identify web-based control panels jboss soa platform login panel was detected. ritikchaddha,righettod detect discovery jboss panel redhat soa cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">JBoss SOA Platform Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/jboss/jboss-soa-platform.yaml" target="_blank" rel="noopener" class="nt-source-link">jboss-soa-platform.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha,righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)welcome to the jboss soa platform&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">JBoss SOA Platform login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">jboss</span><span class="nt-tag">panel</span><span class="nt-tag">redhat</span><span class="nt-tag">soa</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="jboss ws juddi console panel - detect info identify web-based control panels the juddi (java universal description, discovery and integration) registry is a core component of the jboss enterprise soa platform. it is the product&#39;s default service registry and comes included as part of the product. in it are stored the addresses (end-point references) of all the services connected to the enterprise service bus. it was implemented in jaxr and conforms to the uddi specifications. dhiyaneshdk discovery jboss juddi panel redhat cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">JBoss WS JUDDI Console Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/jboss/jboss-juddi.yaml" target="_blank" rel="noopener" class="nt-source-link">jboss-juddi.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)jboss ws&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The jUDDI (Java Universal Description, Discovery and Integration) Registry is a core component of the JBoss Enterprise SOA Platform. It is the product&#39;s default service registry and comes included as part of the product. In it are stored the addresses (end-point references) of all the services connected to the Enterprise Service Bus. It was implemented in JAXR and conforms to the UDDI specifications.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Restrict access to the service if not needed.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">jboss</span><span class="nt-tag">juddi</span><span class="nt-tag">panel</span><span class="nt-tag">redhat</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/ilmila/J2EEScan/blob/master/src/main/java/burp/j2ee/issues/impl/JBossJuddi.java" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="jboss jbpm administration console default login - detect high identify default logins in web-based control panels jboss jbpm administration console default login information was detected. dhiyaneshdk default-login jboss jbpm vuln cwe-522" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">JBoss jBPM Administration Console Default Login - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/jboss/jboss-jbpm-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">jboss-jbpm-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/522.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-522</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;JBossWS&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">JBoss jBPM Administration Console default login information was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">jboss</span><span class="nt-tag">jbpm</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/PortSwigger/j2ee-scan/blob/master/src/main/java/burp/j2ee/issues/impl/JBossjBPMAdminConsole.java" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="jboss jbpm administration console login panel - detect info identify web-based control panels jboss jbpm administration console login panel was detected. dhiyaneshdk discovery jboss login panel redhat cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">JBoss jBPM Administration Console Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/jboss/jboss-jbpm-admin.yaml" target="_blank" rel="noopener" class="nt-source-link">jboss-jbpm-admin.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)jbossws&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">JBoss jBPM Administration Console login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">jboss</span><span class="nt-tag">login</span><span class="nt-tag">panel</span><span class="nt-tag">redhat</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/PortSwigger/j2ee-scan/blob/master/src/main/java/burp/j2ee/issues/impl/JBossjBPMAdminConsole.java" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="jehc-bpm - remote code execute critical identify critical remote vulnerabilities a remote command execution vulnerability in the component /server/executeexec of jehc-bpm &lt;= v2.0.1 allows attackers to execute arbitrary code. the vulnerability exists due to insufficient authorization checks in the executeexec endpoint which allows direct command execution. cve-2025-45854 ritikchaddha cve cve2025 jehc-bpm rce vuln cwe-434,cwe-862" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">JEHC-BPM - Remote Code Execute</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-45854.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-45854.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 17, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/434,CWE-862.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-434,CWE-862</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-45854" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-45854</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)JEHC&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A Remote Command Execution vulnerability in the component /server/executeExec of JEHC-BPM &lt;= v2.0.1 allows attackers to execute arbitrary code. The vulnerability exists due to insufficient authorization checks in the executeExec endpoint which allows direct command execution.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can execute arbitrary operating system commands through the /server/executeExec endpoint due to missing authorization checks, achieving complete server compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade JEHC-BPM to a version later than 2.0.1 that implements proper authorization checks on the executeExec endpoint.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">jehc-bpm</span><span class="nt-tag">rce</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://gist.github.com/Cafe-Tea/bc14b38f4bfd951de2979a24c3358460" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-45854" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="jfinalcms v5.0.0 - directory traversal medium identify critical remote vulnerabilities an issue in the component /common/downcontroller.java of jfinalcms v5.0.0 allows attackers to execute a directory traversal. cve-2023-41599 pussycat0x cve cve2023 jrecms vkev vuln cwe-22" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">JFinalCMS v5.0.0 - Directory Traversal</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-41599.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-41599.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 25, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-41599" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-41599</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches `(?i)content=&#34;JreCms`</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An issue in the component /common/DownController.java of JFinalCMS v5.0.0 allows attackers to execute a directory traversal.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can read arbitrary files from the server through path traversal in the filekey parameter, potentially exposing database credentials, application configuration, and sensitive CMS content.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update JFinalCMS to a version newer than 5.0.0 that validates and sanitizes file paths in DownController.java to prevent directory traversal attacks.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">jrecms</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/wy876/POC/blob/main/JFinalCMS%20%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E(CVE-2023-41599).md" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/wy876/POC" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/xingchennb/POC-" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/Marco-zcl/POC" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/d4n-sec/d4n-sec.github.io" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="jfrog artifactory artifacts exposure low identify critical remote vulnerabilities jfrog artifactory artifact repository was exposed. dhiyaneshdk artifactory misconfig vuln" data-nt-sev="low">
  <div class="nt-card-header">
    <div class="nt-title">JFrog Artifactory Artifacts Exposure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/misconfiguration/jfrog-artifactory-exposure.yaml" target="_blank" rel="noopener" class="nt-source-link">jfrog-artifactory-exposure.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 10, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Jfrog&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">JFrog Artifactory Artifact repository was exposed.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">artifactory</span><span class="nt-tag">misconfig</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://jfrog.com/help/r/jfrog-rest-apis/artifactory-rest-apis" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="jfrog artifactory build - exposure medium identify critical remote vulnerabilities detected exposure of build information in jfrog artifactory via unauthenticated api endpoints. access to these endpoints may disclose sensitive data such as build names, numbers, ci/cd pipeline details, artifact paths, and internal infrastructure information. theamanrawat jfrog artifactory exposure misconfig cicd" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">JFrog Artifactory Build - Exposure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposures/configs/jfrog-artifactory-build-exposure.yaml" target="_blank" rel="noopener" class="nt-source-link">jfrog-artifactory-build-exposure.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> theamanrawat</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 29, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;product&#34;] contains &#34;JFrog:Artifactory&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detected exposure of build information in JFrog Artifactory via unauthenticated API endpoints. Access to these endpoints may disclose sensitive data such as build names, numbers, CI/CD pipeline details, artifact paths, and internal infrastructure information.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">jfrog</span><span class="nt-tag">artifactory</span><span class="nt-tag">exposure</span><span class="nt-tag">misconfig</span><span class="nt-tag">cicd</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://jfrog.com/help/r/jfrog-rest-apis/builds" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://jfrog.com/artifactory/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="jfrog login panel - detect info identify web-based control panels jfrog login panel was detected. dhiyaneshdk detect discovery edb jfrog login panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">JFrog Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/jfrog-login.yaml" target="_blank" rel="noopener" class="nt-source-link">jfrog-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)JFrog&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">JFrog login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">edb</span><span class="nt-tag">jfrog</span><span class="nt-tag">login</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.exploit-db.com/ghdb/6797" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="jhipster platform - default login high identify default logins in web-based control panels detects the presence of jhipster application dashboard or api endpoints that allow authentication using default credentials. jhipster applications by default are often configured with the username &#34;admin&#34; and password &#34;admin&#34;, potentially exposing application management interfaces or sensitive apis if not changed after deployment. ritikchaddha jhipster default-login exposure misconfig" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">JHipster Platform - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/jhipster-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">jhipster-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 15, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)JHipster&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detects the presence of JHipster application dashboard or API endpoints that allow authentication using default credentials. JHipster applications by default are often configured with the username &#34;admin&#34; and password &#34;admin&#34;, potentially exposing application management interfaces or sensitive APIs if not changed after deployment.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">jhipster</span><span class="nt-tag">default-login</span><span class="nt-tag">exposure</span><span class="nt-tag">misconfig</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.jhipster.tech/security/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="js help desk &lt;= 2.8.1 - sql injection critical identify critical remote vulnerabilities the js help desk – best help desk &amp; support plugin plugin for wordpress is vulnerable to sql injection via the ‘email&#39; and &#39;trackingid&#39; parameters in all versions up to 2.8.2 (exclusive) due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing sql query. this makes it possible for unauthenticated attackers to append additional sql queries into already existing queries that can be used to extract sensitive information from the database. cve-2023-50839 shivam kamboj cve cve2023 js-support-ticket sqli unauth wordpress wp wp-plugin cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">JS Help Desk &lt;= 2.8.1 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-50839.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-50839.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Shivam Kamboj</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 20, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-50839" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-50839</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/js-support-ticket/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The JS Help Desk – Best Help Desk &amp; Support Plugin plugin for WordPress is vulnerable to SQL Injection via the ‘email&#39; and &#39;trackingid&#39; parameters in all versions up to 2.8.2 (exclusive) due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can execute arbitrary SQL commands, potentially leading to data theft, data tampering, or database compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest version of JS Help Desk, version 2.8.2 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">js-support-ticket</span><span class="nt-tag">sqli</span><span class="nt-tag">unauth</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-50839" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/js-support-ticket/js-help-desk-281-unauthenticated-sql-injection-via-email-and-trackingid" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="js help desk &lt;= 2.8.2 - sql injection critical identify critical remote vulnerabilities js help desk wordpress plugin 2.8.2 contains a sql injection caused by insufficient escaping and preparation of user-supplied values in &#39;js-support-ticket-token-tkstatus&#39; cookie, letting unauthenticated attackers extract sensitive database information, exploit requires no authentication. cve-2023-7337 shivam kamboj cve cve2023 js-support-ticket sqli wordpress wp wp-plugin cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">JS Help Desk &lt;= 2.8.2 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-7337.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-7337.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Shivam Kamboj</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 6, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-7337" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-7337</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/js-support-ticket/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">JS Help Desk WordPress plugin 2.8.2 contains a SQL injection caused by insufficient escaping and preparation of user-supplied values in &#39;js-support-ticket-token-tkstatus&#39; cookie, letting unauthenticated attackers extract sensitive database information, exploit requires no authentication.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can extract sensitive database information, leading to data disclosure.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest version of JS Help Desk plugin.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">js-support-ticket</span><span class="nt-tag">sqli</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/js-support-ticket/js-help-desk-ai-powered-support-ticketing-system-282-unauthenticated-sql-injection-via-js-support-ticket-token-tkstatus-cookie" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-7337" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="jaeger end-of-life - detect info identify web-based control panels detected jaeger versions that have reached end-of-life (eol) and no longer receive security updates. shivam kamboj tech jaeger eol" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Jaeger End-of-Life - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/technologies/eol/jaeger-eol.yaml" target="_blank" rel="noopener" class="nt-source-link">jaeger-eol.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Shivam Kamboj</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 14, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Jaeger UI&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detected Jaeger versions that have reached End-of-Life (EOL) and no longer receive security updates.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">tech</span><span class="nt-tag">jaeger</span><span class="nt-tag">eol</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://endoflife.date/jaeger" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/jaegertracing/jaeger/issues/6321" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="jalios jcms login panel - detect info identify web-based control panels jalios jcms login panel was detected. righettod discovery jalios jcms panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Jalios JCMS Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/jcms-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">jcms-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)jalios jcms&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Jalios JCMS login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">jalios</span><span class="nt-tag">jcms</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.jalios.com/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="jamf mdm login panel - detect info identify web-based control panels jamf mobile device management login panel was detected. pdteam,idealphase discovery jamf mdm panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Jamf MDM Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/jamf-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">jamf-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pdteam,idealphase</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1262005940&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Jamf Mobile Device Management login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">jamf</span><span class="nt-tag">mdm</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="jamf pro login panel - detect info identify web-based control panels jamf pro login panel was detected. dhiyaneshdk discovery jamf panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Jamf Pro Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/jamf-login.yaml" target="_blank" rel="noopener" class="nt-source-link">jamf-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Jamf Pro&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Jamf Pro login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">jamf</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="jamf pro setup assistant panel - detect info identify web-based control panels jamf pro setup assistant panel was detected. ritikchaddha discovery jamf panel setup cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Jamf Pro Setup Assistant Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/jamf-setup-assistant.yaml" target="_blank" rel="noopener" class="nt-source-link">jamf-setup-assistant.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Jamf Pro Setup&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Jamf Pro Setup Assistant panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">jamf</span><span class="nt-tag">panel</span><span class="nt-tag">setup</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="jan v0.4.12 &#39;readfilesync&#39; - path traversal high identify critical remote vulnerabilities jan v0.4.12 was discovered to contain an arbitrary file read vulnerability via the /v1/app/readfilesync interface. cve-2024-36857 yusuf amr cve cve2024 jan lfi vkev vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Jan v0.4.12 &#39;readFileSync&#39; - Path Traversal</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-36857.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-36857.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Yusuf Amr</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 14, 2025</span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-36857" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-36857</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-165268926&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Jan v0.4.12 was discovered to contain an arbitrary file read vulnerability via the /v1/app/readFileSync interface.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can read arbitrary files from the system via path traversal in the readFileSync interface.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update Jan to a version later than v0.4.12 that patches the path traversal vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">jan</span><span class="nt-tag">lfi</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.wiz.io/vulnerability-database/cve/cve-2024-36857" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/HackAllSec/CVEs/tree/main/Jan%20AFR%20vulnerability" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="janitza gridvis energy management - detect info identify web-based control panels janitza gridvis is an energy monitoring and management software platform by janitza electronics gmbh.
it provides real-time power quality analysis, energy data logging, and grid visualisation for industrial facilities. rxerium detect energy ics janitza panel scada tech" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Janitza GridVis Energy Management - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/janitza-gridvis-detect.yaml" target="_blank" rel="noopener" class="nt-source-link">janitza-gridvis-detect.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 27, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;^GridVis&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Janitza GridVis is an energy monitoring and management software platform by Janitza Electronics GmbH.
It provides real-time power quality analysis, energy data logging, and grid visualisation for industrial facilities.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">detect</span><span class="nt-tag">energy</span><span class="nt-tag">ics</span><span class="nt-tag">janitza</span><span class="nt-tag">panel</span><span class="nt-tag">scada</span><span class="nt-tag">tech</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.janitza.com/gridvis.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="janitza umg power meter - login panel info identify web-based control panels janitza umg series power meters and energy analyzers expose a web interface for energy monitoring and power quality analysis. rxerium discovery energy ics janitza panel power-meter" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Janitza UMG Power Meter - Login Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/janitza-umg-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">janitza-umg-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 27, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Janitza UMG&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Janitza UMG series power meters and energy analyzers expose a web interface for energy monitoring and power quality analysis.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">energy</span><span class="nt-tag">ics</span><span class="nt-tag">janitza</span><span class="nt-tag">panel</span><span class="nt-tag">power-meter</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.janitza.de/energy-analyzers.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="javafaces lfi medium identify critical remote vulnerabilities an unspecified vulnerability in the oracle glassfish server component in oracle fusion middleware 2.1.1, 3.0.1, and 3.1.2; the oracle jdeveloper component in oracle fusion middleware 11.1.2.3.0, 11.1.2.4.0, and 12.1.2.0.0; and the oracle weblogic server component in oracle fusion middleware 10.3.6.0 and 12.1.1 allows remote attackers to affect confidentiality via unknown vectors related to java server faces or web container. cve-2013-3827 random-robbie cve cve2013 edb javafaces lfi oracle vkev vuln nvd-cwe-noinfo" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Javafaces LFI</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2013/CVE-2013-3827.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2013-3827.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Random-Robbie</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/NVD-CWE-NOINFO.html" target="_blank" rel="noopener" class="nt-cwe-link">NVD-CWE-NOINFO</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2013-3827" target="_blank" rel="noopener" class="nt-cve-link">CVE-2013-3827</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)weblogic&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An Unspecified vulnerability in the Oracle GlassFish Server component in Oracle Fusion Middleware 2.1.1, 3.0.1, and 3.1.2; the Oracle JDeveloper component in Oracle Fusion Middleware 11.1.2.3.0, 11.1.2.4.0, and 12.1.2.0.0; and the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6.0 and 12.1.1 allows remote attackers to affect confidentiality via unknown vectors related to Java Server Faces or Web Container.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can exploit local file inclusion through Java Server Faces resource handlers to read sensitive configuration files including WEB-INF/web.xml, exposing Oracle GlassFish, WebLogic, and JDeveloper application configurations.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest patches and updates for the affected software to fix the LFI vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2013</span><span class="nt-tag">edb</span><span class="nt-tag">javafaces</span><span class="nt-tag">lfi</span><span class="nt-tag">oracle</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2013-3827" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.exploit-db.com/exploits/38802" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.oracle.com/security-alerts/cpuoct2013.html" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="http://rhn.redhat.com/errata/RHSA-2014-0029.html" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="jedox web login panel - detect info identify web-based control panels jedox is an enterprise performance management software which is used for planning, analytics and reporting  in finance and other areas such as sales, human resources and procurement. team syslifters / christoph mahrl,aron molnar,patrick pirker,michael wedl detect discovery jedox panel" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Jedox Web Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/jedox-web-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">jedox-web-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Team Syslifters / Christoph MAHRL,Aron MOLNAR,Patrick PIRKER,Michael WEDL</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 11, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)jedox web - login&#34;}) || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)jedox web login&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Jedox is an Enterprise Performance Management software which is used for planning, analytics and reporting  in finance and other areas such as sales, human resources and procurement.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">jedox</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.jedox.com" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="jeeplus cms - sql injection high identify critical remote vulnerabilities a sql injection vulnerability exists in the jeeplus low-code development platform, allowing attackers to manipulate database queries.this can lead to unauthorized data access, modification, or potential compromise of the application. wingby_fkalis jeecg jeeplus sqli vuln cwe-89" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">JeePlus CMS - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/vulnerabilities/other/jeeplus-cms-resetpassword-sqli.yaml" target="_blank" rel="noopener" class="nt-source-link">jeeplus-cms-resetpassword-sqli.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> WingBy_fkalis</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 2, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)jeeplus\\.js&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A SQL injection vulnerability exists in the JeePlus low-code development platform, allowing attackers to manipulate database queries.This can lead to unauthorized data access, modification, or potential compromise of the application.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">jeecg</span><span class="nt-tag">jeeplus</span><span class="nt-tag">sqli</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/wy876/wiki/blob/main/JeePlus%E4%BD%8E%E4%BB%A3%E7%A0%81%E5%BC%80%E5%8F%91%E5%B9%B3%E5%8F%B0/JeePlus%E4%BD%8E%E4%BB%A3%E7%A0%81%E5%BC%80%E5%8F%91%E5%B9%B3%E5%8F%B0%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="http://www.cstam.oyg.cn/detail/429410" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="jeecg boot &lt;= 2.4.5 - information disclosure high identify critical remote vulnerabilities an insecure permissions issue in jeecg-boot 2.4.5 allows unauthenticated remote attackers to gain escalated privilege and view sensitive information via the httptrace interface. cve-2021-37304 ritikchaddha cve cve2021 exposure jeecg vuln cwe-732" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Jeecg Boot &lt;= 2.4.5 - Information Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2021/CVE-2021-37304.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2021-37304.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 18, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/732.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-732</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2021-37304" target="_blank" rel="noopener" class="nt-cve-link">CVE-2021-37304</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)jeecg-boot&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An Insecure Permissions issue in jeecg-boot 2.4.5 allows unauthenticated remote attackers to gain escalated privilege and view sensitive information via the httptrace interface.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can exploit this vulnerability to gain sensitive information from the application.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade Jeecg Boot to a version higher than 2.4.5 to mitigate the vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2021</span><span class="nt-tag">exposure</span><span class="nt-tag">jeecg</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/jeecgboot/jeecg-boot/issues/2793" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2021-37304" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="jeecg boot &lt;= 2.4.5 - sensitive information disclosure high identify critical remote vulnerabilities jeecg boot &lt;= 2.4.5 api interface has unauthorized access and leaks sensitive information such as email,phone and enumerate usernames that exist in the system. cve-2021-37305 ritikchaddha cve cve2021 exposure jeecg vkev vuln cwe-732" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Jeecg Boot &lt;= 2.4.5 - Sensitive Information Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2021/CVE-2021-37305.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2021-37305.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 18, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/732.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-732</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2021-37305" target="_blank" rel="noopener" class="nt-cve-link">CVE-2021-37305</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)jeecg-boot&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Jeecg Boot &lt;= 2.4.5 API interface has unauthorized access and leaks sensitive information such as email,phone and Enumerate usernames that exist in the system.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can exploit this vulnerability to gain access to sensitive information, potentially leading to unauthorized access or data leakage.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade Jeecg Boot to version 2.4.6 or later to fix the vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2021</span><span class="nt-tag">exposure</span><span class="nt-tag">jeecg</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/jeecgboot/jeecg-boot/issues/2794" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2021-37305" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="jeecg p3 biz chat - local file inclusion high identify critical remote vulnerabilities jeecg p3 biz chat 1.0.5 allows remote attackers to read arbitrary files through specific parameters. cve-2023-33510 dhiyaneshdk cve cve2023 jeecg jeecg_p3_biz_chat_project lfi vkev vuln wordpress cwe-668" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Jeecg P3 Biz Chat - Local File Inclusion</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-33510.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-33510.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 19, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/668.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-668</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-33510" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-33510</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1380908726&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Jeecg P3 Biz Chat 1.0.5 allows remote attackers to read arbitrary files through specific parameters.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability can lead to unauthorized access to sensitive files, remote code execution, and potential compromise of the entire system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest patch or update provided by the vendor to fix the LFI vulnerability in Jeecg P3 Biz Chat.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">jeecg</span><span class="nt-tag">jeecg_p3_biz_chat_project</span><span class="nt-tag">lfi</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://twitter.com/momika233/status/1670701256535572481" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://carl1l.github.io/2023/05/08/jeecg-p3-biz-chat-1-0-5-jar-has-arbitrary-file-read-vulnerability/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-33510" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/izj007/wechat" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="jeecg-boot v3.5.1 - sql injection critical identify critical remote vulnerabilities sql injection vulnerability via the title parameter at /sys/dict/loadtreedata in jeecg-boot v3.5.1. cve-2023-38992 ritikchaddha cve cve2023 jeecg jeecg-boot sqli vuln cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Jeecg-Boot v3.5.1 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-38992.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-38992.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 11, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-38992" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-38992</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1380908726&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">SQL injection vulnerability via the title parameter at /sys/dict/loadTreeData in jeecg-boot v3.5.1.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation could lead to unauthorized access to sensitive data.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Implement input validation and use parameterized queries to prevent SQL Injection attacks.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">jeecg</span><span class="nt-tag">jeecg-boot</span><span class="nt-tag">sqli</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/jeecgboot/jeecg-boot/issues/5173" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://my.oschina.net/jeecg/blog/10107636" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-38992" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="jeecg-boot 3.5.0 qurestsql - sql injection critical identify critical remote vulnerabilities a vulnerability classified as critical has been found in jeecg-boot 3.5.0. this affects an unknown part of the file jmreport/qurestsql. the manipulation of the argument apiselectid leads to sql injection. it is possible to initiate the attack remotely. cve-2023-1454 dhiyaneshdk cve cve2023 jeecg sqli vkev vuln cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Jeecg-boot 3.5.0 qurestSql - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-1454.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-1454.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 20, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-1454" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-1454</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1380908726&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A vulnerability classified as critical has been found in jeecg-boot 3.5.0. This affects an unknown part of the file jmreport/qurestSql. The manipulation of the argument apiSelectId leads to sql injection. It is possible to initiate the attack remotely.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized access, data leakage, or data manipulation.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade Jeecg-boot to a patched version or apply the necessary security patches provided by the vendor.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">jeecg</span><span class="nt-tag">sqli</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/Sweelg/CVE-2023-1454-Jeecg-Boot-qurestSql-SQLvuln/tree/master" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-1454" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://vuldb.com/?ctiid.223299" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://vuldb.com/?id.223299" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/Awrrays/FrameVul" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="jeecgboot 3.5.0 - sql injection critical identify critical remote vulnerabilities jeecg-boot 3.5.0 and 3.5.1 have a sql injection vulnerability the id parameter of the /jeecg-boot/jmreport/show interface. cve-2023-34659 ritikchaddha cve cve2023 jeecg sqli vkev vuln cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">JeecgBoot 3.5.0 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-34659.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-34659.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 22, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-34659" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-34659</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1380908726&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">jeecg-boot 3.5.0 and 3.5.1 have a SQL injection vulnerability the id parameter of the /jeecg-boot/jmreport/show interface.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized access, data leakage, or data manipulation.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade JeecgBoot to a patched version or apply the necessary security patches provided by the vendor.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">jeecg</span><span class="nt-tag">sqli</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/jeecgboot/jeecg-boot/issues/4976" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-34659" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/izj007/wechat" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="jeecgboot v3.7.1 - sql injection critical identify critical remote vulnerabilities the jeecgboot application is vulnerable to sql injection via the `gettotaldata` endpoint. an attacker can exploit this vulnerability to extract sensitive information from the database by injecting sql commands. cve-2024-48307 lbb,s4e-io cve cve2024 jeecg sqli vkev vuln cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">JeecgBoot v3.7.1 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-48307.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-48307.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> lbb,s4e-io</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 9, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-48307" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-48307</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1380908726&#34; || service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-250963920&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The JeecgBoot application is vulnerable to SQL Injection via the `getTotalData` endpoint. An attacker can exploit this vulnerability to extract sensitive information from the database by injecting SQL commands.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can execute arbitrary SQL commands to extract sensitive information from the JeecgBoot database.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update JeecgBoot to a version that patches CVE-2024-48307.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">jeecg</span><span class="nt-tag">sqli</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/wy876/POC/blob/main/JeecgBoot/JeecgBoot%E6%8E%A5%E5%8F%A3getTotalData%E5%AD%98%E5%9C%A8%E6%9C%AA%E6%8E%88%E6%9D%83SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E(CVE-2024-48307).md" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/jeecgboot/JeecgBoot/issues/7237" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="jeedom - default login high identify default logins in web-based control panels jeedom default login has been detected. ritikchaddha default-login jeedom misconfig vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Jeedom - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/jeedom/jeedom-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">jeedom-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 28, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;Jeedom&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Jeedom default login has been detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">jeedom</span><span class="nt-tag">misconfig</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="jeedom login panel - detect info identify web-based control panels jeedom login panel was detected. pikpikcu,daffainfo discovery jeedom login panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Jeedom Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/jeedom-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">jeedom-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pikpikcu,daffainfo</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)jeedom&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Jeedom login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">jeedom</span><span class="nt-tag">login</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="jellyfin &lt;10.7.0 - local file inclusion medium identify critical remote vulnerabilities jellyfin before 10.7.0 is vulnerable to local file inclusion. this issue is more prevalent when windows is used as the host os. servers exposed to public internet are potentially at risk. cve-2021-21402 dwisiswant0 cve cve2021 jellyfin lfi vkev vuln cwe-22" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Jellyfin &lt;10.7.0 - Local File Inclusion</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2021/CVE-2021-21402.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2021-21402.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dwisiswant0</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2021-21402" target="_blank" rel="noopener" class="nt-cve-link">CVE-2021-21402</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Jellyfin&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Jellyfin before 10.7.0 is vulnerable to local file inclusion. This issue is more prevalent when Windows is used as the host OS. Servers exposed to public Internet are potentially at risk.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation could allow an attacker to read sensitive files on the server.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">This is fixed in version 10.7.1.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2021</span><span class="nt-tag">jellyfin</span><span class="nt-tag">lfi</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://securitylab.github.com/advisories/GHSL-2021-050-jellyfin/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/jellyfin/jellyfin/security/advisories/GHSA-wg4c-c9g9-rxhx" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/jellyfin/jellyfin/releases/tag/v10.7.1" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/jellyfin/jellyfin/commit/0183ef8e89195f420c48d2600bc0b72f6d3a7fd7" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2021-21402" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="jellyfin console - default login high identify default logins in web-based control panels weak jellyfin credentials were discovered. thefoggiest default-login jellyfin misconfig vuln cwe-522" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Jellyfin Console - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/jellyfin/jellyfin-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">jellyfin-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> thefoggiest</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 31, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/522.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-522</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Jellyfin&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Weak Jellyfin credentials were discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">jellyfin</span><span class="nt-tag">misconfig</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="jellyseerr login panel - detect info identify web-based control panels  ritikchaddha panel jellyseerr detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Jellyseerr Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/jellyseerr-login-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">jellyseerr-login-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 9, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-2017604252&#34;</code></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">jellyseerr</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/Fallenbagel/jellyseerr" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="jenkins - remote command injection critical identify critical remote vulnerabilities jenkins 2.153 and earlier and lts 2.138.3 and earlier are susceptible to a remote command injection via stapler/core/src/main/java/org/kohsuke/stapler/metaclass.java that allows attackers to invoke some methods on java objects by accessing crafted urls that were not intended to be invoked this way. cve-2018-1000861 dhiyaneshdk,pikpikcu cve cve2018 jenkins kev packetstorm rce vkev vulhub vuln cwe-502" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Jenkins - Remote Command Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2018/CVE-2018-1000861.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2018-1000861.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDK,pikpikcu</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/502.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-502</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2018-1000861" target="_blank" rel="noopener" class="nt-cve-link">CVE-2018-1000861</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;81586312&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Jenkins 2.153 and earlier and LTS 2.138.3 and earlier are susceptible to a remote command injection via stapler/core/src/main/java/org/kohsuke/stapler/MetaClass.java that allows attackers to invoke some methods on Java objects by accessing crafted URLs that were not intended to be invoked this way.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability can lead to unauthorized access, data leakage, and potential compromise of the entire Jenkins server.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches and updates provided by Jenkins to mitigate this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2018</span><span class="nt-tag">jenkins</span><span class="nt-tag">kev</span><span class="nt-tag">packetstorm</span><span class="nt-tag">rce</span><span class="nt-tag">vkev</span><span class="nt-tag">vulhub</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/vulhub/vulhub/tree/master/jenkins/CVE-2018-1000861" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1000861" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://jenkins.io/security/advisory/2018-12-05/#SECURITY-595" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="http://packetstormsecurity.com/files/166778/Jenkins-Remote-Code-Execution.html" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://access.redhat.com/errata/RHBA-2019:0024" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="jenkins api panel - detect info identify web-based control panels jenkins api panel was detected. righettod api discovery jenkins panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Jenkins API Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/jenkins-api-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">jenkins-api-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;81586312&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Jenkins API panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">api</span><span class="nt-tag">discovery</span><span class="nt-tag">jenkins</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="jenkins command line interface (cli) path traversal vulnerability critical identify critical remote vulnerabilities jenkins 2.441 and earlier, lts 2.426.2 and earlier does not disable a feature of its cli command parser that replaces
an &#39;@&#39; character followed by a file path in an argument with the file&#39;s contents, allowing unauthenticated attackers
to read arbitrary files on the jenkins controller file system. cve-2024-23897 n3integration cve cve2024 kev vuln cwe-27" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Jenkins Command Line Interface (CLI) Path Traversal Vulnerability</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-23897.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-23897.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> n3integration</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 19, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/27.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-27</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-23897" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-23897</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;product&#34;] contains &#34;Jenkins&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces
an &#39;@&#39; character followed by a file path in an argument with the file&#39;s contents, allowing unauthenticated attackers
to read arbitrary files on the Jenkins controller file system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade affected versions of Jenkins to the latest patched version. If unable to upgrade the affected system,
disabling CLI access can be implemented as a workaround.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">kev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.openwall.com/lists/oss-security/2024/01/24/6" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-23897" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.cve.org/CVERecord?id=CVE-2024-23897" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://www.jenkins.io/security/advisory/2024-01-24/#SECURITY-3314" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://docs.cloudbees.com/docs/cloudbees-ci-kb/latest/client-and-managed-controllers/disable-jenkins-cli#_resolution" target="_blank" rel="noopener" class="nt-ref-link">[5]</a> <a href="https://www.sonarsource.com/blog/excessive-expansion-uncovering-critical-security-vulnerabilities-in-jenkins/" target="_blank" rel="noopener" class="nt-ref-link">[6]</a> <a href="https://www.vicarius.io/vsociety/posts/the-anatomy-of-a-jenkins-vulnerability-cve-2024-23897-revealed-1" target="_blank" rel="noopener" class="nt-ref-link">[7]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="jenkins default login high identify default logins in web-based control panels jenkins credentials of admin:admin were discovered. zandros0 jenkins default-login vuln cwe-522" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Jenkins Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/jenkins/jenkins-default.yaml" target="_blank" rel="noopener" class="nt-source-link">jenkins-default.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Zandros0</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/522.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-522</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;Jenkins&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Jenkins credentials of admin:admin were discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">jenkins</span><span class="nt-tag">default-login</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="jenkins gitlab hook &lt;=1.4.2 - cross-site scripting medium identify critical remote vulnerabilities jenkins gitlab hook 1.4.2 and earlier does not escape project names in the build_now endpoint, resulting in a reflected cross-site scripting vulnerability. cve-2020-2096 madrobot cve cve2020 gitlab jenkins packetstorm plugin vkev vuln xss cwe-79" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Jenkins Gitlab Hook &lt;=1.4.2 - Cross-Site Scripting</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2020/CVE-2020-2096.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2020-2096.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> madrobot</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-79</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2020-2096" target="_blank" rel="noopener" class="nt-cve-link">CVE-2020-2096</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)GitLab&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Jenkins Gitlab Hook 1.4.2 and earlier does not escape project names in the build_now endpoint, resulting in a reflected cross-site scripting vulnerability.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute arbitrary JavaScript code in the context of the victim&#39;s browser, leading to potential data theft or unauthorized actions.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to the latest version of Jenkins Gitlab Hook plugin (&gt;=1.4.3) to mitigate this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2020</span><span class="nt-tag">gitlab</span><span class="nt-tag">jenkins</span><span class="nt-tag">packetstorm</span><span class="nt-tag">plugin</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">xss</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://jenkins.io/security/advisory/2020-01-15/#SECURITY-1683" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="http://www.openwall.com/lists/oss-security/2020/01/15/1" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="http://packetstormsecurity.com/files/155967/Jenkins-Gitlab-Hook-1.4.2-Cross-Site-Scripting.html" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2020-2096" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/Elsfa7-110/kenzer-templates" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="jenkins login detected info identify web-based control panels jenkins is an open source automation server. pdteam discovery jenkins panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Jenkins Login Detected</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/jenkins-login.yaml" target="_blank" rel="noopener" class="nt-source-link">jenkins-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pdteam</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;81586312&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Jenkins is an open source automation server.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Ensure proper access.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">jenkins</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.jenkins.io/doc/book/security/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="jenkins users - exposure info identify critical remote vulnerabilities detected an exposed jenkins asynchpeople endpoint that discloses user information (e.g., users, full names, and profile urls) allowing user enumeration. theamanrawat exposure jenkins vuln discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Jenkins Users - Exposure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/misconfiguration/jenkins/jenkins-users-exposure.yaml" target="_blank" rel="noopener" class="nt-source-link">jenkins-users-exposure.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> theamanrawat</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 4, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;81586312&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detected an exposed Jenkins asynchPeople endpoint that discloses user information (e.g., users, full names, and profile URLs) allowing user enumeration.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">exposure</span><span class="nt-tag">jenkins</span><span class="nt-tag">vuln</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://issues.jenkins.io/browse/JENKINS-18884" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="jetbrains teamcity &gt; 2023.11.3 - authentication bypass critical identify critical remote vulnerabilities in jetbrains teamcity before 2023.11.3 authentication bypass leading to rce was possible cve-2024-23917 iamnoooob,rootxharsh,pdresearch auth-bypass cve cve2024 jetbrains teamcity vkev vuln cwe-288,cwe-306" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">JetBrains TeamCity &gt; 2023.11.3 - Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-23917.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-23917.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> iamnoooob,rootxharsh,pdresearch</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 30, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/288,CWE-306.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-288,CWE-306</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-23917" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-23917</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)teamcity&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">In JetBrains TeamCity before 2023.11.3 authentication bypass leading to RCE was possible</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can bypass authentication to gain administrative access and potentially execute code on the TeamCity server.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update JetBrains TeamCity to version 2023.11.3 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">jetbrains</span><span class="nt-tag">teamcity</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/fkie-cad/nvd-json-data-feeds" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.rapid7.com/db/vulnerabilities/jetbrains-teamcity-cve-2024-23917/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="jinhe oa - sql injection high identify critical remote vulnerabilities sql injection vulnerability in the ljc6/servlet/clobfield interface of jinhe oa jc6. an attacker can obtain sensitive information. ky9oss jc6 jinher sqli vuln cwe-89" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Jinhe OA - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/vulnerabilities/jinhe/jinhe-jc6-sqli.yaml" target="_blank" rel="noopener" class="nt-source-link">jinhe-jc6-sqli.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Ky9oss</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 20, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)金和协同管理平台&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">SQL injection vulnerability in the ljc6/servlet/clobfield interface of Jinhe OA jc6. An attacker can obtain sensitive information.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">jc6</span><span class="nt-tag">jinher</span><span class="nt-tag">sqli</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/wy876/POC/blob/main/%E9%87%91%E5%92%8COA%20jc6%20clobfield%20SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://blog.csdn.net/qq_41904294/article/details/135074649" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="jinher oa - sql injection high identify critical remote vulnerabilities jinher jinher_oa is an office automation software that facilitates workflow management and collaboration within organizations. it sits in the enterprise layer of the tech stack, is typically deployed as self_hosted, and—within the information_technology industry—serves the business_apps domain. cve-2025-10090 dhiyaneshdk cve cve2025 jc6 jinher sqli time-based vkev cwe-74,cwe-89" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Jinher OA - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-10090.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-10090.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 10, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/74,CWE-89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-74,CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-10090" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-10090</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/jc6/platform/sys/login&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">jinher jinher_oa is an office automation software that facilitates workflow management and collaboration within organizations. It sits in the enterprise layer of the tech stack, is typically deployed as self_hosted, and—within the information_technology industry—serves the business_apps domain.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Remote attackers can execute arbitrary SQL commands, potentially leading to data theft or database compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest version.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">jc6</span><span class="nt-tag">jinher</span><span class="nt-tag">sqli</span><span class="nt-tag">time-based</span><span class="nt-tag">vkev</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/Madgeaaaaa/MY_VULN_2/blob/main/D-Link/vuln-2/DIR-803%20Authentication%20Bypass.md" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://vuldb.com/?id.335869" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-14528" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="joget panel - detect info identify web-based control panels joget panel was detected. podalirius discovery joget panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Joget Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/joget/joget-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">joget-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Podalirius</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-1343712810&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Joget panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">joget</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="joomsport &lt;= 5.7.7 - sql injection critical identify critical remote vulnerabilities the joomsport wordpress plugin through 5.7.7 is vulnerable to unauthenticated time-based blind sql injection via the &#39;sortf&#39; get parameter in the player list view. the parameter value is backtick-wrapped and directly concatenated into an order by clause. cve-2026-42647 theamanrawat cve cve2026 joomsport sqli vkev wordpress wp wp-plugin cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">JoomSport &lt;= 5.7.7 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2026/CVE-2026-42647.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2026-42647.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> theamanrawat</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 2, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2026-42647" target="_blank" rel="noopener" class="nt-cve-link">CVE-2026-42647</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-1546880397&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The JoomSport WordPress plugin through 5.7.7 is vulnerable to unauthenticated time-based blind SQL injection via the &#39;sortf&#39; GET parameter in the player list view. The parameter value is backtick-wrapped and directly concatenated into an ORDER BY clause.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can extract any data from the WordPress database including admin credentials, user emails, and plugin-stored secrets via time-based blind SQL injection.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to JoomSport version 5.7.8 or later, which implements column whitelist validation.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2026</span><span class="nt-tag">joomsport</span><span class="nt-tag">sqli</span><span class="nt-tag">vkev</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://patchstack.com/database/wordpress/plugin/joomsport-sports-league-results-management/vulnerability/wordpress-joomsport-plugin-5-7-7-sql-injection-vulnerability" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://plugins.trac.wordpress.org/browser/joomsport-sports-league-results-management/tags/5.7.5/sportleague/base/wordpress/classes/class-jsport-getplayers.php#L153" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://plugins.trac.wordpress.org/browser/joomsport-sports-league-results-management/tags/5.7.5/sportleague/classes/objects/class-jsport-playerlist.php#L80" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42647" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="joomla http header unauthenticated - remote code execution high identify critical remote vulnerabilities joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct php object injection attacks and execute arbitrary php code via the http user-agent header, as exploited in the wild in december 2015 cve-2015-8562 kairos-hk,bolkv,n0ming,roughboy0723 cve cve2015 joomla rce unauth vkev vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Joomla HTTP Header Unauthenticated - Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2015/CVE-2015-8562.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2015-8562.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> kairos-hk,bolkv,n0ming,RoughBoy0723</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 8, 2024</span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2015-8562" target="_blank" rel="noopener" class="nt-cve-link">CVE-2015-8562</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)joomla! - open source content management&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via the HTTP User-Agent header, as exploited in the wild in December 2015</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can execute arbitrary PHP code on the server through PHP object injection, leading to complete server compromise and potential data breach.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to Joomla 3.4.6 or later immediately.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2015</span><span class="nt-tag">joomla</span><span class="nt-tag">rce</span><span class="nt-tag">unauth</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/vulhub/vulhub/tree/master/joomla/CVE-2015-8562" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2015-8562" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="joomla! &lt;3.7.1 - sql injection critical identify critical remote vulnerabilities joomla! before 3.7.1 contains a sql injection vulnerability. an attacker can possibly obtain sensitive information from a database, modify data, and execute unauthorized administrative operations in the context of the affected site. cve-2017-8917 princechaddha cve cve2017 joomla sqli vuln cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Joomla! &lt;3.7.1 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2017/CVE-2017-8917.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2017-8917.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> princechaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2017-8917" target="_blank" rel="noopener" class="nt-cve-link">CVE-2017-8917</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)joomla! - open source content management&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Joomla! before 3.7.1 contains a SQL injection vulnerability. An attacker can possibly obtain sensitive information from a database, modify data, and execute unauthorized administrative operations in the context of the affected site.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability can lead to unauthorized access, data theft, and potential compromise of the entire Joomla! website.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade Joomla! to version 3.7.1 or later to mitigate the SQL Injection vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2017</span><span class="nt-tag">joomla</span><span class="nt-tag">sqli</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://developer.joomla.org/security-centre/692-20170501-core-sql-injection.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2017-8917" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://web.archive.org/web/20211207050608/http://www.securitytracker.com/id/1038522" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="http://www.securitytracker.com/id/1038522" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/binfed/cms-exp" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="joomla! core sql injection high identify critical remote vulnerabilities a sql injection vulnerability in joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary sql commands. cve-2015-7297 princechaddha cve cve2015 joomla packetstorm sqli vuln cwe-89" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Joomla! Core SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2015/CVE-2015-7297.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2015-7297.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> princechaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2015-7297" target="_blank" rel="noopener" class="nt-cve-link">CVE-2015-7297</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)joomla! - open source content management&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability can lead to unauthorized access, data leakage, and potential compromise of the Joomla! CMS.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches and updates provided by Joomla! to mitigate the SQL Injection vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2015</span><span class="nt-tag">joomla</span><span class="nt-tag">packetstorm</span><span class="nt-tag">sqli</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2015-7297" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="http://developer.joomla.org/security-centre/628-20151001-core-sql-injection.html" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.trustwave.com/Resources/SpiderLabs-Blog/Joomla-SQL-Injection-Vulnerability-Exploit-Results-in-Full-Administrative-Access/" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="http://packetstormsecurity.com/files/134097/Joomla-3.44-SQL-Injection.html" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="http://packetstormsecurity.com/files/134494/Joomla-Content-History-SQL-Injection-Remote-Code-Execution.html" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="joomla! panel info identify web-based control panels  its0x08 panel joomla discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Joomla! Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/joomla-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">joomla-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> its0x08</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)joomla! - open source content management&#34;</code></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">joomla</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="joomla! webservice - password disclosure medium identify critical remote vulnerabilities an issue was discovered in joomla! 4.0.0 through 4.2.7. an improper access check allows unauthorized access to webservice endpoints. cve-2023-23752 badboycxcc,sascha brendel cve cve2023 joomla kev vkev vuln" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Joomla! Webservice - Password Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-23752.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-23752.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> badboycxcc,Sascha Brendel</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-23752" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-23752</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)joomla! - open source content management&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An issue was discovered in Joomla! 4.0.0 through 4.2.7. An improper access check allows unauthorized access to webservice endpoints.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">The vulnerability can lead to unauthorized access to user passwords, compromising the confidentiality of user accounts.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to Joomla! version 4.2.8 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">joomla</span><span class="nt-tag">kev</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://unsafe.sh/go-149780.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://twitter.com/gov_hack/status/1626471960141238272/photo/1" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://developer.joomla.org/security-centre/894-20230201-core-improper-access-check-in-webservice-endpoints.html" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-23552" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/20142995/pocsuite3" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="joomlaux jux real estate 3.4.0 - reflected xss medium identify critical remote vulnerabilities a vulnerability was found in joomlaux jux real estate 3.4.0 on joomla. it has been classified as problematic. affected is an unknown function of the file /extensions/realestate/index.php/properties/list/list-with-sidebar/realties. the manipulation of the argument itemid/jp_yearbuilt leads to cross site scripting. it is possible to launch the attack remotely. the exploit has been disclosed to the public and may be used. the vendor was contacted early about this disclosure but did not respond in any way. cve-2025-2127 3th1c_yuk1 cve cve2025 joomla joomlaux vuln cwe-79" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">JoomlaUX JUX Real Estate 3.4.0 - Reflected XSS</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-2127.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-2127.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 3th1c_yuk1</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 12, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-79</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-2127" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-2127</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)joomlaux&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A vulnerability was found in JoomlaUX JUX Real Estate 3.4.0 on Joomla. It has been classified as problematic. Affected is an unknown function of the file /extensions/realestate/index.php/properties/list/list-with-sidebar/realties. The manipulation of the argument Itemid/jp_yearbuilt leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can inject malicious JavaScript through the Itemid and jp_yearbuilt parameters, potentially stealing user session cookies, redirecting users to malicious sites, or performing unauthorized actions in the context of authenticated users.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to the latest patched version of JUX Real Estate that properly sanitizes user input.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">joomla</span><span class="nt-tag">joomlaux</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-2127" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://vuldb.com/?id.299040" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://vuldb.com/?ctiid.299040" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="joplin server login - panel info identify web-based control panels joplin server login panel detected. pussycat0x discovery joplin login panel" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Joplin Server Login - Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/joplin-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">joplin-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 15, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Joplin Server&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Joplin Server login panel detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">joplin</span><span class="nt-tag">login</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="jorani 1.0.0 - remote code execution critical identify critical remote vulnerabilities jorani 1.0.0, an attacker could leverage path traversal to access files and execute code on the server. cve-2023-26469 pussycat0x cve cve2023 jorani packetstorm rce vkev vuln cwe-22" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Jorani 1.0.0 - Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-26469.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-26469.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 30, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-26469" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-26469</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-2032163853&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Jorani 1.0.0, an attacker could leverage path traversal to access files and execute code on the server.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the target system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade Jorani to a patched version or apply the necessary security patches.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">jorani</span><span class="nt-tag">packetstorm</span><span class="nt-tag">rce</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-26469" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/Orange-Cyberdefense/CVE-repository/blob/master/PoCs/CVE_Jorani.py" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/advisories/GHSA-7r9h-9r47-7vjj" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="http://packetstormsecurity.com/files/174248/Jorani-Remote-Code-Execution.html" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://jorani.org/security-features-in-lms.html" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="jorani login panel - detect info identify web-based control panels jorani login panel was detected. dhiyaneshdk discovery jorani login panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Jorani Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/jorani-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">jorani-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 28, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Login - Jorani&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Jorani login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">jorani</span><span class="nt-tag">login</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="journyx - xml external entities injection (xxe) high identify critical remote vulnerabilities the &#34;soap_cgi.pyc&#34; api handler allows the xml body of soap requests to contain references to external entities. this allows an unauthenticated attacker to read local files, perform server-side request forgery, and overwhelm the web server resources. cve-2024-6893 s4e-io cve cve2024 journyx vkev vuln xxe cwe-611" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Journyx - XML External Entities Injection (XXE)</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-6893.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-6893.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> s4e-io</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 9, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/611.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-611</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-6893" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-6893</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-109972155&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The &#34;soap_cgi.pyc&#34; API handler allows the XML body of SOAP requests to contain references to external entities. This allows an unauthenticated attacker to read local files, perform server-side request forgery, and overwhelm the web server resources.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can exploit XXE to read local files, perform SSRF attacks, and cause denial of service by overwhelming server resources.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update Journyx to version 11.5.5 or later to address the XXE vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">journyx</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">xxe</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://securityforeveryone.com/tools/journyx-xxe-cve-2024-6893" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://korelogic.com/Resources/Advisories/KL-001-2024-010.txt" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://packetstormsecurity.com/files/180005/Journyx-11.5.4-XML-Injection.html" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-6893" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="journyx 11.5.4 - reflected cross site scripting medium identify critical remote vulnerabilities attackers can craft a malicious link that once clicked will execute arbitrary javascript in the context of the journyx web application. cve-2024-6892 dhiyaneshdk cve cve2024 journyx seclists vuln xss cwe-79,cwe-81" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Journyx 11.5.4 - Reflected Cross Site Scripting</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-6892.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-6892.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 11, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/79,CWE-81.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-79,CWE-81</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-6892" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-6892</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Journyx&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Attackers can craft a malicious link that once clicked will execute arbitrary JavaScript in the context of the Journyx web application.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can craft malicious URLs with XSS payloads in the error_description parameter to execute arbitrary JavaScript when victims click the link.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update Journyx to version 11.5.5 or later to address the reflected XSS vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">journyx</span><span class="nt-tag">seclists</span><span class="nt-tag">vuln</span><span class="nt-tag">xss</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://korelogic.com/Resources/Advisories/KL-001-2024-009.txt" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="http://seclists.org/fulldisclosure/2024/Aug/7" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/fkie-cad/nvd-json-data-feeds" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="jsherp boot panel - detect info identify web-based control panels  dhiyaneshdk panel jsherp login detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">JshERP Boot Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/jsherp-boot-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">jsherp-boot-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 26, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-1298131932&#34;</code></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">jsherp</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="jumpserver &gt; 3.6.4 - information disclosure medium identify critical remote vulnerabilities jumpserver is an open source bastion host and a professional operation and maintenance security audit system. starting in version 3.0.0 and prior to versions 3.5.5 and 3.6.4, session replays can download without authentication. session replays stored in s3, oss, or other cloud storage are not affected. the api `/api/v1/terminal/sessions/` permission control is broken and can be accessed anonymously. sessionviewset permission classes set to `[rbacpermission | issessionassignee]`, relation is or, so any permission matched will be allowed. versions 3.5.5 and 3.6.4 have a fix. after upgrading, visit the api `$host/api/v1/terminal/sessions/?limit=1`. the expected http response code is 401 (`not_authenticated`). cve-2023-42442 xianke cve cve2023 exposure fit2cloud jumpserver vuln cwe-287" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">JumpServer &gt; 3.6.4 - Information Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-42442.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-42442.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> xianke</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 20, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/287.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-287</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-42442" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-42442</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)jumpserver&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">JumpServer is an open source bastion host and a professional operation and maintenance security audit system. Starting in version 3.0.0 and prior to versions 3.5.5 and 3.6.4, session replays can download without authentication. Session replays stored in S3, OSS, or other cloud storage are not affected. The api `/api/v1/terminal/sessions/` permission control is broken and can be accessed anonymously. SessionViewSet permission classes set to `[RBACPermission | IsSessionAssignee]`, relation is or, so any permission matched will be allowed. Versions 3.5.5 and 3.6.4 have a fix. After upgrading, visit the api `$HOST/api/v1/terminal/sessions/?limit=1`. The expected http response code is 401 (`not_authenticated`).</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">The vulnerability allows an attacker to gain sensitive information from the JumpServer application.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches and updates from the vendor to address this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">exposure</span><span class="nt-tag">fit2cloud</span><span class="nt-tag">jumpserver</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/jumpserver/jumpserver/blob/v3.6.1/apps/terminal/api/session/session.py#L91" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-42442" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/jumpserver/jumpserver/commit/0a58bba59cd275bab8e0ae58bf4b359fbc5eb74a" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/Marco-zcl/POC" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/nomi-sec/PoC-in-GitHub" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="jumpserver login panel - detect info identify web-based control panels jumpserver open source bastion host login panel was detected. lu4nx,righettod discovery jumpserver login panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">JumpServer Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/jumpserver-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">jumpserver-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> lu4nx,righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)&#39;JumpServer&#39;&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">JumpServer Open Source Bastion Host login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">jumpserver</span><span class="nt-tag">login</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.jumpserver.org/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/jumpserver/jumpserver" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="juniper j-web - remote code execution critical identify critical remote vulnerabilities a php external variable modification vulnerability in j-web of juniper networks junos os on ex series and srx series allows an unauthenticated, network-based attacker to control certain environments variables to execute remote commands cve-2023-36845 yaser_s cve cve2023 juniper kev packetstorm rce unauth vkev vuln cwe-473" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Juniper J-Web - Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-36845.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-36845.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> yaser_s</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 19, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/473.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-473</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-36845" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-36845</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)juniper web device manager&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series and SRX Series allows an unauthenticated, network-based attacker to control certain environments variables to execute remote commands</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected device.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches and updates from the vendor to address this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">juniper</span><span class="nt-tag">kev</span><span class="nt-tag">packetstorm</span><span class="nt-tag">rce</span><span class="nt-tag">unauth</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://vulncheck.com/blog/juniper-cve-2023-36845" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-36845" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://labs.watchtowr.com/cve-2023-36844-and-friends-rce-in-juniper-firewalls/" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="http://packetstormsecurity.com/files/174865/Juniper-SRX-Firewall-EX-Switch-Remote-Code-Execution.html" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://supportportal.juniper.net/JSA72300" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="juniper j-web panel - detect info identify web-based control panels juniper j-web panel was detected. bhutch panel juniper vpn login discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Juniper J-Web Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/juniper-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">juniper-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> bhutch</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 31, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Juniper Web Device Manager&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Juniper J-Web panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">juniper</span><span class="nt-tag">vpn</span><span class="nt-tag">login</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.juniper.net/documentation/us/en/software/jweb-ex/jweb-ex-application-package/topics/concept/ex-series-j-web-interface-overview.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="juniper web device manager - cross-site scripting medium identify critical remote vulnerabilities juniper web device manager (j-web) in junos os contains a cross-site scripting vulnerability. this can allow an unauthenticated attacker to run malicious scripts reflected off j-web to the victim&#39;s browser in the context of their session within j-web, which can allow the attacker to steal cookie-based authentication credentials and launch other attacks. this issue affects all versions prior to 19.1r3-s9; 19.2 versions prior to 19.2r3-s6; 19.3 versions prior to 19.3r3-s7; 19.4 versions prior to 19.4r2-s7, 19.4r3-s8; 20.1 versions prior to 20.1r3-s5; 20.2 versions prior to 20.2r3-s5; 20.3 versions prior to 20.3r3-s5; 20.4 versions prior to 20.4r3-s4; 21.1 versions prior to 21.1r3-s4; 21.2 versions prior to 21.2r3-s1; 21.3 versions prior to 21.3r3; 21.4 versions prior to 21.4r2; 22.1 versions prior to 22.1r2. cve-2022-22242 evergreencartoons cve cve2022 juniper junos vkev vuln xss cwe-79" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Juniper Web Device Manager - Cross-Site Scripting</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-22242.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-22242.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> EvergreenCartoons</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-79</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-22242" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-22242</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Juniper Web Device Manager&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Juniper Web Device Manager (J-Web) in Junos OS contains a cross-site scripting vulnerability. This can allow an unauthenticated attacker to run malicious scripts reflected off J-Web to the victim&#39;s browser in the context of their session within J-Web, which can allow the attacker to steal cookie-based authentication credentials and launch other attacks. This issue affects all versions prior to 19.1R3-S9; 19.2 versions prior to 19.2R3-S6; 19.3 versions prior to 19.3R3-S7; 19.4 versions prior to 19.4R2-S7, 19.4R3-S8; 20.1 versions prior to 20.1R3-S5; 20.2 versions prior to 20.2R3-S5; 20.3 versions prior to 20.3R3-S5; 20.4 versions prior to 20.4R3-S4; 21.1 versions prior to 21.1R3-S4; 21.2 versions prior to 21.2R3-S1; 21.3 versions prior to 21.3R3; 21.4 versions prior to 21.4R2; 22.1 versions prior to 22.1R2.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute arbitrary script code in the context of the targeted user&#39;s browser, potentially leading to session hijacking, defacement, or theft of sensitive information.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches or updates provided by Juniper Networks to mitigate this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">juniper</span><span class="nt-tag">junos</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">xss</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://octagon.net/blog/2022/10/28/juniper-sslvpn-junos-rce-and-multiple-vulnerabilities/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://supportportal.juniper.net/s/article/2022-10-Security-Bulletin-Junos-OS-Multiple-vulnerabilities-in-J-Web?language=en_US" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://kb.juniper.net/JSA69899" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-22242" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/ARPSyndicate/kenzer-templates" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="jupyter notebook - remote command execution high identify critical remote vulnerabilities jupyter notebook is an interactive notebook, computer application is a web based visualization, jupyter notebook api/terminals path there are loopholes in the remote command execution. huta0 jupyter notebook rce bypass vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Jupyter Notebook - Remote Command Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/vulnerabilities/jupyter-notebook-rce.yaml" target="_blank" rel="noopener" class="nt-source-link">jupyter-notebook-rce.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> HuTa0</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 18, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)jupyter notebook&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Jupyter Notebook is an interactive Notebook, computer application is a web based visualization, Jupyter Notebook API/terminals path there are loopholes in the remote command execution.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">jupyter</span><span class="nt-tag">notebook</span><span class="nt-tag">rce</span><span class="nt-tag">bypass</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/SCAMagic/SCAMagicScan/blob/de8130a2280ee08d719ac6612e590b8e2678fb97/pocs/poc-yaml-jupyter-notebook-rce.py" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="jupyter notebook login panel - detect info identify web-based control panels jupyter notebook login panel was detected. hakimkt,arafatansari discovery edb exposure jupyter notebook panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Jupyter Notebook Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/jupyter-notebook.yaml" target="_blank" rel="noopener" class="nt-source-link">jupyter-notebook.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> hakimkt,arafatansari</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)JupyterHub&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Jupyter Notebook login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">edb</span><span class="nt-tag">exposure</span><span class="nt-tag">jupyter</span><span class="nt-tag">notebook</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.exploit-db.com/ghdb/7970" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="jupyterhub panel - detect info identify web-based control panels jupyterhub is a multi-user server for jupyter notebooks rxerium ai detect discovery jupyter jupyterhub ml panel" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">JupyterHub Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/jupyterhub-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">jupyterhub-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 27, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;JupyterHub&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">JupyterHub is a multi-user server for Jupyter notebooks</div></div></div>
  <div class="nt-tags"><span class="nt-tag">ai</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">jupyter</span><span class="nt-tag">jupyterhub</span><span class="nt-tag">ml</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/jupyterhub/jupyterhub" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://jupyter.org/hub" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="jupyterhub - default admin discovery high identify default logins in web-based control panels jupyterhub default admin credentials were discovered. for3stco1d default-login jupyterhub vuln cwe-522" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Jupyterhub - Default Admin Discovery</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/jupyterhub/jupyterhub-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">jupyterhub-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> For3stCo1d</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/522.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-522</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;JupyterHub&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Jupyterhub default admin credentials were discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">jupyterhub</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/jupyterhub/jupyterhub" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="justboil.me images plugin - exposed image upload medium identify critical remote vulnerabilities justboil.me images plugin for tinymce contains an exposed dialog interface that could lead to potential security vulnerabilities. the plugin&#39;s dialog-v4.htm file is accessible without proper access controls, which may allow unauthorized access to image upload functionality. 0xr2r justboil tinymce plugin exposure misconfig vuln" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">JustBoil.me Images Plugin - Exposed Image Upload</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/vulnerabilities/other/justboil-me-image-upload.yaml" target="_blank" rel="noopener" class="nt-source-link">justboil-me-image-upload.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0xr2r</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 23, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/plugins/generic/tinymce/plugins/justboil\\.me/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">JustBoil.me Images Plugin for TinyMCE contains an exposed dialog interface that could lead to potential security vulnerabilities. The plugin&#39;s dialog-v4.htm file is accessible without proper access controls, which may allow unauthorized access to image upload functionality.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">justboil</span><span class="nt-tag">tinymce</span><span class="nt-tag">plugin</span><span class="nt-tag">exposure</span><span class="nt-tag">misconfig</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://cxsecurity.com/issue/WLB-2019050108" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="kaco new energy solar inverter - detect info identify web-based control panels kaco new energy is a solar inverter manufacturer. their inverters include a built-in web server
that serves compressed html over http for monitoring inverter status and energy production data.
devices are commonly deployed on residential and commercial solar installations. rxerium detect energy ics inverter kaco panel solar tech" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">KACO New Energy Solar Inverter - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/kaco-new-energy-detect.yaml" target="_blank" rel="noopener" class="nt-source-link">kaco-new-energy-detect.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 27, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-890342445&#34; || any(each(service[&#34;html.titles&#34;]), {# matches &#34;KACO new energy&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">KACO new energy is a solar inverter manufacturer. Their inverters include a built-in web server
that serves compressed HTML over HTTP for monitoring inverter status and energy production data.
Devices are commonly deployed on residential and commercial solar installations.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">detect</span><span class="nt-tag">energy</span><span class="nt-tag">ics</span><span class="nt-tag">inverter</span><span class="nt-tag">kaco</span><span class="nt-tag">panel</span><span class="nt-tag">solar</span><span class="nt-tag">tech</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://kaco-newenergy.com/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="klog server - default login high identify default logins in web-based control panels klog server contains a default login vulnerability. an attacker can obtain access to user accounts and access sensitive information, modify data, and/or execute unauthorized operations. s4e-io default-login klog-server vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">KLog Server - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/klog-server-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">klog-server-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> s4e-io</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 19, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;KLog Server&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">KLog Server contains a default login vulnerability. An attacker can obtain access to user accounts and access sensitive information, modify data, and/or execute unauthorized operations.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">klog-server</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.klogserver.com/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="kaeser sigma air manager - panel info identify web-based control panels detected exposed kaeser sigma air manager login panel th3l0newolf detect discovery kaeser login panel" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Kaeser Sigma Air Manager - Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/kaeser-sigma-air-manager-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">kaeser-sigma-air-manager-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Th3l0newolf</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 27, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;SIGMA AIR MANAGER&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detected exposed Kaeser Sigma Air Manager login panel</div></div></div>
  <div class="nt-tags"><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">kaeser</span><span class="nt-tag">login</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.kaeser.com/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="kanboard - default login high identify default logins in web-based control panels kanboard contains a default login vulnerability. an attacker can obtain access to user accounts and access sensitive information, modify data, and/or execute unauthorized operations. shelled default-login kanboard vuln cwe-522" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Kanboard - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/kanboard-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">kanboard-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> shelled</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/522.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-522</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body.mmh3&#34;] == &#34;1605834045&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Kanboard contains a default login vulnerability. An attacker can obtain access to user accounts and access sensitive information, modify data, and/or execute unauthorized operations.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">kanboard</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://twitter.com/0x_rood/status/1607068644634157059" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/kanboard/kanboard" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://docs.kanboard.org/v1/admin/installation/" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="kanboard login panel - detect info identify web-based control panels kanboard login panel was detected. dhiyaneshdk panel kanboard discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Kanboard Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/kanboard-login.yaml" target="_blank" rel="noopener" class="nt-source-link">kanboard-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;2056442365&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Kanboard login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">kanboard</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="kaseya vsa &lt; 9.5.7 - credential disclosure via windows agent critical identify critical remote vulnerabilities kaseya vsa before 9.5.7 allows credential disclosure, as exploited in the wild in july 2021. by default kaseya vsa on premise offers a download page where the clients for the installation can be downloaded. the default url for this page is https://x.x.x.x/dl.asp when an attacker download a client for windows and installs it, the file kaseyad.ini is generated (c:\program files (x86)\kaseya\xxxxxxxxxx\kaseyad.ini) which contains an agent_guid and agentpassword this agent_guid and agentpassword can be used to log in on dl.asp (https://x.x.x.x/dl.asp?un=840997037507813&amp;pw=113cc622839a4077a84837485ced6b93e440bf66d44057713cb2f95e503a06d9) this request authenticates the client and returns a sessionid cookie that can be used in subsequent attacks to bypass authentication. security issues discovered --- * unauthenticated download page leaks credentials * credentials of agent software can be used to obtain a sessionid (cookie) that can be used for services not intended for use by agents * dl.asp accepts credentials via a get request * access to kaseyad.ini gives an attacker access to sufficient information to penetrate the kaseya installation and its clients. impact --- via the page /dl.asp enough information can be obtained to give an attacker a sessionid that can be used to execute further (semi-authenticated) attacks against the system. cve-2021-30116 daffainfo cve cve2021 kaseya kev virtual_system_administrator vkev vuln cwe-522" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Kaseya VSA &lt; 9.5.7 - Credential Disclosure via Windows Agent</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2021/CVE-2021-30116.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2021-30116.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> daffainfo</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 11, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/522.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-522</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2021-30116" target="_blank" rel="noopener" class="nt-cve-link">CVE-2021-30116</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-1445519482&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Kaseya VSA before 9.5.7 allows credential disclosure, as exploited in the wild in July 2021. By default Kaseya VSA on premise offers a download page where the clients for the installation can be downloaded. The default URL for this page is https://x.x.x.x/dl.asp When an attacker download a client for Windows and installs it, the file KaseyaD.ini is generated (C:\Program Files (x86)\Kaseya\XXXXXXXXXX\KaseyaD.ini) which contains an Agent_Guid and AgentPassword This Agent_Guid and AgentPassword can be used to log in on dl.asp (https://x.x.x.x/dl.asp?un=840997037507813&amp;pw=113cc622839a4077a84837485ced6b93e440bf66d44057713cb2f95e503a06d9) This request authenticates the client and returns a sessionId cookie that can be used in subsequent attacks to bypass authentication. Security issues discovered --- * Unauthenticated download page leaks credentials * Credentials of agent software can be used to obtain a sessionId (cookie) that can be used for services not intended for use by agents * dl.asp accepts credentials via a GET request * Access to KaseyaD.ini gives an attacker access to sufficient information to penetrate the Kaseya installation and its clients. Impact --- Via the page /dl.asp enough information can be obtained to give an attacker a sessionId that can be used to execute further (semi-authenticated) attacks against the system.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can obtain Agent_Guid and AgentPassword credentials via the download page, gaining authenticated access to execute further attacks against Kaseya VSA.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to version 9.5.7 or later to remediate this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2021</span><span class="nt-tag">kaseya</span><span class="nt-tag">kev</span><span class="nt-tag">virtual_system_administrator</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://csirt.divd.nl/2021/07/04/Kaseya-Case-Update-2/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://csirt.divd.nl/2021/07/07/Kaseya-Limited-Disclosure/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://helpdesk.kaseya.com/hc/en-gb/articles/4403440684689-Important-Notice-July-2nd-2021" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://www.secpod.com/blog/kaseya-vsa-zero-day-by-revil/" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2021-30116" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="kasm login panel - detect info identify web-based control panels kasm workspaces login panel was detected. lum8rjack panel kasm login detect discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Kasm Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/kasm-login-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">kasm-login-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> lum8rjack</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 22, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-2144699833&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Kasm workspaces login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">kasm</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://kasmweb.com/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="kavita login panel - detect info identify web-based control panels kavita login panel was detected. ritikchaddha discovery kavita panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Kavita Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/kavita-panel-detect.yaml" target="_blank" rel="noopener" class="nt-source-link">kavita-panel-detect.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)kavita&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Kavita login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">kavita</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/kareadita/kavita" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="kentico - installer privilege escalation critical identify critical remote vulnerabilities kentico 9.0 before 9.0.51 and 10.0 before 10.0.48 are susceptible to a privilege escalation attack. an attacker can obtain global administrator access by visiting cmsinstall/install.aspx and then navigating to the cms administration dashboard. cve-2017-17736 shiar cms cve cve2017 edb install kentico unauth vuln cwe-425" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Kentico - Installer Privilege Escalation</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2017/CVE-2017-17736.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2017-17736.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> shiar</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/425.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-425</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2017-17736" target="_blank" rel="noopener" class="nt-cve-link">CVE-2017-17736</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)kentico database setup&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Kentico 9.0 before 9.0.51 and 10.0 before 10.0.48 are susceptible to a privilege escalation attack. An attacker can obtain Global Administrator access by visiting CMSInstall/install.aspx and then navigating to the CMS Administration Dashboard.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can gain administrative privileges on the Kentico CMS system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to the latest version of Kentico CMS to fix the privilege escalation vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cms</span><span class="nt-tag">cve</span><span class="nt-tag">cve2017</span><span class="nt-tag">edb</span><span class="nt-tag">install</span><span class="nt-tag">kentico</span><span class="nt-tag">unauth</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.exploit-db.com/ghdb/5694" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2017-17736" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://blog.hivint.com/advisory-access-control-bypass-in-kentico-cms-cve-2017-17736-49e1e43ae55b" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/0xSojalSec/Nuclei-TemplatesNuclei-Templates-CVE-2017-17736" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/ARPSyndicate/cvemon" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="kerio connect login panel - detect info identify web-based control panels kerio connect login panel was detected. dhiyaneshdk discovery kerio panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Kerio Connect Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/kerio-connect-client.yaml" target="_blank" rel="noopener" class="nt-source-link">kerio-connect-client.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Kerio Connect Client&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Kerio Connect login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">kerio</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="kerio controle panel - detect info identify web-based control panels protect your network from viruses, malware and malicious activity with gfi keriocontrol, the easy-to-administer yet powerful all-in-one security solution. johnk3r panel kerio login discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Kerio Controle Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/kerion-control-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">kerion-control-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> johnk3r</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 13, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-631002664&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Protect your network from viruses, malware and malicious activity with GFI KerioControl, the easy-to-administer yet powerful all-in-one security solution.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">kerio</span><span class="nt-tag">login</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://gfi.ai/products-and-solutions/network-security-solutions/keriocontrol" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="kettle - default login medium identify default logins in web-based control panels kettle contains a default login vulnerability. an attacker can obtain access to user accounts and access sensitive information, modify data, and/or execute unauthorized operations. for3stco1d default-login kettle vuln cwe-522" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Kettle - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/kettle/kettle-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">kettle-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> For3stCo1d</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/522.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-522</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;http.head.wwwAuthentications&#34;]), {# contains &#39;realm=&#34;Kettle&#39;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Kettle contains a default login vulnerability. An attacker can obtain access to user accounts and access sensitive information, modify data, and/or execute unauthorized operations.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">kettle</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="kettle panel - detect info identify web-based control panels kettle panel was detected. for3stco1d panel kettle discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Kettle Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/kettle-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">kettle-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> For3stCo1d</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;http.head.wwwAuthentications&#34;]), {# contains &#39;realm=&#34;Kettle&#39;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Kettle panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">kettle</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="keycloak - information exposure medium identify critical remote vulnerabilities a flaw was found in keycloak in versions prior to 13.0.0. the client registration endpoint allows fetching information about public clients (like client secret) without authentication which could be an issue if the same public client changed to confidential later. the highest threat from this vulnerability is to data confidentiality. cve-2020-27838 mchklt cve cve2020 exposure keycloak redhat vuln cwe-287" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">KeyCloak - Information Exposure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2020/CVE-2020-27838.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2020-27838.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> mchklt</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 16, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/287.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-287</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2020-27838" target="_blank" rel="noopener" class="nt-cve-link">CVE-2020-27838</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)keycloak&#34;}) || service[&#34;http.body&#34;] matches &#34;(?i)keycloak&#34; || service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-1105083093&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A flaw was found in keycloak in versions prior to 13.0.0. The client registration endpoint allows fetching information about PUBLIC clients (like client secret) without authentication which could be an issue if the same PUBLIC client changed to CONFIDENTIAL later. The highest threat from this vulnerability is to data confidentiality.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">The vulnerability allows an attacker to gain sensitive information from the KeyCloak server.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches or updates provided by the KeyCloak vendor.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2020</span><span class="nt-tag">exposure</span><span class="nt-tag">keycloak</span><span class="nt-tag">redhat</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://bugzilla.redhat.com/show_bug.cgi?id=1906797" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2020-27838" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/muneebaashiq/MBProjects" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/j4k0m/godkiller" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="keycloak admin console configuration disclosure low identify critical remote vulnerabilities detected keycloak admin console configuration was exposing realm name, client id, ssl requirements, and authentication server url enabling reconnaissance and targeted authentication attacks. 0x_akoko keycloak config exposure disclosure" data-nt-sev="low">
  <div class="nt-card-header">
    <div class="nt-title">Keycloak Admin Console Configuration Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposures/configs/keycloak-admin-console-config.yaml" target="_blank" rel="noopener" class="nt-source-link">keycloak-admin-console-config.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_Akoko</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 5, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;product&#34;] contains &#34;RedHat:Keycloak&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detected Keycloak admin console configuration was exposing realm name, client ID, SSL requirements, and authentication server URL enabling reconnaissance and targeted authentication attacks.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">keycloak</span><span class="nt-tag">config</span><span class="nt-tag">exposure</span><span class="nt-tag">disclosure</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.keycloak.org/docs/latest/server_admin/index.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.keycloak.org/docs/latest/securing_apps/index.html" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="keycloak admin login panel - detect info identify web-based control panels keycloak admin login panel was detected. incogbyte,righettod,daffainfo discovery keycloak panel redhat cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Keycloak Admin Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/keycloak-admin-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">keycloak-admin-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> incogbyte,righettod,daffainfo</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-1105083093&#34; || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)keycloak&#34;}) || service[&#34;http.body&#34;] matches &#34;(?i)keycloak&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Keycloak admin login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">keycloak</span><span class="nt-tag">panel</span><span class="nt-tag">redhat</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="kiali - detect info identify web-based control panels kiali panel was detected. righettod panel kiali detect login discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Kiali - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/kiali-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">kiali-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 19, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Kiali&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">kiali panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">kiali</span><span class="nt-tag">detect</span><span class="nt-tag">login</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://kiali.io/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="kibana - local file inclusion critical identify critical remote vulnerabilities kibana versions before 6.4.3 and 5.6.13 contain an arbitrary file inclusion flaw in the console plugin. an attacker with access to the kibana console api could send a request that will attempt to execute javascript which could possibly lead to an attacker executing arbitrary commands with permissions of the kibana process on the host system. cve-2018-17246 princechaddha,thelicato cve cve2018 elastic kibana lfi vkev vulhub vuln cwe-73,cwe-829" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Kibana - Local File Inclusion</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2018/CVE-2018-17246.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2018-17246.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> princechaddha,thelicato</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/73,CWE-829.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-73,CWE-829</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2018-17246" target="_blank" rel="noopener" class="nt-cve-link">CVE-2018-17246</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)kibana&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Kibana versions before 6.4.3 and 5.6.13 contain an arbitrary file inclusion flaw in the Console plugin. An attacker with access to the Kibana Console API could send a request that will attempt to execute JavaScript which could possibly lead to an attacker executing arbitrary commands with permissions of the Kibana process on the host system.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability allows an attacker to read arbitrary files on the server, leading to potential information disclosure and further attacks.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches and updates provided by the vendor to mitigate this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2018</span><span class="nt-tag">elastic</span><span class="nt-tag">kibana</span><span class="nt-tag">lfi</span><span class="nt-tag">vkev</span><span class="nt-tag">vulhub</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/vulhub/vulhub/blob/master/kibana/CVE-2018-17246/README.md" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.elastic.co/community/security" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://discuss.elastic.co/t/elastic-stack-6-4-3-and-5-6-13-security-update/155594" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2018-17246" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://access.redhat.com/errata/RHBA-2018:3743" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="kibana login panel - detect info identify web-based control panels kibana login panel was detected. petruknisme,daffainfo,c-sh0 discovery elastic kibana panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Kibana Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/kibana-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">kibana-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> petruknisme,daffainfo,c-sh0</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)kibana&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Kibana login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">elastic</span><span class="nt-tag">kibana</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="kibana timelion - arbitrary code execution critical identify critical remote vulnerabilities kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the timelion visualizer. an attacker with access to the timelion application could send a request that will attempt to execute javascript code. this could possibly lead to an attacker executing arbitrary commands with permissions of the kibana process on the host system. cve-2019-7609 dwisiswant0 cve cve2019 elastic kev kibana rce vkev vuln cwe-94" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Kibana Timelion - Arbitrary Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2019/CVE-2019-7609.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2019-7609.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dwisiswant0</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/94.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-94</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2019-7609" target="_blank" rel="noopener" class="nt-cve-link">CVE-2019-7609</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)kibana&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker with access to the Timelion application could send a request that will attempt to execute javascript code. This could possibly lead to an attacker executing arbitrary commands with permissions of the Kibana process on the host system.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Arbitrary code execution can result in unauthorized access, data leakage, and system compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches or upgrade to a patched version of Kibana to mitigate the vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2019</span><span class="nt-tag">elastic</span><span class="nt-tag">kev</span><span class="nt-tag">kibana</span><span class="nt-tag">rce</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/mpgn/CVE-2019-7609" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://discuss.elastic.co/t/elastic-stack-6-6-1-and-5-6-15-security-update/169077" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2019-7609" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://www.elastic.co/community/security" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://access.redhat.com/errata/RHBA-2019:2824" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="kiteworks pcn panel - detect info identify web-based control panels kiteworks pcn login panel was detected. righettod accellion detect discovery kiteworks login panel" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Kiteworks PCN Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/kiteworks-pcn-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">kiteworks-pcn-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 29, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-1215318992&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Kiteworks PCN Login Panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">accellion</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">kiteworks</span><span class="nt-tag">login</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.kiteworks.com/platform/private-content-network/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="kivicare clinic &amp; patient management system (ehr) &lt;= 3.6.4 - sql injection high identify critical remote vulnerabilities the kivicare clinic &amp; patient management system (ehr) plugin for wordpress is vulnerable to sql injection via the &#39;visit_type[service_id]&#39; parameter of the tax_calculated_data ajax action in all versions up to, and including, 3.6.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing sql query. this makes it possible for unauthenticated attackers to append additional sql queries into already existing queries that can be used to extract sensitive information from the database. cve-2024-11728 samogod,s4e-io cve cve2024 kivicare-clinic-management-system sqli vuln wordpress wp wp-plugin cwe-89" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">KiviCare Clinic &amp; Patient Management System (EHR) &lt;= 3.6.4 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-11728.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-11728.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> samogod,s4e-io</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 13, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-11728" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-11728</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/kivicare-clinic-management-system&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The KiviCare Clinic &amp; Patient Management System (EHR) plugin for WordPress is vulnerable to SQL Injection via the &#39;visit_type[service_id]&#39; parameter of the tax_calculated_data AJAX action in all versions up to, and including, 3.6.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can execute time-based SQL injection through the visit_type parameter in the tax_calculated_data action to extract the complete clinic database including patient records, medical history, and appointment data.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">To remediate this vulnerability, validate and sanitize all user inputs on the server side before using them in SQL queries. Use prepared statements or stored procedures, and ensure that data is properly escaped.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">kivicare-clinic-management-system</span><span class="nt-tag">sqli</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/samogod/CVE-2024-11728" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://samogod.com/2024/12/11/cve-2024-11728-kivicare-wordpress-unauthenticated-sql-injection/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://plugins.trac.wordpress.org/changeset/3201428/kivicare-clinic-management-system/trunk/app/controllers/KCTaxController.php" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/53c18834-3026-4d4d-888b-add314a0e56e?source=cve" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-11728" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="kiwi tcms information disclosure high identify critical remote vulnerabilities internal info exposed in kiwi tcms. act1on3 kiwitcms exposure misconfig hackerone vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Kiwi TCMS Information Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/vulnerabilities/other/kiwitcms-json-rpc.yaml" target="_blank" rel="noopener" class="nt-source-link">kiwitcms-json-rpc.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> act1on3</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Kiwi TCMS - Login&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Internal info exposed in Kiwi TCMS.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">kiwitcms</span><span class="nt-tag">exposure</span><span class="nt-tag">misconfig</span><span class="nt-tag">hackerone</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://hackerone.com/reports/968402" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://kiwitcms.org/blog/kiwi-tcms-team/2020/08/23/kiwi-tcms-86/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/act1on3/nuclei-templates/blob/master/vulnerabilities/kiwi-information-disclosure.yaml" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="kiwi tcms login panel - detect info identify web-based control panels kiwi tcms login panel was detected. pdteam discovery kiwitcms panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Kiwi TCMS Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/kiwitcms-login.yaml" target="_blank" rel="noopener" class="nt-source-link">kiwitcms-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pdteam</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)kiwi tcms - login&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Kiwi TCMS login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">kiwitcms</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://kiwitcms.org" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="koboldai panel - detect info identify web-based control panels koboldai was detected. koboldai was an ai text adventure and story generation interface that supports multiple local and remote language models including koboldcpp and ai horde. rxerium ai detect discovery koboldai llm panel" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">KoboldAI Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/koboldai-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">koboldai-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 14, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)KoboldAI Lite&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">KoboldAI was detected. KoboldAI was an AI text adventure and story generation interface that supports multiple local and remote language models including koboldcpp and AI Horde.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">ai</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">koboldai</span><span class="nt-tag">llm</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/LostRuins/koboldcpp" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/KoboldAI/KoboldAI-Client" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="koel panel - detect info identify web-based control panels personal audio streaming service that works. rxerium panel koel login discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Koel Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/koel-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">koel-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 27, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Koel&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Personal audio streaming service that works.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">koel</span><span class="nt-tag">login</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://koel.dev/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/koel/koel" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="kong manager oss/admin - exposure medium identify web-based control panels exposed kong manager (oss/admin) interface accessible without authentication. krishna jaishwal kong manager misconfig exposure discovery" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Kong Manager OSS/Admin - Exposure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/kong-manager-exposure.yaml" target="_blank" rel="noopener" class="nt-source-link">kong-manager-exposure.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Krishna Jaishwal</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 8, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Kong Manager&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Exposed Kong Manager (OSS/Admin) interface accessible without authentication.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">kong</span><span class="nt-tag">manager</span><span class="nt-tag">misconfig</span><span class="nt-tag">exposure</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="http://github.com/Kong/kong-manager" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="kopano webapp login panel - detect info identify web-based control panels kopano webapp login panel was detected. righettod panel kopano login detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Kopano WebApp Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/kopano-webapp-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">kopano-webapp-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 23, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Kopano WebApp&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Kopano WebApp login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">kopano</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://kopano.com/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="kraken cluster monitoring dashboard - detect info identify web-based control panels kraken cluster monitoring dashboard was detected. pussycat0x panel kraken cluster discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Kraken Cluster Monitoring Dashboard - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/kraken-cluster-monitoring.yaml" target="_blank" rel="noopener" class="nt-source-link">kraken-cluster-monitoring.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Kraken dashboard&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Kraken Cluster Monitoring Dashboard was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">kraken</span><span class="nt-tag">cluster</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="kubeoperator foreground `kubeconfig` - file download critical identify critical remote vulnerabilities kubeoperator is an open source kubernetes distribution focused on helping enterprises plan, deploy and operate production-level k8s clusters. in kubeoperator versions 3.16.3 and below, api interfaces with unauthorized entities and can leak sensitive information. this vulnerability could be used to take over the cluster under certain conditions. this issue has been patched in version 3.16.4. cve-2023-22480 dhiyaneshdk cve cve2023 exposure fit2cloud k8s kubeconfig kubeoperator vuln cwe-285,cwe-863" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">KubeOperator Foreground `kubeconfig` - File Download</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-22480.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-22480.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 5, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/285,CWE-863.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-285,CWE-863</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-22480" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-22480</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)kubeoperator&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">KubeOperator is an open source Kubernetes distribution focused on helping enterprises plan, deploy and operate production-level K8s clusters. In KubeOperator versions 3.16.3 and below, API interfaces with unauthorized entities and can leak sensitive information. This vulnerability could be used to take over the cluster under certain conditions. This issue has been patched in version 3.16.4.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can download sensitive files from the KubeOperator Foreground kubeconfig file, potentially leading to unauthorized access or exposure of sensitive information.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to the latest version to mitigate this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">exposure</span><span class="nt-tag">fit2cloud</span><span class="nt-tag">k8s</span><span class="nt-tag">kubeconfig</span><span class="nt-tag">kubeoperator</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/KubeOperator/KubeOperator/security/advisories/GHSA-jxgp-jgh3-8jc8" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/PeiQi0/PeiQi-WIKI-Book/blob/main/docs/wiki/webapp/KubeOperator/KubeOperator%20kubeconfig%20%E6%9C%AA%E6%8E%88%E6%9D%83%E8%AE%BF%E9%97%AE%E6%BC%8F%E6%B4%9E%20CVE-2023-22480.md?plain=1" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-22480" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/KubeOperator/KubeOperator/commit/7ef42bf1c16900d13e6376f8be5ecdbfdfb44aaf" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/KubeOperator/KubeOperator/releases/tag/v3.16.4" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="kubepi &lt;= v1.6.4 loginlogssearch - unauthorized access high identify critical remote vulnerabilities kubepi is a modern kubernetes panel. the api interfaces with unauthorized entities and may leak sensitive information. this issue has been patched in version 1.6.4. there are currently no known workarounds. cve-2023-22478 dhiyaneshdk cve cve2023 exposure fit2cloud k8s kubepi vkev vuln cwe-862" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">KubePi &lt;= v1.6.4 LoginLogsSearch - Unauthorized Access</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-22478.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-22478.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 5, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/862.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-862</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-22478" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-22478</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)kubepi&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">KubePi is a modern Kubernetes panel. The API interfaces with unauthorized entities and may leak sensitive information. This issue has been patched in version 1.6.4. There are currently no known workarounds.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can gain unauthorized access to sensitive information.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade KubePi to a version higher than v1.6.4 to mitigate the vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">exposure</span><span class="nt-tag">fit2cloud</span><span class="nt-tag">k8s</span><span class="nt-tag">kubepi</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/PeiQi0/PeiQi-WIKI-Book/blob/main/docs/wiki/webapp/KubePi/KubePi%20LoginLogsSearch%20%E6%9C%AA%E6%8E%88%E6%9D%83%E8%AE%BF%E9%97%AE%E6%BC%8F%E6%B4%9E%20CVE-2023-22478.md" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-22478" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/1Panel-dev/KubePi/security/advisories/GHSA-gqx8-hxmv-c4v4" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/KubeOperator/KubePi/commit/0c6774bf5d9003ae4d60257a3f207c131ff4a6d6" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/KubeOperator/KubePi/releases/tag/v1.6.4" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="kubepi jwtsigkey - admin authentication bypass critical identify critical remote vulnerabilities kubepi is a k8s panel. the jwt authentication function of kubepi through version 1.6.2 uses hard-coded jwtsigkeys, resulting in the same jwtsigkeys for all online projects. this means that an attacker can forge any jwt token to take over the administrator account of any online project. furthermore, they may use the administrator to take over the k8s cluster of the target enterprise. `session.go`, the use of hard-coded jwtsigkey, allows an attacker to use this value to forge jwt tokens arbitrarily. the jwtsigkey is confidential and should not be hard-coded in the code. cve-2023-22463 dhiyaneshdk auth-bypass cve cve2023 fit2cloud k8s kubepi vkev vuln cwe-798" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">KubePi JwtSigKey - Admin Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-22463.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-22463.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 13, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/798.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-798</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-22463" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-22463</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)kubepi&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">KubePi is a k8s panel. The jwt authentication function of KubePi through version 1.6.2 uses hard-coded Jwtsigkeys, resulting in the same Jwtsigkeys for all online projects. This means that an attacker can forge any jwt token to take over the administrator account of any online project. Furthermore, they may use the administrator to take over the k8s cluster of the target enterprise. `session.go`, the use of hard-coded JwtSigKey, allows an attacker to use this value to forge jwt tokens arbitrarily. The JwtSigKey is confidential and should not be hard-coded in the code.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could lead to unauthorized access and control of the Kubernetes cluster.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">The vulnerability has been fixed in 1.6.3. In the patch, JWT key is specified in app.yml. If the user leaves it blank, a random key will be used. There are no workarounds aside from upgrading.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">fit2cloud</span><span class="nt-tag">k8s</span><span class="nt-tag">kubepi</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/PeiQi0/PeiQi-WIKI-Book/blob/main/docs/wiki/webapp/KubePi/KubePi%20JwtSigKey%20%E7%99%BB%E9%99%86%E7%BB%95%E8%BF%87%E6%BC%8F%E6%B4%9E%20CVE-2023-22463.md" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-22463" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/KubeOperator/KubePi/blob/da784f5532ea2495b92708cacb32703bff3a45a3/internal/api/v1/session/session.go#L35" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/KubeOperator/KubePi/commit/3be58b8df5bc05d2343c30371dd5fcf6a9fbbf8b" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/KubeOperator/KubePi/releases/tag/v1.6.3" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="kubeview &lt;=0.1.31 - information disclosure critical identify critical remote vulnerabilities kubeview through 0.1.31 is susceptible to information disclosure. an attacker can obtain control of a kubernetes cluster because api/scrape/kube-system does not require authentication and retrieves certificate files that can be used for authentication as kube-admin. an attacker can thereby possibly obtain sensitive information, modify data, and/or execute unauthorized operations. cve-2022-45933 for3stco1d cve cve2022 exposure kubernetes kubeview kubeview_project vkev vuln cwe-306" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">KubeView &lt;=0.1.31 - Information Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-45933.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-45933.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> For3stCo1d</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/306.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-306</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-45933" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-45933</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)kubeview&#34;}) || service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-379154636&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">KubeView through 0.1.31 is susceptible to information disclosure. An attacker can obtain control of a Kubernetes cluster because api/scrape/kube-system does not require authentication and retrieves certificate files that can be used for authentication as kube-admin. An attacker can thereby possibly obtain sensitive information, modify data, and/or execute unauthorized operations.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can access Kubernetes certificate files through the unauthenticated api/scrape/kube-system endpoint, potentially obtaining kube-admin credentials and gaining complete control over the Kubernetes cluster.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade KubeView to a version higher than 0.1.31 to mitigate the information disclosure vulnerability (CVE-2022-45933).</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">exposure</span><span class="nt-tag">kubernetes</span><span class="nt-tag">kubeview</span><span class="nt-tag">kubeview_project</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/benc-uk/kubeview/issues/95" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-45933" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-45933" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/ARPSyndicate/kenzer-templates" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/Henry4E36/POCS" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="kubeview dashboard - detect info identify web-based control panels kubeview dashboard was detected. ja1sh dashboard discovery exposure k8s kubernetes kubeview kubeview_project panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">KubeView Dashboard - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/kubeview-dashboard.yaml" target="_blank" rel="noopener" class="nt-source-link">kubeview-dashboard.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ja1sh</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-379154636&#34; || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)kubeview&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">KubeView dashboard was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">dashboard</span><span class="nt-tag">discovery</span><span class="nt-tag">exposure</span><span class="nt-tag">k8s</span><span class="nt-tag">kubernetes</span><span class="nt-tag">kubeview</span><span class="nt-tag">kubeview_project</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="kubeflow pipelines panel - detect info identify web-based control panels kubeflow pipelines is an open-source platform for building and deploying portable, scalable ml workflows.
it provides a web ui for managing ml pipelines, experiments, and runs on kubernetes. rxerium ai detect discovery kubeflow kubernetes mlops panel" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Kubeflow Pipelines Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/kubeflow-pipelines-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">kubeflow-pipelines-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 27, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;^Kubeflow Pipelines&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Kubeflow Pipelines is an open-source platform for building and deploying portable, scalable ML workflows.
It provides a web UI for managing ML pipelines, experiments, and runs on Kubernetes.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">ai</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">kubeflow</span><span class="nt-tag">kubernetes</span><span class="nt-tag">mlops</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/kubeflow/pipelines" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.kubeflow.org" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="kubernetes api server - yaml parsing dos (billion laughs) high identify critical remote vulnerabilities the kubernetes api server is vulnerable to a denial of service attack via yaml/json parsing. an attacker can send a specially crafted yaml/json payload that causes exponential memory consumption (billion laughs attack), leading to api server crash. cve-2019-11253 ritikchaddha cve cve2019 k8s kubernetes yaml cwe-400" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Kubernetes API Server - YAML Parsing DoS (Billion Laughs)</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2019/CVE-2019-11253.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2019-11253.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 26, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/400.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-400</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2019-11253" target="_blank" rel="noopener" class="nt-cve-link">CVE-2019-11253</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;product&#34;] contains &#34;Kubernetes:Kubernetes&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The Kubernetes API server is vulnerable to a denial of service attack via YAML/JSON parsing. An attacker can send a specially crafted YAML/JSON payload that causes exponential memory consumption (Billion Laughs attack), leading to API server crash.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can cause the API server to crash or become unavailable by consuming excessive CPU or memory resources.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to Kubernetes v1.13.12, v1.14.8, v1.15.5, v1.16.2 or later versions with fixed input validation.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2019</span><span class="nt-tag">k8s</span><span class="nt-tag">kubernetes</span><span class="nt-tag">yaml</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://gist.github.com/bgeesaman/0e0349e94cd22c48bf14d8a9b7d6b8f2" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/kubernetes/kubernetes/issues/83253" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2019-11253" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="kubernetes enterprise manager panel - detect info identify web-based control panels kubernetes enterprise manager panel was detected. pussycat0x discovery kubernetes panel tech cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Kubernetes Enterprise Manager Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/kubernetes-enterprise-manager.yaml" target="_blank" rel="noopener" class="nt-source-link">kubernetes-enterprise-manager.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)kubernetes web view&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Kubernetes Enterprise Manager panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">kubernetes</span><span class="nt-tag">panel</span><span class="nt-tag">tech</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="kubernetes local cluster web view panel- detect medium identify web-based control panels kubernetes local cluster web view panel discovered. tess discovery k8s kubernetes misconfig panel cwe-200" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Kubernetes Local Cluster Web View Panel- Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/kubernetes-web-view.yaml" target="_blank" rel="noopener" class="nt-source-link">kubernetes-web-view.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> tess</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)kubernetes web view&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Kubernetes local cluster web view panel discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">k8s</span><span class="nt-tag">kubernetes</span><span class="nt-tag">misconfig</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="kubio ai page builder &lt;= 2.5.1 - local file inclusion critical identify critical remote vulnerabilities the kubio ai page builder plugin for wordpress is vulnerable to local file inclusion in all versions up to, and including, 2.5.1 via thekubio_hybrid_theme_load_template function. this makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any php code in those files. this can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included. cve-2025-2294 s4e-io cve cve2025 kubio lfi vkev vuln wordpress wp wp-plugin cwe-22" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Kubio AI Page Builder &lt;= 2.5.1 - Local File Inclusion</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-2294.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-2294.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> s4e-io</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 28, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-2294" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-2294</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)wp-content/plugins/kubio/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The Kubio AI Page Builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.5.1 via thekubio_hybrid_theme_load_template function. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can include and execute arbitrary files through the kubio_hybrid_theme_load_template function, allowing arbitrary PHP code execution and potential complete server compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Fixed in 2.5.2</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">kubio</span><span class="nt-tag">lfi</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/Nxploited/CVE-2025-2294" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://plugins.trac.wordpress.org/browser/kubio/tags/2.5.1/lib/integrations/third-party-themes/editor-hooks.php#L32" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/kubio/kubio-ai-page-builder-251-unauthenticated-local-file-inclusion" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="kyocera printer d-copia253mf - directory traversal high identify critical remote vulnerabilities kyocera printer d-copia253mf plus is susceptible to a directory traversal vulnerability which could allow an attacker to retrieve or view arbitrary files from the affected server. cve-2020-23575 0x_akoko cve cve2020 edb iot kyocera lfi printer vkev vuln cwe-22" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Kyocera Printer d-COPIA253MF - Directory Traversal</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2020/CVE-2020-23575.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2020-23575.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_Akoko</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2020-23575" target="_blank" rel="noopener" class="nt-cve-link">CVE-2020-23575</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-50306417&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Kyocera Printer d-COPIA253MF plus is susceptible to a directory traversal vulnerability which could allow an attacker to retrieve or view arbitrary files from the affected server.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can exploit this vulnerability to read arbitrary files from the server, potentially leading to unauthorized access or sensitive information disclosure.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest firmware update provided by Kyocera to fix the directory traversal vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2020</span><span class="nt-tag">edb</span><span class="nt-tag">iot</span><span class="nt-tag">kyocera</span><span class="nt-tag">lfi</span><span class="nt-tag">printer</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.exploit-db.com/exploits/48561" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2020-23575" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.kyoceradocumentsolutions.com.tr/tr.html" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/ARPSyndicate/kenzer-templates" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="kyocera taskalfa printer - path traversal medium identify critical remote vulnerabilities ccrx has a path traversal vulnerability. path traversal is an attack on web applications. by manipulating the value of the file path, an attacker can gain access to the file system, including source code and critical system settings. cve-2023-34259 gy741 cve cve2023 kyocera lfi packetstorm printer seclists vuln cwe-22" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Kyocera TASKalfa printer - Path Traversal</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-34259.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-34259.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> gy741</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 8, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-34259" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-34259</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-50306417&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">CCRX has a Path Traversal vulnerability. Path Traversal is an attack on web applications. By manipulating the value of the file path, an attacker can gain access to the file system, including source code and critical system settings.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can manipulate file path values to access sensitive file system resources including source code and critical system configuration files.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to the latest version to mitigate this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">kyocera</span><span class="nt-tag">lfi</span><span class="nt-tag">packetstorm</span><span class="nt-tag">printer</span><span class="nt-tag">seclists</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://sec-consult.com/vulnerability-lab/advisory/path-traversal-bypass-denial-of-service-in-kyocera-printer/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.kyoceradocumentsolutions.com/en/our-business/security/information/2023-07-14.html" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://packetstormsecurity.com/files/173397/Kyocera-TASKalfa-4053ci-2VG_S000.002.561-Path-Traversal-Denial-Of-Service.html" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://sec-consult.com/vulnerability-lab/" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://seclists.org/fulldisclosure/2023/Jul/15" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="ldap account manager login panel - detect info identify web-based control panels ldap account manager login panel was detected. dhiyaneshdk discovery ldap panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">LDAP Account Manager Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/ldap-account-manager-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">ldap-account-manager-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)LDAP Account Manager&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">LDAP Account Manager login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">ldap</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.ldap-account-manager.org/lamcms/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="lm studio panel - detect info identify web-based control panels lm studio is a desktop application for discovering, downloading, and running local
llms rxerium ai detect discovery llm lmstudio panel" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">LM Studio Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/lmstudio-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">lmstudio-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 27, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;LM Studio Chat&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">LM Studio is a desktop application for discovering, downloading, and running local
LLMs</div></div></div>
  <div class="nt-tags"><span class="nt-tag">ai</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">llm</span><span class="nt-tag">lmstudio</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://lmstudio.ai" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="loytec lgate-902 6.3.2 - local file inclusion high identify critical remote vulnerabilities loytec lgate-902 6.3.2 is susceptible to local file inclusion which could allow an attacker to manipulate path references and access files and directories (including critical system files) that are stored outside the root folder of the web application running on the device. this can be used to read and configuration files containing, e.g., usernames and passwords. cve-2018-14918 0x_akoko cve cve2018 lfi lgate loytec packetstorm seclists vkev vuln xss cwe-22" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">LOYTEC LGATE-902 6.3.2 - Local File Inclusion</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2018/CVE-2018-14918.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2018-14918.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_Akoko</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2018-14918" target="_blank" rel="noopener" class="nt-cve-link">CVE-2018-14918</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)LGATE-902&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">LOYTEC LGATE-902 6.3.2 is susceptible to local file inclusion which could allow an attacker to manipulate path references and access files and directories (including critical system files) that are stored outside the root folder of the web application running on the device. This can be used to read and configuration files containing, e.g., usernames and passwords.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to read sensitive files on the device, potentially leading to unauthorized access or information disclosure.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest firmware update provided by LOYTEC to fix the LFI vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2018</span><span class="nt-tag">lfi</span><span class="nt-tag">lgate</span><span class="nt-tag">loytec</span><span class="nt-tag">packetstorm</span><span class="nt-tag">seclists</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">xss</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://seclists.org/fulldisclosure/2019/Apr/12" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="http://packetstormsecurity.com/files/152453/Loytec-LGATE-902-XSS-Traversal-File-Deletion.html" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2018-14918" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/ARPSyndicate/kenzer-templates" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/HimmelAward/Goby_POC" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="larecipe &lt; 2.8.1 remote code execution via ssti critical identify critical remote vulnerabilities larecipe is an application that allows users to create documentation with markdown inside a laravel app. versions prior to 2.8.1 are vulnerable to server-side template injection (ssti), which could potentially lead to remote code execution (rce) in vulnerable configurations. cve-2025-53833 iamnoooob,pdresearch cve cve2025 larecipe oss rce ssti vkev vuln cwe-1336" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">LaRecipe &lt; 2.8.1 Remote Code Execution via SSTI</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-53833.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-53833.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> iamnoooob,pdresearch</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 15, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/1336.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-1336</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-53833" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-53833</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/binarytorch/larecipe/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">LaRecipe is an application that allows users to create documentation with Markdown inside a Laravel app. Versions prior to 2.8.1 are vulnerable to Server-Side Template Injection (SSTI), which could potentially lead to Remote Code Execution (RCE) in vulnerable configurations.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers could execute arbitrary commands on the server, access sensitive environment variables, and/or escalate access depending on server configuration.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Users are strongly advised to upgrade to version v2.8.1 or later to receive a patch.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">larecipe</span><span class="nt-tag">oss</span><span class="nt-tag">rce</span><span class="nt-tag">ssti</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/saleem-hadad/larecipe/security/advisories/GHSA-jv7x-xhv2-p5v2" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/advisories/GHSA-jv7x-xhv2-p5v2" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53833" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="labkey server login panel - detect info identify web-based control panels labkey server login panel was detected. tess discovery labkey panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">LabKey Server Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/labkey-server-login.yaml" target="_blank" rel="noopener" class="nt-source-link">labkey-server-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> tess</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)sign in: /home&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">LabKey Server login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">labkey</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="label studio - login panel info identify web-based control panels detects the presence of the label studio login page. dhiyaneshdk label-studio login panel discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Label Studio - Login Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/label-studio-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">label-studio-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 8, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-1649949475&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detects the presence of the Label Studio Login Page.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">label-studio</span><span class="nt-tag">login</span><span class="nt-tag">panel</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="laminas project laminas-http - remote code execution critical identify critical remote vulnerabilities laminas project laminas-http &lt; 2.14.2 and zend framework 3.0.0 contain a deserialization vulnerability caused by __destruct method in zend\\http\\response\\stream, letting attackers control content lead to remote code execution, exploit requires attacker-controlled serialized data. cve-2021-3007 0xanis cve cve2021 deserialization laminas rce vkev zend cwe-502" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Laminas Project laminas-http - Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2021/CVE-2021-3007.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2021-3007.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0xanis</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 5, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/502.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-502</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2021-3007" target="_blank" rel="noopener" class="nt-cve-link">CVE-2021-3007</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)laminas&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Laminas Project laminas-http &lt; 2.14.2 and Zend Framework 3.0.0 contain a deserialization vulnerability caused by __destruct method in Zend\\Http\\Response\\Stream, letting attackers control content lead to remote code execution, exploit requires attacker-controlled serialized data.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can execute arbitrary code remotely by controlling serialized content during deserialization.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to laminas-http 2.14.2 or later; note that Zend Framework is no longer supported.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2021</span><span class="nt-tag">deserialization</span><span class="nt-tag">laminas</span><span class="nt-tag">rce</span><span class="nt-tag">vkev</span><span class="nt-tag">zend</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/Ling-Yizhou/zendframework3-/blob/main/zend%20framework3%20%E5%8F%8D%E5%BA%8F%E5%88%97%E5%8C%96%20rce.md" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://research.checkpoint.com/2021/freakout-leveraging-newest-vulnerabilities-for-creating-a-botnet/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="lancom router login panel - detect info identify web-based control panels lancom router login panel was detected. __fazal,daffainfo discovery lancom panel router cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Lancom Router Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/lancom-router-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">lancom-router-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> __Fazal,daffainfo</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)LANCOM Systems GmbH&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Lancom router login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">lancom</span><span class="nt-tag">panel</span><span class="nt-tag">router</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="langsmith panel - detect info identify web-based control panels langsmith panel was detected. langsmith is langchain&#39;s platform for debugging, testing, evaluating, and monitoring llm applications. rxerium ai detect discovery langchain langsmith llm observability panel" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">LangSmith Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/langsmith-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">langsmith-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 27, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;^LangSmith&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">LangSmith panel was detected. LangSmith is LangChain&#39;s platform for debugging, testing, evaluating, and monitoring LLM applications.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">ai</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">langchain</span><span class="nt-tag">langsmith</span><span class="nt-tag">llm</span><span class="nt-tag">observability</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://smith.langchain.com/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://docs.smith.langchain.com/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="langflow - broken access control critical identify critical remote vulnerabilities langflow is a tool for building and deploying ai-powered agents and workflows. prior to version 1.7.0.dev45, multiple critical api endpoints in langflow are missing authentication controls. the issue allows any unauthenticated user to access sensitive user conversation data, transaction histories, and perform destructive operations including message deletion. this affects endpoints handling personal data and system operations that should require proper authorization. cve-2026-21445 dhiyaneshdk auth-bypass cve cve2026 langflow unauth vkev cwe-306" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Langflow - Broken Access Control</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2026/CVE-2026-21445.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2026-21445.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 8, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/306.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-306</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2026-21445" target="_blank" rel="noopener" class="nt-cve-link">CVE-2026-21445</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Langflow&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.7.0.dev45, multiple critical API endpoints in Langflow are missing authentication controls. The issue allows any unauthenticated user to access sensitive user conversation data, transaction histories, and perform destructive operations including message deletion. This affects endpoints handling personal data and system operations that should require proper authorization.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can access sensitive user data and perform destructive actions, risking data loss and privacy breaches.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to version 1.7.0.dev45 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2026</span><span class="nt-tag">langflow</span><span class="nt-tag">unauth</span><span class="nt-tag">vkev</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/langflow-ai/langflow/security/advisories/GHSA-c5cp-vx83-jhqx" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21445" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="langflow &lt; 1.9.0 - remote code execution critical identify critical remote vulnerabilities langflow versions prior to 1.9.0 are vulnerable to unauthenticated remote code execution (rce) via the build_public_tmp endpoint. attackers can submit a manipulated flow json containing python code that is executed during the build process without proper sandboxing. cve-2026-33017 himind ai cve cve2026 kev langflow passive rce vkev cwe-94" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Langflow &lt; 1.9.0 - Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2026/CVE-2026-33017.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2026-33017.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> himind</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 4, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/94.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-94</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2026-33017" target="_blank" rel="noopener" class="nt-cve-link">CVE-2026-33017</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1727196746&#34; || service[&#34;http.body&#34;] matches &#34;(?i)Langflow&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Langflow versions prior to 1.9.0 are vulnerable to unauthenticated remote code execution (RCE) via the build_public_tmp endpoint. Attackers can submit a manipulated flow JSON containing Python code that is executed during the build process without proper sandboxing.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Remote attackers can execute arbitrary Python code without authentication, leading to full system compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to version 1.9.0 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">ai</span><span class="nt-tag">cve</span><span class="nt-tag">cve2026</span><span class="nt-tag">kev</span><span class="nt-tag">langflow</span><span class="nt-tag">passive</span><span class="nt-tag">rce</span><span class="nt-tag">vkev</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://thehackernews.com/2026/03/critical-langflow-flaw-cve-2026-33017.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.sysdig.com/blog/cve-2026-33017-how-attackers-compromised-langflow-ai-pipelines-in-20-hours" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33017" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="langflow ai - unauthenticated remote code execution critical identify critical remote vulnerabilities langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint.a remote and unauthenticated attacker can send crafted http requests to execute arbitrary code. cve-2025-3248 nvn1729 cve cve2025 injection kev langflow python rce vkev vuln cwe-306" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Langflow AI - Unauthenticated Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-3248.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-3248.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> nvn1729</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 9, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/306.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-306</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-3248" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-3248</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Langflow&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint.A remote and unauthenticated attacker can send crafted HTTP requests to execute arbitrary code.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can execute arbitrary code through crafted POST requests to the /api/v1/validate/code endpoint, achieving complete server compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to Langflow version 1.3.0 or later that properly validates user input before passing it to code execution functions.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">injection</span><span class="nt-tag">kev</span><span class="nt-tag">langflow</span><span class="nt-tag">python</span><span class="nt-tag">rce</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/langflow-ai/langflow/pull/6911" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/langflow-ai/langflow/releases/tag/1.3.0" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="langflow ai &lt;= 1.6.9 - cors misconfiguration critical identify critical remote vulnerabilities langflow ai versions 1.6.9 and earlier are vulnerable to a cors misconfiguration that allows any origin to make credentialed requests. combined with samesite=none cookies, this enables cross-origin token theft and subsequent remote code execution via the /api/v1/validate/code endpoint. cve-2025-34291 686f6c61 cors cve cve2025 kev langflow misconfig oss vkev vuln cwe-942" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Langflow AI &lt;= 1.6.9 - CORS Misconfiguration</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-34291.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-34291.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 686f6c61</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 4, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/942.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-942</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-34291" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-34291</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;product&#34;] contains &#34;Langflow:Langflow&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Langflow AI versions 1.6.9 and earlier are vulnerable to a CORS misconfiguration that allows any origin to make credentialed requests. Combined with SameSite=None cookies, this enables cross-origin token theft and subsequent remote code execution via the /api/v1/validate/code endpoint.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can steal authentication tokens via CORS and execute arbitrary code on the server.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to Langflow version 1.7.0 or later which restricts CORS origins properly.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cors</span><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">kev</span><span class="nt-tag">langflow</span><span class="nt-tag">misconfig</span><span class="nt-tag">oss</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.obsidiansecurity.com/blog/cve-2025-34291-critical-account-takeover-and-rce-vulnerability-in-the-langflow-ai-agent-workflow-platform" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-34291" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/langflow-ai/langflow" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="langfuse panel - detect info identify web-based control panels langfuse panel was detected. langfuse is an open-source llm engineering platform for observability, evaluations, prompt management and analytics. exposed instances may reveal llm prompts, traces, evaluations, and connected api keys. chrisjr404 ai detect langfuse llm login panel" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Langfuse Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/langfuse-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">langfuse-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ChrisJr404</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 14, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Langfuse&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Langfuse panel was detected. Langfuse is an open-source LLM engineering platform for observability, evaluations, prompt management and analytics. Exposed instances may reveal LLM prompts, traces, evaluations, and connected API keys.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">ai</span><span class="nt-tag">detect</span><span class="nt-tag">langfuse</span><span class="nt-tag">llm</span><span class="nt-tag">login</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/langfuse/langfuse" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://langfuse.com/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="lansweeper login panel - detect info identify web-based control panels lansweeper login panel was detected. divya_mudgal discovery lansweeper panel tech cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Lansweeper Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/lansweeper-login.yaml" target="_blank" rel="noopener" class="nt-source-link">lansweeper-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> divya_mudgal</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)lansweeper - login&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Lansweeper login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">lansweeper</span><span class="nt-tag">panel</span><span class="nt-tag">tech</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="lansweeper unauthenticated sql injection critical identify critical remote vulnerabilities lansweeper before 7.1.117.4 allows unauthenticated sql injection. cve-2019-13462 divya_mudgal cve cve2019 lansweeper sqli vkev vuln cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Lansweeper Unauthenticated SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2019/CVE-2019-13462.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2019-13462.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> divya_mudgal</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2019-13462" target="_blank" rel="noopener" class="nt-cve-link">CVE-2019-13462</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)lansweeper - login&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Lansweeper before 7.1.117.4 allows unauthenticated SQL injection.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">This vulnerability can lead to unauthorized access, data leakage, and potential compromise of the entire Lansweeper system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patch or update provided by Lansweeper to fix the SQL Injection vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2019</span><span class="nt-tag">lansweeper</span><span class="nt-tag">sqli</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.nccgroup.com/ae/our-research/technical-advisory-unauthenticated-sql-injection-in-lansweeper/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2019-13462" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.nccgroup.trust/uk/our-research/technical-advisory-unauthenticated-sql-injection-in-lansweeper/" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://www.lansweeper.com/forum/yaf_topics33_Announcements.aspx" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="laravel backpack admin login panel - detect info identify web-based control panels laravel backpack admin login panel was detected. shine admin backpack discovery panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Laravel Backpack Admin Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/backpack/backpack-admin-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">backpack-admin-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> shine</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Backpack Admin&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Laravel Backpack admin login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">admin</span><span class="nt-tag">backpack</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="laravel filemanager v2.5.1 - local file inclusion medium identify critical remote vulnerabilities laravel filemanager (aka unisharp) through version 2.5.1 is vulnerable to local file inclusion via download?working_dir=%2f. cve-2022-40734 arafatansari cve cve2022 laravel lfi traversal unisharp vkev vuln cwe-22" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Laravel Filemanager v2.5.1 - Local File Inclusion</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-40734.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-40734.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> arafatansari</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-40734" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-40734</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Laravel Filemanager&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Laravel Filemanager (aka UniSharp) through version 2.5.1 is vulnerable to local file inclusion via download?working_dir=%2F.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability can lead to unauthorized access, sensitive data exposure, and remote code execution.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to a patched version of Laravel Filemanager v2.5.1 or apply the recommended security patches provided by the vendor.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">laravel</span><span class="nt-tag">lfi</span><span class="nt-tag">traversal</span><span class="nt-tag">unisharp</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/UniSharp/laravel-filemanager/issues/1150" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-40734" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/UniSharp/laravel-filemanager/issues/1150#issuecomment-1320186966" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/UniSharp/laravel-filemanager/issues/1150#issuecomment-1825310417" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/ARPSyndicate/cvemon" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="laravel login - panel detection info identify web-based control panels a laravel login panel was detected. projectdiscoveryai laravel login panel" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Laravel Login - Panel Detection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/laravel-login-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">laravel-login-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ProjectDiscoveryAI</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 6, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches `(?i)Login\s*[\p{Pd}|]?\s*Laravel`})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A Laravel login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">laravel</span><span class="nt-tag">login</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="leantime - detect info identify web-based control panels detects a leantime server, a project management system for non-project managers. icarot tech leantime detect" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Leantime - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/technologies/leantime-detect.yaml" target="_blank" rel="noopener" class="nt-source-link">leantime-detect.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> icarot</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 9, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Leantime&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detects a Leantime server, a project management system for non-project managers.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">tech</span><span class="nt-tag">leantime</span><span class="nt-tag">detect</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/Leantime/leantime" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="learndash lms &lt; 4.10.2 - sensitive information exposure medium identify critical remote vulnerabilities the learndash lms plugin for wordpress is vulnerable to sensitive information exposure in all versions up to, and including, 4.10.1 via api. this makes it possible for unauthenticated attackers to obtain access to quizzes. cve-2024-1210 ritikchaddha cve cve2024 exposure learndash vuln wordpress wp wp-plugin wpscan" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">LearnDash LMS &lt; 4.10.2 - Sensitive Information Exposure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-1210.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-1210.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 20, 2024</span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-1210" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-1210</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/sfwd-lms&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The LearnDash LMS plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.10.1 via API. This makes it possible for unauthenticated attackers to obtain access to quizzes.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can access the LearnDash API to obtain sensitive quiz materials, questions, and course content that should be restricted to enrolled learners.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Fixed in 4.10.2</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">exposure</span><span class="nt-tag">learndash</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">wpscan</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wpscan.com/vulnerability/f4b12179-3112-465a-97e1-314721f7fe3d/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/karlemilnikka/CVE-2024-1208-and-CVE-2024-1210" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-1210" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://www.learndash.com/release-notes/" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/61ca5ab6-5fe9-4313-9b0d-8736663d0e89?source=cve" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="learndash lms &lt; 4.10.2 - sensitive information exposure via assignments medium identify critical remote vulnerabilities the learndash lms plugin for wordpress is vulnerable to sensitive information exposure in all versions up to, and including, 4.10.1 via direct file access due to insufficient protection of uploaded assignments. this makes it possible for unauthenticated attackers to obtain those uploads. cve-2024-1209 ritikchaddha cve cve2024 exposure learndash vuln wordpress wp wp-plugin wpscan" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">LearnDash LMS &lt; 4.10.2 - Sensitive Information Exposure via assignments</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-1209.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-1209.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 21, 2024</span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-1209" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-1209</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/sfwd-lms&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The LearnDash LMS plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.10.1 via direct file access due to insufficient protection of uploaded assignments. This makes it possible for unauthenticated attackers to obtain those uploads.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can access the LearnDash API to obtain uploaded student assignments and coursework that should be restricted to instructors and enrolled learners.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Fixed in 4.10.2</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">exposure</span><span class="nt-tag">learndash</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">wpscan</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wpscan.com/vulnerability/f813a21d-7a6a-4ff4-a43c-3e2991a23c7f/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/karlemilnikka/CVE-2024-1209" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-1209" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://www.learndash.com/release-notes/" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/7191955e-0db1-4ad1-878b-74f90ca59c91?source=cve" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="learndash lms &lt; 4.10.3 - sensitive information exposure medium identify critical remote vulnerabilities the learndash lms plugin for wordpress is vulnerable to sensitive information exposure in all versions up to, and including, 4.10.2 via api. this makes it possible for unauthenticated attackers to obtain access to quiz questions. cve-2024-1208 ritikchaddha cve cve2024 exposure learndash vuln wordpress wp wp-plugin" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">LearnDash LMS &lt; 4.10.3 - Sensitive Information Exposure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-1208.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-1208.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 20, 2024</span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-1208" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-1208</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/sfwd-lms&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The LearnDash LMS plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.10.2 via API. This makes it possible for unauthenticated attackers to obtain access to quiz questions.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can access the LearnDash API to obtain quiz questions, answer options, and point values, compromising the integrity of course assessments.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Fixed in 4.10.3</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">exposure</span><span class="nt-tag">learndash</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/karlemilnikka/CVE-2024-1208-and-CVE-2024-1210" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-1208" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ae735117-e68b-448e-ad41-258d1be3aebc?source=cve" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/nomi-sec/PoC-in-GitHub" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/fkie-cad/nvd-json-data-feeds" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="learnpress &lt; 4.2.6.8.1 - information disclosure medium identify critical remote vulnerabilities learnpress – wordpress lms plugin contains a sensitive information exposure caused by incorrect implementation of get_items_permissions_check function in all versions up to 4.2.6.8, letting unauthenticated attackers extract user emails and basic information. cve-2024-5483 pussycat0x cve cve2024 info-leak learnpress vuln wordpress wp-plugin wpscan cwe-200" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">LearnPress &lt; 4.2.6.8.1 - Information Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-5483.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-5483.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 8, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-5483" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-5483</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/learnpress/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">LearnPress – WordPress LMS Plugin contains a sensitive information exposure caused by incorrect implementation of get_items_permissions_check function in all versions up to 4.2.6.8, letting unauthenticated attackers extract user emails and basic information.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can access sensitive user information, including emails, leading to privacy breaches.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to version 4.2.6.9 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">info-leak</span><span class="nt-tag">learnpress</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">wpscan</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wpscan.com/vulnerability/1f253156-333b-4be6-b727-06237567be1e/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="learnpress &lt; 4.2.7.1 - sql injection critical identify critical remote vulnerabilities the learnpress - wordpress lms plugin plugin for wordpress is vulnerable to sql injection via the &#39;c_only_fields&#39; parameter of the /wp-json/learnpress/v1/courses rest api endpoint in all versions up to, and including, 4.2.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing sql query. this makes it possible for unauthenticated attackers to append additional sql queries into already existing queries that can be used to extract sensitive information from the database. cve-2024-8522 pdresearch,iamnoooob,rootxharsh cve cve2024 learnpress sqli time-based-sqli vkev vuln wordpress wp wp-plugin cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">LearnPress &lt; 4.2.7.1 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-8522.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-8522.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pdresearch,iamnoooob,rootxharsh</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 19, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-8522" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-8522</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/learnpress&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The LearnPress - WordPress LMS Plugin plugin for WordPress is vulnerable to SQL Injection via the &#39;c_only_fields&#39; parameter of the /wp-json/learnpress/v1/courses REST API endpoint in all versions up to, and including, 4.2.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized accessand data leakage.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches and updates from the vendor to address this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">learnpress</span><span class="nt-tag">sqli</span><span class="nt-tag">time-based-sqli</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/advisories/GHSA-3w3r-r6g6-w8x5" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-8522" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="learnpress &lt; 4.2.7.1 - sql injection critical identify critical remote vulnerabilities the learnpress wordpress lms plugin before 4.2.7.1 is vulnerable to unauthenticated sql injection via the &#39;c_fields&#39; parameter in the /wp-json/lp/v1/courses/archive-course rest api endpoint, allowing attackers to extract sensitive information from the database. cve-2024-8529 ritikchaddha,iacker cve cve2024 learnpress sqli time-based-sqli vkev vuln wordpress wp wp-plugin cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">LearnPress &lt; 4.2.7.1 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-8529.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-8529.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha,iacker</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 22, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-8529" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-8529</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)wp-content/plugins/learnpress&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The LearnPress WordPress LMS Plugin before 4.2.7.1 is vulnerable to unauthenticated SQL injection via the &#39;c_fields&#39; parameter in the /wp-json/lp/v1/courses/archive-course REST API endpoint, allowing attackers to extract sensitive information from the database.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can exploit SQL injection through the c_fields parameter to extract sensitive database information including user credentials, course data, and personal information from the LearnPress LMS.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update the LearnPress plugin to version 4.2.7.1 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">learnpress</span><span class="nt-tag">sqli</span><span class="nt-tag">time-based-sqli</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wpscan.com/vulnerability/6b86c089-177b-45b4-979e-4ae08e586e83/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c2b2671e-0db7-4ba9-b574-a0122959e8fc" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-8529" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="learnpress &lt; 4.2.7.4 - course material - information disclosure medium identify critical remote vulnerabilities learnpress – wordpress lms plugin contains a sensitive information exposure caused by insecure handling in class-lp-rest-material-controller.php, letting unauthenticated attackers extract paid course material, exploit requires no authentication. cve-2024-11868 pussycat0x cve cve2024 learnpress vkev wordpress wp-plugin wp-scan cwe-284" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">LearnPress &lt; 4.2.7.4 - Course Material - Information Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-11868.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-11868.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 8, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/284.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-284</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-11868" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-11868</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/learnpress/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">LearnPress – WordPress LMS Plugin contains a sensitive information exposure caused by insecure handling in class-lp-rest-material-controller.php, letting unauthenticated attackers extract paid course material, exploit requires no authentication.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can access and extract sensitive paid course content, leading to intellectual property theft and privacy breaches.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest version beyond 4.2.7.3 or apply security patches provided by the vendor.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">learnpress</span><span class="nt-tag">vkev</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">wp-scan</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wpscan.com/vulnerability/7524ffd8-3506-48f7-89b6-d07b40533756/8" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="learnpress &lt; 4.3.0 - arbitrary callback execution to information exposure medium identify critical remote vulnerabilities the learnpress – wordpress lms plugin plugin for wordpress is vulnerable to sensitive information disclosure in all versions up to, and including, 4.2.9.4. this is due to missing capability checks in the rest endpoint /wp-json/lp/v1/load_content_via_ajax which allows arbitrary callback execution of admin-only template methods. this makes it possible for unauthenticated attackers to retrieve admin curriculum html, quiz questions with correct answers, course materials, and other sensitive educational content via the rest api endpoint granted they can supply valid numeric ids. cve-2025-11368 pussycat0x cve cve2025 learnpress vkev wordpress wp-plugin wp-scan cwe-200" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">LearnPress &lt; 4.3.0 - Arbitrary Callback Execution to Information Exposure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-11368.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-11368.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 8, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-11368" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-11368</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/learnpress/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Sensitive Information Disclosure in all versions up to, and including, 4.2.9.4. This is due to missing capability checks in the REST endpoint /wp-json/lp/v1/load_content_via_ajax which allows arbitrary callback execution of admin-only template methods. This makes it possible for unauthenticated attackers to retrieve admin curriculum HTML, quiz questions with correct answers, course materials, and other sensitive educational content via the REST API endpoint granted they can supply valid numeric IDs.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can access sensitive admin curriculum, quiz answers, and course materials, compromising educational content confidentiality.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest version beyond 4.2.9.4.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">learnpress</span><span class="nt-tag">vkev</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">wp-scan</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wpscan.com/vulnerability/5c40d803-87b3-437b-b514-1e85b43371a0/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="learnpress &lt; 4.3.2 - broken access control medium identify critical remote vulnerabilities the learnpress – wordpress lms plugin plugin for wordpress is vulnerable to unauthorized access of data due to a missing capability check on the statistic function in all versions up to, and including, 4.3.1. this makes it possible for unauthenticated attackers to view the plugin&#39;s orders statistics, including total revenue summaries and order status counts. cve-2025-13956 pussycat0x cve cve2025 exposure learnpress wordpress wp wp-plugin cwe-862" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">LearnPress &lt; 4.3.2 - Broken Access Control</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-13956.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-13956.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 8, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/862.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-862</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-13956" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-13956</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/learnpress/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the statistic function in all versions up to, and including, 4.3.1. This makes it possible for unauthenticated attackers to view the plugin&#39;s orders statistics, including total revenue summaries and order status counts.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can view sensitive order statistics including revenue and order status, leading to information disclosure.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to a version later than 4.3.1 or the latest available version.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">exposure</span><span class="nt-tag">learnpress</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wpscan.com/vulnerability/b4c0e309-45d1-4b00-875d-ec8a76910253/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-13956" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="learnpress &lt;= 4.2.5.7 - sql injection high identify critical remote vulnerabilities the learnpress plugin for wordpress is vulnerable to time-based sql injection via the &#39;order_by&#39; parameter in all versions up to, and including, 4.2.5.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing sql query. this makes it possible for unauthenticated attackers to append additional sql queries into already existing queries that can be used to extract sensitive information from the database. cve-2023-6567 iamnoooob,rootxharsh,pdresearch cve cve2023 learnpress sqli thimpress time-based-sqli vkev vuln wordpress wp wp-plugin wpscan cwe-89" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">LearnPress &lt;= 4.2.5.7 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-6567.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-6567.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> iamnoooob,rootxharsh,pdresearch</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 9, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-6567" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-6567</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/learnpress&#34; || service[&#34;http.body&#34;] matches &#34;(?i)wp-content/plugins/learnpress&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The LearnPress plugin for WordPress is vulnerable to time-based SQL Injection via the &#39;order_by&#39; parameter in all versions up to, and including, 4.2.5.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can execute time-based SQL injection through the order_by parameter to extract the complete WordPress database including user credentials and course data.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Fixed in version 4.2.5.8</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">learnpress</span><span class="nt-tag">sqli</span><span class="nt-tag">thimpress</span><span class="nt-tag">time-based-sqli</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">wpscan</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/learnpress/learnpress-4257-unauthenticated-sql-injection-via-order-by" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://wpscan.com/vulnerability/c5110450-3b4e-4100-8db4-0d7f5d43c12f/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-6567" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://plugins.trac.wordpress.org/changeset/3013957/learnpress" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/6ab578cd-3a0b-43d3-aaa7-0a01f431a4e2?source=cve" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="learnpress plugin &lt; 4.2.0 - local file inclusion critical identify critical remote vulnerabilities local file inclusion vulnerability in learnpress – wordpress lms plugin &lt;= 4.1.7.3.2 versions. cve-2022-47615 dhiyaneshdk cve cve2022 learnpress lfi thimpress vkev vuln wordpress wp wp-plugin cwe-434" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">LearnPress Plugin &lt; 4.2.0 - Local File Inclusion</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-47615.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-47615.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 23, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/434.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-434</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-47615" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-47615</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/learnpress&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Local File Inclusion vulnerability in LearnPress – WordPress LMS Plugin &lt;= 4.1.7.3.2 versions.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could lead to unauthorized access to sensitive files, remote code execution, or information disclosure.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to the latest version of LearnPress Plugin (4.2.0 or higher) to mitigate this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">learnpress</span><span class="nt-tag">lfi</span><span class="nt-tag">thimpress</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/RandomRobbieBF/CVE-2022-47615/tree/main" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-47615" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://patchstack.com/database/vulnerability/learnpress/wordpress-learnpress-plugin-4-1-7-3-2-local-file-inclusion?_s_id=cve" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/RandomRobbieBF/CVE-2022-47615" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="learnpress plugin &lt; 4.2.0 - unauthenticated time-based blind sqli critical identify critical remote vulnerabilities sql injection vulnerability in learnpress – wordpress lms plugin &lt;= 4.1.7.3.2 versions. cve-2022-45808 dhiyaneshdk cve cve2022 learnpress sqli time-based-sqli vkev vuln wordpress wp wp-plugin cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">LearnPress Plugin &lt; 4.2.0 - Unauthenticated Time-Based Blind SQLi</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-45808.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-45808.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 20, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-45808" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-45808</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/learnpress&#34; || service[&#34;http.body&#34;] matches &#34;(?i)wp-content/plugins/learnpress&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">SQL Injection vulnerability in LearnPress – WordPress LMS Plugin &lt;= 4.1.7.3.2 versions.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can execute time-based blind SQL injection through the order_by parameter in the LearnPress courses archive endpoint, potentially extracting sensitive database information including user credentials, course data, and student information.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update LearnPress plugin to version 4.2.0 or later that properly sanitizes and parameterizes the order_by parameter.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">learnpress</span><span class="nt-tag">sqli</span><span class="nt-tag">time-based-sqli</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://patchstack.com/database/vulnerability/learnpress/wordpress-learnpress-wordpress-lms-plugin-plugin-4-1-7-3-2-sql-injection?_s_id=cve" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/RandomRobbieBF/CVE-2022-45808" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="lenovo fan power controller login panel - detect info identify web-based control panels lenovo fan power controller login panel was detected. megamansec discovery lenovo panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Lenovo Fan Power Controller Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/lenovo-fp-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">lenovo-fp-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> megamansec</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)fan and power controller&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Lenovo Fan Power Controller login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">lenovo</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="leostream default login high identify default logins in web-based control panels leostream default admin credentials were discovered. bhutch default-login leostream vuln cwe-522" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Leostream Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/leostream/leostream-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">leostream-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> bhutch</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 6, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/522.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-522</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;Leostream&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Leostream default admin credentials were discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">leostream</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="leostream login panel - detect info identify web-based control panels leostream login panel was detected. praetorian-thendrickson discovery leostream panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Leostream Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/leostream-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">leostream-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> praetorian-thendrickson</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Leostream&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Leostream login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">leostream</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://leostream.com" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="letta letta 0.7.12 - remote code execution high identify critical remote vulnerabilities letta 0.7.12 is vulnerable to remote code execution via post /v1/tools/run in letta.server.rest_api.routers.v1.tools.run_tool_from_source, allowing attackers to execute arbitrary python and os commands via crafted tool source code. cve-2025-51482 raghavarora14 cve cve2025 letta rce vkev cwe-94" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Letta Letta 0.7.12 - Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-51482.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-51482.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> RaghavArora14</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 29, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/94.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-94</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-51482" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-51482</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Letta&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Letta 0.7.12 is vulnerable to remote code execution via POST /v1/tools/run in letta.server.rest_api.routers.v1.tools.run_tool_from_source, allowing attackers to execute arbitrary Python and OS commands via crafted tool source code.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can execute arbitrary Python code through crafted tool source code in the /v1/tools/run endpoint, achieving remote code execution.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade Letta to a version later than 0.7.12 that properly validates and sandboxes tool source code execution.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">letta</span><span class="nt-tag">rce</span><span class="nt-tag">vkev</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.gecko.security/blog/cve-2025-51482" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/letta-ai/letta/pull/2630" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/Kai-One001/Letta-CVE-2025-51482-RCE" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-51482" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="letta panel - detect info identify web-based control panels letta (formerly memgpt) is an open-source framework for building stateful llm agents with long-term memory. rxerium ai detect discovery letta llm memgpt panel" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Letta Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/letta-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">letta-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 27, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;^Letta$&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Letta (formerly MemGPT) is an open-source framework for building stateful LLM agents with long-term memory.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">ai</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">letta</span><span class="nt-tag">llm</span><span class="nt-tag">memgpt</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/letta-ai/letta" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.letta.com" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="librechat &lt;= 0.7.9 - html injection via accept-language header medium identify critical remote vulnerabilities danny-avila/librechat 0.7.9 contains a stored xss caused by improper sanitization of the accept-language header, letting logged-in users inject arbitrary html into the html lang= tag, exploit requires user to be logged in. cve-2025-8848 kazgangap cve cve2025 html-injection librechat cwe-79" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">LibreChat &lt;= 0.7.9 - HTML Injection via Accept-Language Header</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-8848.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-8848.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Kazgangap</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 31, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-79</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-8848" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-8848</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;product&#34;] contains &#34;LibreChat:LibreChat&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">danny-avila/librechat 0.7.9 contains a stored XSS caused by improper sanitization of the Accept-Language header, letting logged-in users inject arbitrary HTML into the html lang= tag, exploit requires user to be logged in.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Logged-in attackers can inject arbitrary HTML leading to cross-site scripting attacks, potentially compromising user sessions or data.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest version where this issue is fixed.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">html-injection</span><span class="nt-tag">librechat</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-8848" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://huntr.com/bounties/a05ebc1f-882a-4adc-b178-d3cefa4b730e" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/danny-avila/LibreChat" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="librechat login panel - detection info identify web-based control panels detected librechat login panel. librechat is an open-source, self-hosted ai chat interface. kazgangap panel librechat discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">LibreChat Login Panel - Detection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/librechat-login-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">librechat-login-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Kazgangap</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 31, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;product&#34;] contains &#34;LibreChat:LibreChat&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detected LibreChat login panel. LibreChat is an open-source, self-hosted AI chat interface.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">librechat</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/danny-avila/LibreChat" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="librenms login panel - detect info identify web-based control panels librenms login panel was detected. pikpikcu librenms panel discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">LibreNMS Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/librenms-login.yaml" target="_blank" rel="noopener" class="nt-source-link">librenms-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pikpikcu</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)librenms&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">LibreNMS login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">librenms</span><span class="nt-tag">panel</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="librephotos panel - detect info identify web-based control panels  ritikchaddha panel librephotos detect login discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">LibrePhotos Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/librephotos-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">librephotos-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 9, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)LibrePhotos&#34;})</code></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">librephotos</span><span class="nt-tag">detect</span><span class="nt-tag">login</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/LibrePhotos/librephotos" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="librespeed panel - detect info identify web-based control panels librespeed is a very lightweight speed test implemented in javascript, using xmlhttprequest and web workers. ritikchaddha panel librespeed detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">LibreSpeed Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/librespeed-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">librespeed-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 8, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)LibreSpeed&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">LibreSpeed is a very lightweight speed test implemented in Javascript, using XMLHttpRequest and Web Workers.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">librespeed</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/librespeed/speedtest" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="liferay login panel - detect info identify web-based control panels liferay login panel was detected, organiccrap,dwisiswant0,ricardomaia discovery liferay panel portal cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Liferay Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/liferay-portal.yaml" target="_blank" rel="noopener" class="nt-source-link">liferay-portal.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> organiccrap,dwisiswant0,ricardomaia</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;129457226&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Liferay login panel was detected,</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">liferay</span><span class="nt-tag">panel</span><span class="nt-tag">portal</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.liferay.com/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/mzer0one/CVE-2020-7961-POC" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="liferay portal unauthenticated &lt; 7.2.1 ce ga2 - remote code execution critical identify critical remote vulnerabilities liferay portal prior to 7.2.1 ce ga2 allows remote attackers to execute arbitrary code via json web services (jsonws). cve-2020-7961 dwisiswant0 cve cve2020 kev liferay packetstorm rce vkev vuln cwe-502" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Liferay Portal Unauthenticated &lt; 7.2.1 CE GA2 - Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2020/CVE-2020-7961.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2020-7961.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dwisiswant0</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/502.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-502</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2020-7961" target="_blank" rel="noopener" class="nt-cve-link">CVE-2020-7961</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;129457226&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary code via JSON web services (JSONWS).</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can execute arbitrary code via JSON web services, leading to complete server compromise and access to all portal data.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade Liferay Portal to version 7.2.1 CE GA2 or later to mitigate the vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2020</span><span class="nt-tag">kev</span><span class="nt-tag">liferay</span><span class="nt-tag">packetstorm</span><span class="nt-tag">rce</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.synacktiv.com/en/publications/how-to-exploit-liferay-cve-2020-7961-quick-journey-to-poc.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://codewhitesec.blogspot.com/2020/03/liferay-portal-json-vulns.html" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/id/117954271" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2020-7961" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="http://packetstormsecurity.com/files/157254/Liferay-Portal-Java-Unmarshalling-Remote-Code-Execution.html" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="lightdash version &lt;= 0.510.3 arbitrary file read high identify critical remote vulnerabilities packages/backend/src/routers in lightdash before 0.510.3
has insecure file endpoints, e.g., they allow .. directory
traversal and do not ensure that an intended file extension
(.csv or .png) is used. cve-2023-35844 dwisiswant0 cve cve2023 lfi lightdash vkev vuln cwe-22" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Lightdash version &lt;= 0.510.3 Arbitrary File Read</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-35844.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-35844.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dwisiswant0</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 20, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-35844" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-35844</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)lightdash&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">packages/backend/src/routers in Lightdash before 0.510.3
has insecure file endpoints, e.g., they allow .. directory
traversal and do not ensure that an intended file extension
(.csv or .png) is used.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">The vulnerability can lead to unauthorized access to sensitive information, potentially exposing user credentials, database credentials, and other confidential data.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade Lightdash to a version higher than 0.510.3 to mitigate the vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">lfi</span><span class="nt-tag">lightdash</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://advisory.dw1.io/59" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-35844" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/lightdash/lightdash/commit/fcc808c84c2cc3afb343063e32a49440d32a553c" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/lightdash/lightdash/compare/0.510.2...0.510.3" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/lightdash/lightdash/pull/5090" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="limesurvey - default admin credentials high identify default logins in web-based control panels detected the limesurvey survey management platform was found to be using default administrator credentials (admin:password). an attacker was able to gain full administrative access to manage surveys, responses, and user accounts. 0x_akoko limesurvey default-login auth" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">LimeSurvey - Default Admin Credentials</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/limesurvey-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">limesurvey-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_Akoko</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 25, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)LimeSurvey&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detected the LimeSurvey survey management platform was found to be using default administrator credentials (admin:password). An attacker was able to gain full administrative access to manage surveys, responses, and user accounts.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">limesurvey</span><span class="nt-tag">default-login</span><span class="nt-tag">auth</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/LimeSurvey/LimeSurvey/blob/master/application/config/config-defaults.php" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.limesurvey.org/manual/Optional_settings" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="lin cms spring boot - default jwt token high identify critical remote vulnerabilities an access control issue in lin cms spring boot v0.2.1 allows attackers to access the backend information and functions within the application. cve-2022-32430 dhiyaneshdk auth-bypass cve cve2022 lin-cms talelin vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Lin CMS Spring Boot - Default JWT Token</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-32430.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-32430.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 3, 2024</span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-32430" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-32430</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)心上无垢，林间有风&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An access control issue in Lin CMS Spring Boot v0.2.1 allows attackers to access the backend information and functions within the application.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can access backend administrative information and functions using a hardcoded default JWT token, potentially gaining complete control over the Lin CMS Spring Boot application including user management and content administration.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update Lin CMS Spring Boot to a version later than 0.2.1 that uses unique JWT secret keys, removes hardcoded tokens, and implements proper token rotation.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">lin-cms</span><span class="nt-tag">talelin</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/TaleLin/lin-cms-spring-boot" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://web.archive.org/web/20220721190946/https://www.mesec.cn/archives/277" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-32430" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="linshare login panel - detect info identify web-based control panels linshare login panel was detected. righettod panel linshare login detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">LinShare Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/linshare-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">linshare-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 21, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)LinShare&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">LinShare login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">linshare</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.linshare.org/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/linagora/linshare" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="linear emerge e3-series - cross-site scripting medium identify critical remote vulnerabilities linear emerge e3-series devices contain a cross-site scripting vulnerability via the type parameter, e.g., to the badging/badge_template_v0.php component. an attacker can inject arbitrary script in the browser of an unsuspecting user in the context of the affected site and thus steal cookie-based authentication credentials and launch other attacks. this affects versions 0.32-08f, 0.32-07p, 0.32-07e, 0.32-09c, 0.32-09b, 0.32-09a, and 0.32-08e. cve-2022-46381 arafatansari cve cve2022 emerge linear niceforyou vkev vuln xss cwe-79" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Linear eMerge E3-Series - Cross-Site Scripting</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-46381.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-46381.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> arafatansari</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-79</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-46381" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-46381</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Linear eMerge&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Linear eMerge E3-Series devices contain a cross-site scripting vulnerability via the type parameter, e.g., to the badging/badge_template_v0.php component. An attacker can inject arbitrary script in the browser of an unsuspecting user in the context of the affected site and thus steal cookie-based authentication credentials and launch other attacks. This affects versions 0.32-08f, 0.32-07p, 0.32-07e, 0.32-09c, 0.32-09b, 0.32-09a, and 0.32-08e.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute arbitrary script code in the context of a victim&#39;s browser, leading to session hijacking, defacement, or theft of sensitive information.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patch or update provided by the vendor to fix the XSS vulnerability in the Linear eMerge E3-Series.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">emerge</span><span class="nt-tag">linear</span><span class="nt-tag">niceforyou</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">xss</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-46381" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/omarhashem123/Security-Research/blob/main/CVE-2022-46381/CVE-2022-46381.txt" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-46381" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/amitlttwo/CVE-2022-46381" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/k0mi-tg/CVE-POC" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="linear emerge e3-series - information disclosure high identify critical remote vulnerabilities linear emerge e3-series devices are susceptible to information disclosure. admin credentials are stored in clear text at the endpoint /test.txt in situations where the default admin credentials have been changed. an attacker can obtain admin credentials, access the admin dashboard, control building access and cameras, and access employee information. cve-2022-31269 for3stco1d cve cve2022 emerge exposure nortekcontrol packetstorm vuln cwe-798" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Linear eMerge E3-Series - Information Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-31269.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-31269.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> For3stCo1d</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/798.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-798</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-31269" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-31269</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)linear emerge&#34;}) || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)emerge&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Linear eMerge E3-Series devices are susceptible to information disclosure. Admin credentials are stored in clear text at the endpoint /test.txt in situations where the default admin credentials have been changed. An attacker can obtain admin credentials, access the admin dashboard, control building access and cameras, and access employee information.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can exploit this vulnerability to gain sensitive information from the device.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest firmware update provided by the vendor to fix the vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">emerge</span><span class="nt-tag">exposure</span><span class="nt-tag">nortekcontrol</span><span class="nt-tag">packetstorm</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://packetstormsecurity.com/files/167990/Nortek-Linear-eMerge-E3-Series-Credential-Disclosure.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.nortekcontrol.com/access-control/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://eg.linkedin.com/in/omar-1-hashem" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31269" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/ARPSyndicate/cvemon" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="linkerd panel - detect info identify web-based control panels linkerd panel was detected. tess discovery exposure linkerd misconfig panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Linkerd Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/linkerd-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">linkerd-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> tess</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)data-controller-namespace&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Linkerd panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">exposure</span><span class="nt-tag">linkerd</span><span class="nt-tag">misconfig</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="linksys smart wi-fi login panel - detect info identify web-based control panels linksys smart wi-fi login panel was detected. pussycat0x tech panel linksys iot discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Linksys Smart Wi-Fi Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/linksys-wifi-login.yaml" target="_blank" rel="noopener" class="nt-source-link">linksys-wifi-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Linksys Smart WI-FI&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Linksys Smart Wi-Fi login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">tech</span><span class="nt-tag">panel</span><span class="nt-tag">linksys</span><span class="nt-tag">iot</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="linkwarden panel - detect info identify web-based control panels linkwarden (linkwarden.app / github.com/linkwarden/linkwarden) is a popular open-source self-hosted bookmark and link archiving manager. default docker port 3000. exposed instances may reveal users&#39; archived link collections, screenshots, and pdfs. chrisjr404 bookmarks detect discovery linkwarden panel selfhosted" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Linkwarden Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/linkwarden-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">linkwarden-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ChrisJr404</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 6, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1726765983&#34; || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Linkwarden&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Linkwarden (linkwarden.app / github.com/linkwarden/linkwarden) is a popular open-source self-hosted bookmark and link archiving manager. Default Docker port 3000. Exposed instances may reveal users&#39; archived link collections, screenshots, and PDFs.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">bookmarks</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">linkwarden</span><span class="nt-tag">panel</span><span class="nt-tag">selfhosted</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/linkwarden/linkwarden" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://linkwarden.app/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="listserv maestro &lt;= 9.0-8 rce medium identify critical remote vulnerabilities a struts-based ognl remote code execution vulnerability exists in listserv maestro before and including version 9.0-8. cve-2010-1870 b0yd apache cve cve2010 edb listserv ognl packetstorm rce vuln cwe-917" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">ListSERV Maestro &lt;= 9.0-8 RCE</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2010/CVE-2010-1870.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2010-1870.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> b0yd</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/917.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-917</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2010-1870" target="_blank" rel="noopener" class="nt-cve-link">CVE-2010-1870</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)struts problem report&#34; || service[&#34;http.body&#34;] matches &#34;(?i)apache struts&#34; || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)struts2 showcase&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A struts-based OGNL remote code execution vulnerability exists in ListSERV Maestro before and including version 9.0-8.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to a patched version of ListSERV Maestro that is not affected by this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">apache</span><span class="nt-tag">cve</span><span class="nt-tag">cve2010</span><span class="nt-tag">edb</span><span class="nt-tag">listserv</span><span class="nt-tag">ognl</span><span class="nt-tag">packetstorm</span><span class="nt-tag">rce</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.securifera.com/advisories/sec-2020-0001/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://packetstormsecurity.com/files/159643/listservmaestro-exec.txt" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.exploit-db.com/exploits/14360" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="http://confluence.atlassian.com/display/FISHEYE/FishEye+Security+Advisory+2010-06-16" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="http://blog.o0o.nu/2010/07/cve-2010-1870-struts2xwork-remote.html" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="listingpro &lt; 2.6.1 - arbitrary plugin installation/activation/deactivation critical identify critical remote vulnerabilities the listingpro - wordpress directory &amp; listing theme for wordpress is vulnerable to arbitrary plugin installation, activation and deactivation in versions before 2.6.1. this is due to a missing capability check on the lp_cc_addons_actions function. this makes it possible for unauthenticated attackers to arbitrarily install, activate and deactivate any plugin. cve-2020-36719 ritikchaddha cve cve2020 listingpro passive vkev vuln wp wp-pluginwordpress cwe-862" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">ListingPro &lt; 2.6.1 - Arbitrary Plugin Installation/Activation/Deactivation</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2020/CVE-2020-36719.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2020-36719.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 24, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/862.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-862</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2020-36719" target="_blank" rel="noopener" class="nt-cve-link">CVE-2020-36719</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/listingpro&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The ListingPro - WordPress Directory &amp; Listing Theme for WordPress is vulnerable to Arbitrary Plugin Installation, Activation and Deactivation in versions before 2.6.1. This is due to a missing capability check on the lp_cc_addons_actions function. This makes it possible for unauthenticated attackers to arbitrarily install, activate and deactivate any plugin.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can arbitrarily install, activate or deactivate plugins, potentially installing malicious plugins to gain complete site control.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to ListingPro version 2.6.1 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2020</span><span class="nt-tag">listingpro</span><span class="nt-tag">passive</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">wp</span><span class="nt-tag">wp-pluginwordpress</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://blog.nintechnet.com/wordpress-listingpro-theme-fixed-a-critical-vulnerability/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2020-36719" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="listingpro &lt; 2.6.1 - sensitive data disclosure high identify critical remote vulnerabilities the listingpro - wordpress directory &amp; listing theme for wordpress is vulnerable to sensitive data exposure in versions before 2.6.1 via the ~/listingpro-plugin/functions.php file. this makes it possible for unauthenticated attackers to extract sensitive data including usernames, full names, email addresses, phone numbers, physical addresses and user post counts. cve-2020-36723 ritikchaddha cve cve2020 exposure listingpro vkev vuln wordpress wp wp-plugin cwe-200" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">ListingPro &lt; 2.6.1 - Sensitive Data Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2020/CVE-2020-36723.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2020-36723.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 24, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2020-36723" target="_blank" rel="noopener" class="nt-cve-link">CVE-2020-36723</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/listingpro&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The ListingPro - WordPress Directory &amp; Listing Theme for WordPress is vulnerable to Sensitive Data Exposure in versions before 2.6.1 via the ~/listingpro-plugin/functions.php file. This makes it possible for unauthenticated attackers to extract sensitive data including usernames, full names, email addresses, phone numbers, physical addresses and user post counts.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can extract sensitive user data including usernames, email addresses, phone numbers, and physical addresses from all registered users.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to ListingPro version 2.6.1 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2020</span><span class="nt-tag">exposure</span><span class="nt-tag">listingpro</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wpscan.com/vulnerability/096e6e16-c14d-42da-8ba3-c271db3385a4/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2020-36723" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="litellm api - swagger ui detection info identify web-based control panels detects exposed litellm api swagger ui interface. litellm is a unified api for 100+ llm providers (openai, azure, anthropic, etc.). rxerium tech litellm swagger api ai llm" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">LiteLLM API - Swagger UI Detection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/technologies/litellm-swagger-detect.yaml" target="_blank" rel="noopener" class="nt-source-link">litellm-swagger-detect.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 20, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)LiteLLM API - Swagger UI&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detects exposed LiteLLM API Swagger UI interface. LiteLLM is a unified API for 100+ LLM providers (OpenAI, Azure, Anthropic, etc.).</div></div></div>
  <div class="nt-tags"><span class="nt-tag">tech</span><span class="nt-tag">litellm</span><span class="nt-tag">swagger</span><span class="nt-tag">api</span><span class="nt-tag">ai</span><span class="nt-tag">llm</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/BerriAI/litellm" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://docs.litellm.ai/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="live helper chat admin login panel - detect info identify web-based control panels live helper chat admin login panel was detected. ritikchaddha discovery livehelperchat panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Live Helper Chat Admin Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/livehelperchat-admin-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">livehelperchat-admin-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)live helper chat&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Live Helper Chat admin login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">livehelperchat</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="livezilla login panel - detect info identify web-based control panels livezilla login panel was detected. __fazal discovery livezilla login panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">LiveZilla Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/livezilla-login-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">livezilla-login-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> __Fazal</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)livezilla&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">LiveZilla login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">livezilla</span><span class="nt-tag">login</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="localai - partial local file read medium identify critical remote vulnerabilities a vulnerability in the /models/apply endpoint of mudler/localai versions 2.15.0 allows for server-side request forgery (ssrf) and partial local file inclusion (lfi). the endpoint supports both http(s)-// and file-// schemes, where the latter can lead to lfi. however, the output is limited due to the length of the error message. this vulnerability can be exploited by an attacker with network access to the localai instance, potentially allowing unauthorized access to internal http(s) servers and partial reading of local files. the issue is fixed in version 2.17. cve-2024-6095 iamnoooob,pdresearch,rootxharsh cve cve2024 lfi localai mudler vuln cwe-918" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">LocalAI - Partial Local File Read</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-6095.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-6095.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> iamnoooob,pdresearch,rootxharsh</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 23, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/918.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-918</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-6095" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-6095</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-976853304&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A vulnerability in the /models/apply endpoint of mudler/localai versions 2.15.0 allows for Server-Side Request Forgery (SSRF) and partial Local File Inclusion (LFI). The endpoint supports both http(s)-// and file-// schemes, where the latter can lead to LFI. However, the output is limited due to the length of the error message. This vulnerability can be exploited by an attacker with network access to the LocalAI instance, potentially allowing unauthorized access to internal HTTP(s) servers and partial reading of local files. The issue is fixed in version 2.17.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can exploit SSRF to access internal HTTP services and partially read local files through error messages, potentially exposing sensitive information.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update LocalAI to version 2.17 or later to address the SSRF and LFI vulnerabilities.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">lfi</span><span class="nt-tag">localai</span><span class="nt-tag">mudler</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/fkie-cad/nvd-json-data-feeds" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/sev-hack/sev-hack" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-6095" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="localgpt panel - detect info identify web-based control panels localgpt is an open-source project that allows users to chat with their documents
locally using llms with no data leaving their device rxerium ai detect discovery llm localgpt panel rag" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">LocalGPT Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/localgpt-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">localgpt-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 27, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;LocalGPT&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">LocalGPT is an open-source project that allows users to chat with their documents
locally using LLMs with no data leaving their device</div></div></div>
  <div class="nt-tags"><span class="nt-tag">ai</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">llm</span><span class="nt-tag">localgpt</span><span class="nt-tag">panel</span><span class="nt-tag">rag</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/PromtEngineer/localGPT" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="lockself login panel - detect info identify web-based control panels lockself login panel was detected. righettod panel lockself login detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">LockSelf Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/lockself-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">lockself-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 9, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)LockSelf&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">LockSelf login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">lockself</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.lockself.com/en/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="locklizard web viewer login panel - detect info identify web-based control panels locklizard web viewer login panel was detected. righettod panel locklizard webviewer discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Locklizard Web Viewer Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/locklizard-webviewer-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">locklizard-webviewer-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Locklizard Web Viewer&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Locklizard Web Viewer login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">locklizard</span><span class="nt-tag">webviewer</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.locklizard.com/pdf_security_webviewer/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="login as user or customer &lt; 3.3 - privilege escalation critical identify critical remote vulnerabilities the plugin lacks authorization checks to ensure that users are allowed to log in as another one, which could allow unauthenticated attackers to obtain a valid admin session. cve-2022-4305 r3y3r53 auth-bypass cve cve2022 login-as-customer-or-user vuln wordpress wp wp-buy wp-plugin wpscan cwe-269" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Login as User or Customer &lt; 3.3 - Privilege Escalation</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-4305.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-4305.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> r3Y3r53</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 17, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/269.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-269</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-4305" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-4305</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/login-as-customer-or-user&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The plugin lacks authorization checks to ensure that users are allowed to log in as another one, which could allow unauthenticated attackers to obtain a valid admin session.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can obtain valid admin sessions by exploiting missing authorization checks in the Login as User or Customer plugin, potentially gaining complete control over the WordPress site and all user accounts.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Fixed in version 3.3</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">login-as-customer-or-user</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-buy</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">wpscan</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wpscan.com/vulnerability/286d972d-7bda-455c-a226-fd9ce5f925bd" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-4305" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/cyllective/CVEs" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="logitech harmony pro installer portal login panel - detect info identify web-based control panels logitech harmony pro installer portal login panel was detected. ritikchaddha panel logitech harmony exposure discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Logitech Harmony Pro Installer Portal Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/logitech-harmony-portal.yaml" target="_blank" rel="noopener" class="nt-source-link">logitech-harmony-portal.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Logitech Harmony Pro Installer&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Logitech Harmony Pro Installer Portal login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">logitech</span><span class="nt-tag">harmony</span><span class="nt-tag">exposure</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="lomnido panel - detect info identify web-based control panels lomnido was detected. righettod lomnido panel login detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Lomnido Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/lomnido-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">lomnido-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 25, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Lomnido Login&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Lomnido was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">lomnido</span><span class="nt-tag">panel</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://lomnido.com/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="looker login panel - detect info identify web-based control panels looker login panel was detected. ritikchaddha,daffainfo panel login looker discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Looker Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/looker-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">looker-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha,daffainfo</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)lookerVersion&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Looker login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">login</span><span class="nt-tag">looker</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="lottiefiles wordpress plugin &lt;= 3.0.0 - missing authorization high identify critical remote vulnerabilities lottiefiles lottiefiles &lt;= 3.0.0 contains a broken access control vulnerability caused by incorrectly configured access control security levels, letting attackers exploit missing authorization, exploit requires no special privileges. cve-2025-68043 pussycat0x cve cve2025 lottiefiles vkev wordpress wp-plugin cwe-862" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">LottieFiles WordPress Plugin &lt;= 3.0.0 - Missing Authorization</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-68043.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-68043.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 24, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/862.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-862</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-68043" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-68043</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/lottiefiles&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">LottieFiles LottieFiles &lt;= 3.0.0 contains a broken access control vulnerability caused by incorrectly configured access control security levels, letting attackers exploit missing authorization, exploit requires no special privileges.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can bypass authorization to access or modify restricted resources, potentially leading to data exposure or unauthorized actions.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest version beyond 3.0.0.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">lottiefiles</span><span class="nt-tag">vkev</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp-plugin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/lottiefiles/lottiefiles-300-missing-authorization" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://patchstack.com/database/Wordpress/Plugin/lottiefiles/vulnerability/wordpress-lottiefiles-plugin-3-0-0-broken-access-control-vulnerability?_s_id=cve" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://plugins.svn.wordpress.org/lottiefiles/" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="loxone intercom video panel - detect info identify web-based control panels loxone intercom video panel was detected. theabhinavgaur panel loxone discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Loxone Intercom Video Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/loxone-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">loxone-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> theabhinavgaur</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Loxone Intercom Video&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Loxone Intercom Video panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">loxone</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="loxone webinterface panel - detect info identify web-based control panels  dhiyaneshdk panel login loxone detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Loxone WebInterface Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/loxone-web-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">loxone-web-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 8, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)&lt;title&gt;Webinterface&lt;/title&gt;&#34;</code></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">login</span><span class="nt-tag">loxone</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="loytec plc - default login high identify default logins in web-based control panels identified loytec plc web interfaces that were accessible using default credentials (admin:loytec4u). these devices were commonly deployed in building automation and industrial control environments. when left unchanged, default credentials could have allowed unauthorized users to gain administrative access to the system. biero-el-corridor default-login loytec vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Loytec PLC - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/loytec/loytec-default-password.yaml" target="_blank" rel="noopener" class="nt-source-link">loytec-default-password.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> biero-el-corridor</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 2, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1081604898&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Identified Loytec PLC web interfaces that were accessible using default credentials (admin:loytec4u). These devices were commonly deployed in building automation and industrial control environments. When left unchanged, default credentials could have allowed unauthorized users to gain administrative access to the system.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">loytec</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="lucee - default login high identify default logins in web-based control panels lucee admin panel using the default login password was discovered. jpg0mez default-login lucee vuln cwe-1392" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Lucee - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/lucee/lucee-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">lucee-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> jpg0mez</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 5, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/1392.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-1392</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;Lucee&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Lucee admin panel using the default login password was discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">lucee</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://support.intranetconnections.com/hc/en-us/articles/115012060627-Lucee-Configuration" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="lucee - unset credentials high identify critical remote vulnerabilities the lucee admin panel has a first-time setup page which allows any user to set the administrator password. jpg0mez lucee default-login unauth vuln cwe-798" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Lucee - Unset Credentials</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/vulnerabilities/other/lucee-unset-credentials.yaml" target="_blank" rel="noopener" class="nt-source-link">lucee-unset-credentials.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> jpg0mez</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 4, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/798.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-798</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Lucee&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The Lucee admin panel has a first-time setup page which allows any user to set the administrator password.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">lucee</span><span class="nt-tag">default-login</span><span class="nt-tag">unauth</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://luceeserver.atlassian.net/browse/LDEV-926" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.petefreitag.com/blog/lucee-admin-password-box/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="lucee &lt; 6.0.1.59 - remote code execution critical identify critical remote vulnerabilities  rootxharsh,iamnoooob,pdresearch lucee oast rce vuln cwe-95" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Lucee &lt; 6.0.1.59 - Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/vulnerabilities/lucee-rce.yaml" target="_blank" rel="noopener" class="nt-source-link">lucee-rce.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rootxharsh,iamnoooob,pdresearch</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 15, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/95.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-95</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Lucee&#34;})</code></div>
  <div class="nt-tags"><span class="nt-tag">lucee</span><span class="nt-tag">oast</span><span class="nt-tag">rce</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://blog.projectdiscovery.io/hello-lucee-let-us-hack-apple-again" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="lucee web and lucee server admin login panel - detect info identify web-based control panels lucee admin login panels were detected in both web and server tabs. dhiyaneshdk,unp4ck panel lucee discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Lucee Web and Lucee Server Admin Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/lucee-login.yaml" target="_blank" rel="noopener" class="nt-source-link">lucee-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDK,unp4ck</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Lucee&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Lucee admin login panels were detected in both Web and Server tabs.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">lucee</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="m-bus converter web interface - detect info identify web-based control panels  dhiyaneshdk panel login m-bus detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">M-Bus Converter Web Interface - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/m-bus-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">m-bus-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 8, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)JC-e converter webinterface&#34;})</code></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">login</span><span class="nt-tag">m-bus</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="m-files web login panel - detect info identify web-based control panels m-files web login panel was detected. nodauf discovery m-files panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">M-Files Web Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/mfiles-web-detect.yaml" target="_blank" rel="noopener" class="nt-source-link">mfiles-web-detect.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Nodauf</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)m-files web&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">M-Files Web login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">m-files</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.m-files.com/about/trust-center/security-advisories/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="mag dashboard login panel - detect info identify web-based control panels mag dashboard login panel was detected. theamanrawat panel mag discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">MAG Dashboard Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/mag-dashboard-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">mag-dashboard-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> theamanrawat</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)MAG Dashboard Login&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">MAG Dashboard login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">mag</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="mcms 5.2.4 - sql injection critical identify critical remote vulnerabilities mcms 5.2.4 contains a sql injection vulnerability via search.do in the file /mdiy/dict/listexcludeapp. an attacker can possibly obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site. cve-2022-25125 co5mos cve cve2022 mcms mingsoft sqli vuln cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">MCMS 5.2.4 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-25125.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-25125.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Co5mos</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-25125" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-25125</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1464851260&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">MCMS 5.2.4 contains a SQL injection vulnerability via search.do in the file /mdiy/dict/listExcludeApp. An attacker can possibly obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized access, data leakage, or data manipulation.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches or updates provided by the vendor to fix the SQL Injection vulnerability in MCMS 5.2.4.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">mcms</span><span class="nt-tag">mingsoft</span><span class="nt-tag">sqli</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/ming-soft/MCMS/issues/90" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://gitee.com/mingSoft/MCMS/issues/I4TGYI" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-25125" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="mcms 5.2.5 - sql injection critical identify critical remote vulnerabilities mcms 5.2.5 contains a sql injection vulnerability via the categoryid parameter in the file icontentdao.xml. an attacker can potentially obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site. cve-2022-23898 co5mos cve cve2022 mcms mingsoft sqli vuln cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">MCMS 5.2.5 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-23898.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-23898.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Co5mos</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-23898" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-23898</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1464851260&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">MCMS 5.2.5 contains a SQL injection vulnerability via the categoryId parameter in the file IContentDao.xml. An attacker can potentially obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized access, data leakage, or data manipulation.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches or updates provided by the vendor to fix the SQL Injection vulnerability in MCMS 5.2.5.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">mcms</span><span class="nt-tag">mingsoft</span><span class="nt-tag">sqli</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/ming-soft/MCMS/issues/62" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/advisories/GHSA-p94q-9q2m-pfh2" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-23898" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="mcp inspector &lt; 0.14.0 unauthenticatedremote code execution critical identify critical remote vulnerabilities the mcp inspector is a developer tool for testing and debugging mcp servers. versions of mcp inspector below 0.14.1 are vulnerable to remote code execution due to lack of authentication between the inspector client and proxy, allowing unauthenticated requests to launch mcp commands over stdio. cve-2025-49596 ye11oc4t ai anthropic cve cve2025 mcp passive unauth vkev vuln cwe-306" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">MCP Inspector &lt; 0.14.0 UnauthenticatedRemote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-49596.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-49596.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ye11oc4t</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 8, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/306.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-306</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-49596" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-49596</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)MCP Inspector&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The MCP inspector is a developer tool for testing and debugging MCP servers. Versions of MCP Inspector below 0.14.1 are vulnerable to remote code execution due to lack of authentication between the Inspector client and proxy, allowing unauthenticated requests to launch MCP commands over stdio.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can launch arbitrary MCP commands over stdio due to lack of authentication between Inspector client and proxy, enabling remote code execution.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Users should immediately upgrade to version 0.14.1 or later to address these vulnerabilities.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">ai</span><span class="nt-tag">anthropic</span><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">mcp</span><span class="nt-tag">passive</span><span class="nt-tag">unauth</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-49596" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/modelcontextprotocol/inspector" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/modelcontextprotocol/inspector/commit/50df0e1ec488f3983740b4d28d2a968f12eb8979" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/modelcontextprotocol/inspector/security/advisories/GHSA-7f8r-222p-6f5g" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://www.oligo.security/blog/critical-rce-vulnerability-in-anthropic-mcp-inspector-cve-2025-49596" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="misp threat intelligence sharing platform panel - detect info identify web-based control panels  johnk3r,darses discovery misp panel" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">MISP Threat Intelligence Sharing Platform Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/misp-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">misp-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> johnk3r,darses</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 31, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-137577333&#34; || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)users - misp&#34;}) || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)errors - misp&#34;})</code></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">misp</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="mlflow &lt; 2.8.1 - sensitive information disclosure high identify critical remote vulnerabilities an issue in mlflow versions 2.8.1 and before allows a remote attacker to obtain sensitive information via a crafted request to rest api. cve-2023-43472 ritikchaddha cve cve2023 exposure mflow vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">MLFlow &lt; 2.8.1 - Sensitive Information Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-43472.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-43472.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 7, 2024</span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-43472" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-43472</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)mlflow&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An issue in MLFlow versions 2.8.1 and before allows a remote attacker to obtain sensitive information via a crafted request to REST API.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can access sensitive information stored in MLFlow.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade MLFlow to a version that has patched CVE-2023-43472.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">exposure</span><span class="nt-tag">mflow</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.contrastsecurity.com/security-influencers/discovering-mlflow-framework-zero-day-vulnerability-machine-language-model-security-contrast-security" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-43472" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="mlflow absolute path traversal critical identify critical remote vulnerabilities absolute path traversal in github repository mlflow/mlflow prior to 2.5.0. cve-2023-3765 dhiyaneshdk cve cve2023 huntr lfi lfprojects mflow vuln cwe-36" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">MLflow Absolute Path Traversal</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-3765.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-3765.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 21, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/36.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-36</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-3765" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-3765</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)mlflow&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Absolute Path Traversal in GitHub repository mlflow/mlflow prior to 2.5.0.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">This vulnerability can lead to unauthorized access to sensitive information stored on the server.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to a patched version of MLflow to mitigate the Absolute Path Traversal vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">huntr</span><span class="nt-tag">lfi</span><span class="nt-tag">lfprojects</span><span class="nt-tag">mflow</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.tenable.com/cve/CVE-2023-3765" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://huntr.dev/bounties/4be5fd63-8a0a-490d-9ee1-f33dc768ed76" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-3765" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/mlflow/mlflow/commit/6dde93758d42455cb90ef324407919ed67668b9b" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="mlflow job api - authentication bypass critical identify critical remote vulnerabilities mlflow latest version contains an authentication bypass caused by unprotected fastapi job endpoints under /ajax-api/3.0/jobs/* when basic-auth is enabled, letting unauthenticated network clients submit and manage jobs, exploit requires job execution enabled and allowlisted job functions. cve-2026-0545 dhiyaneshdk auth-bypass cve cve2026 mlflow cwe-306" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">MLflow Job API - Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2026/CVE-2026-0545.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2026-0545.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 6, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/306.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-306</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2026-0545" target="_blank" rel="noopener" class="nt-cve-link">CVE-2026-0545</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)MLflow&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">MLflow latest version contains an authentication bypass caused by unprotected FastAPI job endpoints under /ajax-api/3.0/jobs/* when basic-auth is enabled, letting unauthenticated network clients submit and manage jobs, exploit requires job execution enabled and allowlisted job functions.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can execute jobs remotely, potentially leading to remote code execution, denial of service, or data exposure.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest version with fixed authentication enforcement on job endpoints.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2026</span><span class="nt-tag">mlflow</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://huntr.com/bounties/b2e5b028-9541-4d29-8703-a76f1a3734d8" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0545" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/mlflow/mlflow" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="mlflow panel - detect info identify web-based control panels mlflow is an open-source platform for managing the end-to-end machine learning
lifecycle including experimentation, reproducibility, and deployment. this template
detects exposed mlflow tracking server ui instances. rxerium ai detect discovery ml mlflow mlops panel" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">MLflow Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/mlflow-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">mlflow-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 27, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;MLflow&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">MLflow is an open-source platform for managing the end-to-end machine learning
lifecycle including experimentation, reproducibility, and deployment. This template
detects exposed MLflow tracking server UI instances.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">ai</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">ml</span><span class="nt-tag">mlflow</span><span class="nt-tag">mlops</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/mlflow/mlflow" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://mlflow.org" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="mofi4500-4gxelte-v2 default login high identify default logins in web-based control panels mofi network mofi4500-4gxelte wireless router default admin credentials were discovered. pikpikcu default-login mofi vuln cwe-522" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">MOFI4500-4GXeLTE-V2 Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/mofi/mofi4500-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">mofi4500-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pikpikcu</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/522.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-522</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;^MOFI4500&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Mofi Network MOFI4500-4GXELTE wireless router default admin credentials were discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">mofi</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.cleancss.com/router-default/Mofi_Network/MOFI4500-4GXELTE" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="moveit transfer - sql injection critical identify critical remote vulnerabilities in progress moveit transfer before 2021.0.8 (13.0.8), 2021.1.6 (13.1.6), 2022.0.6 (14.0.6), 2022.1.7 (14.1.7), and 2023.0.3 (15.0.3), a sql injection vulnerability has been identified in the moveit transfer web application that could allow an unauthenticated attacker to gain unauthorized access to moveit transfer&#39;s database. an attacker could submit a crafted payload to a moveit transfer application endpoint that could result in modification and disclosure of moveit database content. these are fixed versions of the dll drop-in: 2020.1.10 (12.1.10), 2021.0.8 (13.0.8), 2021.1.6 (13.1.6), 2022.0.6 (14.0.6), 2022.1.7 (14.1.7), and 2023.0.3 (15.0.3). cve-2023-35708 daffainfo,jjcho cve cve2023 moveit progress sqli vkev vuln cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">MOVEit Transfer - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-35708.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-35708.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> daffainfo,jjcho</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 23, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-35708" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-35708</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;product&#34;] contains &#34;Progress Software:MOVEit MFT&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">In Progress MOVEit Transfer before 2021.0.8 (13.0.8), 2021.1.6 (13.1.6), 2022.0.6 (14.0.6), 2022.1.7 (14.1.7), and 2023.0.3 (15.0.3), a SQL injection vulnerability has been identified in the MOVEit Transfer web application that could allow an unauthenticated attacker to gain unauthorized access to MOVEit Transfer&#39;s database. An attacker could submit a crafted payload to a MOVEit Transfer application endpoint that could result in modification and disclosure of MOVEit database content. These are fixed versions of the DLL drop-in: 2020.1.10 (12.1.10), 2021.0.8 (13.0.8), 2021.1.6 (13.1.6), 2022.0.6 (14.0.6), 2022.1.7 (14.1.7), and 2023.0.3 (15.0.3).</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can modify and disclose sensitive database content, leading to data breach and potential system compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to fixed versions: 2020.1.10, 2021.0.8, 2021.1.6, 2022.0.6, 2022.1.7, or latest available version.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">moveit</span><span class="nt-tag">progress</span><span class="nt-tag">sqli</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://x.com/wvuuuuuuuuuuuuu/status/1679969146635710469" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://community.progress.com/s/article/MOVEit-Transfer-Critical-Vulnerability-15June2023" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.progress.com/security/moveit-transfer-and-moveit-cloud-vulnerability" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-35708" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="mpdv mikrolab gmbh hydra x, mip 2 &amp; fedra 2 - path traversal high identify critical remote vulnerabilities mpdv mikrolab gmbh hydra x, mip 2, and fedra 2 &lt;= maintenance pack 36 with servicepack 8 (week 36/2025) contain an unauthenticated local file disclosure vulnerability caused by improper validation of the &#34;filename&#34; parameter in the public $schemas$ resource, letting attackers read arbitrary windows os files, exploit requires local access. cve-2025-12055 theamanrawat cve cve2025 lfi mikrolab mpdv vkev cwe-22" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">MPDV Mikrolab GmbH HYDRA X, MIP 2 &amp; FEDRA 2 - Path Traversal</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-12055.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-12055.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> theamanrawat</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 19, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-12055" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-12055</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)MPDV&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">MPDV Mikrolab GmbH HYDRA X, MIP 2, and FEDRA 2 &lt;= Maintenance Pack 36 with Servicepack 8 (week 36/2025) contain an unauthenticated local file disclosure vulnerability caused by improper validation of the &#34;Filename&#34; parameter in the public $SCHEMAS$ resource, letting attackers read arbitrary Windows OS files, exploit requires local access.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can read arbitrary files on the Windows operating system, potentially exposing sensitive information.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to Maintenance Pack 36 with Servicepack 8 (week 36/2025) or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">lfi</span><span class="nt-tag">mikrolab</span><span class="nt-tag">mpdv</span><span class="nt-tag">vkev</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://seclists.org/fulldisclosure/2025/Oct/28" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-12055" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="mpftvc admin login panel - detect info identify web-based control panels mpftvc admin login panel was detected. hardik-solanki,gmeghab panel mpftvc admin discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">MPFTVC Admin Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/mpftvc-admin-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">mpftvc-admin-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Hardik-Solanki,gmeghab</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)AdminLogin - MPFTVC&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">MPFTVC admin login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">mpftvc</span><span class="nt-tag">admin</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="msnswitch firmware mnt.2408 - authentication bypass critical identify critical remote vulnerabilities msnswitch firmware mnt.2408 is susceptible to authentication bypass in the component http://mydeviceip/cgi-bin-sdb/exportsettings.sh. an attacker can arbitrarily configure settings, leading to possible remote code execution and subsequent unauthorized operations. cve-2022-32429 theabhinavgaur config cve cve2022 dump megatech msmswitch packetstorm switch unauth vuln cwe-287" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">MSNSwitch Firmware MNT.2408 - Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-32429.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-32429.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> theabhinavgaur</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/287.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-287</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-32429" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-32429</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-2073748627&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">MSNSwitch Firmware MNT.2408 is susceptible to authentication bypass in the component http://MYDEVICEIP/cgi-bin-sdb/ExportSettings.sh. An attacker can arbitrarily configure settings, leading to possible remote code execution and subsequent unauthorized operations.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability allows an attacker to bypass authentication and gain unauthorized access to the affected device.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest firmware update provided by the vendor to fix the authentication bypass vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">config</span><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">dump</span><span class="nt-tag">megatech</span><span class="nt-tag">msmswitch</span><span class="nt-tag">packetstorm</span><span class="nt-tag">switch</span><span class="nt-tag">unauth</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://packetstormsecurity.com/files/169819/MSNSwitch-Firmware-MNT.2408-Remote-Code-Execution.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://elifulkerson.com/CVE-2022-32429/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-32429" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="http://packetstormsecurity.com/files/169819/MSNSwitch-Firmware-MNT.2408-Remote-Code-Execution.html" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/ARPSyndicate/cvemon" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="mspcontrol login panel - detect info identify web-based control panels mspcontrol login panel was detected. idealphase panel mspcontrol discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">MSPControl Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/mspcontrol-login.yaml" target="_blank" rel="noopener" class="nt-source-link">mspcontrol-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> idealphase</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)MSPControl - Sign In&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">MSPControl login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">mspcontrol</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://mspcontrol.org/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://mspcontrol.org/downloads/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="mstore api &lt; 3.9.8 - sql injection critical identify critical remote vulnerabilities the mstore api wordpress plugin before 3.9.8 is vulnerable to blind sql injection via the product_id parameter. cve-2023-3077 dhiyaneshdk cve cve2023 inspireui mstore-api sqli time-based-sqli vuln wordpress wp wp-plugin wpscan" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">MStore API &lt; 3.9.8 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-3077.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-3077.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 28, 2024</span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-3077" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-3077</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/mstore-api/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The MStore API WordPress plugin before 3.9.8 is vulnerable to Blind SQL injection via the product_id parameter.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Allows an attacker to extract sensitive data from the database</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update MStore API WordPress Plugin to the latest version to mitigate the vulnerability</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">inspireui</span><span class="nt-tag">mstore-api</span><span class="nt-tag">sqli</span><span class="nt-tag">time-based-sqli</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">wpscan</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wpscan.com/vulnerability/9480d0b5-97da-467d-98f6-71a32599a432" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-3077" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="mstore api &lt;= 3.9.1 - authentication bypass critical identify critical remote vulnerabilities the mstore api plugin for wordpress is vulnerable to authentication bypass in versions up to, and including, 3.9.1. this is due to insufficient verification on the user being supplied during the cart sync from mobile rest api request through the plugin. this makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the user id. cve-2023-2734 daffainfo auth-bypass cve cve2023 inspireui mstore_api vkev wordpress wp wp-plugin cwe-200" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">MStore API &lt;= 3.9.1 - Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-2734.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-2734.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> daffainfo</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 30, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-2734" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-2734</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/mstore-api/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.1. This is due to insufficient verification on the user being supplied during the cart sync from mobile REST API request through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the user id.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can log in as any user, including administrators, potentially gaining full control over the site.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to version 3.9.2 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">inspireui</span><span class="nt-tag">mstore_api</span><span class="nt-tag">vkev</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/mstore-api/mstore-api-391-authentication-bypass" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;new=2915729%40mstore-api&amp;old=2913397%40mstore-api&amp;sfp_email=&amp;sfph_mail=#file59" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-2734" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="mstore api &lt;= 3.9.2 - authentication bypass critical identify critical remote vulnerabilities the mstore api plugin for wordpress is vulnerable to authentication bypass in versions up to, and including, 3.9.2. this is due to insufficient verification on the user being supplied during the add listing rest api request through the plugin. this makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the user id. cve-2023-2732 dhiyaneshdk auth-bypass cve cve2023 inspireui mstore-api vkev vuln wordpress wp wp-plugin cwe-288,nvd-cwe-other" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">MStore API &lt;= 3.9.2 - Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-2732.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-2732.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 26, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/288,NVD-CWE-OTHER.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-288,NVD-CWE-OTHER</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-2732" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-2732</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/mstore-api/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.2. This is due to insufficient verification on the user being supplied during the add listing REST API request through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the user id.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can bypass authentication and gain unauthorized access to the MStore API, potentially leading to data breaches or unauthorized actions.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to a patched version of MStore API (version 3.9.3 or above) to mitigate the authentication bypass vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">inspireui</span><span class="nt-tag">mstore-api</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/f00761a7-fe24-49a3-b3e3-a471e05815c1?source=cve" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/RandomRobbieBF/CVE-2023-2732" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://wordpress.org/plugins/mstore-api/" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://plugins.trac.wordpress.org/browser/mstore-api/tags/3.9.0/controllers/listing-rest-api/class.api.fields.php#L1079" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;new=2916124%40mstore-api&amp;old=2915729%40mstore-api&amp;sfp_email=&amp;sfph_mail=#file58" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="mstore api &lt;= 4.10.7 - unauthorized account access and privilege escalation critical identify critical remote vulnerabilities the mstore api plugin for wordpress is vulnerable to unauthorized account access and privilege escalation in versions up to, and including, 4.10.7 due to improper implementation of the apple login feature. this allows unauthenticated attackers to log in as any user as long as they know the user&#39;s email address. cve-2023-3277 daffainfo auth-bypass cve cve2023 inspireui mstore_api vkev wordpress wp wp-plugin" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">MStore API &lt;= 4.10.7 - Unauthorized Account Access and Privilege Escalation</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-3277.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-3277.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> daffainfo</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 30, 2025</span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-3277" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-3277</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/mstore-api/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The MStore API plugin for WordPress is vulnerable to Unauthorized Account Access and Privilege Escalation in versions up to, and including, 4.10.7 due to improper implementation of the Apple login feature. This allows unauthenticated attackers to log in as any user as long as they know the user&#39;s email address.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can log in as any user and escalate privileges, potentially leading to full account compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">No patch available yet; monitor for updates from the developer and apply patches as soon as they are released.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">inspireui</span><span class="nt-tag">mstore_api</span><span class="nt-tag">vkev</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/1c7c0c35-5f44-488f-9fe1-269ea4a73854?source=cve" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;new=2988788%40mstore-api%2Ftrunk&amp;old=2985882%40mstore-api%2Ftrunk&amp;sfp_email=&amp;sfph_mail=" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://plugins.trac.wordpress.org/browser/mstore-api/trunk/controllers/flutter-user.php#L821" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-3277" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="machform admin panel - detect info identify web-based control panels machform admin panel was detected. ritikchaddha admin discovery machform panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">MachForm Admin Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/machform-admin-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">machform-admin-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)MachForm Admin Panel&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">MachForm Admin panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">admin</span><span class="nt-tag">discovery</span><span class="nt-tag">machform</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.machform.com/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="maestro listserv - detect info identify web-based control panels maestro listserv panel was detected. righettod panel maestro detect login discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Maestro LISTSERV - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/maestro-listserv-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">maestro-listserv-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 25, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)LISTSERV Maestro&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Maestro LISTSERV panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">maestro</span><span class="nt-tag">detect</span><span class="nt-tag">login</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.lsoft.com/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.lsoft.com/products/maestro_11.1.asp" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="maestro luci login panel - detect info identify web-based control panels maestro luci login panel was detected. tess panel maestro luci discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Maestro LuCI Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/maestro-login-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">maestro-login-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> tess</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Maestro - LuCI&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Maestro LuCI login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">maestro</span><span class="nt-tag">luci</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="mage ai - insecure default authentication setup medium identify critical remote vulnerabilities a vulnerability was found in mage ai 0.9.75. it has been classified as problematic. this affects an unknown part. the manipulation leads to insecure default initialization of resource. it is possible to initiate the attack remotely. the complexity of an attack is rather high. the exploitability is told to be difficult. the exploit has been disclosed to the public and may be used. the real existence of this vulnerability is still doubted at the moment. after 7 months of repeated follow-ups by the researcher, mage ai has decided to not accept this issue as a valid security vulnerability and has confirmed that they will not be addressing it. cve-2025-2129 zn9988,h0j3n cve cve2025 mage vuln cwe-1188" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Mage AI - Insecure Default Authentication Setup</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-2129.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-2129.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> zn9988,H0j3n</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 24, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/1188.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-1188</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-2129" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-2129</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)&lt;title&gt;Mage&lt;/title&gt;&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A vulnerability was found in Mage AI 0.9.75. It has been classified as problematic. This affects an unknown part. The manipulation leads to insecure default initialization of resource. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. After 7 months of repeated follow-ups by the researcher, Mage AI has decided to not accept this issue as a valid security vulnerability and has confirmed that they will not be addressing it.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can exploit insecure default authentication configuration to gain unauthorized access to Mage AI installations, potentially leading to remote code execution and complete system compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Implement proper authentication configuration by following the vendor&#39;s security hardening guidelines.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">mage</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-2129" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/zn9988/publications/blob/main/2.Mage-AI%20-%20Insecure%20Default%20Authentication%20Setup%20Leading%20to%20Zero-Click%20RCE/README.md" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://vuldb.com/?ctiid.299049" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://vuldb.com/?id.299049" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://vuldb.com/?submit.510690" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="mage ai panel - detect info identify web-based control panels mage ai (mage.ai / github.com/mage-ai/mage-ai) is an open-source data pipeline + orchestration platform with a notebook-style ui. self-hosted instances default to tcp 6789 and historically have shipped without authentication. exposed instances may reveal pipeline source, secrets, and provide an authenticated path to arbitrary code execution via custom blocks. chrisjr404 detect mageai panel" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Mage AI Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/mageai-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">mageai-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ChrisJr404</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 19, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Mage&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Mage AI (mage.ai / github.com/mage-ai/mage-ai) is an open-source data pipeline + orchestration platform with a notebook-style UI. Self-hosted instances default to TCP 6789 and historically have shipped without authentication. Exposed instances may reveal pipeline source, secrets, and provide an authenticated path to arbitrary code execution via custom blocks.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">detect</span><span class="nt-tag">mageai</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/mage-ai/mage-ai" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://docs.mage.ai/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="magnolia cms default login - detect high identify default logins in web-based control panels magnolia cms default login credentials were detected. pussycat0x default-login magnolia vuln cwe-200" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Magnolia CMS Default Login - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/magnolia-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">magnolia-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;Magnolia is a registered trademark&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Magnolia CMS default login credentials were detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">magnolia</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.magnolia-cms.com/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="magnolia cms login panel - detect info identify web-based control panels magnolia cms login panel was detected. pussycat0x discovery login magnolia panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Magnolia CMS Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/magnolia-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">magnolia-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Magnolia is a registered trademark&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Magnolia CMS login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">login</span><span class="nt-tag">magnolia</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.magnolia-cms.com/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="magnusbilling - default login high identify default logins in web-based control panels magnusbilling installs with a default administrative account using the credentials root / magnus. if unchanged, these credentials grant full access to the system, allowing attackers to manage billing data, modify configurations, and potentially execute arbitrary code or commands via exposed interfaces. dhiyaneshdk default-login mbilling vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">MagnusBilling - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/magnusbilling/magnusbilling-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">magnusbilling-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 20, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;MagnusBilling&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">MagnusBilling installs with a default administrative account using the credentials root / magnus. If unchanged, these credentials grant full access to the system, allowing attackers to manage billing data, modify configurations, and potentially execute arbitrary code or commands via exposed interfaces.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An unauthenticated attacker can gain full administrative control over the MagnusBilling platform, leading to compromise of billing systems, data leakage, and potential pivoting into internal infrastructure.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">mbilling</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="magnusbilling - login panel info identify web-based control panels identified an exposed magnusbilling login panel. dhiyaneshdk discovery login magnusbilling mbilling panel" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">MagnusBilling - Login Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/mbilling-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">mbilling-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 20, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)MagnusBilling&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Identified an exposed MagnusBilling login panel.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">login</span><span class="nt-tag">magnusbilling</span><span class="nt-tag">mbilling</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="mail mint &lt; 1.19.5 - unauthenticated email disclosure high identify critical remote vulnerabilities mail mint wordpress plugin &lt; 1.19.5 contains an information disclosure vulnerability caused by lack of authorization in a rest api endpoint, letting unauthenticated users retrieve email addresses of blog users, exploit requires no authentication. cve-2026-2025 0x_akoko cve cve2026 exposure mail-mint unauth vkev vuln wordpress wp-plugin cwe-200" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Mail Mint &lt; 1.19.5 - Unauthenticated Email Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2026/CVE-2026-2025.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2026-2025.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_Akoko</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 16, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2026-2025" target="_blank" rel="noopener" class="nt-cve-link">CVE-2026-2025</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/mail-mint/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Mail Mint WordPress plugin &lt; 1.19.5 contains an information disclosure vulnerability caused by lack of authorization in a REST API endpoint, letting unauthenticated users retrieve email addresses of blog users, exploit requires no authentication.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can retrieve email addresses of users, leading to privacy breaches and potential phishing attacks.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to version 1.19.5 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2026</span><span class="nt-tag">exposure</span><span class="nt-tag">mail-mint</span><span class="nt-tag">unauth</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp-plugin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wpscan.com/vulnerability/1b815cde-cd9d-46fa-a6ab-3d2851705e7b/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2025" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://wordpress.org/plugins/mail-mint/" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="mailenable mail service &lt; v10 - cross-site scripting medium identify critical remote vulnerabilities cross site scripting (xss) vulnerability in mailenable before v10 allows a remote attacker to execute arbitrary code via the failure.aspx component. cve-2025-44148 ritikchaddha cve cve2025 mailenable vuln xss cwe-79" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">MailEnable Mail Service &lt; v10 - Cross-Site Scripting</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-44148.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-44148.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 17, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-79</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-44148" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-44148</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)MailEnable&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Cross Site Scripting (XSS) vulnerability in MailEnable before v10 allows a remote attacker to execute arbitrary code via the failure.aspx component.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can execute arbitrary JavaScript in victim browsers through the state parameter in failure.aspx, potentially leading to session hijacking and credential theft.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to MailEnable version 10 or later that properly sanitizes user input in the failure.aspx component.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">mailenable</span><span class="nt-tag">vuln</span><span class="nt-tag">xss</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/barisbaydur/CVE-2025-44148" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-44148" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="mailhog panel - detect info identify web-based control panels mailhog panel was detected. kh4sh3i panel mailhog mail smtp discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">MailHog Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/mailhog-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">mailhog-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> kh4sh3i</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)mailhog&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">MailHog panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">mailhog</span><span class="nt-tag">mail</span><span class="nt-tag">smtp</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/mailhog/MailHog" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="mailwatch login panel - detect info identify web-based control panels mailwatch login panel was detected. oppsec panel mailwatch discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">MailWatch Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/mailwatch-login.yaml" target="_blank" rel="noopener" class="nt-source-link">mailwatch-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> oppsec</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)MailWatch Login Page&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">MailWatch login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">mailwatch</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="mailpit &lt; 1.28.3 - server-side request forgery high identify critical remote vulnerabilities mailpit &lt;= 1.28.0 contains a server-side request forgery caused by insufficient validation of internal ip addresses in the /proxy endpoint, letting attackers make requests to internal network resources, exploit requires crafted http get requests. cve-2026-21859 omarkurt axllent cve cve2026 mailpit oast oob ssrf vkev cwe-918" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Mailpit &lt; 1.28.3 - Server-Side Request Forgery</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2026/CVE-2026-21859.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2026-21859.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> omarkurt</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 21, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/918.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-918</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2026-21859" target="_blank" rel="noopener" class="nt-cve-link">CVE-2026-21859</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Mailpit&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Mailpit &lt;= 1.28.0 contains a server-side request forgery caused by insufficient validation of internal IP addresses in the /proxy endpoint, letting attackers make requests to internal network resources, exploit requires crafted HTTP GET requests.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can access internal network services and APIs, potentially exposing sensitive internal resources.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to version 1.28.1 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">axllent</span><span class="nt-tag">cve</span><span class="nt-tag">cve2026</span><span class="nt-tag">mailpit</span><span class="nt-tag">oast</span><span class="nt-tag">oob</span><span class="nt-tag">ssrf</span><span class="nt-tag">vkev</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://rosecurify.com/advisories/RO-26-001-mailpit-server-side-request-forgery-ssrf/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/axllent/mailpit/security/advisories/GHSA-8v65-47jx-7mfr" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="mainwp dashboard &lt;= 3.1.2 - stored cross-site scripting high identify critical remote vulnerabilities mainwp dashboard – the private wordpress manager for multiple website maintenance plugin for wordpress versions up to 3.1.2 contains a stored cross-site scripting caused by insufficient input sanitization and output escaping in &#39;mwp_setup_purchase_username&#39; parameter, letting unauthenticated attackers inject and execute arbitrary scripts when users access affected pages. cve-2016-15041 flame cve cve2016 mainwp wordpress xss wp wp-plugin vkev cwe-79" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">MainWP Dashboard &lt;= 3.1.2 - Stored Cross-Site Scripting</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2016/CVE-2016-15041.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2016-15041.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> flame</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 25, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-79</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2016-15041" target="_blank" rel="noopener" class="nt-cve-link">CVE-2016-15041</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/mainwp&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">MainWP Dashboard – The Private WordPress Manager for Multiple Website Maintenance plugin for WordPress versions up to 3.1.2 contains a stored cross-site scripting caused by insufficient input sanitization and output escaping in &#39;mwp_setup_purchase_username&#39; parameter, letting unauthenticated attackers inject and execute arbitrary scripts when users access affected pages.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can inject scripts that execute in users&#39; browsers, potentially leading to session hijacking, defacement, or redirection.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest version of the plugin that addresses this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2016</span><span class="nt-tag">mainwp</span><span class="nt-tag">wordpress</span><span class="nt-tag">xss</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">vkev</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://klikki.fi/mainwp-admin-panel-unauthenticated-stored-xss/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="majordomo - unauthenticated rce critical identify critical remote vulnerabilities majordomo contains a remote code execution caused by an include order bug and lack of exit after redirect in admin panel&#39;s php console, letting unauthenticated attackers execute arbitrary php code via crafted get requests. cve-2026-27174 0x_akoko cve cve2026 majordomo php rce unauth vkev cwe-94" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">MajorDoMo - Unauthenticated RCE</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2026/CVE-2026-27174.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2026-27174.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_Akoko</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 23, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/94.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-94</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2026-27174" target="_blank" rel="noopener" class="nt-cve-link">CVE-2026-27174</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)templates/application\\.html&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">MajorDoMo contains a remote code execution caused by an include order bug and lack of exit after redirect in admin panel&#39;s PHP console, letting unauthenticated attackers execute arbitrary PHP code via crafted GET requests.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can execute arbitrary PHP code remotely, potentially leading to full system compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest version with the fix for the include order bug and proper exit after redirect.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2026</span><span class="nt-tag">majordomo</span><span class="nt-tag">php</span><span class="nt-tag">rce</span><span class="nt-tag">unauth</span><span class="nt-tag">vkev</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27174" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/sergejey/majordomo/issues/1177" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://chocapikk.com/posts/2026/majordomo-revisited" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://www.vulncheck.com/advisories/majordomo-unauthenticated-remote-code-execution-via-admin-console-eval" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="majordomo thumb.php - os command injection critical identify critical remote vulnerabilities majordomo (aka major domestic module) before 0662e5e allows command execution via thumb.php shell metacharacters. note: this is unrelated to the majordomo mailing-list manager. cve-2023-50917 dhiyaneshdk cve cve2023 majordomo mjdm os packetstorm rce seclists vkev vuln cwe-77" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">MajorDoMo thumb.php - OS Command Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-50917.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-50917.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 10, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/77.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-77</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-50917" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-50917</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1903390397&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">MajorDoMo (aka Major Domestic Module) before 0662e5e allows command execution via thumb.php shell metacharacters. NOTE: this is unrelated to the Majordomo mailing-list manager.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can execute arbitrary OS commands via shell metacharacters in the thumb.php transport parameter, potentially compromising the entire system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update MajorDoMo to a version newer than commit 0662e5e which addresses the command injection vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">majordomo</span><span class="nt-tag">mjdm</span><span class="nt-tag">os</span><span class="nt-tag">packetstorm</span><span class="nt-tag">rce</span><span class="nt-tag">seclists</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="http://packetstormsecurity.com/files/176273/MajorDoMo-Remote-Code-Execution.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="http://seclists.org/fulldisclosure/2023/Dec/19" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/sergejey/majordomo/commit/0662e5ebfb133445ff6154b69c61019357092178" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/sergejey/majordomo/commit/3ec3ffb863ea3c2661ab27d398776c551f4daaac" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-50917" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="maltrail panel - detect info identify web-based control panels maltrail is a malicious traffic detection system, utilizing publicly available (black)lists containing malicious and/or generally suspicious trails, along with static trails compiled from various av reports and custom user defined lists, where trail can be anything from domain name, url (e.g. hxxp://109.162.38.120/harsh02.exe for known malicious executable), ip address (e.g. 185.130.5.231 for known attacker) or http user-agent header value. ritikchaddha panel maltrail detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Maltrail Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/maltrail-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">maltrail-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 19, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Maltrail&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Maltrail is a malicious traffic detection system, utilizing publicly available (black)lists containing malicious and/or generally suspicious trails, along with static trails compiled from various AV reports and custom user defined lists, where trail can be anything from domain name, URL (e.g. hXXp://109.162.38.120/harsh02.exe for known malicious executable), IP address (e.g. 185.130.5.231 for known attacker) or HTTP User-Agent header value.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">maltrail</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="malwared (build your own botnet) - detect info identify web-based control panels detects the presence of the malwared - build your own botnet tool on the target system. pdteam panel malware byob botnet oss detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Malwared (Build Your Own Botnet) - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/malwared-byob.yaml" target="_blank" rel="noopener" class="nt-source-link">malwared-byob.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pdteam</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 17, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;487145192&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detects the presence of the Malwared - Build Your Own Botnet tool on the target system.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">malware</span><span class="nt-tag">byob</span><span class="nt-tag">botnet</span><span class="nt-tag">oss</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/malwaredllc/byob" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="malwared byob - unauthenticated remote code execution critical identify critical remote vulnerabilities malwared byob - unauthenticated rce allows remote code execution. pdteam rce malware byob botnet oss vuln" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Malwared BYOB - Unauthenticated Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/vulnerabilities/malwared-byob-rce.yaml" target="_blank" rel="noopener" class="nt-source-link">malwared-byob-rce.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pdteam</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 17, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;487145192&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Malwared BYOB - Unauthenticated RCE allows remote code execution.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Potential unauthorized access and control of the target system by threat actors.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Remove any instances of the Malwared - Build Your Own Botnet tool from the target system and conduct a thorough security audit.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">rce</span><span class="nt-tag">malware</span><span class="nt-tag">byob</span><span class="nt-tag">botnet</span><span class="nt-tag">oss</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://blog.chebuya.com/posts/unauthenticated-remote-command-execution-on-byob/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/chebuya/exploits/tree/main/BYOB-RCE" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/malwaredllc/byob" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="manageengine applications manager - default credentials high identify default logins in web-based control panels default credentials grants administrative access to manageengine applications manager, which can be later escalated into a rce via db queries. 0midc13 default-login manageengine vuln zoho" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">ManageEngine Applications Manager - Default Credentials</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/zoho/app-manager-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">app-manager-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0midC13</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 2, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;Applications Manager Login Screen&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Default credentials grants administrative access to ManageEngine Applications Manager, which can be later escalated into a RCE via DB queries.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">manageengine</span><span class="nt-tag">vuln</span><span class="nt-tag">zoho</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.manageengine.com/products/applications_manager/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="manageengine servicedesk 9.3.9328 - arbitrary file retrieval high identify critical remote vulnerabilities manageengine servicedesk 9.3.9328 is vulnerable to an arbitrary file retrieval due to improper restrictions of the pathname used in the name parameter for the download-snapshot path. an unauthenticated remote attacker can use this vulnerability to download arbitrary files. cve-2017-11512 0x_akoko cve cve2017 lfr manageengine tenable unauth vkev vuln cwe-22" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">ManageEngine ServiceDesk 9.3.9328 - Arbitrary File Retrieval</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2017/CVE-2017-11512.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2017-11512.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_Akoko</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2017-11512" target="_blank" rel="noopener" class="nt-cve-link">CVE-2017-11512</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)manageengine&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">ManageEngine ServiceDesk 9.3.9328 is vulnerable to an arbitrary file retrieval due to improper restrictions of the pathname used in the name parameter for the download-snapshot path. An unauthenticated remote attacker can use this vulnerability to download arbitrary files.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can access sensitive files on the server, potentially leading to unauthorized access or data leakage.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to a patched version of ManageEngine ServiceDesk 9.3.9328 or apply the necessary security patches.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2017</span><span class="nt-tag">lfr</span><span class="nt-tag">manageengine</span><span class="nt-tag">tenable</span><span class="nt-tag">unauth</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://exploit.kitploit.com/2017/11/manageengine-servicedesk-cve-2017-11512.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.tenable.com/security/research/tra-2017-31" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2017-11512" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/ARPSyndicate/kenzer-templates" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/ARPSyndicate/cvemon" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="mantisbt &lt;=2.30 - arbitrary password reset/admin access high identify critical remote vulnerabilities mantisbt through 2.3.0 allows arbitrary password reset and unauthenticated admin access via an empty confirm_hash value to verify.php. cve-2017-7615 bp0lr,dwisiswant0 cve cve2017 edb mantisbt unauth vuln cwe-640" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">MantisBT &lt;=2.30 - Arbitrary Password Reset/Admin Access</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2017/CVE-2017-7615.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2017-7615.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> bp0lr,dwisiswant0</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/640.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-640</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2017-7615" target="_blank" rel="noopener" class="nt-cve-link">CVE-2017-7615</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;662709064&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">MantisBT through 2.3.0 allows arbitrary password reset and unauthenticated admin access via an empty confirm_hash value to verify.php.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability can lead to unauthorized password resets and unauthorized administrative access.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade MantisBT to a version higher than 2.30 to mitigate this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2017</span><span class="nt-tag">edb</span><span class="nt-tag">mantisbt</span><span class="nt-tag">unauth</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://sourceforge.net/projects/mantisbt/files/mantis-stable/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="http://hyp3rlinx.altervista.org/advisories/MANTIS-BUG-TRACKER-PRE-AUTH-REMOTE-PASSWORD-RESET.txt" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.exploit-db.com/exploits/41890" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="http://www.openwall.com/lists/oss-security/2017/04/16/2" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2017-7615" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="mantisbt default admin login high identify default logins in web-based control panels a mantisbt default admin login was discovered. for3stco1d,yashvardhantripathi default-login mantisbt vuln cwe-522" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">MantisBT Default Admin Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/mantisbt/mantisbt-default-credential.yaml" target="_blank" rel="noopener" class="nt-source-link">mantisbt-default-credential.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> For3stCo1d,YashVardhanTripathi</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/522.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-522</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;MantisBT&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A MantisBT default admin login was discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">mantisbt</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://mantisbt.org/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="mantisbt login panel - detect info identify web-based control panels mantisbt login panel was detected. makyotox,daffainfo discovery mantisbt panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">MantisBT Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/mantisbt-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">mantisbt-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> makyotox,daffainfo</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;662709064&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">MantisBT login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">mantisbt</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.mantisbt.org/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="mapsvg &lt; 6.2.20 - unauthenticated sqli critical identify critical remote vulnerabilities the mapsvg wordpress plugin before 6.2.20 does not validate and escape a parameter via a rest endpoint before using it in a sql statement, leading to a sql injection exploitable by unauthenticated users. cve-2022-0592 dhiyaneshdk cve cve2022 mapsvg sqli time-based-sqli vkev vuln wordpress wp wp-plugin wpscan cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">MapSVG &lt; 6.2.20 - Unauthenticated SQLi</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-0592.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-0592.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 20, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-0592" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-0592</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/mapsvg/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The MapSVG WordPress plugin before 6.2.20 does not validate and escape a parameter via a REST endpoint before using it in a SQL statement, leading to a SQL Injection exploitable by unauthenticated users.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can execute SQL injection via REST API endpoint to extract database contents or execute arbitrary commands, potentially compromising the entire WordPress database.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to MapSVG version 6.2.20 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">mapsvg</span><span class="nt-tag">sqli</span><span class="nt-tag">time-based-sqli</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">wpscan</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wpscan.com/vulnerability/5d8d53ad-dc88-4b50-a292-fc447484c27b/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="maptiler tileserver-php v2.0 - unauthenticated file read high identify critical remote vulnerabilities maptiler tileserver-php v2.0 contains a directory traversal caused by improper sanitization of get parameters in rendertile function, letting attackers read arbitrary files on the server, exploit requires crafted web requests cve-2025-44137 0x_akoko cve cve2025 lfi maptiler tileserver traversal vkev cwe-22" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">MapTiler Tileserver-php v2.0 - Unauthenticated File Read</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-44137.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-44137.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_Akoko</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 7, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-44137" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-44137</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)TileServer-php&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">MapTiler Tileserver-php v2.0 contains a directory traversal caused by improper sanitization of GET parameters in renderTile function, letting attackers read arbitrary files on the server, exploit requires crafted web requests</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can read arbitrary files on the server, potentially exposing sensitive information.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest version of MapTiler Tileserver-php.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">lfi</span><span class="nt-tag">maptiler</span><span class="nt-tag">tileserver</span><span class="nt-tag">traversal</span><span class="nt-tag">vkev</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-44137" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/mheranco/CVE-2025-44137" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="maptiler tileserver-php v2.0 - unauthenticated xss medium identify critical remote vulnerabilities maptiler tileserver-php v2.0 contains a reflected xss caused by unencoded reflection of the get parameter \&#34;layer\&#34; in an error message, letting unauthenticated attackers execute arbitrary script on victim browsers. cve-2025-44136 0x_akoko cve cve2025 maptiler tileserver vkev xss cwe-79" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">MapTiler Tileserver-php v2.0 - Unauthenticated XSS</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-44136.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-44136.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_Akoko</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 7, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-79</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-44136" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-44136</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)TileServer-php&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">MapTiler Tileserver-php v2.0 contains a reflected XSS caused by unencoded reflection of the GET parameter \&#34;layer\&#34; in an error message, letting unauthenticated attackers execute arbitrary script on victim browsers.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can execute arbitrary JavaScript in victim browsers, leading to session hijacking or phishing.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest version of MapTiler Tileserver-php.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">maptiler</span><span class="nt-tag">tileserver</span><span class="nt-tag">vkev</span><span class="nt-tag">xss</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-44136" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/mheranco/CVE-2025-44136" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="marimo panel - detect info identify web-based control panels marimo is an open-source reactive python notebook and app framework that replaces jupyter
with git-friendly, reproducible notebooks. rxerium ai detect discovery marimo notebook panel python" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Marimo Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/marimo-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">marimo-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 27, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;marimo&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Marimo is an open-source reactive Python notebook and app framework that replaces Jupyter
with git-friendly, reproducible notebooks.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">ai</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">marimo</span><span class="nt-tag">notebook</span><span class="nt-tag">panel</span><span class="nt-tag">python</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/marimo-team/marimo" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://marimo.io" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="mastersam star gate v11 - local file inclusion high identify critical remote vulnerabilities mastersam star gate v11 is vulnerable to a directory traversal attack via the endpoint /adama/adama/downloadservice. an attacker can exploit this vulnerability by manipulating the file parameter to access arbitrary files on the server, potentially leading to the exposure of sensitive information. cve-2024-55457 dhiyaneshdk adama cve cve2024 lfi mastersam v11 vkev vuln cwe-22" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">MasterSAM Star Gate v11 - Local File Inclusion</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-55457.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-55457.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 6, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-55457" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-55457</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)MasterSAM&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">MasterSAM Star Gate v11 is vulnerable to a directory traversal attack via the endpoint /adama/adama/downloadService. An attacker can exploit this vulnerability by manipulating the file parameter to access arbitrary files on the server, potentially leading to the exposure of sensitive information.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can exploit directory traversal to read arbitrary files from the server, potentially exposing sensitive configuration data, credentials, and system files.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Contact MasterSAM for a patched version of Star Gate v11 that addresses the directory traversal vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">adama</span><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">lfi</span><span class="nt-tag">mastersam</span><span class="nt-tag">v11</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/h13nh04ng/CVE-2024-55457-PoC" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://x.com/cyber_advising/status/1876034270852231257" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="masterstudy lms wordpress plugin &lt;= 3.2.5 - sql injection critical identify critical remote vulnerabilities the masterstudy lms wordpress plugin for online courses and education plugin for wordpress is vulnerable to union based sql injection via the &#39;user&#39; parameter of the /lms/stm-lms/order/items rest route in all versions up to, and including, 3.2.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing sql query. this makes it possible for unauthenticated attackers to append additional sql queries into already existing queries that can be used to extract sensitive information from the database. cve-2024-1512 s4e-io cve cve2024 sqli time-based-sqli vuln wordpress wp-plugin" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">MasterStudy LMS WordPress Plugin &lt;= 3.2.5 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-1512.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-1512.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> s4e-io</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 11, 2024</span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-1512" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-1512</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)wp-content/plugins/masterstudy-lms-learning-management-system/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The MasterStudy LMS WordPress Plugin for Online Courses and Education plugin for WordPress is vulnerable to union based SQL Injection via the &#39;user&#39; parameter of the /lms/stm-lms/order/items REST route in all versions up to, and including, 3.2.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can extract sensitive information from the database including usernames, passwords, and other confidential data via time-based SQL injection.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update MasterStudy LMS plugin to version 3.2.6 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">sqli</span><span class="nt-tag">time-based-sqli</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp-plugin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-1512" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/rat-c/CVE-2024-1512" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://blog.csdn.net/m0_60571842/article/details/139901296" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d6b6d824-51d3-4da9-a39a-b957368df4dc?source=cve" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="masteriyo lms &lt;= 1.7.3 - insecure direct object reference medium identify critical remote vulnerabilities authentication bypass using an alternate path or channel vulnerability in masteriyo masteriyo - lms. unauth access to course progress.this issue affects masteriyo - lms: from n/a through 1.7.3. cve-2024-33939 sourabh-sahu cve cve2024 idor learning-management-system lms unauth vkev wordpress wp-plugin cwe-288" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Masteriyo LMS &lt;= 1.7.3 - Insecure Direct Object Reference</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-33939.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-33939.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Sourabh-Sahu</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 20, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/288.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-288</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-33939" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-33939</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/learning-management-system/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Authentication Bypass Using an Alternate Path or Channel vulnerability in Masteriyo Masteriyo - LMS. Unauth access to course progress.This issue affects Masteriyo - LMS: from n/a through 1.7.3.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An unauthenticated attacker can access course progress and user learning data without logging in.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update the Masteriyo LMS plugin to the latest version and enforce proper authentication and authorization checks on REST API endpoints.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">idor</span><span class="nt-tag">learning-management-system</span><span class="nt-tag">lms</span><span class="nt-tag">unauth</span><span class="nt-tag">vkev</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp-plugin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wpscan.com/vulnerability/57c0054a-b713-4f7c-8e41-c009b07624a6/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-33939" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="matomo panel - detect info identify web-based control panels google analytics alternative that protects your data and your customers privacy. arr0way,userdehghani detect discovery login matomo panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Matomo Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/matomo-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">matomo-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Arr0way,userdehghani</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 13, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-2023266783&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">google analytics alternative that protects your data and your customers privacy.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">login</span><span class="nt-tag">matomo</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://matomo.org/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://matomo.org/faq/on-premise/installing-matomo/#getting-started" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="mattermost login - panel info identify web-based control panels mattermost login panel was discovered. darses discovery login mattermost panel" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Mattermost Login - Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/mattermost-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">mattermost-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> darses</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 10, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)&#39;content=\&#34;Mattermost\&#34;&#39;&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Mattermost Login Panel was discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">login</span><span class="nt-tag">mattermost</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="metube instance detected info identify web-based control panels a metube instance was detected. rxerium metube detect panel login discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">MeTube Instance Detected</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/metube-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">metube-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 10, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)MeTube&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A MeTube instance was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">metube</span><span class="nt-tag">detect</span><span class="nt-tag">panel</span><span class="nt-tag">login</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/alexta69/metube" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="mealie panel - detect info identify web-based control panels detected mealie was a self-hosted recipe manager and meal planner with a vue/nuxt frontend and fastapi backend. chrisjr404 detect discovery mealie panel recipe selfhosted" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Mealie Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/mealie-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">mealie-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ChrisJr404</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 6, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Mealie&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detected Mealie was a self-hosted recipe manager and meal planner with a Vue/Nuxt frontend and FastAPI backend.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">mealie</span><span class="nt-tag">panel</span><span class="nt-tag">recipe</span><span class="nt-tag">selfhosted</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/mealie-recipes/mealie" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://mealie.io/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="media library assistant &lt; 2.82 - unauthenticated limited local file inclusion high identify critical remote vulnerabilities media library assistant plugin for wordpress before 2.82 contains a local file inclusion caused by unsanitized mla_gallery link parameter, letting attackers include arbitrary local files, exploit requires access to the vulnerable link. cve-2020-11732 sourabh-sahu cve cve2020 media-library-assistant unauth vkev wordpress wp wp-plugin wpscan" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Media Library Assistant &lt; 2.82 - Unauthenticated Limited Local File Inclusion</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2020/CVE-2020-11732.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2020-11732.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Sourabh-Sahu</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 30, 2025</span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2020-11732" target="_blank" rel="noopener" class="nt-cve-link">CVE-2020-11732</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)wp-content/plugins/media-library-assistant&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Media Library Assistant plugin for WordPress before 2.82 contains a local file inclusion caused by unsanitized mla_gallery link parameter, letting attackers include arbitrary local files, exploit requires access to the vulnerable link.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can include arbitrary local files, potentially leading to information disclosure or code execution.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to version 2.82 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2020</span><span class="nt-tag">media-library-assistant</span><span class="nt-tag">unauth</span><span class="nt-tag">vkev</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">wpscan</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wpscan.com/vulnerability/80d60584-fa03-407e-a7bd-32d507a1046d/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="meduza stealer panel - detect info identify web-based control panels meduza stealer panel were detected. dwisiswant0 rat meduza-stealer c2 panel vuln" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Meduza Stealer Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/c2/meduza-stealer.yaml" target="_blank" rel="noopener" class="nt-source-link">meduza-stealer.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dwisiswant0</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 25, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Meduza Stealer&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Meduza Stealer panel were detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">rat</span><span class="nt-tag">meduza-stealer</span><span class="nt-tag">c2</span><span class="nt-tag">panel</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="memos 0.13.2 - cross-site scripting &amp; ssrf medium identify critical remote vulnerabilities an ssrf vulnerability exists at the `/o/get/image` that allows unauthenticated users to enumerate the internal network and retrieve images. the response from the image request is then copied into the response of the current server request, causing a reflected xss vulnerability. ritikchaddha cve cve2024 memos vkev vuln xss cwe-79" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Memos 0.13.2 - Cross-Site Scripting &amp; SSRF</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-29029.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-29029.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 4, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-79</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Memos&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An SSRF vulnerability exists at the `/o/get/image` that allows unauthenticated users to enumerate the internal network and retrieve images. The response from the image request is then copied into the response of the current server request, causing a reflected XSS vulnerability.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can inject malicious scripts and perform SSRF attacks, compromising user data and accessing internal resources.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update Memos to version 0.13.3 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">memos</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">xss</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://securitylab.github.com/advisories/GHSL-2023-154_GHSL-2023-156_memos/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-29029" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="memos panel - detect info identify web-based control panels memos is a privacy-first, lightweight note-taking service rxerium detect discovery memos panel usememos" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Memos Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/memos-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">memos-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 27, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)memos&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Memos is a privacy-first, lightweight note-taking service</div></div></div>
  <div class="nt-tags"><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">memos</span><span class="nt-tag">panel</span><span class="nt-tag">usememos</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/usememos/memos" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.usememos.com/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="meshcentral login panel - detect info identify web-based control panels meshcentral login panel was detected. dhiyaneshdk discovery meshcentral panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">MeshCentral Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/meshcentral-login.yaml" target="_blank" rel="noopener" class="nt-source-link">meshcentral-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)meshcentral - login&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">MeshCentral login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">meshcentral</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="mesop ai sandbox &lt;= 1.2.2 - remote code execution critical identify critical remote vulnerabilities mesop &lt;= 1.2.2 contains an unrestricted remote code execution caused by unauthenticated ingestion and execution of base64-encoded python code in the /exec-py endpoint of ai/testing module, letting attackers execute arbitrary commands on the host, exploit requires http access to the server. cve-2026-33057 sammiee5311,liyander cve cve2026 mesop oss rce cwe-94" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Mesop AI Sandbox &lt;= 1.2.2 - Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2026/CVE-2026-33057.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2026-33057.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> sammiee5311,liyander</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 4, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/94.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-94</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2026-33057" target="_blank" rel="noopener" class="nt-cve-link">CVE-2026-33057</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Mesop&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Mesop &lt;= 1.2.2 contains an unrestricted remote code execution caused by unauthenticated ingestion and execution of base64-encoded Python code in the /exec-py endpoint of ai/testing module, letting attackers execute arbitrary commands on the host, exploit requires HTTP access to the server.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can execute arbitrary commands on the host, leading to full system compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to version 1.2.3 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2026</span><span class="nt-tag">mesop</span><span class="nt-tag">oss</span><span class="nt-tag">rce</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/mesop-dev/mesop/security/advisories/GHSA-gjgx-rvqr-6w6v" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33057" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="metinfo cms &lt;= 8.1 - remote code execution critical identify critical remote vulnerabilities metinfo cms 7.9, 8.0, and 8.1 contain an unauthenticated php code injection vulnerability caused by insufficient input neutralization in the execution path, letting remote attackers execute arbitrary code remotely, exploit requires crafted requests. cve-2026-29014 0x_akoko cve cve2026 metinfo php rce vkev cwe-94" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">MetInfo CMS &lt;= 8.1 - Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2026/CVE-2026-29014.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2026-29014.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_Akoko</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 8, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/94.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-94</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2026-29014" target="_blank" rel="noopener" class="nt-cve-link">CVE-2026-29014</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)MetInfo&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">MetInfo CMS 7.9, 8.0, and 8.1 contain an unauthenticated PHP code injection vulnerability caused by insufficient input neutralization in the execution path, letting remote attackers execute arbitrary code remotely, exploit requires crafted requests.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Remote attackers can execute arbitrary code, gaining full control over the affected server.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest version beyond 8.1.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2026</span><span class="nt-tag">metinfo</span><span class="nt-tag">php</span><span class="nt-tag">rce</span><span class="nt-tag">vkev</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://karmainsecurity.com/KIS-2026-06" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.metinfo.cn" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-29014" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="metabase - local file inclusion high identify critical remote vulnerabilities metabase is an open source data analytics platform. in affected versions a local file inclusion security issue has been discovered with the custom geojson map (`admin-&gt;settings-&gt;maps-&gt;custom maps-&gt;add a map`) support and potential local file inclusion (including environment variables). urls were not validated prior to being loaded. cve-2021-41277 0x_akoko,dhiyaneshdk cve cve2021 kev lfi metabase vkev vuln cwe-200,cwe-22" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Metabase - Local File Inclusion</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2021/CVE-2021-41277.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2021-41277.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_Akoko,DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200,CWE-22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200,CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2021-41277" target="_blank" rel="noopener" class="nt-cve-link">CVE-2021-41277</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)metabase&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Metabase is an open source data analytics platform. In affected versions a local file inclusion security issue has been discovered with the custom GeoJSON map (`admin-&gt;settings-&gt;maps-&gt;custom maps-&gt;add a map`) support and potential local file inclusion (including environment variables). URLs were not validated prior to being loaded.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">The vulnerability can result in unauthorized access to sensitive files or execution of arbitrary code on the affected system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">This issue is fixed in 0.40.5 and .40.5 and higher. If you are unable to upgrade immediately, you can mitigate this by including rules in your reverse proxy or load balancer or WAF to provide a validation filter before the application.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2021</span><span class="nt-tag">kev</span><span class="nt-tag">lfi</span><span class="nt-tag">metabase</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/metabase/metabase/security/advisories/GHSA-w73v-6p7p-fpfr" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2021-41277" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://twitter.com/90security/status/1461923313819832324" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/metabase/metabase/commit/042a36e49574c749f944e19cf80360fd3dc322f0" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/pen4uin/vulnerability-research-list" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="metabase &lt; 0.46.6.1 - remote code execution critical identify critical remote vulnerabilities metabase open source before 0.46.6.1 and metabase enterprise before 1.46.6.1 allow attackers to execute arbitrary commands on the server, at the server&#39;s privilege level. authentication is not required for exploitation. the other fixed versions are 0.45.4.1, 1.45.4.1, 0.44.7.1, 1.44.7.1, 0.43.7.2, and 1.43.7.2. cve-2023-38646 rootxharsh,iamnoooob,pdresearch cve cve2023 metabase oss rce vkev vuln" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Metabase &lt; 0.46.6.1 - Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-38646.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-38646.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rootxharsh,iamnoooob,pdresearch</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 29, 2023</span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-38646" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-38646</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)metabase&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary commands on the server, at the server&#39;s privilege level. Authentication is not required for exploitation. The other fixed versions are 0.45.4.1, 1.45.4.1, 0.44.7.1, 1.44.7.1, 0.43.7.2, and 1.43.7.2.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the target system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade Metabase to version 0.46.6.1 or later to mitigate this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">metabase</span><span class="nt-tag">oss</span><span class="nt-tag">rce</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.metabase.com/blog/security-advisory" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/metabase/metabase/releases/tag/v0.46.6.1" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://mp.weixin.qq.com/s/ATFwFl-D8k9QfQfzKjZFDg" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://news.ycombinator.com/item?id=36812256" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://blog.assetnote.io/2023/07/22/pre-auth-rce-metabase/" target="_blank" rel="noopener" class="nt-ref-link">[5]</a> <a href="https://gist.github.com/testanull/a7beb2777bbf550f3cf533d2794477fe" target="_blank" rel="noopener" class="nt-ref-link">[6]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="metabase installer - exposure high identify critical remote vulnerabilities detected metabase installer page, allowing unauthorized database setup and configuration. 0x_akoko exposure metabase installer misconfig vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Metabase Installer - Exposure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/misconfiguration/installer/metabase-installer-exposure.yaml" target="_blank" rel="noopener" class="nt-source-link">metabase-installer-exposure.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_Akoko</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 8, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Metabase&#34;}) &amp;&amp; service[&#34;http.body&#34;] contains &#34;setup&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detected Metabase installer page, allowing unauthorized database setup and configuration.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">exposure</span><span class="nt-tag">metabase</span><span class="nt-tag">installer</span><span class="nt-tag">misconfig</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.metabase.com/docs/latest/installation-and-operation/installing-metabase" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="metabase login panel - detect info identify web-based control panels metabase login panel was detected. revblock,daffainfo discovery login metabase panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Metabase Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/metabase-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">metabase-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> revblock,daffainfo</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)metabase&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Metabase login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">login</span><span class="nt-tag">metabase</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="metaflow ui panel - detect info identify web-based control panels metaflow is an open-source ml platform created by netflix for building and managing real-life data science projects.
the metaflow ui provides a web interface for monitoring and managing metaflow runs and flows. rxerium ai detect discovery metaflow mlops netflix panel" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Metaflow UI Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/metaflow-ui-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">metaflow-ui-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 27, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;^Metaflow UI&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Metaflow is an open-source ML platform created by Netflix for building and managing real-life data science projects.
The Metaflow UI provides a web interface for monitoring and managing Metaflow runs and flows.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">ai</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">metaflow</span><span class="nt-tag">mlops</span><span class="nt-tag">netflix</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/Netflix/metaflow-ui" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://metaflow.org" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="metasploit panel - detect info identify web-based control panels metasploit web panel is detected lu4nx discovery login metasploit panel rapid7 cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Metasploit Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/metasploit-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">metasploit-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> lu4nx</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 23, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)metasploit&#34;}) || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)metasploit - setup and configuration&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Metasploit Web Panel is detected</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">login</span><span class="nt-tag">metasploit</span><span class="nt-tag">panel</span><span class="nt-tag">rapid7</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="metasploit setup and configuration page - detect info identify web-based control panels metasploit setup and configuration page was detected. ritikchaddha discovery metasploit panel rapid7 setup cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Metasploit Setup and Configuration Page - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/metasploit-setup-page.yaml" target="_blank" rel="noopener" class="nt-source-link">metasploit-setup-page.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)metasploit - setup and configuration&#34;}) || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)metasploit&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Metasploit setup and configuration page was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">metasploit</span><span class="nt-tag">panel</span><span class="nt-tag">rapid7</span><span class="nt-tag">setup</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="metersphere login panel - detect info identify web-based control panels metersphere login panel was detected. pdteam panel metersphere discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">MeterSphere Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/metersphere-login.yaml" target="_blank" rel="noopener" class="nt-source-link">metersphere-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pdteam</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)metersphere&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">MeterSphere login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">metersphere</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/metersphere/metersphere" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="metersphere - arbitrary file read high identify critical remote vulnerabilities metersphere is an open source continuous testing platform. in affected versions an improper access control vulnerability exists in `/api/jmeter/download/files`, which allows any user to download any file without authentication. this issue may expose all files available to the running process. this issue has been addressed in version 1.20.20 lts and 2.7.1 cve-2023-25573 dhiyaneshdk cve cve2023 lfi metersphere vkev vuln cwe-862" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Metersphere - Arbitrary File Read</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-25573.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-25573.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 14, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/862.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-862</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-25573" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-25573</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)metersphere&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Metersphere is an open source continuous testing platform. In affected versions an improper access control vulnerability exists in `/api/jmeter/download/files`, which allows any user to download any file without authentication. This issue may expose all files available to the running process. This issue has been addressed in version 1.20.20 lts and 2.7.1</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">This vulnerability can lead to unauthorized access to sensitive information, such as configuration files, credentials, and other sensitive data.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Users are advised to upgrade. There are no known workarounds for this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">lfi</span><span class="nt-tag">metersphere</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/Threekiii/Awesome-POC/blob/master/Web%E5%BA%94%E7%94%A8%E6%BC%8F%E6%B4%9E/Metersphere%20file%20%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E%20CVE-2023-25573.md" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-25573" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/metersphere/metersphere/security/advisories/GHSA-mcwr-j9vm-5g8h" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/20142995/sectool" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/KayCHENvip/vulnerability-poc" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="micro focus application lifecycle management - panel info identify web-based control panels micro focus application lifecycle management login panel was detected. righettod panel microfocus login detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Micro Focus Application Lifecycle Management - Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/microfocus-lifecycle-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">microfocus-lifecycle-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 21, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Micro\u00a0Focus\u00a0Application\u00a0Lifecycle\u00a0Management&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Micro Focus Application Lifecycle Management login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">microfocus</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.opentext.com/products/alm-quality-center" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="micro focus filr login panel - detect info identify web-based control panels micro focus filr login panel was detected. ritikchaddha,righettod detect discovery filr microfocus panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Micro Focus Filr Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/microfocus-filr-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">microfocus-filr-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha,righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)micro focus filr&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Micro Focus Filr login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">filr</span><span class="nt-tag">microfocus</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="micro focus vibe login panel - detect info identify web-based control panels micro focus vibe login panel was detected. ritikchaddha,righettod discovery microfocus panel vibe cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Micro Focus Vibe Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/microfocus-vibe-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">microfocus-vibe-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha,righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)micro focus vibe&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Micro Focus Vibe login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">microfocus</span><span class="nt-tag">panel</span><span class="nt-tag">vibe</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="microsoft exchange - authentication bypass high identify critical remote vulnerabilities microsoft exchange server information disclosure vulnerability. this vulnerability enables an attacker to bypass authentication and gain access to the exchange server&#39;s internal. cve-2021-33766 daffainfo auth-bypass cve cve2021 exchange kev microsoft vkev vuln nvd-cwe-noinfo" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Microsoft Exchange - Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2021/CVE-2021-33766.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2021-33766.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> daffainfo</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 10, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/NVD-CWE-NOINFO.html" target="_blank" rel="noopener" class="nt-cwe-link">NVD-CWE-NOINFO</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2021-33766" target="_blank" rel="noopener" class="nt-cve-link">CVE-2021-33766</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)outlook&#34;}) || service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1768726119&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Microsoft Exchange Server Information Disclosure Vulnerability. This vulnerability enables an attacker to bypass authentication and gain access to the Exchange Server&#39;s internal.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can bypass authentication using a SecurityToken cookie, gaining access to Exchange Server&#39;s internal API endpoints and sensitive information.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply security updates provided by Microsoft to fix the authentication bypass vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2021</span><span class="nt-tag">exchange</span><span class="nt-tag">kev</span><span class="nt-tag">microsoft</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-33766" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.zerodayinitiative.com/advisories/ZDI-21-798/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/demossl/CVE-2021-33766-ProxyToken" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2021-33766" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="microsoft exchange - pre-auth ssrf / acl bypass (proxynotfound) critical identify critical remote vulnerabilities microsoft exchange server contains a remote code execution caused by improper input validation in the server component, letting remote attackers execute arbitrary code, exploit requires network access to the server. daffainfo cve cve2021 exchange microsoft rce ssrf vkev d-cwe-noinfo" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Microsoft Exchange - Pre-Auth SSRF / ACL Bypass (ProxyNotFound)</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2021/CVE-2021-28481.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2021-28481.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> daffainfo</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 20, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/D-CWE-NOINFO.html" target="_blank" rel="noopener" class="nt-cwe-link">D-CWE-NOINFO</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;product&#34;] contains &#34;Microsoft:Exchange Server&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Microsoft Exchange Server contains a remote code execution caused by improper input validation in the server component, letting remote attackers execute arbitrary code, exploit requires network access to the server.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can execute arbitrary code remotely, potentially leading to full system compromise or data breach</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches and updates provided by Microsoft for Exchange Server</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2021</span><span class="nt-tag">exchange</span><span class="nt-tag">microsoft</span><span class="nt-tag">rce</span><span class="nt-tag">ssrf</span><span class="nt-tag">vkev</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://sec.vnpt.vn/2021/04/microsoft-exchange-from-deserialization-to-post-auth-rce-cve-2021-28482" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://hitcon.org/2021/agenda/279d7810-e619-4dc3-9113-b11bad5277ec/The%20Proxy%20Era%20of%20Microsoft%20Exchange%20Server.pdf" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.youtube.com/watch?v=vn4niT9XEIM" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2021-28481" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://nvd.nist.gov/vuln/detail/cve-2021-28481" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="microsoft exchange - pre-auth ssrf / acl bypass (proxynotfound) critical identify critical remote vulnerabilities microsoft exchange server contains a remote code execution caused by improper input validation in the server component, letting remote attackers execute arbitrary code, exploit requires network access to the server. cve-2021-28480 daffainfo cve cve2021 exchange microsoft rce ssrf d-cwe-noinfo" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Microsoft Exchange - Pre-Auth SSRF / ACL Bypass (ProxyNotFound)</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2021/CVE-2021-28480.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2021-28480.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> daffainfo</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 20, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/D-CWE-NOINFO.html" target="_blank" rel="noopener" class="nt-cwe-link">D-CWE-NOINFO</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2021-28480" target="_blank" rel="noopener" class="nt-cve-link">CVE-2021-28480</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;product&#34;] contains &#34;Microsoft:Exchange Server&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Microsoft Exchange Server contains a remote code execution caused by improper input validation in the server component, letting remote attackers execute arbitrary code, exploit requires network access to the server.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can execute arbitrary code remotely, potentially leading to full system compromise or data breach</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches and updates provided by Microsoft for Exchange Server</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2021</span><span class="nt-tag">exchange</span><span class="nt-tag">microsoft</span><span class="nt-tag">rce</span><span class="nt-tag">ssrf</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://sec.vnpt.vn/2021/04/microsoft-exchange-from-deserialization-to-post-auth-rce-cve-2021-28482" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://hitcon.org/2021/agenda/279d7810-e619-4dc3-9113-b11bad5277ec/The%20Proxy%20Era%20of%20Microsoft%20Exchange%20Server.pdf" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.youtube.com/watch?v=vn4niT9XEIM" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2021-28480" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://nvd.nist.gov/vuln/detail/cve-2021-28480" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="microsoft exchange admin center login panel - detect info identify web-based control panels microsoft exchange admin center login panel was detected. r3dg33k discovery exchange microsoft panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Microsoft Exchange Admin Center Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/microsoft-exchange-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">microsoft-exchange-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> r3dg33k</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1768726119&#34; || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)outlook&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Microsoft Exchange Admin Center login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">exchange</span><span class="nt-tag">microsoft</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://docs.microsoft.com/en-us/answers/questions/58814/block-microsoft-exchange-server-2016-exchange-admi.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="microsoft exchange server end-of-life - detect info identify web-based control panels detected microsoft exchange server versions that have reached end-of-life (eol) and no longer receive security updates. shivam kamboj tech msexchange eol" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Microsoft Exchange Server End-of-Life - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/technologies/eol/msexchange-eol.yaml" target="_blank" rel="noopener" class="nt-source-link">msexchange-eol.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Shivam Kamboj</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 3, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;product&#34;] contains &#34;Microsoft:Outlook Web Access&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detected Microsoft Exchange Server versions that have reached End-of-Life (EOL) and no longer receive security updates.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">tech</span><span class="nt-tag">msexchange</span><span class="nt-tag">eol</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://endoflife.date/msexchange" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://learn.microsoft.com/en-us/exchange/new-features/build-numbers-and-release-dates" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="microsoft exchange server pre-auth post based cross-site scripting medium identify critical remote vulnerabilities microsoft exchange server is vulnerable to a spoofing vulnerability. be aware this cve id is unique from cve-2021-42305. cve-2021-41349 rootxharsh,iamnoooob cve cve2021 exchange microsoft vkev vuln xss" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Microsoft Exchange Server Pre-Auth POST Based Cross-Site Scripting</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2021/CVE-2021-41349.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2021-41349.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rootxharsh,iamnoooob</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2021-41349" target="_blank" rel="noopener" class="nt-cve-link">CVE-2021-41349</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1768726119&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Microsoft Exchange Server is vulnerable to a spoofing vulnerability. Be aware this CVE ID is unique from CVE-2021-42305.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute arbitrary script code in the context of the targeted user&#39;s browser, potentially leading to session hijacking, data theft, or other malicious activities.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security updates provided by Microsoft to mitigate this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2021</span><span class="nt-tag">exchange</span><span class="nt-tag">microsoft</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">xss</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.microsoft.com/en-us/download/details.aspx?id=103643" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/httpvoid/CVE-Reverse/tree/master/CVE-2021-41349" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2021-41349" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-41349" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-41349" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="microsoft exchange web service - detect info identify web-based control panels microsoft exchange web services was detected. bhutch,userdehghani discovery exchange microsoft ms panel tech" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Microsoft Exchange Web Service - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/ms-exchange-web-service.yaml" target="_blank" rel="noopener" class="nt-source-link">ms-exchange-web-service.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> bhutch,userdehghani</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 2, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)outlook&#34;}) || service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1768726119&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Microsoft Exchange Web Services was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">exchange</span><span class="nt-tag">microsoft</span><span class="nt-tag">ms</span><span class="nt-tag">panel</span><span class="nt-tag">tech</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://learn.microsoft.com/en-us/exchange/client-developer/exchange-web-services/start-using-web-services-in-exchange" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://pentestlab.blog/tag/ews/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="microsoft windows &#39;http.sys&#39; - remote code execution critical identify critical remote vulnerabilities http.sys in microsoft windows 7 sp1, windows server 2008 r2 sp1, windows 8, windows 8.1, and windows server 2012 gold and r2 allows remote attackers to execute arbitrary code via crafted http requests, aka &#34;http.sys remote code execution vulnerability.&#34; cve-2015-1635 phillipo cve cve2015 iis kev microsoft rce vkev vuln cwe-94" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Microsoft Windows &#39;HTTP.sys&#39; - Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2015/CVE-2015-1635.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2015-1635.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Phillipo</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 23, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/94.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-94</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2015-1635" target="_blank" rel="noopener" class="nt-cve-link">CVE-2015-1635</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.head.server&#34;] matches `(?i)microsoft-iis`</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote attackers to execute arbitrary code via crafted HTTP requests, aka &#34;HTTP.sys Remote Code Execution Vulnerability.&#34;</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can execute arbitrary code remotely on Windows servers running vulnerable HTTP.sys, potentially leading to complete system compromise and data breach.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply Microsoft security update MS15-034 immediately to patch the vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2015</span><span class="nt-tag">iis</span><span class="nt-tag">kev</span><span class="nt-tag">microsoft</span><span class="nt-tag">rce</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.exploit-db.com/exploits/36773" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.securitysift.com/an-analysis-of-ms15-034/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2015-1635" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="http://www.securitytracker.com/id/1032109" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/b1gbroth3r/shoMe" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="microsys promotic scada - login panel info identify web-based control panels microsys promotic is a scada/hmi software platform widely deployed in central european
industrial and building automation applications. the embedded web server exposes a
runtime panel accessible over http on non-standard ports. rxerium discovery ics microsys ot panel promotic scada" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Microsys Promotic SCADA - Login Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/microsys-promotic-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">microsys-promotic-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 27, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;PROMOTIC&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Microsys Promotic is a SCADA/HMI software platform widely deployed in central European
industrial and building automation applications. The embedded web server exposes a
runtime panel accessible over HTTP on non-standard ports.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">ics</span><span class="nt-tag">microsys</span><span class="nt-tag">ot</span><span class="nt-tag">panel</span><span class="nt-tag">promotic</span><span class="nt-tag">scada</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.microsys.cz/en/products/promotic/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="microweber &lt;1.1.20 - information disclosure high identify critical remote vulnerabilities microweber before 1.1.20 is susceptible to information disclosure via userfiles/modules/users/controller/controller.php. an attacker can disclose the users database via a /modules/ post request and thus potentially access sensitive information, modify data, and/or execute unauthorized operations. cve-2020-13405 ritikchaddha,amit-jd cve cve2020 disclosure microweber unauth vuln cwe-306" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Microweber &lt;1.1.20 - Information Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2020/CVE-2020-13405.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2020-13405.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha,amit-jd</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/306.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-306</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2020-13405" target="_blank" rel="noopener" class="nt-cve-link">CVE-2020-13405</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)microweber&#34; || service[&#34;favicon.ico.image.mmh3&#34;] == &#34;780351152&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Microweber before 1.1.20 is susceptible to information disclosure via userfiles/modules/users/controller/controller.php. An attacker can disclose the users database via a /modules/ POST request and thus potentially access sensitive information, modify data, and/or execute unauthorized operations.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can exploit this vulnerability to gain unauthorized access to sensitive information.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade Microweber to version 1.1.20 or later to mitigate the vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2020</span><span class="nt-tag">disclosure</span><span class="nt-tag">microweber</span><span class="nt-tag">unauth</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://rhinosecuritylabs.com/research/microweber-database-disclosure/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/microweber/microweber/commit/269320e0e0e06a1785e1a1556da769a34280b7e6" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2020-13405" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/merlinepedra/RHINOECURITY-CVEs" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/mrnazu/CVE-2020-13405" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="microweber &lt;1.2.15 - cross-site scripting medium identify critical remote vulnerabilities microweber prior to 1.2.15 contains a reflected cross-site scripting vulnerability. an attacker can execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. this can allow the attacker to steal cookie-based authentication credentials and launch other attacks. cve-2022-1439 pikpikcu cve cve2022 huntr microweber vkev vuln xss cwe-79" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Microweber &lt;1.2.15 - Cross-Site Scripting</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-1439.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-1439.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pikpikcu</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-79</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-1439" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-1439</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;780351152&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Microweber prior to 1.2.15 contains a reflected cross-site scripting vulnerability. An attacker can execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to inject malicious scripts into web pages viewed by users, leading to potential data theft, session hijacking, or defacement of the affected website.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to Microweber CMS version 1.2.15 or later, which includes proper input sanitization to mitigate the XSS vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">huntr</span><span class="nt-tag">microweber</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">xss</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://huntr.dev/bounties/86f6a762-0f3d-443d-a676-20f8496907e0/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://huntr.dev/bounties/86f6a762-0f3d-443d-a676-20f8496907e0" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/microweber/microweber/commit/ad3928f67b2cd4443f4323d858b666d35a919ba8" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-1439" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/ARPSyndicate/cvemon" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="mikrotik router os login panel - detect info identify web-based control panels mikrotik router os login panel was detected. gy741 panel login mikrotik discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">MikroTik Router OS Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/mikrotik/mikrotik-routeros.yaml" target="_blank" rel="noopener" class="nt-source-link">mikrotik-routeros.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> gy741</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)mikrotik routeros &gt; administration&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">MikroTik Router OS login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">login</span><span class="nt-tag">mikrotik</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://systemweakness.com/routeros-user-with-just-ftp-policy-can-write-to-filesystem-cve-2021-27221-e3e45d780dfe" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="mikrotik routeros admin login panel - detect info identify web-based control panels mikrotik routeros admin login panel was detected. its0x08,dhiyaneshdk discovery login mikrotik panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">MikroTik RouterOS Admin Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/mikrotik/mikrotik-routeros-old.yaml" target="_blank" rel="noopener" class="nt-source-link">mikrotik-routeros-old.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> its0x08,DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)mikrotik routeros &gt; administration&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">MikroTik RouterOS admin login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">login</span><span class="nt-tag">mikrotik</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="milesight routers - information disclosure high identify critical remote vulnerabilities a critical security vulnerability has been identified in milesight industrial cellular routers, compromising the security of sensitive credentials and permitting unauthorized access. this vulnerability stems from a misconfiguration that results in directory listing being enabled on the router systems, rendering log files publicly accessible. these log files, while containing sensitive information such as admin and other user passwords (encrypted as a security measure), can be exploited by attackers via the router&#39;s web interface. the presence of a hardcoded aes secret key and initialization vector (iv) in the javascript code further exacerbates the situation, facilitating the decryption of these passwords. this chain of vulnerabilities allows malicious actors to gain unauthorized access to the router. cve-2023-43261 gy741 cve cve2023 disclosure iot milesight router unauth vkev vuln cwe-532" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Milesight Routers - Information Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-43261.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-43261.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> gy741</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 2, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/532.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-532</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-43261" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-43261</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)rt_title&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A critical security vulnerability has been identified in Milesight Industrial Cellular Routers, compromising the security of sensitive credentials and permitting unauthorized access. This vulnerability stems from a misconfiguration that results in directory listing being enabled on the router systems, rendering log files publicly accessible. These log files, while containing sensitive information such as admin and other user passwords (encrypted as a security measure), can be exploited by attackers via the router&#39;s web interface. The presence of a hardcoded AES secret key and initialization vector (IV) in the JavaScript code further exacerbates the situation, facilitating the decryption of these passwords. This chain of vulnerabilities allows malicious actors to gain unauthorized access to the router.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can access publicly exposed log files containing encrypted admin and user passwords, then decrypt them using the hardcoded AES key found in JavaScript code, gaining full administrative access to industrial cellular routers.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update Milesight Industrial Cellular Router firmware to disable directory listing, restrict access to log files, and remove hardcoded cryptographic keys from the web interface.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">disclosure</span><span class="nt-tag">iot</span><span class="nt-tag">milesight</span><span class="nt-tag">router</span><span class="nt-tag">unauth</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://medium.com/@win3zz/inside-the-router-how-i-accessed-industrial-routers-and-reported-the-flaws-29c34213dfdf" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/win3zz/CVE-2023-43261" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-43261" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="http://milesight.com" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="http://ur5x.com" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="minio browser login panel - detect info identify web-based control panels minio browser login panel was detected. pikpikcu discovery minio panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">MinIO Browser Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/minio-browser.yaml" target="_blank" rel="noopener" class="nt-source-link">minio-browser.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pikpikcu</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)minio browser&#34;}) || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)minio console&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">MinIO Browser login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">minio</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="minio cluster deployment - information disclosure high identify critical remote vulnerabilities minio is susceptible to information disclosure. in a cluster deployment starting with release.2019-12-17t23-16-33z and prior to release.2023-03-20t20-16-18z, minio returns all environment variables, including minio_secret_key and minio_root_password. an attacker can potentially obtain sensitive information, modify data, and/or execute unauthorized operations without entering necessary credentials. all users of distributed deployment are impacted. cve-2023-28432 mr-xn console cve cve2023 exposure kev minio vkev vuln cwe-200,nvd-cwe-noinfo" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">MinIO Cluster Deployment - Information Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-28432.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-28432.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Mr-xn</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200,NVD-CWE-NOINFO.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200,NVD-CWE-NOINFO</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-28432" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-28432</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)symfony profiler&#34; || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)minio console&#34;}) || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)minio browser&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">MinIO is susceptible to information disclosure. In a cluster deployment starting with RELEASE.2019-12-17T23-16-33Z and prior to RELEASE.2023-03-20T20-16-18Z, MinIO returns all environment variables, including MINIO_SECRET_KEY and MINIO_ROOT_PASSWORD. An attacker can potentially obtain sensitive information, modify data, and/or execute unauthorized operations without entering necessary credentials. All users of distributed deployment are impacted.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can gain unauthorized access to sensitive information stored in the MinIO cluster.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">All users are advised to upgrade to RELEASE.2023-03-20T20-16-18Z.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">console</span><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">exposure</span><span class="nt-tag">kev</span><span class="nt-tag">minio</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/minio/minio/security/advisories/GHSA-6xvq-wj2x-3h3q" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/minio/minio/pull/16853/files" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/golang/vulndb/issues/1667" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/CVEProject/cvelist/blob/master/2023/28xxx/CVE-2023-28432.json" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-28432" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="minio console login panel - detect info identify web-based control panels minio console login panel was detected. pussycat0x discovery minio panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">MinIO Console Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/minio-console.yaml" target="_blank" rel="noopener" class="nt-source-link">minio-console.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)MinIO Console&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">MinIO Console login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">minio</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="mingsoft mcms - sql injection critical identify critical remote vulnerabilities sql injection vulnerability in mingsoft mcms up to 5.2.9 via the sqlwhere parameter in /cms/category/list. cve-2022-4375 ritikchaddha cve cve2022 mcms mingsoft sqli vuln cwe-707,cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Mingsoft MCMS - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-4375.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-4375.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 5, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/707,CWE-89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-707,CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-4375" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-4375</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1464851260&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">SQL injection vulnerability in Mingsoft MCMS up to 5.2.9 via the sqlWhere parameter in /cms/category/list.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation could lead to unauthorized access to sensitive data.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the vendor-supplied patch or update to the latest version.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">mcms</span><span class="nt-tag">mingsoft</span><span class="nt-tag">sqli</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://gitee.com/mingSoft/MCMS/issues/I61TG5" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-4375" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="mingsoft mcms 5.2.9 - sql injection critical identify critical remote vulnerabilities mingsoft mcms v5.2.9 contains a sql injection caused by unsanitized categorytype parameter at /content/list.do, letting attackers execute arbitrary sql commands, exploit requires crafted input. cve-2023-50578 ritikchaddha cve cve2023 mcms mingsoft sqli vuln cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Mingsoft MCMS 5.2.9 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-50578.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-50578.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 5, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-50578" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-50578</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1464851260&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Mingsoft MCMS v5.2.9 contains a SQL injection caused by unsanitized categoryType parameter at /content/list.do, letting attackers execute arbitrary SQL commands, exploit requires crafted input.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can execute arbitrary SQL commands, potentially leading to data leakage, modification, or deletion.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest version of Mingsoft MCMS or apply security patches that sanitize input parameters.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">mcms</span><span class="nt-tag">mingsoft</span><span class="nt-tag">sqli</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://gitee.com/mingSoft/MCMS/issues/I8MAJK" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-50578" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="mingsoft mcms v5.2.7 - sql injection critical identify critical remote vulnerabilities mingsoft mcms v5.2.7 contains an sql injection vulnerability via /cms/content/list that allows unauthenticated attackers to execute arbitrary sql commands on the affected database server. cve-2022-26585 ritikchaddha cve cve2022 mcms mingsoft sqli vuln cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Mingsoft MCMS v5.2.7 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-26585.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-26585.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 1, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-26585" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-26585</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1464851260&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Mingsoft MCMS v5.2.7 contains an SQL injection vulnerability via /cms/content/list that allows unauthenticated attackers to execute arbitrary SQL commands on the affected database server.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can execute arbitrary SQL commands through the categoryId parameter in /cms/content/list, potentially extracting sensitive database information, modifying data, or compromising the entire Mingsoft MCMS database.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade Mingsoft MCMS to version 5.2.8 or later, which contains patches for this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">mcms</span><span class="nt-tag">mingsoft</span><span class="nt-tag">sqli</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://gitee.com/mingSoft/MCMS/issues/I4W1S9" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-26585" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="minio default login high identify default logins in web-based control panels minio default admin credentials were discovered. pikpikcu default-login minio vuln cwe-522" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Minio Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/minio/minio-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">minio-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pikpikcu</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/522.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-522</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;symfony Profiler&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Minio default admin credentials were discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">minio</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://docs.min.io/docs/minio-quickstart-guide.html#" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="mirantis kubernetes engine panel - detect info identify web-based control panels mirantis kubernetes engine panel was detected. pussycat0x devops discovery k8s kube kubernetes panel tech cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Mirantis Kubernetes Engine Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/kubernetes-mirantis.yaml" target="_blank" rel="noopener" class="nt-source-link">kubernetes-mirantis.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Mirantis Kubernetes Engine&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Mirantis Kubernetes Engine panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">devops</span><span class="nt-tag">discovery</span><span class="nt-tag">k8s</span><span class="nt-tag">kube</span><span class="nt-tag">kubernetes</span><span class="nt-tag">panel</span><span class="nt-tag">tech</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="mirth connect - default admin credentials high identify default logins in web-based control panels detected mirth connect was using default credentials admin:admin. mirth connect is a widely used healthcare integration engine for hl7, fhir, and other medical data standards. 0x_akoko default-login healthcare mirth misconfig cwe-798" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Mirth Connect - Default Admin Credentials</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/mirth/mirth-connect-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">mirth-connect-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_Akoko</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 8, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/798.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-798</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Mirth Connect&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detected Mirth Connect was using default credentials admin:admin. Mirth Connect is a widely used healthcare integration engine for HL7, FHIR, and other medical data standards.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">healthcare</span><span class="nt-tag">mirth</span><span class="nt-tag">misconfig</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.nextgen.com/products-and-services/integration-engine" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://docs.nextgen.com/bundle/Mirth_Connect_v4.4.1/page/connect/connect/topics/c_Getting_Started_mirth_connect_ug.html" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="mistserver installation wizard - exposure high identify critical remote vulnerabilities mistserver installation/setup wizard is publicly accessible, allowing unauthorized users to create admin accounts and take full control of the streaming server. this is a first-user-wins vulnerability. dhiyaneshdk misconfig mistserver install exposure" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">MistServer Installation Wizard - Exposure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/misconfiguration/installer/mistserver-installer.yaml" target="_blank" rel="noopener" class="nt-source-link">mistserver-installer.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 24, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)MistServer&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">MistServer installation/setup wizard is publicly accessible, allowing unauthorized users to create admin accounts and take full control of the streaming server. This is a first-user-wins vulnerability.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can create an admin account on unconfigured MistServer instances,
gaining full control over the streaming server configuration and content.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">misconfig</span><span class="nt-tag">mistserver</span><span class="nt-tag">install</span><span class="nt-tag">exposure</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://docs.mistserver.org/mistserver/configuration" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://mistserver.org/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="mitel 6000 - default login high identify default logins in web-based control panels this template detects the use of default credentials (admin:22222) on mitel 6000 devices, which may allow unauthorized access to system information. matejsmycka mitel mitel-6000 default-login vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Mitel 6000 - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/mitel/mitel-6000-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">mitel-6000-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> matejsmycka</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 29, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.head.server&#34;] matches &#34;Aragorn Mitel&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">This template detects the use of default credentials (admin:22222) on Mitel 6000 devices, which may allow unauthorized access to system information.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">mitel</span><span class="nt-tag">mitel-6000</span><span class="nt-tag">default-login</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wiki.bicomsystems.com/UADs/Mitel_6930" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="mitel login panel - detect info identify web-based control panels mitel login panel was detected. ritikchaddha discovery mitel panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Mitel Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/mitel-panel-detect.yaml" target="_blank" rel="noopener" class="nt-source-link">mitel-panel-detect.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)mitel networks&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Mitel login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">mitel</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="mitel micollab - arbitary file read critical identify critical remote vulnerabilities the mitel collab arbitrary file read vulnerability allows an unauthenticated attacker to read arbitrary files from the underlying file system on a mitel collab server. exploiting this flaw involves sending specially crafted requests to the server, bypassing access controls and allowing the attacker to retrieve sensitive files. cve-2024-55550 dhiyaneshdk,watchtowr auth-bypass cmg-suite cve cve2024 kev lfi mitel vkev vuln cwe-22" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Mitel MiCollab - Arbitary File Read</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-55550.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-55550.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk,watchTowr</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 11, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-55550" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-55550</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Mitel Networks&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The Mitel Collab Arbitrary File Read vulnerability allows an unauthenticated attacker to read arbitrary files from the underlying file system on a Mitel Collab server. Exploiting this flaw involves sending specially crafted requests to the server, bypassing access controls and allowing the attacker to retrieve sensitive files.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can bypass authentication and exploit path traversal to read arbitrary files from the MiCollab server, exposing sensitive configuration, credentials, and system data.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update Mitel MiCollab according to MISA-2024-0029 advisory to address the authentication bypass and path traversal vulnerabilities.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">cmg-suite</span><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">kev</span><span class="nt-tag">lfi</span><span class="nt-tag">mitel</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/watchtowrlabs/Mitel-MiCollab-Auth-Bypass_CVE-2024-41713" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://labs.watchtowr.com/where-theres-smoke-theres-fire-mitel-micollab-cve-2024-35286-cve-2024-41713-and-an-0day/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-misa-2024-0029" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="mitel micollab - authentication bypass high identify critical remote vulnerabilities a vulnerability in the nupoint unified messaging (npm) component of mitel micollab through 9.8 sp1 fp2 (9.8.1.201) could allow an unauthenticated attacker to conduct a path traversal attack, due to insufficient input validation. a successful exploit could allow unauthorized access, enabling the attacker to view, corrupt, or delete users&#39; data and system configurations. cve-2024-41713 dhiyaneshdk,watchtowr auth-bypass cmg-suite cve cve204 kev mitel vkev vuln cwe-22" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Mitel MiCollab - Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-41713.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-41713.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK,watchTowr</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 5, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-41713" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-41713</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Mitel Networks&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct a path traversal attack, due to insufficient input validation. A successful exploit could allow unauthorized access, enabling the attacker to view, corrupt, or delete users&#39; data and system configurations.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can exploit path traversal to access sensitive user data, system configurations, and corrupt or delete information.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update Mitel MiCollab to a version later than 9.8 SP1 FP2 that patches CVE-2024-41713.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">cmg-suite</span><span class="nt-tag">cve</span><span class="nt-tag">cve204</span><span class="nt-tag">kev</span><span class="nt-tag">mitel</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-misa-2024-0029" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://labs.watchtowr.com/where-theres-smoke-theres-fire-mitel-micollab-cve-2024-35286-cve-2024-41713-and-an-0day/?123" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-41713" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="mitel micollab - information disclosure &amp; denial of service critical identify critical remote vulnerabilities mitel micollab before 9.4 sp1 fp1 and mivoice business express through 8.1 contain a vulnerability in the tp-240 component caused by improper handling, letting remote attackers obtain sensitive information and cause denial of service, exploit requires remote access. cve-2022-26143 theamanrawat cve cve2022 kev micollab mitel passive vkev cwe-306" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Mitel MiCollab - Information Disclosure &amp; Denial of Service</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-26143.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-26143.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> theamanrawat</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 29, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/306.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-306</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-26143" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-26143</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)MiCollab End User Portal&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business Express through 8.1 contain a vulnerability in the TP-240 component caused by improper handling, letting remote attackers obtain sensitive information and cause denial of service, exploit requires remote access.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can retrieve sensitive information and cause performance degradation or denial of service, including DDoS attacks.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to version 9.4 SP1 FP1 or later for MiCollab, and latest version for MiVoice Business Express.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">kev</span><span class="nt-tag">micollab</span><span class="nt-tag">mitel</span><span class="nt-tag">passive</span><span class="nt-tag">vkev</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-26143" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="mitel micollab &lt;= 9.8.0.33 - sql injection critical identify critical remote vulnerabilities a vulnerability in nupoint messenger (npm) of mitel micollab through 9.8.0.33 allows an unauthenticated attacker to conduct a sql injection attack due to insufficient sanitization of user input. a successful exploit could allow an attacker to access sensitive information and execute arbitrary database and management operations. cve-2024-35286 daffainfo cve cve2024 micollab mitel sqli vkev vuln cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Mitel MiCollab &lt;= 9.8.0.33 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-35286.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-35286.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> daffainfo</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 12, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-35286" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-35286</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Mitel\&#34; html:\&#34;MiCollab&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A vulnerability in NuPoint Messenger (NPM) of Mitel MiCollab through 9.8.0.33 allows an unauthenticated attacker to conduct a SQL injection attack due to insufficient sanitization of user input. A successful exploit could allow an attacker to access sensitive information and execute arbitrary database and management operations.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can execute arbitrary SQL queries to access sensitive information and execute arbitrary database and management operations.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update Mitel MiCollab to a version later than 9.8.0.33.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">micollab</span><span class="nt-tag">mitel</span><span class="nt-tag">sqli</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-24-0014" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://labs.watchtowr.com/where-theres-smoke-theres-fire-mitel-micollab-cve-2024-35286-cve-2024-41713-and-an-0day/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="mitel micollab awv 8.1.2.4 and 9.1.3 - directory traversal medium identify critical remote vulnerabilities a directory traversal vulnerability in the web conference component of mitel micollab awv before 8.1.2.4 and 9.x before 9.1.3 could allow an attacker to access arbitrary files from restricted directories of the server via a crafted url, due to insufficient access validation. a successful exploit could allow an attacker to access sensitive information from the restricted directories. cve-2020-11798 ritikchaddha cve cve2020 lfi micollab mitel packetstorm vkev vuln cwe-22" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Mitel MiCollab AWV 8.1.2.4 and 9.1.3 - Directory Traversal</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2020/CVE-2020-11798.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2020-11798.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 25, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2020-11798" target="_blank" rel="noopener" class="nt-cve-link">CVE-2020-11798</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Mitel\&#34; html:\&#34;MiCollab&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A Directory Traversal vulnerability in the web conference component of Mitel MiCollab AWV before 8.1.2.4 and 9.x before 9.1.3 could allow an attacker to access arbitrary files from restricted directories of the server via a crafted URL, due to insufficient access validation. A successful exploit could allow an attacker to access sensitive information from the restricted directories.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can exploit this vulnerability to view, modify, or delete arbitrary files on the system, potentially leading to unauthorized access or data leakage.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches or updates provided by Mitel to mitigate the vulnerability and prevent unauthorized access.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2020</span><span class="nt-tag">lfi</span><span class="nt-tag">micollab</span><span class="nt-tag">mitel</span><span class="nt-tag">packetstorm</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://packetstormsecurity.com/files/171751/mma913-traversallfi.txt" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2020-11798" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="http://packetstormsecurity.com/files/171751/Mitel-MiCollab-AWV-8.1.2.4-9.1.3-Directory-Traversal-LFI.html" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://www.mitel.com/-/media/mitel/file/pdf/support/security-advisories/security-bulletin-20-0005-01.pdf" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-20-0005" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="mitel micollab login panel - detect info identify web-based control panels mitel micollab login panel was detected. righettod,darses detect discovery login mitel panel" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Mitel MiCollab Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/mitel-micollab-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">mitel-micollab-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod,darses</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 7, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)MiCollab End User Portal&#34; || service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-1922044295&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Mitel MiCollab login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">login</span><span class="nt-tag">mitel</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.mitel.com/products/micollab-miteam-meetings-collaboration-software" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="mitel nupoint unified messaging panel - detect info identify web-based control panels mitel nupoint unified messaging login panel was detected. s4e-io panel mitel nupoint-unified-messaging detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Mitel NuPoint Unified Messaging Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/mitel-nupoint-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">mitel-nupoint-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> s4e-io</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 10, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)mitel networks&#34; || service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-1922044295&#34; || service[&#34;http.body&#34;] matches &#34;(?i)micollab end user portal&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Mitel NuPoint Unified Messaging login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">mitel</span><span class="nt-tag">nupoint-unified-messaging</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="mobile management platform panel - detect info identify web-based control panels mobile management platform panel was detected. ritikchaddha discovery management mobile panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Mobile Management Platform Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/mobile-management-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">mobile-management-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)移动管理平台-企业管理&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Mobile Management Platform panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">management</span><span class="nt-tag">mobile</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="mobileiron core &amp; connector &lt;= v10.6 &amp; sentry &lt;= v9.8 - remote code execution critical identify critical remote vulnerabilities a remote code execution vulnerability in mobileiron core &amp; connector versions 10.3.0.3 and earlier, 10.4.0.0, 10.4.0.1, 10.4.0.2, 10.4.0.3, 10.5.1.0, 10.5.2.0 and 10.6.0.0; and sentry versions 9.7.2 and earlier, and 9.8.0; and monitor and reporting database (rdb) version 2.0.0.1 and earlier contain a vulnerability that allows remote attackers to execute arbitrary code via unspecified vectors. cve-2020-15505 dwisiswant0 cve cve2020 kev mobileiron rce sentry vkev vuln cwe-706" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">MobileIron Core &amp; Connector &lt;= v10.6 &amp; Sentry &lt;= v9.8 - Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2020/CVE-2020-15505.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2020-15505.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dwisiswant0</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/706.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-706</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2020-15505" target="_blank" rel="noopener" class="nt-cve-link">CVE-2020-15505</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;967636089&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A remote code execution vulnerability in MobileIron Core &amp; Connector versions 10.3.0.3 and earlier, 10.4.0.0, 10.4.0.1, 10.4.0.2, 10.4.0.3, 10.5.1.0, 10.5.2.0 and 10.6.0.0; and Sentry versions 9.7.2 and earlier, and 9.8.0; and Monitor and Reporting Database (RDB) version 2.0.0.1 and earlier contain a vulnerability that allows remote attackers to execute arbitrary code via unspecified vectors.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected system, potentially leading to complete compromise of the MobileIron infrastructure.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade MobileIron Core &amp; Connector and Sentry to versions above v10.6 &amp; v9.8 respectively</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2020</span><span class="nt-tag">kev</span><span class="nt-tag">mobileiron</span><span class="nt-tag">rce</span><span class="nt-tag">sentry</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://blog.orange.tw/2020/09/how-i-hacked-facebook-again-mobileiron-mdm-rce.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/iamnoooob/CVE-Reverse/tree/master/CVE-2020-15505" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/iamnoooob/CVE-Reverse/blob/master/CVE-2020-15505/hessian.py#L10" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/orangetw/JNDI-Injection-Bypass" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15505" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="mobileiron core - remote unauthenticated api access critical identify critical remote vulnerabilities ivanti endpoint manager mobile (epmm), formerly mobileiron core, since cve-2023-35082 arises from the same place as cve-2023-35078, specifically the permissive nature of certain entries in the mifs web application’s security filter chain. cve-2023-35082 dhiyaneshdk cve cve2023 epmm ivanti kev mobileiron vkev vuln cwe-287" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">MobileIron Core - Remote Unauthenticated API Access</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-35082.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-35082.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 3, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/287.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-287</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-35082" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-35082</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;362091310&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Ivanti Endpoint Manager Mobile (EPMM), formerly MobileIron Core, Since CVE-2023-35082 arises from the same place as CVE-2023-35078, specifically the permissive nature of certain entries in the mifs web application’s security filter chain.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Remote attackers can exploit this vulnerability to gain unauthorized access to sensitive data and perform malicious actions.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrading to the latest version of Ivanti Endpoint Manager Mobile (EPMM)</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">epmm</span><span class="nt-tag">ivanti</span><span class="nt-tag">kev</span><span class="nt-tag">mobileiron</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.rapid7.com/blog/post/2023/08/02/cve-2023-35082-mobileiron-core-unauthenticated-api-access-vulnerability/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-35082" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://forums.ivanti.com/s/article/CVE-2023-35082-Remote-Unauthenticated-API-Access-Vulnerability-in-MobileIron-Core-11-2-and-older?language=en_US" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/Chocapikk/CVE-2023-35082" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/Ostorlab/KEV" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="mobileiron sentry panel - detect info identify web-based control panels mobileiron sentry panel was detected. pdteam panel mobileiron discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">MobileIron Sentry Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/mobileiron-sentry.yaml" target="_blank" rel="noopener" class="nt-source-link">mobileiron-sentry.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pdteam</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 26, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;967636089&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">MobileIron Sentry panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">mobileiron</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://help.ivanti.com/mi/help/en_us/sntry/9.9.0/gdcl/Content/SentryGuide/MobileIron_Sentry_overvi.htm" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="mobotix - default login high identify default logins in web-based control panels mobotix contains a default admin login vulnerability. an attacker can obtain access to user accounts and access sensitive information, modify data, and/or execute unauthorized operations. robotshell default-login iot mobotix vuln webcam cwe-798" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Mobotix - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/mobotix/mobotix-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">mobotix-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> robotshell</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/798.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-798</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;Mobotix&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Mobotix contains a default admin login vulnerability. An attacker can obtain access to user accounts and access sensitive information, modify data, and/or execute unauthorized operations.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">iot</span><span class="nt-tag">mobotix</span><span class="nt-tag">vuln</span><span class="nt-tag">webcam</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.mobotix.com/sites/default/files/2020-01/mx_RM_CameraSoftwareManual_en_200131.pdf" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="modoboa &lt; 2.1.0 - improper authorization critical identify critical remote vulnerabilities improper authorization in github repository modoboa/modoboa prior to 2.1.0. cve-2023-2227 ritikchaddha,princechaddha cve cve2023 disclosure exposure modoboa vuln cwe-285" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Modoboa &lt; 2.1.0 - Improper Authorization</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-2227.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-2227.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha,princechaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 25, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/285.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-285</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-2227" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-2227</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1949005079&#34; || service[&#34;http.body&#34;] matches &#34;(?i)modoboa&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Improper Authorization in GitHub repository modoboa/modoboa prior to 2.1.0.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can access sensitive configuration parameters including default passwords and authentication settings through the API endpoint, potentially compromising the entire email management system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update Modoboa to version 2.1.0 or later that implements proper authorization checks for the parameters API endpoint.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">disclosure</span><span class="nt-tag">exposure</span><span class="nt-tag">modoboa</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://huntr.com/bounties/351f9055-2008-4af0-b820-01ff66678bf3" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/modoboa/modoboa/commit/7bcd3f6eb264d4e3e01071c97c2bac51cdd6fe97" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-2227" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="modoboa login panel - detect info identify web-based control panels modoboa login panel was detected. kh4sh3i discovery mail modoboa panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Modoboa Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/modoboa-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">modoboa-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> kh4sh3i</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)modoboa&#34; || service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1949005079&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Modoboa login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">mail</span><span class="nt-tag">modoboa</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://modoboa.org" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/modoboa/modoboa" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="modular ds - broken access control high identify critical remote vulnerabilities modular ds = 2.5.1 contains a broken access control vulnerability caused by incorrect privilege assignment, letting attackers escalate their privileges, exploit requires no special conditions. cve-2026-23550 dhiyaneshdk cve cve2026 wordpress wp-plugin wp auth-bypass modular-connector vkev cwe-266" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Modular DS - Broken Access Control</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2026/CVE-2026-23550.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2026-23550.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 16, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/266.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-266</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2026-23550" target="_blank" rel="noopener" class="nt-cve-link">CVE-2026-23550</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/plugins/modular-connector/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Modular DS = 2.5.1 contains a broken access control vulnerability caused by incorrect privilege assignment, letting attackers escalate their privileges, exploit requires no special conditions.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can escalate their privileges, potentially gaining unauthorized access to sensitive functions or data.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest version beyond 2.5.1.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2026</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">wp</span><span class="nt-tag">auth-bypass</span><span class="nt-tag">modular-connector</span><span class="nt-tag">vkev</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://help.modulards.com/en/article/modular-ds-security-release-modular-connector-252-dm3mv0/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://patchstack.com/database/wordpress/plugin/modular-connector/vulnerability/wordpress-modular-ds-monitor-update-and-backup-multiple-websites-plugin-2-5-1-privilege-escalation-vulnerability" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="molgenis - default login high identify default logins in web-based control panels attempts to login to molgenis using the default credentials (admin/admin). successful login may indicate a security risk due to unchanged default credentials. ritikchaddha molgenis default-login exposure vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Molgenis - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/molgenis/molgenis-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">molgenis-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 8, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] contains &#34;MOLGENIS&#34; || service[&#34;last.http.body&#34;] contains &#34;MOLGENIS&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Attempts to login to Molgenis using the default credentials (admin/admin). Successful login may indicate a security risk due to unchanged default credentials.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">molgenis</span><span class="nt-tag">default-login</span><span class="nt-tag">exposure</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://molgenis.org/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/molgenis/molgenis-emx2" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="mongodb ops manager login panel - detect info identify web-based control panels mongodb ops manager login panel was detected. dhiyaneshdk discovery mongodb panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">MongoDB Ops Manager Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/mongodb-ops-manager.yaml" target="_blank" rel="noopener" class="nt-source-link">mongodb-ops-manager.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)MongoDB Ops Manager&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">MongoDB Ops Manager login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">mongodb</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="mongoose - nosql injection critical identify critical remote vulnerabilities nosql injection vulnerability in mongoose &lt; 8.9.5 affecting the populate() function&#39;s match option. this vulnerability exists due to an incomplete fix for cve-2024-53900. while direct $where injection is blocked, attackers can bypass this protection by nesting $where operators within logical operators like $and, allowing execution of arbitrary javascript code on mongodb server, bypassing authentication, and accessing sensitive administrative data. cve-2025-23061 namhyunko cve cve2025 mongoose nodejs nosql vuln cwe-94" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Mongoose - NoSQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-23061.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-23061.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> NamhyunKo</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 20, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/94.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-94</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-23061" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-23061</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Mongoose&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">NoSQL injection vulnerability in Mongoose &lt; 8.9.5 affecting the populate() function&#39;s match option. This vulnerability exists due to an incomplete fix for CVE-2024-53900. While direct $where injection is blocked, attackers can bypass this protection by nesting $where operators within logical operators like $and, allowing execution of arbitrary JavaScript code on MongoDB server, bypassing authentication, and accessing sensitive administrative data.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can bypass authentication and execute arbitrary JavaScript code on MongoDB servers through nested $where operators in the populate() function, potentially accessing sensitive administrative data and compromising database integrity.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to Mongoose version 8.9.5 or later that properly blocks nested $where operators.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">mongoose</span><span class="nt-tag">nodejs</span><span class="nt-tag">nosql</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/Automattic/mongoose/commit/64a9f9706f2428c49e0cfb8e223065acc645f7bc" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/Automattic/mongoose/releases/tag/8.9.5" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/NamhyeonKo/mongoose-cve-lab" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-23061" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="monitorr panel - detect info identify web-based control panels  ritikchaddha detect discovery monitorr panel" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Monitorr Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/monitorr-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">monitorr-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 25, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-211006074&#34;</code></div>
  <div class="nt-tags"><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">monitorr</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="monsta ftp - detect info identify web-based control panels detects monsta ftp web-based file manager interface. rxerium tech monsta ftp detect" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Monsta FTP - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/monsta-ftp-detect.yaml" target="_blank" rel="noopener" class="nt-source-link">monsta-ftp-detect.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 11, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Monsta FTP&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detects Monsta FTP web-based file manager interface.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">tech</span><span class="nt-tag">monsta</span><span class="nt-tag">ftp</span><span class="nt-tag">detect</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.monstaftp.com/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="monstra admin panel - detect info identify web-based control panels monstra admin panel was detected. ritikchaddha panel monstra discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Monstra Admin Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/monstra-admin-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">monstra-admin-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;419828698&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Monstra admin panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">monstra</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/monstra-cms/monstra/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="moodle lti module reflected - cross-site scripting medium identify critical remote vulnerabilities a reflected xss issue was identified in the lti module of moodle. the vulnerability exists due to insufficient sanitization of user-supplied data in the lti module. a remote attacker can trick the victim to follow a specially crafted link and execute arbitrary html and script code in user&#39;s browser in context of vulnerable website to steal potentially sensitive information, change appearance of the web page, can perform phishing and drive-by-download attacks. cve-2022-35653 iamnoooob,pdresearch cve cve2022 moodle vkev vuln xss cwe-79" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Moodle LTI module Reflected - Cross-Site Scripting</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-35653.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-35653.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> iamnoooob,pdresearch</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 7, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-79</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-35653" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-35653</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Moodle&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A reflected XSS issue was identified in the LTI module of Moodle. The vulnerability exists due to insufficient sanitization of user-supplied data in the LTI module. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user&#39;s browser in context of vulnerable website to steal potentially sensitive information, change appearance of the web page, can perform phishing and drive-by-download attacks.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can inject malicious JavaScript through the LTI module that executes in educators&#39; or students&#39; browsers, potentially stealing Moodle session credentials and accessing sensitive course information.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update Moodle to a patched version that properly sanitizes user input in the LTI module and prevents execution of injected scripts.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">moodle</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">xss</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="http://git.moodle.org/gw?p=moodle.git&amp;a=search&amp;h=HEAD&amp;st=commit&amp;s=MDL-72299" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-35653" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://bugzilla.redhat.com/show_bug.cgi?id=2106277" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6MOKYVRNFNAODP2XSMGJ5CRDUZCZKAR3/" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MTKUSFPSYFINSQFSOHDQIDVE6FWBEU6V/" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="moodle workplace login panel - detect info identify web-based control panels moodle workplace login panel was detected. righettod panel moodle login detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Moodle Workplace Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/moodle-workplace-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">moodle-workplace-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 9, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)moodle&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Moodle workplace login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">moodle</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://moodle.com/solutions/workplace/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="morningstar prostar mppt solar charge controller - detect info identify web-based control panels morningstar prostar mppt is a solar charge controller with a built-in web server providing
live data monitoring for off-grid and industrial solar installations.
the exposed interface displays real-time array, battery, and load data without authentication. rxerium detect energy ics morningstar panel scada solar tech" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Morningstar ProStar MPPT Solar Charge Controller - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/morningstar-prostar-mppt-detect.yaml" target="_blank" rel="noopener" class="nt-source-link">morningstar-prostar-mppt-detect.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 27, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;^Prostar MPPT - Live Data&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Morningstar ProStar MPPT is a solar charge controller with a built-in web server providing
live data monitoring for off-grid and industrial solar installations.
The exposed interface displays real-time array, battery, and load data without authentication.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">detect</span><span class="nt-tag">energy</span><span class="nt-tag">ics</span><span class="nt-tag">morningstar</span><span class="nt-tag">panel</span><span class="nt-tag">scada</span><span class="nt-tag">solar</span><span class="nt-tag">tech</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.morningstarcorp.com/products/prostar-mppt/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="movable type pro login panel - detect info identify web-based control panels movable type pro login panel was detected. dhiyaneshdk discovery movable panel sixapart cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Movable Type Pro Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/movable-type-login.yaml" target="_blank" rel="noopener" class="nt-source-link">movable-type-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)サインイン \\| movable type pro&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Movable Type Pro login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">movable</span><span class="nt-tag">panel</span><span class="nt-tag">sixapart</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="moxa mxview one - network management panel info identify web-based control panels moxa mxview one is a network management platform for industrial ethernet
infrastructure, ot network monitoring, and topology visualisation. it is
widely used in manufacturing, energy, and transportation to manage industrial
switches and routers. rxerium discovery ics industrial-ethernet moxa mxview networking ot panel" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Moxa MXview One - Network Management Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/moxa-mxview-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">moxa-mxview-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 27, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;MXview One Central Manager&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Moxa MXview One is a network management platform for industrial Ethernet
infrastructure, OT network monitoring, and topology visualisation. It is
widely used in manufacturing, energy, and transportation to manage industrial
switches and routers.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">ics</span><span class="nt-tag">industrial-ethernet</span><span class="nt-tag">moxa</span><span class="nt-tag">mxview</span><span class="nt-tag">networking</span><span class="nt-tag">ot</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.moxa.com/en/products/industrial-network-infrastructure/network-management-software/mxview-series/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="multiple shipping address woocommerce &lt; 2.0 - sql injection high identify critical remote vulnerabilities the multiple shipping address woocommerce plugin before 2.0 does not properly sanitize and escape numerous parameters before using them in sql statements via some ajax actions available to unauthenticated users, leading to unauthenticated sql injections. cve-2022-0783 ritikchaddha cve cve2022 multiple-shipping-address-woocommerce sqli vuln wordpress wp wp-plugin cwe-89" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Multiple Shipping Address Woocommerce &lt; 2.0 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-0783.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-0783.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 28, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-0783" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-0783</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)wp-content/plugins/multiple-shipping-address-woocommerce&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The Multiple Shipping Address Woocommerce plugin before 2.0 does not properly sanitize and escape numerous parameters before using them in SQL statements via some AJAX actions available to unauthenticated users, leading to unauthenticated SQL injections.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can execute time-based blind SQL injection to extract database contents, potentially exposing sensitive WooCommerce customer and order data.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update the Multiple Shipping Address Woocommerce plugin to version 2.0 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">multiple-shipping-address-woocommerce</span><span class="nt-tag">sqli</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wpscan.com/vulnerability/4d594424-8048-482d-b61c-45be1e97a8ba/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-0783" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="munin monitoring dashboard - exposure medium identify critical remote vulnerabilities detected munin monitoring dashboard, exposing system metrics and server statistics. 0x_akoko exposure munin monitoring misconfig vuln" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Munin Monitoring Dashboard - Exposure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/misconfiguration/unauth-munin.yaml" target="_blank" rel="noopener" class="nt-source-link">unauth-munin.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_Akoko</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 4, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Munin&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detected Munin monitoring dashboard, exposing system metrics and server statistics.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">exposure</span><span class="nt-tag">munin</span><span class="nt-tag">monitoring</span><span class="nt-tag">misconfig</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://munin-monitoring.org/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="mybb - full path disclosure low identify critical remote vulnerabilities detected mybb forum software exposed the server&#39;s full filesystem path through php fatal errors when files that implemented interfaces were accessed without dependencies. 0x_akoko mybb misconfig fpd" data-nt-sev="low">
  <div class="nt-card-header">
    <div class="nt-title">MyBB - Full Path Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/misconfiguration/mybb-full-path-disclosure.yaml" target="_blank" rel="noopener" class="nt-source-link">mybb-full-path-disclosure.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_Akoko</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 12, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)MyBB&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detected MyBB forum software exposed the server&#39;s full filesystem path through PHP fatal errors when files that implemented interfaces were accessed without dependencies.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">mybb</span><span class="nt-tag">misconfig</span><span class="nt-tag">fpd</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://mybb.com/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="mybb installation panel - detect high identify web-based control panels mybb installation panel was detected. ritikchaddha panel mybb forum discovery cwe-200" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">MyBB Installation Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/mybb/mybb-forum-install.yaml" target="_blank" rel="noopener" class="nt-source-link">mybb-forum-install.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)mybb&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">MyBB installation panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">mybb</span><span class="nt-tag">forum</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="mybb login panel - detect info identify web-based control panels mybb login panel was detected. ritikchaddha panel mybb forum discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">MyBB Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/mybb-forum-detect.yaml" target="_blank" rel="noopener" class="nt-source-link">mybb-forum-detect.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)mybb&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">MyBB login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">mybb</span><span class="nt-tag">forum</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="myq print server panel - detect info identify web-based control panels  darses panel myq detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">MyQ Print Server Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/myq-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">myq-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> darses</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 21, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-924708843&#34; || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)MyQ&#34;}) || service[&#34;favicon.ico.image.mmh3&#34;] == &#34;864100810&#34; || service[&#34;favicon.ico.image.mmh3&#34;] == &#34;784616151&#34; || service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-2012429205&#34;</code></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">myq</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="mystrom panel - detect info identify web-based control panels mystrom panel was detected. fabaff panel mystrom iot discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">MyStrom Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/mystrom-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">mystrom-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> fabaff</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)myStrom&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Mystrom panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">mystrom</span><span class="nt-tag">iot</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="mystic stealer panel - detect info identify web-based control panels mystic stealer panel were detected. pussycat0x tech rat mystic-stealer c2 panel vuln" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Mystic Stealer Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/c2/mystic-stealer.yaml" target="_blank" rel="noopener" class="nt-source-link">mystic-stealer.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 7, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Mystic Stealer&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Mystic Stealer panel were detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">tech</span><span class="nt-tag">rat</span><span class="nt-tag">mystic-stealer</span><span class="nt-tag">c2</span><span class="nt-tag">panel</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="n-able n-central &lt; 2024.2 - authentication bypass detection critical identify critical remote vulnerabilities n-central server versions prior to 2024.2 contain an authentication bypass in the user interface, letting attackers access restricted areas without proper credentials, exploit requires no specific conditions. cve-2024-28200 rxerium cve cve2024 n-able ncentral passive vkev vuln cwe-287" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">N-able N-central &lt; 2024.2 - Authentication Bypass Detection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-28200.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-28200.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 22, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/287.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-287</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-28200" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-28200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;product&#34;] contains &#34;N-able:N-central&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">N-central server versions prior to 2024.2 contain an authentication bypass in the user interface, letting attackers access restricted areas without proper credentials, exploit requires no specific conditions.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can access sensitive user interface features, potentially leading to unauthorized data access or control.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to version 2024.2 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">n-able</span><span class="nt-tag">ncentral</span><span class="nt-tag">passive</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://status.n-able.com/2024/07/02/n-central-critical-security-fix-details/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://me.n-able.com/s/security-advisory/aArVy0000000673KAA/cve202428200-ncentral-authentication-bypass" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.incibe.es/incibe-cert/alerta-temprana/vulnerabilidades/cve-2024-28200" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-28200" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="n-central - authentication bypass medium identify critical remote vulnerabilities n-central &lt; 2025.4 can generate sessionids for unauthenticated users this issue affects n-central: before 2025.4. cve-2025-9316 dhiyaneshdk,horizon3ai cve cve2025 n-central session-leak vkev cwe-1284" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">N-central - Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-9316.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-9316.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK,horizon3ai</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 18, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/1284.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-1284</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-9316" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-9316</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)N-central Login&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">N-central &lt; 2025.4 can generate sessionIDs for unauthenticated users This issue affects N-central: before 2025.4.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can hijack sessions without authentication, potentially leading to unauthorized access.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to version 2025.4 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">n-central</span><span class="nt-tag">session-leak</span><span class="nt-tag">vkev</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-9316" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/horizon3ai/n-able_n-central_xxe_file_read/blob/main/ncentral_xxe_file_read.py" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="n-central login panel - detect info identify web-based control panels n-central login panel was detected. theabhinavgaur discovery n-central panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">N-central Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/ncentral-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">ncentral-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> theabhinavgaur</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)N-central Login&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">N-central login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">n-central</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="n8n - config medium identify critical remote vulnerabilities the `/rest/settings` endpoint in n8n was publicly exposed, which could have disclosed internal configuration details and sensitive application information. icarot n8n config exposed vuln" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">N8n - Config</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposures/configs/n8n-config.yaml" target="_blank" rel="noopener" class="nt-source-link">n8n-config.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> icarot</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 2, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)n8n.io*workflow automation&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The `/rest/settings` endpoint in N8n was publicly exposed, which could have disclosed internal configuration details and sensitive application information.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">n8n</span><span class="nt-tag">config</span><span class="nt-tag">exposed</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/n8n-io/n8n" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="nakivo backup and replication solution - unauthenticated arbitrary file read high identify critical remote vulnerabilities nakivo backup &amp; replication is a data protection solution used for backing up and restoring virtualized and physical environments. a vulnerability has been identified in certain versions of nakivo backup &amp; replication that allows an unauthenticated attacker to read arbitrary files on the underlying system. cve-2024-48248 dhiyaneshdk backup cve cve2024 kev lfi nakivo vkev vuln cwe-36" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">NAKIVO Backup and Replication Solution - Unauthenticated Arbitrary File Read</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-48248.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-48248.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 26, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/36.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-36</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-48248" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-48248</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)NAKIVO&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">NAKIVO Backup &amp; Replication is a data protection solution used for backing up and restoring virtualized and physical environments. A vulnerability has been identified in certain versions of NAKIVO Backup &amp; Replication that allows an unauthenticated attacker to read arbitrary files on the underlying system.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can read arbitrary files from the NAKIVO Backup &amp; Replication server.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update NAKIVO Backup &amp; Replication to a version that patches CVE-2024-48248.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">backup</span><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">kev</span><span class="nt-tag">lfi</span><span class="nt-tag">nakivo</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://labs.watchtowr.com/the-best-security-is-when-we-all-agree-to-keep-everything-secret-except-the-secrets-nakivo-backup-replication-cve-2024-48248/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="nconf login panel - detect info identify web-based control panels nconf login panel was detected. ritikchaddha discovery nconf panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">NConf Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/nconf-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">nconf-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)nconf&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">NConf login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">nconf</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="netgear routers - authentication bypass high identify critical remote vulnerabilities netgear r8500, r8300, r7000, r6400, r7300, r7100lg, r6300v2, wndr3400v3, wnr3500lv2, r6250, r6700, r6900, and r8000 devices are susceptible to authentication bypass via simple crafted requests to the web management server. cve-2017-5521 princechaddha auth-bypass cve cve2017 kev netgear router vkev vuln cwe-200" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">NETGEAR Routers - Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2017/CVE-2017-5521.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2017-5521.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> princechaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2017-5521" target="_blank" rel="noopener" class="nt-cve-link">CVE-2017-5521</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.head.wwwAuthenticate&#34;] matches `(?i)^Basic realm=&#34;NETGEAR`</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">NETGEAR R8500, R8300, R7000, R6400, R7300, R7100LG, R6300v2, WNDR3400v3, WNR3500Lv2, R6250, R6700, R6900, and R8000 devices are susceptible to authentication bypass via simple crafted requests to the web management server.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability can lead to unauthorized configuration changes, network compromise, and potential exposure of sensitive information.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest firmware update provided by NETGEAR to mitigate this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2017</span><span class="nt-tag">kev</span><span class="nt-tag">netgear</span><span class="nt-tag">router</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/cve-2017-5521-bypassing-authentication-on-netgear-routers/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="http://kb.netgear.com/30632/Web-GUI-Password-Recovery-and-Exposure-Security-Vulnerability" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2017-5521" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://www.exploit-db.com/exploits/41205/" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/Ostorlab/known_exploited_vulnerbilities_detectors" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="netgear routers - remote code execution high identify critical remote vulnerabilities netgear routers r6250 before 1.0.4.6.beta, r6400 before 1.0.1.18.beta, r6700 before 1.0.1.14.beta, r6900, r7000 before 1.0.7.6.beta, r7100lg before 1.0.0.28.beta, r7300dst before 1.0.0.46.beta, r7900 before 1.0.1.8.beta, r8000 before 1.0.3.26.beta, d6220, d6400, d7000, and possibly others allow remote attackers to execute arbitrary commands via shell metacharacters in the path info to cgi-bin/. cve-2016-6277 pikpikcu cve cve2016 iot kev netgear rce vkev vuln cwe-352" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">NETGEAR Routers - Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2016/CVE-2016-6277.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2016-6277.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pikpikcu</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/352.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-352</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2016-6277" target="_blank" rel="noopener" class="nt-cve-link">CVE-2016-6277</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.head.wwwAuthenticate&#34;] matches `(?i)^Basic realm=&#34;NETGEAR`</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">NETGEAR routers R6250 before 1.0.4.6.Beta, R6400 before 1.0.1.18.Beta, R6700 before 1.0.1.14.Beta, R6900, R7000 before 1.0.7.6.Beta, R7100LG before 1.0.0.28.Beta, R7300DST before 1.0.0.46.Beta, R7900 before 1.0.1.8.Beta, R8000 before 1.0.3.26.Beta, D6220, D6400, D7000, and possibly others allow remote attackers to execute arbitrary commands via shell metacharacters in the path info to cgi-bin/.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability allows an attacker to execute arbitrary code on the affected router, potentially leading to unauthorized access, data theft, or network compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest firmware update provided by NETGEAR to mitigate this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2016</span><span class="nt-tag">iot</span><span class="nt-tag">kev</span><span class="nt-tag">netgear</span><span class="nt-tag">rce</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.sj-vs.net/2016/12/10/temporary-fix-for-cert-vu582384-cwe-77-on-netgear-r7000-and-r6400-routers/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2016-6277" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="http://www.sj-vs.net/a-temporary-fix-for-cert-vu582384-cwe-77-on-netgear-r7000-and-r6400-routers/" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://www.kb.cert.org/vuls/id/582384" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="http://kb.netgear.com/000036386/CVE-2016-582384" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="ni web-based configuration &amp; monitoring - detect info identify web-based control panels  dhiyaneshdk,matejsmycka detect ni web-based panel discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">NI Web-based Configuration &amp; Monitoring - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/national-instruments/ni-web-based-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">ni-web-based-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK,matejsmycka</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 24, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)NI Web-based Configuration &amp; Monitoring&#34;}) || service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1192389544&#34;</code></div>
  <div class="nt-tags"><span class="nt-tag">detect</span><span class="nt-tag">ni</span><span class="nt-tag">web-based</span><span class="nt-tag">panel</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="np data cache panel - detect info identify web-based control panels np data cache panel was detected. tess np panel cache discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">NP Data Cache Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/np-data-cache.yaml" target="_blank" rel="noopener" class="nt-source-link">np-data-cache.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> tess</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)NP Data Cache&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">NP Data Cache panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">np</span><span class="nt-tag">panel</span><span class="nt-tag">cache</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="nps - authentication bypass high identify critical remote vulnerabilities this will reveal all parameters configured on the nps, including the account username and password of the proxy. sleepingbag945 nps auth-bypass vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">NPS - Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/vulnerabilities/nps/nps-auth-bypass.yaml" target="_blank" rel="noopener" class="nt-source-link">nps-auth-bypass.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> SleepingBag945</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)window\\.nps&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">This will reveal all parameters configured on the NPS, including the account username and password of the proxy.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">nps</span><span class="nt-tag">auth-bypass</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://mari0er.club/post/nps.html/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="nport web console login panel - detect info identify web-based control panels nport web console login panel was detected. prajiteshsingh discovery nport panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">NPort Web Console Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/nport-web-console.yaml" target="_blank" rel="noopener" class="nt-source-link">nport-web-console.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> prajiteshsingh</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)NPort Web Console&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">NPort Web Console login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">nport</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.moxa.com/en/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="ns-asg application security gateway 6.3 - sql injection medium identify critical remote vulnerabilities a vulnerability was found in netentsec ns-asg application security gateway 6.3. it has been classified as critical. this affects an unknown part of the file /protocol/index.php. the manipulation of the argument ipaddr leads to sql injection. it is possible to initiate the attack remotely. the exploit has been disclosed to the public and may be used. cve-2024-2330 s4e-io cve cve2024 ns-asg sqli vkev vuln cwe-89" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">NS-ASG Application Security Gateway 6.3 - Sql Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-2330.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-2330.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> s4e-io</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 11, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-2330" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-2330</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)“NS-ASG”&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A vulnerability was found in Netentsec NS-ASG Application Security Gateway 6.3. It has been classified as critical. This affects an unknown part of the file /protocol/index.php. The manipulation of the argument IPAddr leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Authenticated attackers can extract sensitive database information via SQL injection in the NS-ASG Application Security Gateway.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update NS-ASG Application Security Gateway to a version newer than 6.3.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">ns-asg</span><span class="nt-tag">sqli</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=2024-2330" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-2330" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/jikedaodao/cve/blob/main/NS-ASG-sql-addmacbind.md" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://vuldb.com/?ctiid.256281" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://vuldb.com/?id.256281" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="nsq admin panel - detect medium identify web-based control panels nsq admin panel was detected. random-robbie nsq admin panel exposure discovery cwe-200" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">NSQ Admin Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/nsq-admin-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">nsq-admin-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> random-robbie</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)nsqadmin&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">NSQ admin panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">nsq</span><span class="nt-tag">admin</span><span class="nt-tag">panel</span><span class="nt-tag">exposure</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nsq.io/components/nsqd.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="nuuo nvrmini - remote command execution critical identify critical remote vulnerabilities nuuo nvrmini is vulnerable to unauthenticated remote command execution through the upgrade_handle.php file. the vulnerability allows an attacker to execute arbitrary commands by manipulating the uploaddir parameter. cve-2018-14933 ritikchaddha cve cve2018 kev nuuo rce vkev vuln cwe-78" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">NUUO NVRmini - Remote Command Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2018/CVE-2018-14933.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2018-14933.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 16, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/78.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-78</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2018-14933" target="_blank" rel="noopener" class="nt-cve-link">CVE-2018-14933</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)NUUO&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">NUUO NVRmini is vulnerable to unauthenticated remote command execution through the upgrade_handle.php file. The vulnerability allows an attacker to execute arbitrary commands by manipulating the uploaddir parameter.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can execute arbitrary commands on the NUUO NVRmini device by manipulating the uploaddir parameter in upgrade_handle.php, leading to complete device compromise and potential unauthorized access to video surveillance systems and recordings.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update NUUO NVRmini to a patched version later than the 2016 firmware that properly validates the uploaddir parameter and restricts command execution.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2018</span><span class="nt-tag">kev</span><span class="nt-tag">nuuo</span><span class="nt-tag">rce</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.exploit-db.com/exploits/45070" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.cve.org/CVERecord?id=CVE-2018-14933" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2018-14933" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="nzbget login panel - detect info identify web-based control panels nzbget login panel was detected. dhiyaneshdk discovery nzbget panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">NZBGet Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/nzbget-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">nzbget-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)nzbget&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">NZBGet login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">nzbget</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="nacos - information disclosure high identify critical remote vulnerabilities nacos unauthorized download of configuration information. s4e-io config exposure nacos tech vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Nacos - Information Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/vulnerabilities/other/nacos-info-leak.yaml" target="_blank" rel="noopener" class="nt-source-link">nacos-info-leak.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> s4e-io</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 24, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Nacos&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Nacos unauthorized download of configuration information.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">config</span><span class="nt-tag">exposure</span><span class="nt-tag">nacos</span><span class="nt-tag">tech</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/wy876/POC/blob/main/Nacos/Nacos%E6%9C%AA%E6%8E%88%E6%9D%83%E4%B8%8B%E8%BD%BD%E9%85%8D%E7%BD%AE%E4%BF%A1%E6%81%AF.md" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="nagvis login panel - detect info identify web-based control panels nagvis login panel was detected. ritikchaddha discovery nagvis panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">NagVis Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/nagvis-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">nagvis-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)nagvis&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">NagVis login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">nagvis</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="nagios default login high identify default logins in web-based control panels nagios default admin credentials were discovered. iamthefrogy default-login nagios vuln cwe-522" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Nagios Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/nagios/nagios-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">nagios-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> iamthefrogy</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/522.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-522</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Nagios Core&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Nagios default admin credentials were discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">nagios</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.nagios.org" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="nagios log server - detect info identify web-based control panels detects the presence of nagios log server by identifying specific response patterns, http headers, or unique page elements. ritikchaddha detect discovery login nagios nagios-logserver panel" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Nagios Log Server - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/nagios/nagios-logserver-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">nagios-logserver-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 24, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1460499495&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detects the presence of Nagios Log Server by identifying specific response patterns, HTTP headers, or unique page elements.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">login</span><span class="nt-tag">nagios</span><span class="nt-tag">nagios-logserver</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="nagios login panel - detect info identify web-based control panels nagios login panel was detected. ritikchaddha panel nagios discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Nagios Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/nagios-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">nagios-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)nagios&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Nagios login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">nagios</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="nagios xi default admin login - detect critical identify default logins in web-based control panels nagios xi default admin login credentials were detected. ritikchaddha default-login nagios nagiosxi vuln cwe-1391" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Nagios XI Default Admin Login - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/nagios/nagiosxi-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">nagiosxi-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/1391.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-1391</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;Nagios XI&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Nagios XI default admin login credentials were detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">nagios</span><span class="nt-tag">nagiosxi</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nagiosxi.demos.nagios.com/nagiosxi/login.php?redirect=/nagiosxi/index.php%3f&amp;noauth=1" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="nagios xi login panel - detect info identify web-based control panels nagios xi login panel was detected. ritikchaddha discovery nagios nagios-xi panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Nagios XI Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/nagios-xi-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">nagios-xi-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)nagios xi&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Nagios XI login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">nagios</span><span class="nt-tag">nagios-xi</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="nagiosxi &lt;= 5.4.12 - sql injection high identify critical remote vulnerabilities a sql injection issue was discovered in nagios xi before 5.4.13 via the admin/info.php key1 parameter. cve-2018-10736 dhiyaneshdk cve cve2018 nagios sqli vuln cwe-89" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">NagiosXI &lt;= 5.4.12 - SQL injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2018/CVE-2018-10736.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2018-10736.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 2, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2018-10736" target="_blank" rel="noopener" class="nt-cve-link">CVE-2018-10736</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)nagios xi&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/info.php key1 parameter.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Authenticated administrators can execute arbitrary SQL commands to access, modify, or delete database contents, potentially compromising the entire Nagios XI instance.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to Nagios XI version 5.4.13 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2018</span><span class="nt-tag">nagios</span><span class="nt-tag">sqli</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/0ps/pocassistdb" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/jweny/pocassistdb" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://vulners.com/seebug/SSV:97266" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="nagiosxi &lt;= 5.4.12 `commandline.php` sql injection high identify critical remote vulnerabilities a sql injection issue was discovered in nagios xi before 5.4.13 via the admin/commandline.php cname parameter. cve-2018-10735 dhiyaneshdk cve cve2018 nagios sqli vuln cwe-89" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">NagiosXI &lt;= 5.4.12 `commandline.php` SQL injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2018/CVE-2018-10735.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2018-10735.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 2, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2018-10735" target="_blank" rel="noopener" class="nt-cve-link">CVE-2018-10735</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)nagios xi&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/commandline.php cname parameter.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Authenticated administrators can execute arbitrary SQL commands to access, modify, or delete database contents, potentially compromising the entire Nagios XI instance.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to Nagios XI version 5.4.13 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2018</span><span class="nt-tag">nagios</span><span class="nt-tag">sqli</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://vulners.com/seebug/SSV:97266" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/chaitin/xray/blob/master/pocs/nagio-cve-2018-10735.yml" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="nagiosxi &lt;= 5.4.12 logbook.php sql injection high identify critical remote vulnerabilities a sql injection issue was discovered in nagios xi before 5.4.13 via the admin/logbook.php txtsearch parameter. cve-2018-10737 dhiyaneshdk cve cve2018 nagios sqli vkev vuln cwe-89" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">NagiosXI &lt;= 5.4.12 logbook.php SQL injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2018/CVE-2018-10737.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2018-10737.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 2, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2018-10737" target="_blank" rel="noopener" class="nt-cve-link">CVE-2018-10737</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1460499495&#34; || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)nagios xi&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/logbook.php txtSearch parameter.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Authenticated administrators can execute arbitrary SQL commands to access, modify, or delete database contents, potentially compromising the entire Nagios XI instance.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to Nagios XI version 5.4.13 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2018</span><span class="nt-tag">nagios</span><span class="nt-tag">sqli</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://vulners.com/seebug/SSV:97267" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2018-10737" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="nagiosxi &lt;= 5.4.12 menuaccess.php - sql injection high identify critical remote vulnerabilities a sql injection issue was discovered in nagios xi before 5.4.13 via the admin/menuaccess.php chbkey1 parameter. cve-2018-10738 dhiyaneshdk cve cve2018 nagios sqli vuln cwe-89" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">NagiosXI &lt;= 5.4.12 menuaccess.php - SQL injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2018/CVE-2018-10738.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2018-10738.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 2, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2018-10738" target="_blank" rel="noopener" class="nt-cve-link">CVE-2018-10738</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)nagios xi&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/menuaccess.php chbKey1 parameter.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Authenticated administrators can execute arbitrary SQL commands to access, modify, or delete database contents, potentially compromising the entire Nagios XI instance.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to Nagios XI version 5.4.13 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2018</span><span class="nt-tag">nagios</span><span class="nt-tag">sqli</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://qkl.seebug.org/vuldb/ssvid-97268" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://vuldb.com/de/?id.117807" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="navicat on-prem server panel - detect info identify web-based control panels navicat on-prem server is an on-premise solution that provides you with the option to host a cloud environment for storing navicat objects internally at your location. in our on-prem environment, you can enjoy complete control over your system and maintain 100% privacy. it is secure and reliable that allow you to maintain a level of control that the cloud often cannot. ritikchaddha panel navicat on-prem detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Navicat On-Prem Server Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/navicat-server-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">navicat-server-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 21, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;598296063&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Navicat On-Prem Server is an on-premise solution that provides you with the option to host a cloud environment for storing Navicat objects internally at your location. In our On-Prem environment, you can enjoy complete control over your system and maintain 100% privacy. It is secure and reliable that allow you to maintain a level of control that the cloud often cannot.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">navicat</span><span class="nt-tag">on-prem</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="navidrome &lt;=0.54.5 - authentication bypass in subsonic api medium identify critical remote vulnerabilities navidrome is an open source web-based music collection server and streamer. starting in version 0.52.0 and prior to version 0.54.5, in certain subsonic api endpoints, a flaw in the authentication check process allows an attacker to specify any arbitrary username that does not exist on the system, along with a salted hash of an empty password. under these conditions, navidrome treats the request as authenticated, granting access to various subsonic endpoints without requiring valid credentials. an attacker can use any non-existent username to bypass the authentication system and gain access to various read-only data in navidrome, such as user playlists. however, any attempt to modify data fails with a &#34;permission denied&#34; error due to insufficient permissions, limiting the impact to unauthorized viewing of information. version 0.54.5 contains a patch for this issue. cve-2025-27112 iamnoooob,rootxharsh,pdresearch cve cve2025 navidrome vkev vuln cwe-287" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Navidrome &lt;=0.54.5 - Authentication Bypass in Subsonic API</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-27112.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-27112.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> iamnoooob,rootxharsh,pdresearch</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 4, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/287.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-287</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-27112" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-27112</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)content=\&#34;Navidrome&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Navidrome is an open source web-based music collection server and streamer. Starting in version 0.52.0 and prior to version 0.54.5, in certain Subsonic API endpoints, a flaw in the authentication check process allows an attacker to specify any arbitrary username that does not exist on the system, along with a salted hash of an empty password. Under these conditions, Navidrome treats the request as authenticated, granting access to various Subsonic endpoints without requiring valid credentials. An attacker can use any non-existent username to bypass the authentication system and gain access to various read-only data in Navidrome, such as user playlists. However, any attempt to modify data fails with a &#34;permission denied&#34; error due to insufficient permissions, limiting the impact to unauthorized viewing of information. Version 0.54.5 contains a patch for this issue.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can bypass authentication using non-existent usernames and empty password hashes to gain read-only access to user playlists and other data through Subsonic API endpoints.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to Navidrome version 0.54.5 or later that properly validates authentication credentials.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">navidrome</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/advisories/GHSA-c3p4-vm8f-386p" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="ncast busifacade - remote command execution high identify critical remote vulnerabilities the ncast yingshi high-definition intelligent recording and playback system is a newly developed audio and video recording and playback system. the system has rce vulnerabilities in versions 2017 and earlier. cve-2024-0305 bmcel cve cve2024 ncast ncast_project rce vkev vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Ncast busiFacade - Remote Command Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-0305.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-0305.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> BMCel</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 26, 2024</span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-0305" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-0305</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)高清智能录播系统&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The Ncast Yingshi high-definition intelligent recording and playback system is a newly developed audio and video recording and playback system. The system has RCE vulnerabilities in versions 2017 and earlier.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Allows remote attackers to execute arbitrary code on the affected system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches and updates from the vendor to address this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">ncast</span><span class="nt-tag">ncast_project</span><span class="nt-tag">rce</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://cxsecurity.com/cveshow/CVE-2024-0305" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-0305" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://vuldb.com/?id.249872" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://vuldb.com/?ctiid.249872" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/Marco-zcl/POC" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="neo4j browser - detect info identify web-based control panels the neo4j browser has been detected. dhiyaneshdk discovery exposure neo4j panel unauth cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Neo4j Browser - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/neo4j-browser.yaml" target="_blank" rel="noopener" class="nt-source-link">neo4j-browser.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)neo4j browser&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The Neo4j Browser has been detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">exposure</span><span class="nt-tag">neo4j</span><span class="nt-tag">panel</span><span class="nt-tag">unauth</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="neobox web server login panel - detect info identify web-based control panels neobox web server login panel was detected. pikpikcu panel neobox webserver discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Neobox Web Server Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/neobox-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">neobox-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pikpikcu</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)NeoboxUI&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Neobox Web Server login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">neobox</span><span class="nt-tag">webserver</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="netalert x - arbitary file read critical identify critical remote vulnerabilities a directory traversal vulnerability has been identified in netalertx versions v24.7.18 - v24.9.12. cve-2024-48766 s4e-io cve cve2024 lfi netalertx vkev vuln cwe-22" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">NetAlert X - Arbitary File Read</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-48766.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-48766.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> s4e-io</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 17, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-48766" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-48766</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)netalert x&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A directory traversal vulnerability has been identified in NetAlertX versions v24.7.18 - v24.9.12.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">This vulnerability allows remote attackers to list directories on the affected system. Successful exploitation could enable unauthorized users to explore the system’s internal structure.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Fixed in v24.10.12</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">lfi</span><span class="nt-tag">netalertx</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://advisories.checkpoint.com/defense/advisories/public/2025/cpai-2024-1358.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/rapid7/metasploit-framework/pull/19881" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/jokob-sk/NetAlertX" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="netbox - default admin credentials high identify default logins in web-based control panels detected that netbox was using the default credentials admin:admin. the official netbox-docker deployment set superuser_name=admin and superuser_password=admin by default. 0x_akoko auth default-login netbox" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">NetBox - Default Admin Credentials</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/netbox/netbox-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">netbox-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_Akoko</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 8, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)NetBox&#34;}) &amp;&amp; service[&#34;http.body&#34;] contains &#34;netbox-community&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detected that NetBox was using the default credentials admin:admin. The official netbox-docker deployment set SUPERUSER_NAME=admin and SUPERUSER_PASSWORD=admin by default.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth</span><span class="nt-tag">default-login</span><span class="nt-tag">netbox</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/netbox-community/netbox-docker" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://docs.netbox.dev/en/stable/integrations/rest-api/#authenticating-to-the-api" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="netmri &lt; 7.6.1 - authentication bypass via hardcoded credentials medium identify critical remote vulnerabilities an issue was discovered in infoblox netmri before 7.6.1. authentication bypass via a hardcoded credential can occur. cve-2025-32815 iamnoooob,pdresearch auth-bypass cve cve2025 hardcoded infoblox netmri vkev vuln cwe-287" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">NetMRI &lt; 7.6.1 - Authentication Bypass via Hardcoded Credentials</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-32815.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-32815.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> iamnoooob,pdresearch</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 7, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/287.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-287</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-32815" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-32815</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-319724102&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An issue was discovered in Infoblox NETMRI before 7.6.1. Authentication Bypass via a Hardcoded credential can occur.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can bypass authentication using hardcoded credentials to access administrative functions and read sensitive system files including /etc/shadow.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to Infoblox NetMRI version 7.6.1 or later and change all default credentials immediately.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">hardcoded</span><span class="nt-tag">infoblox</span><span class="nt-tag">netmri</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://rhinosecuritylabs.com/research/infoblox-multiple-cves/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-32815" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="netmri unauthenticated sql injection via skipjackusername critical identify critical remote vulnerabilities an issue was discovered in infoblox netmri before 7.6.1. unauthenticated sql injection can occur. cve-2025-32814 iamnoooob,pdresearch cve cve2025 error-based netmri rails sqli unauth vkev vuln cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">NetMRI Unauthenticated SQL Injection via skipjackUsername</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-32814.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-32814.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> iamnoooob,pdresearch</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 7, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-32814" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-32814</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-319724102&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An issue was discovered in Infoblox NETMRI before 7.6.1. Unauthenticated SQL Injection can occur.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can extract sensitive data including encrypted passwords through SQL injection in the skipjackUsername parameter, potentially leading to complete system compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to Infoblox NetMRI version 7.6.1 or later that properly sanitizes SQL input parameters.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">error-based</span><span class="nt-tag">netmri</span><span class="nt-tag">rails</span><span class="nt-tag">sqli</span><span class="nt-tag">unauth</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-32814" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://rhinosecuritylabs.com/research/infoblox-multiple-cves/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="netmizer logmanagement system data - directory exposure high identify critical remote vulnerabilities directory exposure vulnerability in the netmizer log management system of beijing lingzhou network technology co., ltd. due to the loose control of /data, attackers can use this vulnerability to obtain sensitive information. dhiyaneshdk netmizer exposure listing vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">NetMizer LogManagement System Data - Directory Exposure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/vulnerabilities/netmizer/netmizer-data-listing.yaml" target="_blank" rel="noopener" class="nt-source-link">netmizer-data-listing.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 5, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)NetMizer&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Directory Exposure vulnerability in the NetMizer log management system of Beijing Lingzhou Network Technology Co., Ltd. Due to the loose control of /data, attackers can use this vulnerability to obtain sensitive information.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">netmizer</span><span class="nt-tag">exposure</span><span class="nt-tag">listing</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/Threekiii/Awesome-POC/blob/master/%E7%BD%91%E7%BB%9C%E8%AE%BE%E5%A4%87%E6%BC%8F%E6%B4%9E/NetMizer%20%E6%97%A5%E5%BF%97%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F%20data%20%E7%9B%AE%E5%BD%95%E9%81%8D%E5%8E%86%E6%BC%8F%E6%B4%9E.md" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="netmizer logmanagement system cmd.php - remote code execution critical identify critical remote vulnerabilities remote command execution vulnerability in the netmizer log management system cmd.php, and the attacker can execute the command by passing in the cmd parameter. dhiyaneshdk cmd netmizer rce vuln cwe-78" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">NetMizer LogManagement System cmd.php - Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/vulnerabilities/netmizer/netmizer-cmd-rce.yaml" target="_blank" rel="noopener" class="nt-source-link">netmizer-cmd-rce.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 5, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/78.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-78</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)NetMizer&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Remote Command Execution vulnerability in the NetMizer log management system cmd.php, and the attacker can execute the command by passing in the cmd parameter.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cmd</span><span class="nt-tag">netmizer</span><span class="nt-tag">rce</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/Threekiii/Awesome-POC/blob/master/%E7%BD%91%E7%BB%9C%E8%AE%BE%E5%A4%87%E6%BC%8F%E6%B4%9E/NetMizer%20%E6%97%A5%E5%BF%97%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F%20cmd.php%20%E8%BF%9C%E7%A8%8B%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E.md" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="netsus server default login high identify default logins in web-based control panels netsus server default admin credentials were discovered. princechaddha default-login netsus vuln cwe-522" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">NetSUS Server Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/netsus/netsus-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">netsus-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> princechaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/522.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-522</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;NetSUS Server Login&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">NetSUS Server default admin credentials were discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">netsus</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="netsus server login panel - detect info identify web-based control panels netsus server login panel was detected. dhiyaneshdk panel netsus login discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">NetSUS Server Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/netsus-server-login.yaml" target="_blank" rel="noopener" class="nt-source-link">netsus-server-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)NetSUS Server Login&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">NetSUS Server login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">netsus</span><span class="nt-tag">login</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="netscaler console - panel info identify web-based control panels netscaler console login panel was discovered. dhiyaneshdk netscaler console panel login discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">NetScaler Console - Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/netscaler-console-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">netscaler-console-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 23, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)NetScaler Console&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">NetScaler Console login panel was discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">netscaler</span><span class="nt-tag">console</span><span class="nt-tag">panel</span><span class="nt-tag">login</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://docs.netscaler.com/en-us/netscaler-console-service/overview.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="netscaler console - sensitive information disclosure critical identify critical remote vulnerabilities sensitive information disclosure in netscaler console cve-2024-6235 dhiyaneshdk cve cve2024 exposure netscaler vkev vuln cwe-287" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">NetScaler Console - Sensitive Information Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-6235.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-6235.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 23, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/287.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-287</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-6235" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-6235</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)NetScaler Gateway&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Sensitive information disclosure in NetScaler Console</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can access sensitive information including session secrets and administrative credentials from the NetScaler Console without proper authentication.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the patches specified in Citrix advisory CTX677998 to address the information disclosure vulnerability in NetScaler Console.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">exposure</span><span class="nt-tag">netscaler</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://support.citrix.com/article/CTX677998" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://attackerkb.com/topics/7zebEgmGLs/cve-2024-6235" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/cve-2024-6235" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="netdata dashboard panel - detect info identify web-based control panels netdata dashboard panel was detected. pussycat0x discovery netdata panel tech cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Netdata Dashboard Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/netdata-dashboard-detected.yaml" target="_blank" rel="noopener" class="nt-source-link">netdata-dashboard-detected.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)netdata dashboard&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Netdata Dashboard panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">netdata</span><span class="nt-tag">panel</span><span class="nt-tag">tech</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="netdata panel - detect info identify web-based control panels netdata panel was discovered. techbrunchfr,righettod,matejsmycka panel netdata login dashboard discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Netdata Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/netdata-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">netdata-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> TechbrunchFR,righettod,matejsmycka</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)netdata dashboard&#34;}) || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Netdata Console&#34;}) || service[&#34;http.head.server&#34;] matches &#34;netdata embedded http server&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Netdata panel was discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">netdata</span><span class="nt-tag">login</span><span class="nt-tag">dashboard</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/netdata/netdata" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.netdata.cloud/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="netdisco admin - default login critical identify default logins in web-based control panels detects use of hard-coded credentials in netdisco. ritikchaddha default-login netdisco vuln" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Netdisco Admin - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/netdisco/netdisco-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">netdisco-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 7, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;Netdisco&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detects use of hard-coded credentials in Netdisco.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can potentially exploit this vulnerability to gain unauthorized access to sensitive information.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update the application to remove hard-coded credentials and implement secure credential management practices.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">netdisco</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="netentsec ns-icg - default login high identify default logins in web-based control panels netentsec ns-icg contains a default login vulnerability. an attacker can obtain access to user accounts and access sensitive information, modify data, and/or execute unauthorized operations. pikpikcu default-login nsicg vuln cwe-522" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Netentsec NS-ICG - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/nsicg/nsicg-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">nsicg-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pikpikcu</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/522.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-522</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.head.server&#34;] matches &#34;(?i)netentsec&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Netentsec NS-ICG contains a default login vulnerability. An attacker can obtain access to user accounts and access sensitive information, modify data, and/or execute unauthorized operations.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">nsicg</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.cnvd.org.cn/flaw/show/CNVD-2016-08603" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="netflix conductor ui panel - detect info identify web-based control panels netflix conductor ui panel was detected. c-sh0 conductor discovery netflix panel webserver cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Netflix Conductor UI Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/netflix-conductor-ui.yaml" target="_blank" rel="noopener" class="nt-source-link">netflix-conductor-ui.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> c-sh0</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)conductor ui&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Netflix Conductor UI panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">conductor</span><span class="nt-tag">discovery</span><span class="nt-tag">netflix</span><span class="nt-tag">panel</span><span class="nt-tag">webserver</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="netflow analyzer - default login high identify default logins in web-based control panels netflow analyzer default login was discovered. dhiyaneshdk default-login misconfig netflow vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Netflow Analyzer - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/netflow/netflow-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">netflow-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 18, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;Login - Netflow Analyzer&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Netflow Analyzer default login was discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">misconfig</span><span class="nt-tag">netflow</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="netflow analyzer login - panel info identify web-based control panels  dhiyaneshdk netflow analyzer panel login discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Netflow Analyzer Login - Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/netflow-analyzer-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">netflow-analyzer-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 18, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Login - Netflow Analyzer&#34;</code></div>
  <div class="nt-tags"><span class="nt-tag">netflow</span><span class="nt-tag">analyzer</span><span class="nt-tag">panel</span><span class="nt-tag">login</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="netgear dgn2200 - improper authentication high identify critical remote vulnerabilities a vulnerability in the netgear dgn2200 router with firmware version v1.0.0.46 and earlier permits unauthorized individuals to bypass the authentication. when adding &#34;?x=1.gif&#34; to the requested url, it will be recognized as passing the authentication. cve-2024-57046 ritikchaddha auth-bypass cve cve2024 dgn2200 netgear router vkev vuln cwe-287" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Netgear DGN2200 - Improper Authentication</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-57046.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-57046.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 11, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/287.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-287</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-57046" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-57046</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)DGN2200&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A vulnerability in the Netgear DGN2200 router with firmware version v1.0.0.46 and earlier permits unauthorized individuals to bypass the authentication. When adding &#34;?x=1.gif&#34; to the requested url, it will be recognized as passing the authentication.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers on the local network can bypass authentication by appending &#39;?x=1.gif&#39; to URLs, gaining unauthorized access to administrative functions and router configuration.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update Netgear DGN2200 router to firmware version later than v1.0.0.46 that addresses the authentication bypass vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">dgn2200</span><span class="nt-tag">netgear</span><span class="nt-tag">router</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/Shuanunio/CVE_Requests/blob/main/Netgear/DGN2200/ACL%20bypass%20Vulnerability%20in%20Netgear%20DGN2200.md" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.netgear.com/about/security/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-57046" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="netgear wnr614 - improper authentication high identify critical remote vulnerabilities a vulnerability in the netgear wnr614 router permits unauthorized individuals to bypass the authentication. when adding &#34;%00currentsetting.htm&#34; to the the requested url, it will be recognized as passing the authentication. ritikchaddha cve cve2024 netgear router exposure wnr614 unauth vuln cwe-200" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Netgear WNR614 - Improper Authentication</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/vulnerabilities/netgear/netgear-wnr614-auth-bypass.yaml" target="_blank" rel="noopener" class="nt-source-link">netgear-wnr614-auth-bypass.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 11, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)WNR614&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A vulnerability in the Netgear WNR614 router permits unauthorized individuals to bypass the authentication. When adding &#34;%00currentsetting.htm&#34; to the the requested url, it will be recognized as passing the authentication.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">netgear</span><span class="nt-tag">router</span><span class="nt-tag">exposure</span><span class="nt-tag">wnr614</span><span class="nt-tag">unauth</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/Shuanunio/CVE_Requests/blob/main/Netgear/WNR614/assets/image-20241210153405727.png" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/Shuanunio/CVE_Requests/blob/main/Netgear/WNR614/ACL%20bypass%20Vulnerability%20in%20Netgear%20WNR614.md" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="netgear-wn604 downloadfile.php - information disclosure medium identify critical remote vulnerabilities there is an information leakage vulnerability in the downloadfile.php interface of netgear wn604. a remote attacker using file authentication can use this vulnerability to obtain the administrator account and password information of the wireless router, causing the router&#39;s background to be controlled. the attacker can initiate damage to the wireless network or further threaten it. cve-2024-6646 pussycat0x cve cve2024 netgear vuln cwe-200" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Netgear-WN604 downloadFile.php - Information Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-6646.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-6646.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 17, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-6646" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-6646</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Netgear&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">There is an information leakage vulnerability in the downloadFile.php interface of Netgear WN604. A remote attacker using file authentication can use this vulnerability to obtain the administrator account and password information of the wireless router, causing the router&#39;s background to be controlled. The attacker can initiate damage to the wireless network or further threaten it.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can download configuration files containing administrator account and password information, enabling complete router compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update Netgear WN604 to the latest firmware version that addresses the information disclosure vulnerability in downloadFile.php.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">netgear</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/wy876/POC/blob/main/Ncast%E9%AB%98%E6%B8%85%E6%99%BA%E8%83%BD%E5%BD%95%E6%92%AD%E7%B3%BB%E7%BB%9F%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/mikutool/vul/issues/1" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://vuldb.com/?ctiid.271052" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://vuldb.com/?id.271052" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://vuldb.com/?submit.367382" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="netis wifi router - information disclosure high identify critical remote vulnerabilities an issue in netis wifi6 router nx10 2.0.1.3643 and 2.0.1.3582 and netis wifi 11ac router nc65 3.0.0.3749 and netis wifi 11ac router nc63 3.0.0.3327 and 3.0.0.3503 and netis wifi 11ac router nc21 3.0.0.3800, 3.0.0.3500 and 3.0.0.3329 and netis wifi router mw5360 1.0.1.3442 and 1.0.1.3031 allows a remote attacker to obtain sensitive information via the mode_name, wl_link parameters of the skk_get.cgi component. cve-2024-48455 s4e-io exposure netis router vkev vuln cwe-200" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Netis Wifi Router - Information Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-48455.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-48455.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> s4e-io</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 8, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-48455" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-48455</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Netis&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An issue in Netis Wifi6 Router NX10 2.0.1.3643 and 2.0.1.3582 and Netis Wifi 11AC Router NC65 3.0.0.3749 and Netis Wifi 11AC Router NC63 3.0.0.3327 and 3.0.0.3503 and Netis Wifi 11AC Router NC21 3.0.0.3800, 3.0.0.3500 and 3.0.0.3329 and Netis Wifi Router MW5360 1.0.1.3442 and 1.0.1.3031 allows a remote attacker to obtain sensitive information via the mode_name, wl_link parameters of the skk_get.cgi component.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can access sensitive router configuration information including network settings and credentials.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update affected Netis router models to versions that patch the information disclosure vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">exposure</span><span class="nt-tag">netis</span><span class="nt-tag">router</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://attackerkb.com/topics/L6qgmDIMa1/cve-2024-48455" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/users/h00die-gr3y/projects/1/views/1" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-48455" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="netmaker - hardcoded dns secret key high identify critical remote vulnerabilities netmaker makes networks with wireguard. prior to versions 0.17.1 and 0.18.6, hardcoded dns key usage has been found in netmaker allowing unauth users to interact with dns api endpoints. cve-2023-32077 iamnoooob,rootxharsh,pdresearch cve cve2023 exposure gravitl info-key netmaker vuln cwe-321,cwe-798" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Netmaker - Hardcoded DNS Secret Key</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-32077.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-32077.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> iamnoooob,rootxharsh,pdresearch</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 29, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/321,CWE-798.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-321,CWE-798</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-32077" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-32077</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)netmaker&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Netmaker makes networks with WireGuard. Prior to versions 0.17.1 and 0.18.6, hardcoded DNS key usage has been found in Netmaker allowing unauth users to interact with DNS API endpoints.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can access DNS API endpoints using the hardcoded secret key, potentially manipulating DNS configurations and redirecting WireGuard network traffic in the Netmaker VPN infrastructure.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update Netmaker to version 0.17.1 or 0.18.6 or later that removes hardcoded credentials and implements proper authentication for DNS API endpoints.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">exposure</span><span class="nt-tag">gravitl</span><span class="nt-tag">info-key</span><span class="nt-tag">netmaker</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="netris dashboard panel - detect info identify web-based control panels netris dashboard panel was detected. theamanrawat panel netris discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Netris Dashboard Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/netris-dashboard-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">netris-dashboard-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> theamanrawat</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Netris Dashboard&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Netris Dashboard panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">netris</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="netsparker login panel - detect info identify web-based control panels netsparker login panel was detected. pussycat0x panel netsparker discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Netsparker Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/netsparker-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">netsparker-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Sign in to Netsparker Enterprise&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Netsparker login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">netsparker</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.invicti.com/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="network technologies inc enviromux - default login high identify default logins in web-based control panels the enviromux environment monitoring system from network technologies inc was found to be using its default login credentials. this default configuration could have allowed unauthorized users to gain access to the web management interface without authentication, potentially leading to information disclosure or unauthorized control over environmental monitoring systems. m.sarmad shafiq default-login enviromux networktechnologies vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Network Technologies Inc ENVIROMUX - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/nti/enviromuux-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">enviromuux-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> M.Sarmad Shafiq</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 14, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;ENVIROMUX&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The ENVIROMUX environment monitoring system from Network Technologies Inc was found to be using its default login credentials. This default configuration could have allowed unauthorized users to gain access to the web management interface without authentication, potentially leading to information disclosure or unauthorized control over environmental monitoring systems.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">enviromux</span><span class="nt-tag">networktechnologies</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="http://www.networktechinc.com/download/d-environment-monitor-16.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="http://www.networktechinc.com/pdf/man154.pdf" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="newspaper theme 6.4–6.7.1 - privilege escalation critical identify critical remote vulnerabilities newspaper theme versions 6.4 to 6.7.1 for wordpress lacked proper options access control through td_ajax_update_panel, which led to a privilege escalation vulnerability. cve-2016-10972 pussycat0x cve cve2016 newspaper passive vkev vuln wordpress wp wp-theme wpscan wpscan cwe-269" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Newspaper Theme 6.4–6.7.1 - Privilege Escalation</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2016/CVE-2016-10972.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2016-10972.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 24, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/269.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-269</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2016-10972" target="_blank" rel="noopener" class="nt-cve-link">CVE-2016-10972</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)wp-content/themes/mTheme-Unus/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Newspaper Theme versions 6.4 to 6.7.1 for WordPress lacked proper options access control through td_ajax_update_panel, which led to a Privilege Escalation vulnerability.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can escalate their privileges to administrator level, allowing complete control over the WordPress site including content manipulation, user management, and potential site takeover.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to Newspaper Theme version 6.7.2 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2016</span><span class="nt-tag">newspaper</span><span class="nt-tag">passive</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-theme</span><span class="nt-tag">wpscan</span><span class="nt-tag">wpscan</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wpscan.com/vulnerability/5365ecca-93e2-4bfc-bd4a-6f61d7d75e96/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="next terminal - default login high identify default logins in web-based control panels next terminal default login was discovered. ritikchaddha default-login next next-terminal vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Next Terminal - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/next-terminal/next-terminal-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">next-terminal-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 4, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Next Terminal&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Next Terminal default login was discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">next</span><span class="nt-tag">next-terminal</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/dushixiang/next-terminal" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="next.js &lt;9.3.2 - local file inclusion medium identify critical remote vulnerabilities next.js versions before 9.3.2 are vulnerable to local file inclusion. an attacker can craft special requests to access files in the dist directory (.next). this does not affect files outside of the dist directory (.next). in general, the dist directory only holds build assets unless your application intentionally stores other assets under this directory. cve-2020-5284 rootxharsh,iamnoooob,dwisiswant0 cve cve2020 lfi nextjs vkev vuln zeit cwe-22,cwe-23" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Next.js &lt;9.3.2 - Local File Inclusion</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2020/CVE-2020-5284.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2020-5284.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rootxharsh,iamnoooob,dwisiswant0</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22,CWE-23.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22,CWE-23</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2020-5284" target="_blank" rel="noopener" class="nt-cve-link">CVE-2020-5284</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/_next/static&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Next.js versions before 9.3.2 are vulnerable to local file inclusion. An attacker can craft special requests to access files in the dist directory (.next). This does not affect files outside of the dist directory (.next). In general, the dist directory only holds build assets unless your application intentionally stores other assets under this directory.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can exploit this vulnerability to read sensitive files on the server, potentially leading to unauthorized access or information disclosure.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">This issue is fixed in version 9.3.2.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2020</span><span class="nt-tag">lfi</span><span class="nt-tag">nextjs</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">zeit</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/zeit/next.js/releases/tag/v9.3.2" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/zeit/next.js/security/advisories/GHSA-fq77-7p7r-83rj" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2020-5284" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/Z0fhack/Goby_POC" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/merlinepedra/nuclei-templates" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="next.js cache poisoning high identify critical remote vulnerabilities next.js is vulnerable to cache poisoning through the x-middleware-prefetch and x-invoke-status headers. this can result in dos by serving an empty json object or error page instead of the intended content, affecting ssr responses. ice3man543 cache cve cve2023 next-js vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Next.js Cache Poisoning</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/vulnerabilities/nextjs/next-js-cache-poisoning.yaml" target="_blank" rel="noopener" class="nt-source-link">next-js-cache-poisoning.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Ice3man543</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 23, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/_next/static&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Next.js is vulnerable to cache poisoning through the x-middleware-prefetch and x-invoke-status headers. This can result in DoS by serving an empty JSON object or error page instead of the intended content, affecting SSR responses.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cache</span><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">next-js</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/vercel/next.js/compare/v13.4.20-canary.12...v13.4.20-canary.13" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/valentin-panov/nextjs-no-cache-issue" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://zhero-web-sec.github.io/research-and-things/nextjs-and-cache-poisoning-a-quest-for-the-black-hole" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="nextgen gallery &lt;= 3.59 - missing authorization to unauthenticated information disclosure medium identify critical remote vulnerabilities the wordpress gallery plugin – nextgen gallery plugin for wordpress is vulnerable to unauthorized access of data due to a missing capability check on the get_item function in versions up to, and including, 3.59. this makes it possible for unauthenticated attackers to extract sensitive data including exif and other metadata of any image uploaded through the plugin. cve-2024-3097 dhiyaneshdk cve cve2024 imagely info-leak nextgen-gallery vuln wordpress wp-plugin cwe-862" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">NextGEN Gallery &lt;= 3.59 - Missing Authorization to Unauthenticated Information Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-3097.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-3097.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 15, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/862.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-862</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-3097" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-3097</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/nextgen-gallery/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The WordPress Gallery Plugin – NextGEN Gallery plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_item function in versions up to, and including, 3.59. This makes it possible for unauthenticated attackers to extract sensitive data including EXIF and other metadata of any image uploaded through the plugin.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can perform unauthorized actions within the NextGEN Gallery plugin.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update NextGEN Gallery to version 3.60 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">imagely</span><span class="nt-tag">info-leak</span><span class="nt-tag">nextgen-gallery</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp-plugin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://plugins.trac.wordpress.org/browser/nextgen-gallery/trunk/src/REST/Admin/Block.php#L40" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/75f87f99-9f0d-46c2-a6f1-3c1ea0176303?source=cve" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://zpbrent.github.io/pocs/8-plugin-nextgen-gallery-InfoDis-20240327.mp4" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/fkie-cad/nvd-json-data-feeds" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="nextcloudpi login - panel info identify web-based control panels detects the presence of a nextcloudpi login page. nextcloudpi is a ready-to-use nextcloud instance for raspberry pi. ritikchaddha nextcloud nextcloudpi login panel discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">NextcloudPi Login - Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/nextcloudpi-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">nextcloudpi-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 3, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)NextcloudPi&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detects the presence of a NextcloudPi login page. NextcloudPi is a ready-to-use Nextcloud instance for Raspberry Pi.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">nextcloud</span><span class="nt-tag">nextcloudpi</span><span class="nt-tag">login</span><span class="nt-tag">panel</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/nextcloud/nextcloudpi" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="nexus default login high identify default logins in web-based control panels nexus default admin credentials were discovered. pikpikcu default-login nexus vuln cwe-522" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Nexus Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/nexus/nexus-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">nexus-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pikpikcu</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/522.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-522</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.head.setCookie&#34;] contains &#34;NXSESSIONID&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Nexus default admin credentials were discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">nexus</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="nexus login panel - detect info identify web-based control panels nexus login panel was detected. righettod panel nexus login detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Nexus Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/nexus-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">nexus-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 10, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Sonatype Nexus Repository&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Nexus login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">nexus</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.sonatype.com/products/sonatype-nexus-repository" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="nexus repository manager - anonymous access enabled medium identify critical remote vulnerabilities detected nexus repository manager instance with anonymous access enabled, allowing unauthenticated users to list and browse repositories containing private artifacts including source code, packages, and docker images. 0x_akoko misconfig nexus sonatype exposure unauth cwe-276" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Nexus Repository Manager - Anonymous Access Enabled</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/misconfiguration/nexus-repository-anonymous-access.yaml" target="_blank" rel="noopener" class="nt-source-link">nexus-repository-anonymous-access.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_Akoko</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 10, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/276.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-276</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Nexus Repository Manager&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detected Nexus Repository Manager instance with anonymous access enabled, allowing unauthenticated users to list and browse repositories containing private artifacts including source code, packages, and Docker images.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">misconfig</span><span class="nt-tag">nexus</span><span class="nt-tag">sonatype</span><span class="nt-tag">exposure</span><span class="nt-tag">unauth</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://help.sonatype.com/en/anonymous-access.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://help.sonatype.com/en/access-control.html" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="nginx admin manager login panel - detect info identify web-based control panels nginx admin manager login panel was detected. ritikchaddha panel nginx admin discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Nginx Admin Manager Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/nginx-admin-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">nginx-admin-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)nginx admin manager&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Nginx Admin Manager login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">nginx</span><span class="nt-tag">admin</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://ng-admin.jslsolucoes.com/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="nginx proxy manager - default login high identify default logins in web-based control panels default nginx proxy manager credentials was discovered. barttran2000 default-login nginx proxy-manager vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Nginx Proxy Manager - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/nginx/nginx-proxy-manager-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">nginx-proxy-manager-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> barttran2000</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 16, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;Nginx Proxy Manager&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Default Nginx Proxy Manager credentials was discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">nginx</span><span class="nt-tag">proxy-manager</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="nginx proxy manager login panel - detect info identify web-based control panels nginx proxy manager login panel was detected. dhiyaneshdk discovery nginx panel proxy cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Nginx Proxy Manager Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/nginx-proxy-manager.yaml" target="_blank" rel="noopener" class="nt-source-link">nginx-proxy-manager.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Nginx Proxy Manager&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Nginx Proxy Manager login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">nginx</span><span class="nt-tag">panel</span><span class="nt-tag">proxy</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="nginx ui - broken access control critical identify critical remote vulnerabilities network attackers can fully control nginx service, including config modification and service restart, leading to complete service takeover. cve-2026-33032 dhiyaneshdk cve cve2026 mcp misconfig nginx-ui unauth vkev cwe-306" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Nginx UI - Broken Access Control</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2026/CVE-2026-33032.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2026-33032.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 16, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/306.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-306</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2026-33032" target="_blank" rel="noopener" class="nt-cve-link">CVE-2026-33032</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Nginx UI&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Network attackers can fully control nginx service, including config modification and service restart, leading to complete service takeover.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An unauthenticated attacker with a valid MCP session ID can inject arbitrary nginx configurations,create reverse proxies for credential theft, and achieve remote code execution via nginx config primitives.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to nginx-ui v2.3.4 or later which adds AuthRequired() to /mcp_message.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2026</span><span class="nt-tag">mcp</span><span class="nt-tag">misconfig</span><span class="nt-tag">nginx-ui</span><span class="nt-tag">unauth</span><span class="nt-tag">vkev</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-h6c2-x2m2-mwhf" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/0xJacky/nginx-ui/commit/413dc631" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33032" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="nginx ui &lt; 2.3.3 - information disclosure critical identify critical remote vulnerabilities nginx ui &lt; 2.3.3 contains an information disclosure vulnerability caused by unauthenticated access to /api/backup endpoint exposing encryption keys in x-backup-security header, letting unauthenticated attackers download and decrypt full system backups. cve-2026-27944 omarkurt cve cve2026 exposure nginx-ui unauth vkev cwe-306" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Nginx UI &lt; 2.3.3 - Information Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2026/CVE-2026-27944.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2026-27944.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> omarkurt</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 8, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/306.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-306</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2026-27944" target="_blank" rel="noopener" class="nt-cve-link">CVE-2026-27944</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;product&#34;] contains &#34;Nginx UI:Nginx UI&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Nginx UI &lt; 2.3.3 contains an information disclosure vulnerability caused by unauthenticated access to /api/backup endpoint exposing encryption keys in X-Backup-Security header, letting unauthenticated attackers download and decrypt full system backups.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can access and decrypt full system backups, exposing sensitive data including credentials and private keys.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to version 2.3.3 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2026</span><span class="nt-tag">exposure</span><span class="nt-tag">nginx-ui</span><span class="nt-tag">unauth</span><span class="nt-tag">vkev</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/advisories/GHSA-g9w5-qffc-6762" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.tenable.com/security/research/tra-2026-17" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://vulnerabletarget.com/VT-2026-27944" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="nginx ui panel - detect info identify web-based control panels nginx ui panel was detected. gy741 panel nginx exposure f5 discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Nginx UI Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/nginx-ui-dashboard.yaml" target="_blank" rel="noopener" class="nt-source-link">nginx-ui-dashboard.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> gy741</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)nginx ui&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Nginx UI panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">nginx</span><span class="nt-tag">exposure</span><span class="nt-tag">f5</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/schenkd/nginx-ui" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="ninja tables &lt;4.1.9 - unauthenticated arbitrary file read high identify critical remote vulnerabilities the ninja tables plugin for wordpress (versions &lt; 4.1.9) is vulnerable to an unauthenticated arbitrary file download vulnerability. the issue exists due to the improper validation of the &#39;url&#39; parameter in the &#39;ninja_table_force_download&#39; ajax action. xbow,dhiyaneshdk file-download lfi ninja-tables unauth vuln wordpress wp-plugin" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Ninja Tables &lt;4.1.9 - Unauthenticated Arbitrary File Read</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/vulnerabilities/wordpress/wp-ninja-tables-lfi.yaml" target="_blank" rel="noopener" class="nt-source-link">wp-ninja-tables-lfi.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> xbow,DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 15, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/ninja-tables/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The Ninja Tables plugin for WordPress (versions &lt; 4.1.9) is vulnerable to an unauthenticated arbitrary file download vulnerability. The issue exists due to the improper validation of the &#39;url&#39; parameter in the &#39;ninja_table_force_download&#39; AJAX action.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An unauthenticated attacker can download sensitive files from the server, such as &#39;/etc/passwd&#39; or &#39;/wp-config.php&#39;, potentially exposing sensitive information including database credentials.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update the Ninja Tables plugin to version 4.1.9 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">file-download</span><span class="nt-tag">lfi</span><span class="nt-tag">ninja-tables</span><span class="nt-tag">unauth</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp-plugin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://xbow.com/blog/xbow-ninja-tables/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://ninjatables.com/docs/change-log/#521-date-july-9-2025" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="noescape login panel - detect info identify web-based control panels noescape login panel was detected. dhiyaneshdk panel noescape discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">NoEscape Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/noescape-login.yaml" target="_blank" rel="noopener" class="nt-source-link">noescape-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)NoEscape - Login&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">NoEscape login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">noescape</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="nocobase - default login high identify default logins in web-based control panels nocobase default login was discovered. fur1na, icarot default-login nocobase vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">NocoBase - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/nocobase/nocobase-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">nocobase-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Fur1na, icarot</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 22, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;http.bodies&#34;]), {# matches &#34;&#39;NOCOBASE_&#39;&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">NocoBase default login was discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">nocobase</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.nocobase.com/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/nocobase/nocobase" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://docs.nocobase.com/welcome/getting-started/installation/docker-compose" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="nocodb panel - detect info identify web-based control panels nocodb login panel was discovered. userdehghani panel nocodb login detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">NocoDB Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/nocodb-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">nocodb-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> userdehghani</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 13, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;206985584&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">NocoDB Login panel was discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">nocodb</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.nocodb.com/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://docs.nocodb.com/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="nocodb version &lt;= 0.106.1 - arbitrary file read high identify critical remote vulnerabilities nocodb through 0.106.1 has a path traversal vulnerability that allows an unauthenticated attacker to access arbitrary files on the server by manipulating the path parameter of the /download route. this vulnerability could allow an attacker to access sensitive files and data on the server, including configuration files, source code, and other sensitive information. cve-2023-35843 dwisiswant0 cve cve2023 lfi nocodb vkev vuln cwe-22" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">NocoDB version &lt;= 0.106.1 - Arbitrary File Read</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-35843.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-35843.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dwisiswant0</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 20, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-35843" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-35843</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-2017596142&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">NocoDB through 0.106.1 has a path traversal vulnerability that allows an unauthenticated attacker to access arbitrary files on the server by manipulating the path parameter of the /download route. This vulnerability could allow an attacker to access sensitive files and data on the server, including configuration files, source code, and other sensitive information.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">The vulnerability can lead to unauthorized access to sensitive information, potentially exposing user credentials, database contents, and other confidential data.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade NocoDB to a version higher than 0.106.1 to mitigate the vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">lfi</span><span class="nt-tag">nocodb</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://advisory.dw1.io/60" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-35843" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/nocodb/nocodb/blob/6decfa2b20c28db9946bddce0bcb1442b683ecae/packages/nocodb/src/lib/controllers/attachment.ctl.ts#L62-L74" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/nocodb/nocodb/blob/f7ee7e3beb91d313a159895d1edc1aba9d91b0bc/packages/nocodb/src/controllers/attachments.controller.ts#L55-L66" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/0x783kb/Security-operation-book" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="node red dashboard &lt;2.26.2 - local file inclusion high identify critical remote vulnerabilities nodered-dashboard before 2.26.2 is vulnerable to local file inclusion because it allows ui_base/js/..%2f directory traversal to read files. cve-2021-3223 gy741,pikpikcu cve cve2021 lfi node-red-dashboard node.js nodered vkev vuln cwe-22" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Node RED Dashboard &lt;2.26.2 - Local File Inclusion</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2021/CVE-2021-3223.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2021-3223.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> gy741,pikpikcu</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2021-3223" target="_blank" rel="noopener" class="nt-cve-link">CVE-2021-3223</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Node-RED&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">NodeRED-Dashboard before 2.26.2 is vulnerable to local file inclusion because it allows ui_base/js/..%2f directory traversal to read files.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can exploit this vulnerability to access sensitive information, such as configuration files, credentials, or other sensitive data stored on the server.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade Node RED Dashboard to version 2.26.2 or later to mitigate the vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2021</span><span class="nt-tag">lfi</span><span class="nt-tag">node-red-dashboard</span><span class="nt-tag">node.js</span><span class="nt-tag">nodered</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/node-red/node-red-dashboard/issues/669" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3223" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/node-red/node-red-dashboard/releases/tag/2.26.2" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2021-3223" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/ARPSyndicate/cvemon" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="node-red - default login critical identify default logins in web-based control panels allows attacker to log in and execute rce on the node-red panel using the default credentials. savik dashboard default-login node-red vuln" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Node-Red - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/node-red/nodered-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">nodered-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> savik</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 21, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;321591353&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Allows attacker to log in and execute RCE on the Node-Red panel using the default credentials.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">dashboard</span><span class="nt-tag">default-login</span><span class="nt-tag">node-red</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://quentinkaiser.be/pentesting/2018/09/07/node-red-rce/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="node.js repl history disclosure low identify critical remote vulnerabilities the node.js repl history file (.node_repl_history) was exposed, which had contained a log of commands entered into the node.js interactive shell. pussycat0x exposure nodejs history disclosure misconfiguration" data-nt-sev="low">
  <div class="nt-card-header">
    <div class="nt-title">Node.js REPL History Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposures/configs/node-repl-history-disclosure.yaml" target="_blank" rel="noopener" class="nt-source-link">node-repl-history-disclosure.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 18, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)\\.node_repl_history&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The Node.js REPL history file (.node_repl_history) was exposed, which had contained a log of commands entered into the Node.js interactive shell.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">exposure</span><span class="nt-tag">nodejs</span><span class="nt-tag">history</span><span class="nt-tag">disclosure</span><span class="nt-tag">misconfiguration</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nodejs.org/api/repl.html#persistent-history" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://joshtronic.com/2022/12/18/nodejs-repl-history/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="nodebb xml-rpc request xmlrpc.php - xml injection critical identify critical remote vulnerabilities a remote code execution (rce) vulnerability in the xmlrpc.php endpoint of nodebb inc nodebb forum software prior to v1.18.6 allows attackers to execute arbitrary code via crafted xml-rpc requests. cve-2023-43187 0xparth cve cve2023 nodebb rce vuln cwe-91" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">NodeBB XML-RPC Request xmlrpc.php - XML Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-43187.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-43187.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0xParth</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 6, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/91.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-91</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-43187" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-43187</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)nodebb&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A remote code execution (RCE) vulnerability in the xmlrpc.php endpoint of NodeBB Inc NodeBB forum software prior to v1.18.6 allows attackers to execute arbitrary code via crafted XML-RPC requests.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can inject arbitrary PHP code through crafted XML-RPC requests to the xmlrpc.php endpoint, potentially gaining full control over the NodeBB forum server and accessing user data.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update NodeBB to version 1.18.6 or later that properly validates and sanitizes XML-RPC input to prevent code injection attacks.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">nodebb</span><span class="nt-tag">rce</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/jagat-singh-chaudhary/CVE/blob/main/CVE-2023-43187" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-43187" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="nodogsplash - directory traversal high identify critical remote vulnerabilities nodogsplash product was affected by a directory traversal vulnerability that also impacted the openwrt product. this vulnerability was addressed in nodogsplash version 5.0.1. exploiting this vulnerability, remote attackers could read arbitrary files from the target system. cve-2023-39120 numan türle cve2023 cve lfi openwrt nodogsplash vuln cwe-22" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Nodogsplash - Directory Traversal</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-39120.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-39120.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Numan Türle</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 5, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-39120" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-39120</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)OpenWRT&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Nodogsplash product was affected by a directory traversal vulnerability that also impacted the OpenWrt product. This vulnerability was addressed in Nodogsplash version 5.0.1. Exploiting this vulnerability, remote attackers could read arbitrary files from the target system.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can exploit this vulnerability to view, modify, or delete sensitive files on the system, potentially leading to unauthorized access, data leakage, or system compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to the latest version to mitigate this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve2023</span><span class="nt-tag">cve</span><span class="nt-tag">lfi</span><span class="nt-tag">openwrt</span><span class="nt-tag">nodogsplash</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-39120" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/nodogsplash/nodogsplash/commit/a745a5d635925d2a6f0e0530bdc0eac645b672ed" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://gist.github.com/numanturle/55cb758bacc4930a081e79c2a6a769b6" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/openwrt/routing/pull/997" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="nordex control wind farm portal login panel - detect info identify web-based control panels nordex control wind farm portal login panel was detected. geeknik panel nordex iot discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Nordex Control Wind Farm Portal Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/nordex-wind-farm-portal.yaml" target="_blank" rel="noopener" class="nt-source-link">nordex-wind-farm-portal.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> geeknik</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Nordex Control&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Nordex Control Wind Farm Portal login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">nordex</span><span class="nt-tag">iot</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.nordex-online.com/en/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="normhost backup server manager panel - detect info identify web-based control panels normhost backup server manager panel was detected. pussycat0x panel normhost discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Normhost Backup Server Manager Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/normhost-backup-server-manager.yaml" target="_blank" rel="noopener" class="nt-source-link">normhost-backup-server-manager.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Normhost Backup server manager&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Normhost Backup server manager panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">normhost</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="nortek linear emerge e3-series - sql injection critical identify critical remote vulnerabilities nortek linear emerge e3-series 0.32-08f, 0.32-07p, 0.32-07e, 0.32-09c, 0.32-09b, 0.32-09a, and 0.32-08e were discovered to contain a sql injection vulnerability via the idt parameter. cve-2022-38627 daffainfo,omarhashem666 cve cve2022 emerge linear nortek sqli vkev vuln cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Nortek Linear eMerge E3-Series - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-38627.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-38627.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> daffainfo,omarhashem666</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 24, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-38627" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-38627</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Linear eMerge&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Nortek Linear eMerge E3-Series 0.32-08f, 0.32-07p, 0.32-07e, 0.32-09c, 0.32-09b, 0.32-09a, and 0.32-08e were discovered to contain a SQL injection vulnerability via the idt parameter.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can exploit SQL injection in the idt parameter to extract sensitive access control data including badge information, user credentials, and building security configurations from the eMerge access control system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update Nortek Linear eMerge E3-Series firmware to a patched version that uses parameterized queries and properly sanitizes the idt parameter.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">emerge</span><span class="nt-tag">linear</span><span class="nt-tag">nortek</span><span class="nt-tag">sqli</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/omarhashem123/Security-Research/tree/main/CVE-2022-38627" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://omar0x01.medium.com/15cebd072ed6" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-38627" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="nortek linear emerge e3-series &lt;0.32-08f - remote command injection critical identify critical remote vulnerabilities nortek linear emerge e3-series devices before 0.32-08f are susceptible to remote command injection via readerno. an attacker can execute malware, obtain sensitive information, modify data, and/or gain full control over a compromised system without entering necessary credentials. note: this vulnerability exists because of an incomplete fix for cve-2019-7256. cve-2022-31499 pikpikcu cve cve2022 emerge nortekcontrol packetstorm rce time-based-sqli vkev vuln cwe-78" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Nortek Linear eMerge E3-Series &lt;0.32-08f - Remote Command Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-31499.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-31499.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pikpikcu</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/78.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-78</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-31499" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-31499</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)emerge&#34;}) || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)linear emerge&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Nortek Linear eMerge E3-Series devices before 0.32-08f are susceptible to remote command injection via ReaderNo. An attacker can execute malware, obtain sensitive information, modify data, and/or gain full control over a compromised system without entering necessary credentials. NOTE: this vulnerability exists because of an incomplete fix for CVE-2019-7256.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability allows remote attackers to execute arbitrary commands on the affected system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to a patched version of Nortek Linear eMerge E3-Series (&gt;=0.32-08f) to mitigate this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">emerge</span><span class="nt-tag">nortekcontrol</span><span class="nt-tag">packetstorm</span><span class="nt-tag">rce</span><span class="nt-tag">time-based-sqli</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://packetstormsecurity.com/files/167991/Nortek-Linear-eMerge-E3-Series-Command-Injection.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/omarhashem123/CVE-2022-31499" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="http://packetstormsecurity.com/files/167991/Nortek-Linear-eMerge-E3-Series-Command-Injection.html" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31499" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://eg.linkedin.com/in/omar-1-hashem" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="nortek linear emerge panel - detect info identify web-based control panels nortek linear emerge panel was detected. arafatansari discovery emerge nortek nortekcontrol panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Nortek Linear eMerge Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/eMerge-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">eMerge-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> arafatansari</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)emerge&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Nortek Linear eMerge panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">emerge</span><span class="nt-tag">nortek</span><span class="nt-tag">nortekcontrol</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="notificationx &lt;= 2.8.2 - sql injection critical identify critical remote vulnerabilities the notificationx - best fomo, social proof, woocommerce sales popup &amp; notification bar plugin with elementor plugin for wordpress is vulnerable to sql injection via the &#39;type&#39; parameter in all versions up to, and including, 2.8.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing sql query.  this makes it possible for unauthenticated attackers to append additional sql queries into already existing queries that can be used to extract sensitive information from the database. cve-2024-1698 dhiyaneshdk cve cve2024 notificationx sqli time-based-sqli vkev vuln wordpress wp-plugin wpscan" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">NotificationX &lt;= 2.8.2 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-1698.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-1698.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 13, 2024</span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-1698" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-1698</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/notificationx&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The NotificationX - Best FOMO, Social Proof, WooCommerce Sales Popup &amp; Notification Bar Plugin With Elementor plugin for WordPress is vulnerable to SQL Injection via the &#39;type&#39; parameter in all versions up to, and including, 2.8.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can extract sensitive database information including usernames, passwords, and other confidential data via time-based SQL injection.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update NotificationX plugin to version 2.8.3 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">notificationx</span><span class="nt-tag">sqli</span><span class="nt-tag">time-based-sqli</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">wpscan</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://plugins.trac.wordpress.org/changeset/3040809/notificationx/trunk/includes/Core/Database.php" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://plugins.trac.wordpress.org/changeset/3040809/notificationx/trunk/includes/Core/Rest/Analytics.php" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e110ea99-e2fa-4558-bcf3-942a35af0b91?source=cve" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/fkie-cad/nvd-json-data-feeds" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-1698" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="notificationx dropshipping &lt; 4.4 - sql injection critical identify critical remote vulnerabilities the plugin does not properly sanitise and escape a parameter before using it in a sql statement via a rest endpoint available to unauthenticated users, leading to a sql injection ritikchaddha cve cve2022 notificationx sqli vkev vuln woocommerce wordpress wp wp-plugin cwe-20" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">NotificationX Dropshipping &lt; 4.4 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-3481.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-3481.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 25, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/20.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-20</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/woocommerce-dropshipping&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The plugin does not properly sanitise and escape a parameter before using it in a SQL statement via a REST endpoint available to unauthenticated users, leading to a SQL injection</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can exploit time-based SQL injection through the REST endpoint to extract sensitive WooCommerce data including customer information, order details, and payment records.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update NotificationX Dropshipping plugin to version 4.4 or later that properly sanitizes and escapes parameters in REST endpoints.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">notificationx</span><span class="nt-tag">sqli</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">woocommerce</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wpscan.com/vulnerability/c5e395f8-257e-49eb-afbd-9c1e26045373" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-3481" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="nozomi guardian login panel - detect info identify web-based control panels nozomi guardian login panel was detected. robotshell panel nozomi discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Nozomi Guardian Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/nozomi-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">nozomi-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> robotshell</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Please Login \\| Nozomi Networks Console&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Nozomi Guardian login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">nozomi</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="nsfocus - arbitrary user login high identify critical remote vulnerabilities nsfocus bastion host has an arbitrary user login vulnerability. attackers can use the vulnerability to log in any user by including www/local_user.php ritikchaddha nsfocus auth-bypass vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Nsfocus - Arbitrary User Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/vulnerabilities/other/nsfocus-auth-bypass.yaml" target="_blank" rel="noopener" class="nt-source-link">nsfocus-auth-bypass.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 10, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/needUsbkey\\.php\\?username=&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Nsfocus bastion host has an arbitrary user login vulnerability. Attackers can use the vulnerability to log in any user by including www/local_user.php</div></div></div>
  <div class="nt-tags"><span class="nt-tag">nsfocus</span><span class="nt-tag">auth-bypass</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://forum.butian.net/article/251" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="nuxeo platform login panel - detect info identify web-based control panels nuxeo platform login panel was detected. kishore-hariram discovery nuxeo panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Nuxeo Platform Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/nuxeo-platform-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">nuxeo-platform-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> kishore-hariram</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Nuxeo Platform&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Nuxeo Platform login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">nuxeo</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="o2 router setup panel - detect info identify web-based control panels o2 router setup panel was detected. ritikchaddha panel o2 easy iot router discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">O2 Router Setup Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/o2-easy-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">o2-easy-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)O2 Easy Setup&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">O2 router setup panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">o2</span><span class="nt-tag">easy</span><span class="nt-tag">iot</span><span class="nt-tag">router</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="o2oa - default login high identify default logins in web-based control panels o2oa is an open source and free enterprise and team office platform. it provides four major platforms portal management, process management, information management, and data management. it integrates many functions such as work reporting, project collaboration, mobile oa, document sharing, process approval, and data collaboration. meet various management and collaboration needs of enterprises. sleepingbag945 default-login o2oa vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">O2OA - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/o2oa/o2oa-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">o2oa-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> SleepingBag945</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 18, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;O2OA&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">O2OA is an open source and free enterprise and team office platform. It provides four major platforms portal management, process management, information management, and data management. It integrates many functions such as work reporting, project collaboration, mobile OA, document sharing, process approval, and data collaboration. Meet various management and collaboration needs of enterprises.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">o2oa</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="ocs inventory login panel - detect info identify web-based control panels ocs inventory login panel was detected. pikpikcu,ritikchaddha discovery ocs-inventory panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">OCS Inventory Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/ocs-inventory-login.yaml" target="_blank" rel="noopener" class="nt-source-link">ocs-inventory-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pikpikcu,ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)OCS Inventory&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">OCS Inventory login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">ocs-inventory</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="okiok s-filer portal login panel - detect info identify web-based control panels okiok s-filer portal login panel was detected. johnk3r okiko panel discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">OKIOK S-Filer Portal Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/okiko-sfiler-portal.yaml" target="_blank" rel="noopener" class="nt-source-link">okiko-sfiler-portal.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> johnk3r</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)S-Filer&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">OKIOK S-Filer Portal login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">okiko</span><span class="nt-tag">panel</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="olt web management interface login panel - detect info identify web-based control panels olt web management interface login panel was detected. dhiyaneshdk edb panel olt discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">OLT Web Management Interface Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/olt-web-interface.yaml" target="_blank" rel="noopener" class="nt-source-link">olt-web-interface.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)OLT Web Management Interface&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">OLT Web Management Interface login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">edb</span><span class="nt-tag">panel</span><span class="nt-tag">olt</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.exploit-db.com/ghdb/8020" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="olympic banking system login panel - detect info identify web-based control panels olympic banking system was detected. righettod panel olympic login discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">OLYMPIC Banking System Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/olympic-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">olympic-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 22, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)olympic banking system&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">OLYMPIC Banking System was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">olympic</span><span class="nt-tag">login</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.olympicbankingsystem.com/en/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="opnsense panel - detect info identify web-based control panels opnsense panel was detected. splint3r7,johnk3r panel login detect opnsense discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">OPNsense Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/opnsense-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">opnsense-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Splint3r7,johnk3r</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 17, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-1148190371&#34; || service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-1068289244&#34; || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)\\| OPNsense&#34;}) || service[&#34;http.head.server&#34;] matches &#34;OPNsense&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">OPNsense panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">opnsense</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="osasi login - panel info identify web-based control panels osasi login panel was discovered. biero-el-corridor detect discovery login osasi panel" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">OSASI Login - Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/osasi-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">osasi-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> biero-el-corridor</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 2, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/css/osasiasp\\.css&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">OSASI Login panel was discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">login</span><span class="nt-tag">osasi</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="osasi plc - default login high identify default logins in web-based control panels detected osasi plc web interface accessible with default credentials, potentially allowing unauthorized administrative access to industrial control systems. biero-el-corridor default-login osasi plc vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">OSASI PLC - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/osasi/osasi-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">osasi-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> biero-el-corridor</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 2, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-268676052&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detected OSASI PLC web interface accessible with default credentials, potentially allowing unauthorized administrative access to industrial control systems.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">osasi</span><span class="nt-tag">plc</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="osisoft pi vision - login panel info identify web-based control panels osisoft pi vision (now aveva pi vision) is a web-based data visualisation
platform for the pi system, widely used in energy, utilities, oil and gas,
and manufacturing for real-time operational data monitoring. exposed instances
may provide access to sensitive operational technology data. rxerium aveva discovery energy historian ics osisoft panel pi-system pi-vision scada" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">OSIsoft PI Vision - Login Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/osisoft-pi-vision-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">osisoft-pi-vision-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 27, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;^PI Vision&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">OSIsoft PI Vision (now AVEVA PI Vision) is a web-based data visualisation
platform for the PI System, widely used in energy, utilities, oil and gas,
and manufacturing for real-time operational data monitoring. Exposed instances
may provide access to sensitive operational technology data.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">aveva</span><span class="nt-tag">discovery</span><span class="nt-tag">energy</span><span class="nt-tag">historian</span><span class="nt-tag">ics</span><span class="nt-tag">osisoft</span><span class="nt-tag">panel</span><span class="nt-tag">pi-system</span><span class="nt-tag">pi-vision</span><span class="nt-tag">scada</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.aveva.com/en/products/pi-vision/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://docs.aveva.com/bundle/pi-vision/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="osnexus quantastor manager panel - detect info identify web-based control panels osnexus quantastor manager login panel was detected. charles d. discovery login osnexus panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">OSNEXUS QuantaStor Manager Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/osnexus-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">osnexus-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Charles D.</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 13, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)OSNEXUS QuantaStor Manager&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">OSNEXUS QuantaStor Manager login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">login</span><span class="nt-tag">osnexus</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="otobo login panel - detect info identify web-based control panels otobo login panel was detected. princechaddha panel otobo discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">OTOBO Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/otobo-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">otobo-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> princechaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)otobo&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">OTOBO login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">otobo</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/rotheross/otobo" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="ocomon login panel - detect info identify web-based control panels a tiny helpdesk system written in php dogasantos discovery ocomon ocomon_project oss panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">OcoMon Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/ocomon-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">ocomon-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dogasantos</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)ocomon&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">a tiny helpdesk system written in php</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">ocomon</span><span class="nt-tag">ocomon_project</span><span class="nt-tag">oss</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://sourceforge.net/projects/ocomonphp/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="octobercms - default admin discovery high identify default logins in web-based control panels octobercms default admin credentials were discovered. princechaddha default-login octobercms oss vuln cwe-522" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">OctoberCMS - Default Admin Discovery</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/octobercms/octobercms-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">octobercms-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> princechaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/522.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-522</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;3823102&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">OctoberCMS default admin credentials were discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">octobercms</span><span class="nt-tag">oss</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/octobercms/october" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://octobercms.com/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="odoo - database manager discovery low identify web-based control panels odoo database manager was discovered. __fazal,r3dg33k backup discovery odoo panel" data-nt-sev="low">
  <div class="nt-card-header">
    <div class="nt-title">Odoo - Database Manager Discovery</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/odoo-database-manager.yaml" target="_blank" rel="noopener" class="nt-source-link">odoo-database-manager.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> __Fazal,R3dg33k</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)odoo&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Odoo database manager was discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">backup</span><span class="nt-tag">discovery</span><span class="nt-tag">odoo</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="odoo - panel detect info identify web-based control panels  dhiyaneshdk,righettod discovery login odoo panel" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Odoo - Panel Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/odoo-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">odoo-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK,righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 17, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)odoo&#34;})</code></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">login</span><span class="nt-tag">odoo</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="odoo apps - cross-site scripting via prototype pollution high identify critical remote vulnerabilities jquery-bbq 1.2.1 contains a prototype pollution caused by improperly controlled modification of object prototype attributes, letting malicious users inject properties into object.prototype, exploit requires malicious user interaction. cve-2021-20086 1337rokudenashi cve cve2021 jquery odoo proto vuln xss cwe-1321" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Odoo Apps - Cross-Site Scripting via Prototype Pollution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2021/CVE-2021-20086.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2021-20086.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 1337rokudenashi</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 8, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/1321.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-1321</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2021-20086" target="_blank" rel="noopener" class="nt-cve-link">CVE-2021-20086</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Odoo&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">jquery-bbq 1.2.1 contains a prototype pollution caused by improperly controlled modification of object prototype attributes, letting malicious users inject properties into Object.prototype, exploit requires malicious user interaction.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can modify Object.prototype, leading to potential security issues like property overwrites and application behavior manipulation.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest version of jquery-bbq that addresses this vulnerability or apply patches to prevent prototype pollution.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2021</span><span class="nt-tag">jquery</span><span class="nt-tag">odoo</span><span class="nt-tag">proto</span><span class="nt-tag">vuln</span><span class="nt-tag">xss</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.tenable.com/security/research/tra-2022-10" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2021-20086" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="odoo openerp database selector panel - detect info identify web-based control panels odoo openerp database selector panel was detected. impramodsargar openerp panel odoo discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Odoo OpenERP Database Selector Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/openerp-database.yaml" target="_blank" rel="noopener" class="nt-source-link">openerp-database.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> impramodsargar</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)odoo&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Odoo OpenERP database selector panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">openerp</span><span class="nt-tag">panel</span><span class="nt-tag">odoo</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="office web apps server panel - detect info identify web-based control panels microsoft office web app login panel was discovered. dhiyaneshdk discovery login microsoft office-webapps panel cwe-668" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Office Web Apps Server Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/office-webapps-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">office-webapps-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 4, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/668.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-668</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)provide a link that opens word&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Microsoft Office Web App Login Panel was discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">login</span><span class="nt-tag">microsoft</span><span class="nt-tag">office-webapps</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.microsoft.com/en-in/microsoft-365/free-office-online-for-the-web" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="officekeeper admin login panel - detect info identify web-based control panels officekeeper admin login panel was detected. gy741 officekeeper dlp panel discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">OfficeKeeper Admin Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/officekeeper-admin-login.yaml" target="_blank" rel="noopener" class="nt-source-link">officekeeper-admin-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> gy741</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-800060828&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">OfficeKeeper admin login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">officekeeper</span><span class="nt-tag">dlp</span><span class="nt-tag">panel</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="okta login panel - detect info identify web-based control panels okta login panel was detected. pussycat0x panel okta login discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Okta Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/okta-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">okta-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)okta&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Okta login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">okta</span><span class="nt-tag">login</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="omnia mpx 1.5.0+r1 - local file inclusion critical identify critical remote vulnerabilities telos alliance omnia mpx node through 1.5.0+r1 is vulnerable to local file inclusion via logs/downloadmainlog. by retrieving userdb.json allows an attacker to retrieve cleartext credentials and escalate privileges via the control panel. cve-2022-36642 arafatansari,ritikchaddha,for3stco1d cve cve2022 edb lfi omnia telosalliance traversal vkev vuln cwe-862" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Omnia MPX 1.5.0+r1 - Local File Inclusion</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-36642.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-36642.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> arafatansari,ritikchaddha,For3stCo1d</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/862.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-862</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-36642" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-36642</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Omnia MPX Node \\| Login&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Telos Alliance Omnia MPX Node through 1.5.0+r1 is vulnerable to local file inclusion via logs/downloadMainLog. By retrieving userDB.json allows an attacker to retrieve cleartext credentials and escalate privileges via the control panel.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to read arbitrary files on the server, potentially leading to further compromise of the system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patch or upgrade to a non-vulnerable version of Omnia MPX.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">edb</span><span class="nt-tag">lfi</span><span class="nt-tag">omnia</span><span class="nt-tag">telosalliance</span><span class="nt-tag">traversal</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.exploit-db.com/exploits/50996" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://cyber-guy.gitbook.io/cyber-guy/pocs/omnia-node-mpx-auth-bypass-via-lfd" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-36642" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://www.telosalliance.com/radio-processing/audio-interfaces/omnia-mpx-node" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="omnia mpx node login panel - detect info identify web-based control panels omnia mpx node login panel was detected. arafatansari discovery omnia omniampx panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Omnia MPX Node Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/omniampx-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">omniampx-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> arafatansari</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Omnia MPX&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Omnia MPX Node login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">omnia</span><span class="nt-tag">omniampx</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="omnissa workspace one uem - path traversal high identify critical remote vulnerabilities omnissa workspace one uem contains a path traversal caused by crafted get requests to restricted api endpoints, letting malicious actors access sensitive information, exploit requires sending crafted requests. dhiyaneshdk,slcyber airwatch cve cve2025 omnissa traversal vkev vuln workspace" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Omnissa Workspace ONE UEM - Path Traversal</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-25231.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-25231.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK,slcyber</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 30, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/airwatch/default\\.aspx&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Omnissa Workspace ONE UEM contains a path traversal caused by crafted GET requests to restricted API endpoints, letting malicious actors access sensitive information, exploit requires sending crafted requests.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Malicious actors can access sensitive information by exploiting path traversal in API endpoints.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest version.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">airwatch</span><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">omnissa</span><span class="nt-tag">traversal</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">workspace</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://slcyber.io/assetnote-security-research-center/secondary-context-path-traversal-in-omnissa-workspace-one-uem/#wrap-up-&amp;-acknowledgements" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.omnissa.com/omsa-2025-0004/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-25231" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="onedev &lt; 4.0.3 - user access token leak high identify critical remote vulnerabilities onedev before version 4.0.3 contains an insecure endpoint that allows retrieval of arbitrary user details, including access tokens, due to missing security checks on /users/{id}, letting attackers leak sensitive data and impersonate users, exploit requires no special conditions. cve-2021-21246 dhiyaneshdk auth-bypass cve cve2021 onedev token-leak cwe-862" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">OneDev &lt; 4.0.3 - User Access Token Leak</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2021/CVE-2021-21246.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2021-21246.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 23, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/862.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-862</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2021-21246" target="_blank" rel="noopener" class="nt-cve-link">CVE-2021-21246</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)OneDev&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">OneDev before version 4.0.3 contains an insecure endpoint that allows retrieval of arbitrary user details, including access tokens, due to missing security checks on /users/{id}, letting attackers leak sensitive data and impersonate users, exploit requires no special conditions.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can access sensitive user data and tokens, leading to impersonation, data leaks, and potential full account compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to version 4.0.3 or later where user info is removed from the REST API.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2021</span><span class="nt-tag">onedev</span><span class="nt-tag">token-leak</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/theonedev/onedev/security/advisories/GHSA-66v7-gg85-f4gx" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/theonedev/onedev/commit/a4491e5f79dc6cc96eac20972eedc8905ddf6089" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2021-21246" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://securitylab.github.com/advisories/GHSL-2020-214_223-onedev/" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="onedev panel - detect info identify web-based control panels onedev is a git server with ci/cd, kanban, and packages. vultza tech detect onedev discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">OneDev Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/onedev-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">onedev-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> vultza</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 28, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)OneDev&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">OneDev is a Git Server with CI/CD, Kanban, and Packages.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">tech</span><span class="nt-tag">detect</span><span class="nt-tag">onedev</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/theonedev/onedev" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="onedev.io &lt; 11.0.9 - arbitrary file read high identify critical remote vulnerabilities files on the host computer can be accessed by directory traversal. cve-2024-45309 isacaya cve cve2024 lfi onedev vkev vuln cwe-22" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">OneDev.io &lt; 11.0.9 - Arbitrary File Read</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-45309.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-45309.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> isacaya</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 23, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-45309" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-45309</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)onedev\\.io&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Files on the host computer can be accessed by directory traversal.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker would be able to view the contents of a file on the computer.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to version 11.0.9.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">lfi</span><span class="nt-tag">onedev</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://x.com/Siebene7/status/1848727539046617324" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/theonedev/onedev/security/advisories/GHSA-7wg5-6864-v489" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-45309" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="open game panel login panel - detect info identify web-based control panels open game panel login panel was detected. dhiyaneshdk panel edb discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Open Game Panel Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/open-game-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">open-game-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Open Game Panel&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Open Game Panel login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">edb</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.exploit-db.com/ghdb/7418" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="open virtualization userportal &amp; webadmin panel detection info identify web-based control panels open virtualization userportal &amp; webadmin panels were detected. open virtualization manager is an open-source distributed virtualization solution designed to manage enterprise infrastructure. ovirt uses the trusted kvm hypervisor and is built upon several other community projects, including libvirt, gluster, patternfly, and ansible. idealphase panel ovirt oss discovery cwe-668" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Open Virtualization Userportal &amp; Webadmin Panel Detection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/open-virtualization-manager-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">open-virtualization-manager-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> idealphase</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/668.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-668</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Ovirt-Engine&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Open Virtualization Userportal &amp; Webadmin panels were detected. Open Virtualization Manager is an open-source distributed virtualization solution designed to manage enterprise infrastructure. oVirt uses the trusted KVM hypervisor and is built upon several other community projects, including libvirt, Gluster, PatternFly, and Ansible.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">ovirt</span><span class="nt-tag">oss</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.ovirt.org/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.ovirt.org/dropped/admin-guide/virt/console-client-resources.html" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="open web analytics login - detect info identify web-based control panels detects the presence of open web analytics login page. dhiyaneshdk open-web-analytics login panel discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Open Web Analytics Login - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/open-web-analytics-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">open-web-analytics-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 17, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)OWA CONFIG SETTINGS&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detects the presence of Open Web Analytics login page.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">open-web-analytics</span><span class="nt-tag">login</span><span class="nt-tag">panel</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="open webui - default login critical identify default logins in web-based control panels detected the presence of an openwebui panel with default credentials (admin@localhost/admin). successful authentication using these default credentials allows attackers to access the admin interface and potentially perform remote code execution by defining a custom &#34;tool&#34;. matejsmycka default-login vuln openwebui" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Open WebUI - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/openwebui/openwebui-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">openwebui-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> matejsmycka</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 18, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-286484075&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detected the presence of an OpenWebUI panel with default credentials (admin@localhost/admin). Successful authentication using these default credentials allows attackers to access the admin interface and potentially perform remote code execution by defining a custom &#34;tool&#34;.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">vuln</span><span class="nt-tag">openwebui</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://openwebui.com/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="openam login panel - detect info identify web-based control panels openam login panel was detected. philippedelteil discovery forgerock login openam opensso panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">OpenAM Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/openam-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">openam-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> philippedelteil</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)openam&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">OpenAM login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">forgerock</span><span class="nt-tag">login</span><span class="nt-tag">openam</span><span class="nt-tag">opensso</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="openbao web ui panel - detect info identify web-based control panels detects the presence of the openbao web console. ritikchaddha detect openbao panel ui" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">OpenBao Web UI Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/openbao-webui-detect.yaml" target="_blank" rel="noopener" class="nt-source-link">openbao-webui-detect.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 6, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)OpenBao&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detects the presence of the OpenBao web console.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">detect</span><span class="nt-tag">openbao</span><span class="nt-tag">panel</span><span class="nt-tag">ui</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/openbao/openbao" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="openbullet 2 - panel info identify web-based control panels openbullet was detected. mastercho openbullet panel login discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">OpenBullet 2 - Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/openbullet2-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">openbullet2-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> MaStErChO</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 25, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-1264095219&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Openbullet was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">openbullet</span><span class="nt-tag">panel</span><span class="nt-tag">login</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="opencats - default login high identify default logins in web-based control panels opencats contains a default admin login vulnerability. an attacker can obtain access to user accounts and access sensitive information, modify data, and/or execute unauthorized operations. arafatansari default-login opencats vuln cwe-522" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">OpenCATS - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/others/opencats-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">opencats-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> arafatansari</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/522.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-522</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)opencats&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">OpenCATS contains a default admin login vulnerability. An attacker can obtain access to user accounts and access sensitive information, modify data, and/or execute unauthorized operations.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">opencats</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="opencats login panel - detect info identify web-based control panels opencats login panel was detected. arafatansari discovery opencats panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">OpenCATS Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/opencats-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">opencats-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> arafatansari</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)opencats&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">OpenCATS login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">opencats</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="opencms 14 &amp; 15 - cross site scripting medium identify critical remote vulnerabilities cross-site scripting (xss) vulnerability in alkacon software open cms, affecting versions 14 and 15 of the &#39;mercury&#39; template. cve-2023-6379 msegoviag alkacon cve cve2023 opencms vuln xss cwe-79" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">OpenCMS 14 &amp; 15 - Cross Site Scripting</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-6379.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-6379.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> msegoviag</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 3, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-79</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-6379" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-6379</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)opencms&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Cross-site scripting (XSS) vulnerability in Alkacon Software Open CMS, affecting versions 14 and 15 of the &#39;Mercury&#39; template.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can inject malicious JavaScript through multiple parameters in OpenCMS Mercury template pages to steal user session cookies and execute attacks against OpenCMS users.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to version OpenCMS 16</div></div></div>
  <div class="nt-tags"><span class="nt-tag">alkacon</span><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">opencms</span><span class="nt-tag">vuln</span><span class="nt-tag">xss</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.incibe.es/incibe-cert/alerta-temprana/vulnerabilidades/cve-2023-6379" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-6379" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-alkacon-software-opencms" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/fkie-cad/nvd-json-data-feeds" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/msegoviag/msegoviag" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="opencart core 4.0.2.3 &#39;search&#39; - sql injection high identify critical remote vulnerabilities opencart allows sql injection via parameter &#39;search&#39; in /index.php?route=product/search&amp;search=. exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database. s4e-io opencart sqli time-based-sqli vuln cwe-89" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">OpenCart Core 4.0.2.3 &#39;search&#39; - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/vulnerabilities/other/opencart-core-sqli.yaml" target="_blank" rel="noopener" class="nt-source-link">opencart-core-sqli.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> s4e-io</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 2, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)OpenCart&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Opencart allows SQL Injection via parameter &#39;search&#39; in /index.php?route=product/search&amp;search=. Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">opencart</span><span class="nt-tag">sqli</span><span class="nt-tag">time-based-sqli</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.exploit-db.com/exploits/51940" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://cxsecurity.com/issue/WLB-2024040004" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="opencart login panel - detect info identify web-based control panels opencart login panel was detected. ricardomaia discovery opencart panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">OpenCart Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/opencart-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">opencart-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ricardomaia</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)opencart&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">OpenCart login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">opencart</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.opencart.com" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="opencode &lt; 1.0.216 - unauthenticated remote code execution high identify critical remote vulnerabilities opencode versions prior to 1.0.216 contain an unauthenticated remote code execution vulnerability. the application exposes session and shell execution endpoints without proper authentication, allowing remote attackers to create sessions and execute arbitrary shell commands on the underlying server. cve-2026-22812 princechaddha cve cve2026 opencode rce unauth cwe-306" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">OpenCode &lt; 1.0.216 - Unauthenticated Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2026/CVE-2026-22812.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2026-22812.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> princechaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 28, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/306.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-306</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2026-22812" target="_blank" rel="noopener" class="nt-cve-link">CVE-2026-22812</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)opencode&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">OpenCode versions prior to 1.0.216 contain an unauthenticated remote code execution vulnerability. The application exposes session and shell execution endpoints without proper authentication, allowing remote attackers to create sessions and execute arbitrary shell commands on the underlying server.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can execute arbitrary commands on the server, potentially leading to full system compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade OpenCode to version 1.0.216 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2026</span><span class="nt-tag">opencode</span><span class="nt-tag">rce</span><span class="nt-tag">unauth</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/rohmatariow/CVE-2026-22812-exploit" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22812" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="openemr - default admin discovery high identify default logins in web-based control panels openemr default admin credentials were discovered. geekby default-login openemr vuln cwe-522" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">OpenEMR - Default Admin Discovery</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/openemr/openemr-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">openemr-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Geekby</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/522.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-522</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;OpenEMR&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">OpenEMR default admin credentials were discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">openemr</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/openemr/openemr-devops/tree/master/docker/openemr/6.1.0/#openemr-official-docker-image" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="openemr product registration panel - detect info identify web-based control panels openemr product registration panel was detected. pussycat0x discovery open-emr openemr panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">OpenEMR Product Registration Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/openemr-detect.yaml" target="_blank" rel="noopener" class="nt-source-link">openemr-detect.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)openemr&#34; || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)openemr&#34;}) || service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1971268439&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">OpenEMR Product Registration panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">open-emr</span><span class="nt-tag">openemr</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="openedge login panel - detect info identify web-based control panels an openedge login panel was detected. rxerium panel openedge login detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">OpenEdge Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/openedge-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">openedge-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 13, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Welcome to Progress Application Server for OpenEdge&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An OpenEdge login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">openedge</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="openenergymonitor emoncms - login panel info identify web-based control panels emoncms is an open-source energy monitoring web application by openenergymonitor,
used in homes and small businesses to track electricity, gas, and temperature.
the login page is commonly exposed on port 80, 443, or 8010. rxerium discovery emoncms energy ics iot monitoring panel" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">OpenEnergyMonitor emonCMS - Login Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/emoncms-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">emoncms-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 27, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;^Emoncms - user login&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">emonCMS is an open-source energy monitoring web application by OpenEnergyMonitor,
used in homes and small businesses to track electricity, gas, and temperature.
The login page is commonly exposed on port 80, 443, or 8010.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">emoncms</span><span class="nt-tag">energy</span><span class="nt-tag">ics</span><span class="nt-tag">iot</span><span class="nt-tag">monitoring</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://emoncms.org/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/emoncms/emoncms" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="openhands panel - detect info identify web-based control panels openhands (formerly opendevin) was detected. openhands is an open-source ai software engineering agent platform that can write code, run commands, and perform development tasks autonomously. exposed instances may allow unauthenticated access to the agent. rxerium agent ai detect discovery opendevin openhands panel" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">OpenHands Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/openhands-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">openhands-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 14, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)OpenHands&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">OpenHands (formerly OpenDevin) was detected. OpenHands is an open-source AI software engineering agent platform that can write code, run commands, and perform development tasks autonomously. Exposed instances may allow unauthenticated access to the agent.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">agent</span><span class="nt-tag">ai</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">opendevin</span><span class="nt-tag">openhands</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/All-Hands-AI/OpenHands" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.all-hands.dev/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="openlitespeed webadmin - default login high identify default logins in web-based control panels detected openlitespeed webadmin console was using default credentials. 0x_akoko default-login openlitespeed litespeed webadmin" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">OpenLiteSpeed WebAdmin - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/openlitespeed/openlitespeed-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">openlitespeed-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_Akoko</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 23, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)OpenLiteSpeed WebAdmin&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detected OpenLiteSpeed WebAdmin Console was using default credentials.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">openlitespeed</span><span class="nt-tag">litespeed</span><span class="nt-tag">webadmin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.digitalocean.com/community/tutorials/how-to-install-the-openlitespeed-web-server-on-ubuntu-18-04" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="openmediavault - default login high identify default logins in web-based control panels  dhiyaneshdk default-login openmediavault vuln cwe-522" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">OpenMediaVault - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/openmediavault/openmediavault-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">openmediavault-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 8, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/522.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-522</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;OpenMediaVault&#34;})</code></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">openmediavault</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://forum.openmediavault.org/index.php?thread/7784-default-login/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://soltveit.org/openmediavault-default-password/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="openmetadata - admin user enumeration medium identify critical remote vulnerabilities enumerates the admin users registered on openmetadata server. icarot openmetadata open-metadata userenum discovery" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">OpenMetadata - Admin User Enumeration</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposures/configs/openmetadata-admin-userenum.yaml" target="_blank" rel="noopener" class="nt-source-link">openmetadata-admin-userenum.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> icarot</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 11, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)OpenMetadata&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Enumerates the admin users registered on OpenMetadata server.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">openmetadata</span><span class="nt-tag">open-metadata</span><span class="nt-tag">userenum</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/open-metadata/OpenMetadata" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="openobserve login panel - detect info identify web-based control panels openobserve products was detected. righettod panel openobserve login discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">OpenObserve Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/openobserve-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">openobserve-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 18, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)OpenObserve&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">OpenObserve products was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">openobserve</span><span class="nt-tag">login</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/openobserve/openobserve" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="openplc webserver v3 - default login high identify default logins in web-based control panels identifies default credentials (openplc:openplc) on openplc webserver v3, allowing unauthorized access to the web interface. machevalia,shriyanss openplc default-login iot vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">OpenPLC Webserver v3 - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/openplc/openplc-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">openplc-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> machevalia,shriyanss</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 25, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)OpenPLC&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Identifies default credentials (openplc:openplc) on OpenPLC Webserver v3, allowing unauthorized access to the web interface.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">openplc</span><span class="nt-tag">default-login</span><span class="nt-tag">iot</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="openproject - default admin credentials high identify default logins in web-based control panels detected openproject was found using the default administrator credentials admin:admin. an attacker could gain full administrative control, including user management, project data, and system configuration. 0x_akoko auth default-login misconfig openproject" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">OpenProject - Default Admin Credentials</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/openproject-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">openproject-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_Akoko</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 8, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)OpenProject&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detected OpenProject was found using the default administrator credentials admin:admin. An attacker could gain full administrative control, including user management, project data, and system configuration.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth</span><span class="nt-tag">default-login</span><span class="nt-tag">misconfig</span><span class="nt-tag">openproject</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.openproject.org/docs/installation-and-operations/installation/manual/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.openproject.org/docs/api/introduction/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/opf/openproject" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="openproject &lt; 12.5.4 - project identifiers exposure medium identify critical remote vulnerabilities openproject versions before 12.5.6 generate a publicly accessible robots.txt file revealing project identifiers, even if the instance is set to &#39;login required&#39;, letting attackers gather project info, exploit requires no authentication. cve-2023-33960 0x_akoko api cve cve2023 exposure openproject cwe-200" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">OpenProject &lt; 12.5.4 - Project Identifiers Exposure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-33960.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-33960.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_Akoko</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 13, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-33960" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-33960</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)OpenProject&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">OpenProject versions before 12.5.6 generate a publicly accessible robots.txt file revealing project identifiers, even if the instance is set to &#39;Login required&#39;, letting attackers gather project info, exploit requires no authentication.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can enumerate project identifiers, potentially aiding targeted attacks or information gathering.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to version 12.5.6 or later, or apply the provided patch to versions above 10.0.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">api</span><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">exposure</span><span class="nt-tag">openproject</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.openproject.org/docs/release-notes/12-5-4/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/opf/openproject/security/advisories/GHSA-4r3x-x7xf-h2gc" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-33960" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="openscada - panel info identify web-based control panels openscada is an open-source scada (supervisory control and data acquisition)
system. exposed instances may provide access to industrial control interfaces
and operational technology (ot) data without authentication. rxerium discovery ics openscada panel scada" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">OpenSCADA - Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/openscada-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">openscada-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 27, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;^OpenSCADA&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">OpenSCADA is an open-source SCADA (Supervisory Control and Data Acquisition)
system. Exposed instances may provide access to industrial control interfaces
and operational technology (OT) data without authentication.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">ics</span><span class="nt-tag">openscada</span><span class="nt-tag">panel</span><span class="nt-tag">scada</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://oscada.org" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://sourceforge.net/projects/oscada/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="opensis 7.3 - sql injection critical identify critical remote vulnerabilities opensis community edition version 7.3 is vulnerable to sql injection via the username parameter of index.php. cve-2020-6637 pikpikcu cve cve2020 opensis os4ed sqli vuln cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">OpenSIS 7.3 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2020/CVE-2020-6637.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2020-6637.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pikpikcu</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2020-6637" target="_blank" rel="noopener" class="nt-cve-link">CVE-2020-6637</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)opensis&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">OpenSIS Community Edition version 7.3 is vulnerable to SQL injection via the USERNAME parameter of index.php.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized access, data manipulation, or data leakage.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patch or upgrade to a patched version of OpenSIS.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2020</span><span class="nt-tag">opensis</span><span class="nt-tag">os4ed</span><span class="nt-tag">sqli</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://cinzinga.com/CVE-2020-6637/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2020-6637" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://sourceforge.net/projects/opensis-ce/files/" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/OS4ED/openSIS-Responsive-Design/commit/1127ae0bb7c3a2883febeabc6b71ad8d73510de8" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://opensis.com/" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="opensis login panel - detect info identify web-based control panels opensis login panel was detected. pikpikcu discovery login opensis os4ed panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">OpenSIS Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/opensis-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">opensis-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pikpikcu</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)opensis&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">OpenSIS login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">login</span><span class="nt-tag">opensis</span><span class="nt-tag">os4ed</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="opensearch dashboard panel - detect info identify web-based control panels opensearch dashboard is a visualization and management tool for opensearch. this template detects the presence of the opensearch dashboard login panel, which is the default authentication interface for accessing the dashboard. ritikchaddha opensearch dashboard login panel detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">OpenSearch Dashboard Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/opensearch-dashboard-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">opensearch-dashboard-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 16, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)OpenSearch&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">OpenSearch Dashboard is a visualization and management tool for OpenSearch. This template detects the presence of the OpenSearch Dashboard login panel, which is the default authentication interface for accessing the dashboard.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">opensearch</span><span class="nt-tag">dashboard</span><span class="nt-tag">login</span><span class="nt-tag">panel</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://opensearch.org/docs/latest/dashboards/index/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="opensign login panel - detect info identify web-based control panels opensign login panel was discovered. righettod panel opensign login detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">OpenSign Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/opensign-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">opensign-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 23, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)opensign&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">OpenSign Login panel was discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">opensign</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.opensignlabs.com/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/OpenSignLabs/OpenSign" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="opentext content server login panel - detect info identify web-based control panels opentext content server products was detected. righettod panel opentext login discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">OpenText Content Server Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/opentext-contentserver-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">opentext-contentserver-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 6, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Content Server&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">OpenText Content Server products was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">opentext</span><span class="nt-tag">login</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.opentext.com/products/document-management" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="openvpn admin login panel - detect info identify web-based control panels openvpn admin login panel was detected. ritikchaddha admin config discovery openvpn panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">OpenVPN Admin Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/openvpn-admin.yaml" target="_blank" rel="noopener" class="nt-source-link">openvpn-admin.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)openvpn-admin&#34;}) || service[&#34;http.body&#34;] matches &#34;(?i)router management - server openvpn&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">OpenVPN Admin login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">admin</span><span class="nt-tag">config</span><span class="nt-tag">discovery</span><span class="nt-tag">openvpn</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="openvpn connect panel - detect info identify web-based control panels openvpn connect panel was detected. ritikchaddha panel openvpn connect vpn discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">OpenVPN Connect Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/openvpn-connect.yaml" target="_blank" rel="noopener" class="nt-source-link">openvpn-connect.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)openvpn connect&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">OpenVPN Connect panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">openvpn</span><span class="nt-tag">connect</span><span class="nt-tag">vpn</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="openvpn server router management panel - detect info identify web-based control panels openvpn server router management panel was detected. ritikchaddha discovery openvpn panel router cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">OpenVPN Server Router Management Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/openvpn-router-management.yaml" target="_blank" rel="noopener" class="nt-source-link">openvpn-router-management.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)router management - server openvpn&#34; || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)openvpn-admin&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">OpenVPN Server Router Management Panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">openvpn</span><span class="nt-tag">panel</span><span class="nt-tag">router</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="openvz web panel login panel - detect info identify web-based control panels openvz web panel login panel was detected. nullfuzz panel openvz discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">OpenVZ Web Panel Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/openvz-web-login.yaml" target="_blank" rel="noopener" class="nt-source-link">openvz-web-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> nullfuzz</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-1898583197&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">OpenVZ Web Panel login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">openvz</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/sibprogrammer/owp" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="openvas login panel - detect info identify web-based control panels an openvas admin login panel was detected. rxerium panel openvas admin login discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">OpenVas Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/openvas-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">openvas-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 27, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1606029165&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An OpenVas Admin login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">openvas</span><span class="nt-tag">admin</span><span class="nt-tag">login</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://openvas.org/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="openx/revive adserver login panel - detect info identify web-based control panels openx login panel was detected. note that openx is now a revive adserver. pikpikcu,righettod adserver discovery login openx panel revive revive-adserver cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">OpenX/Revive Adserver Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/openx-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">openx-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pikpikcu,righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)revive adserver&#34;}) || service[&#34;favicon.ico.image.mmh3&#34;] == &#34;106844876&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">OpenX login panel was detected. Note that OpenX is now a Revive Adserver.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">adserver</span><span class="nt-tag">discovery</span><span class="nt-tag">login</span><span class="nt-tag">openx</span><span class="nt-tag">panel</span><span class="nt-tag">revive</span><span class="nt-tag">revive-adserver</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.revive-adserver.com/download/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="openfire admin console login panel - detect info identify web-based control panels openfire admin console login panel was detected. theamanrawat admin console discovery igniterealtime openfire panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Openfire Admin Console Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/openfire-admin-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">openfire-admin-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> theamanrawat</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)openfire admin console&#34;}) || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)openfire&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Openfire Admin Console login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">admin</span><span class="nt-tag">console</span><span class="nt-tag">discovery</span><span class="nt-tag">igniterealtime</span><span class="nt-tag">openfire</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="openfire administration console - authentication bypass high identify critical remote vulnerabilities openfire is an xmpp server licensed under the open source apache license. openfire&#39;s administrative console, a web-based application, was found to be vulnerable to a path traversal attack via the setup environment. this permitted an unauthenticated user to use the unauthenticated openfire setup environment in an already configured openfire environment to access restricted pages in the openfire admin console reserved for administrative users. this vulnerability affects all versions of openfire that have been released since april 2015, starting with version 3.10.0. cve-2023-32315 vsh00t auth-bypass console cve cve2023 igniterealtime kev openfire vkev vuln cwe-22" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Openfire Administration Console - Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-32315.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-32315.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> vsh00t</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 1, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-32315" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-32315</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)openfire&#34;}) || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)openfire admin console&#34;}) || service[&#34;http.body&#34;] matches &#34;(?i)welcome to openfire setup&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Openfire is an XMPP server licensed under the Open Source Apache License. Openfire&#39;s administrative console, a web-based application, was found to be vulnerable to a path traversal attack via the setup environment. This permitted an unauthenticated user to use the unauthenticated Openfire Setup Environment in an already configured Openfire environment to access restricted pages in the Openfire Admin Console reserved for administrative users. This vulnerability affects all versions of Openfire that have been released since April 2015, starting with version 3.10.0.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to gain unauthorized access to the Openfire Administration Console.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">The problem has been patched in Openfire release 4.7.5 and 4.6.8, and further improvements will be included in the yet-to-be released first version on the 4.8 branch (which is expected to be version 4.8.0). Users are advised to upgrade. If an Openfire upgrade isn’t available for a specific release, or isn’t quickly actionable, users may see the linked github advisory (GHSA-gw42-f939-fhvm) for mitigation advice.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">console</span><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">igniterealtime</span><span class="nt-tag">kev</span><span class="nt-tag">openfire</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/advisories/GHSA-gw42-f939-fhvm" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-32315" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/izzz0/CVE-2023-32315-POC" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/Ostorlab/known_exploited_vulnerbilities_detectors" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/TLGKien/SploitusCrawl" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="opentwrt login / configuration interface info identify web-based control panels  for3stco1d,techbrunchfr discovery openwrt panel router" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Opentwrt Login / Configuration Interface</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/openwrt-login.yaml" target="_blank" rel="noopener" class="nt-source-link">openwrt-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> For3stCo1d,TechbrunchFR</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)openwrt - luci&#34;})</code></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">openwrt</span><span class="nt-tag">panel</span><span class="nt-tag">router</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://openwrt.org" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/openwrt/luci" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="opentwrt luci - admin login page info identify web-based control panels an opentwrt admin login page was discovered. for3stco1d default-login discovery openwrt panel x-wrt" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Opentwrt luCI - Admin Login Page</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/openwrt/openwrt-luci-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">openwrt-luci-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> For3stCo1d</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 2, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)openwrt - luci&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An Opentwrt admin login page was discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">discovery</span><span class="nt-tag">openwrt</span><span class="nt-tag">panel</span><span class="nt-tag">x-wrt</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://forum.archive.openwrt.org/viewtopic.php?id=16611" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="openweb ui panel - detect info identify web-based control panels openwebui was detected - a platform for running ai on your own terms rxerium,righettod panel openwebui login detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Openweb UI Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/openwebui-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">openwebui-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium,righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 6, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-286484075&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">OpenWebUI was detected - a platform for running AI on your own terms</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">openwebui</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://openwebui.com/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="opinio login panel - detect info identify web-based control panels opinio login panel was detected. righettod panel opinio login detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Opinio Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/opinio-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">opinio-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 21, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Opinio&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Opinio login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">opinio</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.objectplanet.com/opinio/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="opsview monitor pro - local file inclusion high identify critical remote vulnerabilities opsview monitor pro prior to 5.1.0.162300841, prior to 5.0.2.27475, prior to 4.6.4.162391051, and 4.5.x without a certain 2016 security patch is vulnerable to unauthenticated local file inclusion and can be exploited by issuing a specially crafted http get request utilizing a simple bypass. cve-2016-10367 0x_akoko cve cve2016 lfi opsview vkev vuln cwe-22" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Opsview Monitor Pro - Local File Inclusion</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2016/CVE-2016-10367.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2016-10367.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_akoko</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2016-10367" target="_blank" rel="noopener" class="nt-cve-link">CVE-2016-10367</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Opsview&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Opsview Monitor Pro prior to 5.1.0.162300841, prior to 5.0.2.27475, prior to 4.6.4.162391051, and 4.5.x without a certain 2016 security patch is vulnerable to unauthenticated local file inclusion and can be exploited by issuing a specially crafted HTTP GET request utilizing a simple bypass.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can read sensitive files on the server, potentially leading to unauthorized access or information disclosure.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to the latest version of Opsview Monitor Pro to fix the local file inclusion vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2016</span><span class="nt-tag">lfi</span><span class="nt-tag">opsview</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.trustwave.com/en-us/resources/security-resources/security-advisories/?fid=18774" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.trustwave.com/Resources/Security-Advisories/Advisories/TWSL2016-016/?fid=8341" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2016-10367" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/ARPSyndicate/cvemon" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/ARPSyndicate/kenzer-templates" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="opto 22 groov - panel info identify web-based control panels opto 22 groov is an iiot and industrial automation platform providing browser-based
hmi and edge computing capabilities. the groov view and groov admin interfaces allow
control of industrial devices and data acquisition systems. exposed instances may
provide unauthenticated access to industrial control panels. rxerium discovery groov ics iot opto22 panel" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Opto 22 groov - Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/opto22-groov-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">opto22-groov-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 27, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches `(?i)&lt;i&gt;groov&lt;/i&gt; is a registered trademark of Opto 22.`</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Opto 22 groov is an IIoT and industrial automation platform providing browser-based
HMI and edge computing capabilities. The groov View and groov Admin interfaces allow
control of industrial devices and data acquisition systems. Exposed instances may
provide unauthenticated access to industrial control panels.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">groov</span><span class="nt-tag">ics</span><span class="nt-tag">iot</span><span class="nt-tag">opto22</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.opto22.com/products/product-container/groov-epic" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.opto22.com/products/product-container/groov-rio" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="oracle adf faces deserialization of untrusted data vulnerability critical identify critical remote vulnerabilities vulnerability in versions 12.2.1.3.0 and 12.2.1.4.0 of the oracle application development
framework (adf) component of oracle fusion middleware that allows for unauthenticated
attackers to remotely execute arbitrary code. cve-2022-21445 n3integration cve cve2022 kev vuln rce cwe-502" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Oracle ADF Faces Deserialization of Untrusted Data Vulnerability</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-21445.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-21445.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> n3integration</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 19, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/502.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-502</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-21445" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-21445</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;product&#34;] matches &#34;(?i)Oracle:WebLogic&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Vulnerability in versions 12.2.1.3.0 and 12.2.1.4.0 of the Oracle Application Development
Framework (ADF) component of Oracle Fusion Middleware that allows for unauthenticated
attackers to remotely execute arbitrary code.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">kev</span><span class="nt-tag">vuln</span><span class="nt-tag">rce</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-21445" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.cve.org/CVERecord?id=CVE-2022-21445" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.oracle.com/security-alerts/cpuapr2022.html" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="oracle access management login panel - detect info identify web-based control panels oracle access management login panel was detected. righettod detect discovery login oracle panel" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Oracle Access Management Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/oracle-access-management.yaml" target="_blank" rel="noopener" class="nt-source-link">oracle-access-management.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 29, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/oam/pages/css/login_page\\.css&#34; || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)oracle access management&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Oracle Access Management login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">login</span><span class="nt-tag">oracle</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.oracle.com/security/identity-management/access-management/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="oracle access manager - remote code execution critical identify critical remote vulnerabilities the oracle access manager  portion of oracle fusion middleware (component: opensso agent) is vulnerable to remote code execution. supported versions that are affected are 11.1.2.3.0, 12.2.1.3.0 and 12.2.1.4.0. this is an easily exploitable vulnerability that allows unauthenticated attackers with network access via http to compromise oracle access manager. cve-2021-35587 cckuailong cve cve2021 java kev oam oracle rce unauth vkev vuln cwe-502" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Oracle Access Manager - Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2021/CVE-2021-35587.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2021-35587.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> cckuailong</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/502.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-502</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2021-35587" target="_blank" rel="noopener" class="nt-cve-link">CVE-2021-35587</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)oracle access management&#34;}) || service[&#34;http.body&#34;] matches &#34;(?i)/oam/pages/css/login_page\\.css&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The Oracle Access Manager  portion of Oracle Fusion Middleware (component: OpenSSO Agent) is vulnerable to remote code execution. Supported versions that are affected are 11.1.2.3.0, 12.2.1.3.0 and 12.2.1.4.0. This is an easily exploitable vulnerability that allows unauthenticated attackers with network access via HTTP to compromise Oracle Access Manager.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches provided by Oracle to mitigate this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2021</span><span class="nt-tag">java</span><span class="nt-tag">kev</span><span class="nt-tag">oam</span><span class="nt-tag">oracle</span><span class="nt-tag">rce</span><span class="nt-tag">unauth</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://testbnull.medium.com/oracle-access-manager-pre-auth-rce-cve-2021-35587-analysis-1302a4542316" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2021-35587" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.oracle.com/security-alerts/cpujan2022.html" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/ARPSyndicate/kenzer-templates" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/GrrrDog/Java-Deserialization-Cheat-Sheet" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="oracle agile product lifecycle management (plm) incorrect authorization vulnerability high identify critical remote vulnerabilities a vulnerability found within version 9.3.6 of the oracle agile plm framework allows an unauthenticated
attacker access to critical data or complete access to all oracle agile plm framework accessible data. cve-2024-21287 n3integration cve cve2024 kev vuln disclosure passive cwe-863" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Oracle Agile Product Lifecycle Management (PLM) Incorrect Authorization Vulnerability</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-21287.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-21287.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> n3integration</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 17, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/863.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-863</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-21287" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-21287</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;product&#34;] contains &#34;Oracle:Agile PLM Framework&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A vulnerability found within version 9.3.6 of the Oracle Agile PLM Framework allows an unauthenticated
attacker access to critical data or complete access to all Oracle Agile PLM Framework accessible data.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">kev</span><span class="nt-tag">vuln</span><span class="nt-tag">disclosure</span><span class="nt-tag">passive</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-21287" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.cve.org/CVERecord?id=CVE-2024-21287" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.oracle.com/security-alerts/alert-cve-2024-21287.html" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="oracle application server panel - detect info identify web-based control panels oracle application server login panel was detected. righettod panel oracle containers login detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Oracle Application Server Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/oracle-application-server-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">oracle-application-server-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 8, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Oracle Containers for J2EE&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Oracle Application Server login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">oracle</span><span class="nt-tag">containers</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.oracle.com/middleware/technologies/internet-application-server.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="oracle business intelligence default login high identify default logins in web-based control panels oracle business intelligence default admin credentials were discovered. milo2012 default-login oracle vuln cwe-522" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Oracle Business Intelligence Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/oracle/businessintelligence-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">businessintelligence-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> milo2012</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/522.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-522</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)oracle business intelligence sign in&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Oracle Business Intelligence default admin credentials were discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">oracle</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://docs.oracle.com/cd/E12096_01/books/AnyDeploy/AnyDeployMisc2.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="oracle business intelligence login panel - detect info identify web-based control panels oracle business intelligence login panel was detected. dhiyaneshdk,righettod detect discovery login oracle panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Oracle Business Intelligence Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/oracle-business-intelligence.yaml" target="_blank" rel="noopener" class="nt-source-link">oracle-business-intelligence.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk,righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)oracle business intelligence sign in&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Oracle Business Intelligence login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">login</span><span class="nt-tag">oracle</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.oracle.com/business-analytics/business-intelligence/technologies/bi.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="oracle commerce business control center login panel - detect info identify web-based control panels oracle commerce business control center login panel was detected. dhiyaneshdk,righettod discovery login oracle panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Oracle Commerce Business Control Center Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/oracle-business-control.yaml" target="_blank" rel="noopener" class="nt-source-link">oracle-business-control.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDk,righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)oracle commerce&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Oracle Commerce Business Control Center login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">login</span><span class="nt-tag">oracle</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://docs.oracle.com/cd/E23095_01/Platform.93/ATGBCCAdminGuide/html/s0101introductiontotheatgbusinesscont01.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="oracle e-business suite 12.2.3–12.2.14 – remote code execution critical identify critical remote vulnerabilities oracle concurrent processing 12.2.3-12.2.14 contains a remote code execution caused by unauthenticated network access via http, letting unauthenticated attackers fully compromise the system, exploit requires network access via http. cve-2025-61882 testanull,watchtowr,dhiyaneshdk,pussycat0x cve cve2025 ebusiness kev lfi oracle rce ssrf vkev vuln cwe-287" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Oracle E-Business Suite 12.2.3–12.2.14 – Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-61882.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-61882.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> testanull,watchtowr,DhiyaneshDk,pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 6, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/287.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-287</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-61882" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-61882</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)E-Business Suite&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Oracle Concurrent Processing 12.2.3-12.2.14 contains a remote code execution caused by unauthenticated network access via HTTP, letting unauthenticated attackers fully compromise the system, exploit requires network access via HTTP.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can fully compromise Oracle Concurrent Processing, leading to complete system takeover.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest available version beyond 12.2.14.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">ebusiness</span><span class="nt-tag">kev</span><span class="nt-tag">lfi</span><span class="nt-tag">oracle</span><span class="nt-tag">rce</span><span class="nt-tag">ssrf</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://labs.watchtowr.com/well-well-well-its-another-day-oracle-e-business-suite-pre-auth-rce-chain-cve-2025-61882well-well-well-its-another-day-oracle-e-business-suite-pre-auth-rce-chain-cve-2025-61882/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/watchtowrlabs/watchTowr-vs-Oracle-E-Business-Suite-CVE-2025-61882" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.oracle.com/security-alerts/alert-cve-2025-61882.html" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://blogs.oracle.com/security/post/apply-july-2025-cpu" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://vred.mbbank.com.vn/p/oracle-e-business-suite-authentication" target="_blank" rel="noopener" class="nt-ref-link">[5]</a> <a href="https://gist.github.com/testanull/a897473577b8650932221172e50304ce#file-ebs_cve-2025-61882_poc-py" target="_blank" rel="noopener" class="nt-ref-link">[6]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="oracle e-business suite &lt;=12.2 - authentication bypass high identify critical remote vulnerabilities oracle e-business suite (component: manage proxies) 12.1 and 12.2 are susceptible to an easily exploitable vulnerability that allows an unauthenticated attacker with network access via http to compromise it by self-registering for an account. successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all oracle e-business suite accessible data. cve-2022-21500 3th1c_yuk1,tess,0xpugal auth-bypass cve cve2022 misconfig oracle vkev vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Oracle E-Business Suite &lt;=12.2 - Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-21500.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-21500.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 3th1c_yuk1,tess,0xpugal</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-21500" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-21500</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)login\&#34; \&#34;x-oracle-dms-ecid&#34;}) || service[&#34;http.body&#34;] matches &#34;(?i)oracle uix&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Oracle E-Business Suite (component: Manage Proxies) 12.1 and 12.2 are susceptible to an easily exploitable vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise it by self-registering for an account. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle E-Business Suite accessible data.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to bypass authentication and gain unauthorized access to the Oracle E-Business Suite application.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the necessary security patches or updates provided by Oracle to mitigate this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">misconfig</span><span class="nt-tag">oracle</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://orwaatyat.medium.com/my-new-discovery-in-oracle-e-business-login-panel-that-allowed-to-access-for-all-employees-ed0ec4cad7ac" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://twitter.com/GodfatherOrwa/status/1514720677173026816" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.oracle.com/security-alerts/alert-cve-2022-21500.html" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-21500" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://www.oracle.com/security-alerts/cpujul2022.html" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="oracle e-business suite login panel - detect info identify web-based control panels oracle e-business suite login panel was detected. righettod panel oracle login detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Oracle E-Business Suite Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/oracle-ebusiness-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">oracle-ebusiness-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 21, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Oracle UIX&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Oracle E-Business Suite login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">oracle</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.oracle.com/applications/ebusiness/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="oracle forms &amp; reports rce (cve-2012-3152 &amp; cve-2012-3153) medium identify critical remote vulnerabilities an unspecified vulnerability in the oracle reports developer component in oracle fusion middleware 11.1.1.4,
11.1.1.6, and 11.1.2.0 allows remote attackers to affect confidentiality and integrity via unknown
vectors related to report server component. cve-2012-3153 sid ahmed malaoui @ realistic security cve cve2012 edb oracle rce vkev vuln nvd-cwe-noinfo" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Oracle Forms &amp; Reports RCE (CVE-2012-3152 &amp; CVE-2012-3153)</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2012/CVE-2012-3153.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2012-3153.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Sid Ahmed MALAOUI @ Realistic Security</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/NVD-CWE-NOINFO.html" target="_blank" rel="noopener" class="nt-cwe-link">NVD-CWE-NOINFO</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2012-3153" target="_blank" rel="noopener" class="nt-cve-link">CVE-2012-3153</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)weblogic&#34;}) || service[&#34;http.body&#34;] matches &#34;(?i)weblogic application server&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An unspecified vulnerability in the Oracle Reports Developer component in Oracle Fusion Middleware 11.1.1.4,
11.1.1.6, and 11.1.2.0 allows remote attackers to affect confidentiality and integrity via unknown
vectors related to Report Server Component.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability can lead to unauthorized remote code execution.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the necessary patches and updates provided by Oracle to mitigate this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2012</span><span class="nt-tag">edb</span><span class="nt-tag">oracle</span><span class="nt-tag">rce</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2012-3152" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.exploit-db.com/exploits/31737" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.oracle.com/security-alerts/cpuoct2012.html" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="http://blog.netinfiltration.com/2013/11/03/oracle-reports-cve-2012-3152-and-cve-2012-3153/" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="oracle fusion - directory traversal/local file inclusion high identify critical remote vulnerabilities oracle business intelligence enterprise edition 5.5.0.0.0, 12.2.1.3.0, and 12.2.1.4.0 are vulnerable to local file inclusion vulnerabilities via &#34;getpreviewimage.&#34; cve-2020-14864 ivo palazzolo (@palaziv) cve cve2020 kev lfi oracle packetstorm vkev vuln cwe-22" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Oracle Fusion - Directory Traversal/Local File Inclusion</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2020/CVE-2020-14864.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2020-14864.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Ivo Palazzolo (@palaziv)</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2020-14864" target="_blank" rel="noopener" class="nt-cve-link">CVE-2020-14864</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)oracle business intelligence sign in&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Oracle Business Intelligence Enterprise Edition 5.5.0.0.0, 12.2.1.3.0, and 12.2.1.4.0 are vulnerable to local file inclusion vulnerabilities via &#34;getPreviewImage.&#34;</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to read sensitive files, execute arbitrary code, or gain unauthorized access to the system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches and updates provided by Oracle to fix this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2020</span><span class="nt-tag">kev</span><span class="nt-tag">lfi</span><span class="nt-tag">oracle</span><span class="nt-tag">packetstorm</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="http://packetstormsecurity.com/files/159748/Oracle-Business-Intelligence-Enterprise-Edition-5.5.0.0.0-12.2.1.3.0-12.2.1.4.0-LFI.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.oracle.com/security-alerts/cpuoct2020.html" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2020-14864" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/merlinepedra/nuclei-templates" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/sobinge/nuclei-templates" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="oracle fusion middleware weblogic server administration console - remote code execution high identify critical remote vulnerabilities the oracle fusion middleware weblogic server admin console in versions 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0 is vulnerable to an easily exploitable vulnerability that allows high privileged attackers with network access via http to compromise oracle weblogic server. cve-2020-14883 pdteam,vicrack cve cve2020 kev oracle packetstorm rce vkev vuln weblogic" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Oracle Fusion Middleware WebLogic Server Administration Console - Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2020/CVE-2020-14883.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2020-14883.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pdteam,vicrack</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2020-14883" target="_blank" rel="noopener" class="nt-cve-link">CVE-2020-14883</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)oracle peoplesoft sign-in&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The Oracle Fusion Middleware WebLogic Server admin console in versions 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0 is vulnerable to an easily exploitable vulnerability that allows high privileged attackers with network access via HTTP to compromise Oracle WebLogic Server.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the necessary patches or updates provided by Oracle to mitigate this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2020</span><span class="nt-tag">kev</span><span class="nt-tag">oracle</span><span class="nt-tag">packetstorm</span><span class="nt-tag">rce</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">weblogic</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://packetstormsecurity.com/files/160143/Oracle-WebLogic-Server-Administration-Console-Handle-Remote-Code-Execution.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14883" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.oracle.com/security-alerts/cpuoct2020.html" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="http://packetstormsecurity.com/files/160143/Oracle-WebLogic-Server-Administration-Console-Handle-Remote-Code-Execution.html" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/1n7erface/PocList" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="oracle identity manager rest webservices - authentication bypass critical identify critical remote vulnerabilities vulnerability in the identity manager product of oracle fusion middleware (component: rest webservices). supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. easily exploitable vulnerability allows unauthenticated attacker with network access via http to compromise identity manager. successful attacks of this vulnerability can result in takeover of identity manager. cve-2025-61757 ritikchaddha auth-bypass cve cve2025 identity-manager kev oracle rce vkev cwe-306" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Oracle Identity Manager REST WebServices - Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-61757.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-61757.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 21, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/306.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-306</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-61757" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-61757</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)oracle access management&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Identity Manager. Successful attacks of this vulnerability can result in takeover of Identity Manager.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Allows unauthenticated attacker to fully compromise Oracle Identity Manager via HTTP(S), leading to complete loss of confidentiality, integrity, and availability.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security updates released by Oracle as referenced in the October 2025 Critical Patch Update.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">identity-manager</span><span class="nt-tag">kev</span><span class="nt-tag">oracle</span><span class="nt-tag">rce</span><span class="nt-tag">vkev</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://slcyber.io/research-center/breaking-oracles-identity-manager-pre-auth-rce/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61757" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="oracle integrated lights out manager login panel - detect info identify web-based control panels oracle integrated lights out manager login panel was detected. dhiyaneshdk discovery login oracle panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Oracle Integrated Lights Out Manager Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/oracle-integrated-manager.yaml" target="_blank" rel="noopener" class="nt-source-link">oracle-integrated-manager.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Oracle\\(R\\) Integrated Lights Out Manager&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Oracle Integrated Lights Out Manager login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">login</span><span class="nt-tag">oracle</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="oracle opera login - detect info identify web-based control panels  dhiyaneshdk,righettod panel opera oracle detect discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Oracle Opera Login - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/oracle-opera-login.yaml" target="_blank" rel="noopener" class="nt-source-link">oracle-opera-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK,righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 2, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Oracle Opera&#34;})</code></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">opera</span><span class="nt-tag">oracle</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="oracle peoplesoft - default login high identify default logins in web-based control panels oracle peoplesoft contains a default admin login vulnerability. an attacker can obtain access to user accounts and access sensitive information, modify data, and/or execute unauthorized operations. logicalhunter default-login fuzz oracle peoplesoft vuln cwe-522" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Oracle PeopleSoft - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/oracle/peoplesoft-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">peoplesoft-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> LogicalHunter</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/522.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-522</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;Oracle PeopleSoft Sign-in&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Oracle PeopleSoft contains a default admin login vulnerability. An attacker can obtain access to user accounts and access sensitive information, modify data, and/or execute unauthorized operations.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">fuzz</span><span class="nt-tag">oracle</span><span class="nt-tag">peoplesoft</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.oracle.com/applications/peoplesoft/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://erpscan.io/press-center/blog/peoplesoft-default-accounts/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="oracle peoplesoft enterprise login panel - detect info identify web-based control panels oracle peoplesoft enterprise login panel detected. dhiyaneshdk discovery login oracle panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Oracle PeopleSoft Enterprise Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/oracle-people-enterprise.yaml" target="_blank" rel="noopener" class="nt-source-link">oracle-people-enterprise.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)oracle peoplesoft enterprise&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Oracle PeopleSoft Enterprise login panel detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">login</span><span class="nt-tag">oracle</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="oracle peoplesoft login panel - detect info identify web-based control panels oracle peoplesoft login panel was detected. idealphase,righettod detect discovery login oracle panel peoplesoft cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Oracle PeopleSoft Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/oracle-peoplesoft-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">oracle-peoplesoft-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> idealphase,righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 2, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Oracle PeopleSoft Sign-in&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Oracle PeopleSoft login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">login</span><span class="nt-tag">oracle</span><span class="nt-tag">panel</span><span class="nt-tag">peoplesoft</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.oracle.com/applications/peoplesoft/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="oracle peoplesoft - unauthenticated file read high identify critical remote vulnerabilities vulnerability in the peoplesoft enterprise peopletools product of oracle peoplesoft (component- portal).  supported versions that are affected are 8.59 and  8.60. easily exploitable vulnerability allows unauthenticated attacker with network access via http to compromise peoplesoft enterprise peopletools.  successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all peoplesoft enterprise peopletools accessible data. cve-2023-22047 tuo4n8 cve cve2023 lfi oracle peoplesoft vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Oracle Peoplesoft - Unauthenticated File Read</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-22047.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-22047.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> tuo4n8</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 2, 2025</span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-22047" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-22047</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)oracle peoplesoft enterprise&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component- Portal).  Supported versions that are affected are 8.59 and  8.60. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can read arbitrary files from the PeopleSoft server through the wsrp-url parameter in the Portal component, potentially accessing critical data including configuration files and sensitive employee information.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update Oracle PeopleSoft Enterprise PeopleTools to a version newer than 8.60 that validates and restricts file:// URLs in the wsrp-url parameter.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">lfi</span><span class="nt-tag">oracle</span><span class="nt-tag">peoplesoft</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-22047" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://x.com/tuo4n8/status/1907279143517266286" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="oracle retail xstore suite - pre-authenticated path traversal high identify critical remote vulnerabilities vulnerability in the oracle retail xstore office product of oracle retail applications (component: security). supported versions that are affected are 19.0.5, 20.0.3, 20.0.4, 22.0.0 and 23.0.1. easily exploitable vulnerability allows unauthenticated attacker with network access via http to compromise oracle retail xstore office. while the vulnerability is in oracle retail xstore office, attacks may significantly impact additional products (scope change). cve-2024-21136 dhiyaneshdk cve cve2024 lfi oracle vkev vuln xstore" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Oracle Retail Xstore Suite - Pre-authenticated Path Traversal</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-21136.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-21136.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 23, 2025</span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-21136" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-21136</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)xstoremgwt&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Vulnerability in the Oracle Retail Xstore Office product of Oracle Retail Applications (component: Security). Supported versions that are affected are 19.0.5, 20.0.3, 20.0.4, 22.0.0 and 23.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Xstore Office. While the vulnerability is in Oracle Retail Xstore Office, attacks may significantly impact additional products (scope change).</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Retail Xstore Office accessible data.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches and updates from the vendor to address this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">lfi</span><span class="nt-tag">oracle</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">xstore</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.oracle.com/security-alerts/cpuapr2024.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.synacktiv.com/en/advisories/oracle-retail-xstore-suite-pre-authenticated-path-traversal" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-21136" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="oracle weblogic login panel - detect info identify web-based control panels oracle weblogic login panel was detected. bing0o,meme-lord discovery login oracle panel weblogic cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Oracle WebLogic Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/weblogic-login.yaml" target="_blank" rel="noopener" class="nt-source-link">weblogic-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> bing0o,meme-lord</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)oracle peoplesoft sign-in&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Oracle WebLogic login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">login</span><span class="nt-tag">oracle</span><span class="nt-tag">panel</span><span class="nt-tag">weblogic</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="oracle weblogic server - remote code execution critical identify critical remote vulnerabilities the oracle weblogic server component of oracle fusion middleware (subcomponent: web services) versions 10.3.6.0, 12.1.3.0, 12.2.1.2 and 12.2.1.3 contain an easily exploitable vulnerability that allows unauthenticated attackers with network access via t3 to compromise oracle weblogic server. cve-2018-2893 milo2012 cve cve2018 deserialization network oracle rce tcp vkev vuln weblogic" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Oracle WebLogic Server - Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/network/cves/2018/CVE-2018-2893.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2018-2893.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> milo2012</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2018-2893" target="_blank" rel="noopener" class="nt-cve-link">CVE-2018-2893</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)oracle peoplesoft sign-in&#34;}) and service[&#34;service.transport&#34;] contains &#34;tcp&#34; and service[&#34;protocol&#34;] contains &#34;http&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services) versions 10.3.6.0, 12.1.3.0, 12.2.1.2 and 12.2.1.3 contain an easily exploitable vulnerability that allows unauthenticated attackers with network access via T3 to compromise Oracle WebLogic Server.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Install the suitable patch as per the Oracle Critical Patch Update advisory</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2018</span><span class="nt-tag">deserialization</span><span class="nt-tag">network</span><span class="nt-tag">oracle</span><span class="nt-tag">rce</span><span class="nt-tag">tcp</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">weblogic</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.anquanke.com/post/id/152164" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://vulners.com/nessus/WEBLOGIC_CVE_2018_2893.NASL" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2018-2893" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="http://www.securitytracker.com/id/1041301" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="oracle weblogic server - remote code execution critical identify critical remote vulnerabilities oracle weblogic server (oracle fusion middleware (component: wls core components) is susceptible to a remote code execution vulnerability. supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 2.2.1.3.0 and 12.2.1.4.0. this easily exploitable vulnerability could allow unauthenticated attackers with network access via iiop to compromise oracle weblogic server. cve-2020-2551 dwisiswant0 cve cve2020 kev oracle rce unauth vkev vuln weblogic" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Oracle WebLogic Server - Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2020/CVE-2020-2551.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2020-2551.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dwisiswant0</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2020-2551" target="_blank" rel="noopener" class="nt-cve-link">CVE-2020-2551</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)oracle peoplesoft sign-in&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Oracle WebLogic Server (Oracle Fusion Middleware (component: WLS Core Components) is susceptible to a remote code execution vulnerability. Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 2.2.1.3.0 and 12.2.1.4.0. This easily exploitable vulnerability could allow unauthenticated attackers with network access via IIOP to compromise Oracle WebLogic Server.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches provided by Oracle to mitigate this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2020</span><span class="nt-tag">kev</span><span class="nt-tag">oracle</span><span class="nt-tag">rce</span><span class="nt-tag">unauth</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">weblogic</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/hktalent/CVE-2020-2551" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2020-2551" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.oracle.com/security-alerts/cpujan2020.html" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/neilzhang1/Chinese-Charts" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/pjgmonteiro/Pentest-tools" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="oracle weblogic server - remote command execution critical identify critical remote vulnerabilities the oracle weblogic server component of oracle fusion middleware (subcomponent: web services) allows unauthenticated attackers with network access via http to compromise oracle weblogic server. versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. cve-2019-2725 dwisiswant0 cve cve2019 packetstorm kev edb oracle weblogic rce vkev vuln cwe-74" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Oracle WebLogic Server - Remote Command Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2019/CVE-2019-2725.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2019-2725.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dwisiswant0</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/74.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-74</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2019-2725" target="_blank" rel="noopener" class="nt-cve-link">CVE-2019-2725</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)weblogic&#34;}) || service[&#34;http.body&#34;] matches &#34;(?i)weblogic application server&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services) allows unauthenticated attackers with network access via HTTP to compromise Oracle WebLogic Server. Versions that are affected are 10.3.6.0.0 and 12.1.3.0.0.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can compromise Oracle WebLogic Server via the Web Services component, potentially leading to complete server takeover and unauthorized access to sensitive data.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches provided by Oracle to fix the vulnerability and ensure proper input validation and sanitization of XML data.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2019</span><span class="nt-tag">packetstorm</span><span class="nt-tag">kev</span><span class="nt-tag">edb</span><span class="nt-tag">oracle</span><span class="nt-tag">weblogic</span><span class="nt-tag">rce</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://paper.seebug.org/910/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.exploit-db.com/exploits/46780/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.oracle.com/security-alerts/cpujan2020.html" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2019-2725" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="http://packetstormsecurity.com/files/152756/Oracle-Weblogic-Server-Deserialization-Remote-Code-Execution.html" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="oracle weblogic server local file inclusion high identify critical remote vulnerabilities an easily exploitable local file inclusion vulnerability allows unauthenticated attackers with network access via http to compromise oracle weblogic server. supported versions that are affected are 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. successful attacks of this vulnerability can result in unauthorized and sometimes complete access to critical data. cve-2022-21371 paradessia,narluin cve cve2022 lfi oracle packetstorm vkev vuln weblogic cwe-22" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Oracle WebLogic Server Local File Inclusion</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-21371.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-21371.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> paradessia,narluin</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-21371" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-21371</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)oracle peoplesoft sign-in&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An easily exploitable local file inclusion vulnerability allows unauthenticated attackers with network access via HTTP to compromise Oracle WebLogic Server. Supported versions that are affected are 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Successful attacks of this vulnerability can result in unauthorized and sometimes complete access to critical data.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can read sensitive files containing credentials, configuration details, or other sensitive information.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches provided by Oracle to fix the vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">lfi</span><span class="nt-tag">oracle</span><span class="nt-tag">packetstorm</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">weblogic</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.oracle.com/security-alerts/cpujan2022.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-21371" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://gist.github.com/picar0jsu/f3e32939153e4ced263d3d0c79bd8786" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="http://packetstormsecurity.com/files/165736/Oracle-WebLogic-Server-14.1.1.0.0-Local-File-Inclusion.html" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/Mr-xn/CVE-2022-21371" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="oracle weblogic uddi explorer panel - detect info identify web-based control panels oracle weblogic uddi explorer panel was detected. pdteam panel oracle weblogic tenable discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Oracle WebLogic UDDI Explorer Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/weblogic-uddiexplorer.yaml" target="_blank" rel="noopener" class="nt-source-link">weblogic-uddiexplorer.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pdteam</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)oracle peoplesoft sign-in&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Oracle WebLogic UDDI Explorer panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">oracle</span><span class="nt-tag">weblogic</span><span class="nt-tag">tenable</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.tenable.com/plugins/was/112421" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="orchid core vms panel - detect info identify web-based control panels orchid core vms panel was detected. princechaddha discovery ipconfigure orchid panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Orchid Core VMS Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/orchid-vms-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">orchid-vms-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> princechaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)orchid core vms&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Orchid Core VMS panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">ipconfigure</span><span class="nt-tag">orchid</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="order delivery date pro for woocommerce &lt; 12.3.1 - arbitrary option update critical identify critical remote vulnerabilities the order delivery date wordpress plugin before 12.3.1 does not have authorization and csrf checks when importing settings. furthermore it also lacks proper checks to only update options relevant to the order delivery date wordpress plugin before 12.3.1. this leads to attackers being able to modify the default_user_role to administrator and users_can_register, allowing them to register as an administrator of the site for complete site takeover. cve-2025-2907 iamnoooob,rootxharsh,pdresearch cve cve2025 order-delivery-date takeover vkev vuln wordpress wp wp-plugin cwe-352,cwe-862" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Order Delivery Date Pro for WooCommerce &lt; 12.3.1 - Arbitrary Option Update</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-2907.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-2907.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> iamnoooob,rootxharsh,pdresearch</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 2, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/352,CWE-862.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-352,CWE-862</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-2907" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-2907</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)wp-content/plugins/order-delivery-date-for-woocommerce&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The Order Delivery Date WordPress plugin before 12.3.1 does not have authorization and CSRF checks when importing settings. Furthermore it also lacks proper checks to only update options relevant to the Order Delivery Date WordPress plugin before 12.3.1. This leads to attackers being able to modify the default_user_role to administrator and users_can_register, allowing them to register as an administrator of the site for complete site takeover.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can modify WordPress options to enable user registration with administrator role, allowing complete site takeover without authentication.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to version 12.3.1 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">order-delivery-date</span><span class="nt-tag">takeover</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wpscan.com/vulnerability/2e513930-ec01-4dc6-8991-645c5267e14c/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-2907" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="ourmgmt3 admin login panel - detect info identify web-based control panels ourmgmt3 admin login panel was detected. ritikchaddha panel ourmgmt3 discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">OurMGMT3 Admin Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/ourmgmt3-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">ourmgmt3-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)OurMGMT3&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">OurMGMT3 admin login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">ourmgmt3</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="outback power mate3s gateway - detect info identify web-based control panels outback power mate3s is a system hub and gateway for outback fx-series inverter-chargers
used in off-grid, grid-hybrid, and battery backup solar power systems.
the built-in web interface exposes system status, battery metrics, and inverter data. rxerium detect energy ics outback panel scada solar tech" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">OutBack Power Mate3s Gateway - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/outback-power-detect.yaml" target="_blank" rel="noopener" class="nt-source-link">outback-power-detect.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 27, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;Outback Power&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">OutBack Power Mate3s is a system hub and gateway for OutBack FX-series inverter-chargers
used in off-grid, grid-hybrid, and battery backup solar power systems.
The built-in web interface exposes system status, battery metrics, and inverter data.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">detect</span><span class="nt-tag">energy</span><span class="nt-tag">ics</span><span class="nt-tag">outback</span><span class="nt-tag">panel</span><span class="nt-tag">scada</span><span class="nt-tag">solar</span><span class="nt-tag">tech</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.outbackpower.com/outback-products/communications/detail/mate3s" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="outsystems service center login panel - detect info identify web-based control panels outsystems service center login panel was detected. righettod panel outsystems login detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">OutSystems Service Center Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/outsystems-servicecenter-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">outsystems-servicecenter-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 2, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)outsystems&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">OutSystems Service Center login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">outsystems</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.outsystems.com/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="outline panel - detect info identify web-based control panels outline (getoutline.com / github.com/outline/outline) is a popular open-source team knowledge base / wiki, often self-hosted as a notion alternative. exposed self-hosted instances may reveal team documents and provide a path to login enumeration if sso is misconfigured. chrisjr404 detect discovery knowledge-base outline panel wiki" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Outline Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/outline-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">outline-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ChrisJr404</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 4, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;811213058&#34; || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Outline&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Outline (getoutline.com / github.com/outline/outline) is a popular open-source team knowledge base / wiki, often self-hosted as a Notion alternative. Exposed self-hosted instances may reveal team documents and provide a path to login enumeration if SSO is misconfigured.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">knowledge-base</span><span class="nt-tag">outline</span><span class="nt-tag">panel</span><span class="nt-tag">wiki</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/outline/outline" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.getoutline.com/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="owncloud - phpinfo configuration high identify critical remote vulnerabilities an issue was discovered in owncloud owncloud/graphapi 0.2.x before 0.2.1 and 0.3.x before 0.3.1. the graphapi app relies on a third-party getphpinfo.php library that provides a url. when this url is accessed, it reveals the configuration details of the php environment (phpinfo). this information includes all the environment variables of the webserver. in containerized deployments, these environment variables may include sensitive data such as the owncloud admin password, mail server credentials, and license key. simply disabling the graphapi app does not eliminate the vulnerability. additionally, phpinfo exposes various other potentially sensitive configuration details that could be exploited by an attacker to gather information about the system. cve-2023-49103 ritikchaddha config cve cve2023 kev owncloud phpinfo vkev vuln cwe-200" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">OwnCloud - Phpinfo Configuration</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-49103.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-49103.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 23, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-49103" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-49103</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)owncloud&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An issue was discovered in ownCloud owncloud/graphapi 0.2.x before 0.2.1 and 0.3.x before 0.3.1. The graphapi app relies on a third-party GetPhpInfo.php library that provides a URL. When this URL is accessed, it reveals the configuration details of the PHP environment (phpinfo). This information includes all the environment variables of the webserver. In containerized deployments, these environment variables may include sensitive data such as the ownCloud admin password, mail server credentials, and license key. Simply disabling the graphapi app does not eliminate the vulnerability. Additionally, phpinfo exposes various other potentially sensitive configuration details that could be exploited by an attacker to gather information about the system.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can access phpinfo configuration details exposing sensitive credentials including admin passwords, mail server credentials, and license keys in containerized deployments.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade ownCloud graphapi to version 0.2.1 or 0.3.1 or later, and remove or secure the GetPhpInfo.php file.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">config</span><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">kev</span><span class="nt-tag">owncloud</span><span class="nt-tag">phpinfo</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/creacitysec/CVE-2023-49103/blob/main/exploit.py" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-49103" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://owncloud.com/security-advisories/disclosure-of-sensitive-credentials-and-configuration-in-containerized-deployments/" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://www.labs.greynoise.io//grimoire/2023-11-29-owncloud-redux/" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://attackerkb.com/topics/G9urDj4Cg2/cve-2023-49103" target="_blank" rel="noopener" class="nt-ref-link">[5]</a> <a href="https://www.rapid7.com/blog/post/2023/12/01/etr-cve-2023-49103-critical-information-disclosure-in-owncloud-graph-api/" target="_blank" rel="noopener" class="nt-ref-link">[6]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="owncast - default credentials high identify default logins in web-based control panels detected owncast using default admin credentials admin:abc123. the admin api was accessible via http basic authentication, allowing full server configuration access. 0x_akoko admin default-login owncast streaming vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Owncast - Default Credentials</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/owncast-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">owncast-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_Akoko</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 8, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Owncast&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detected Owncast using default admin credentials admin:abc123. The admin API was accessible via HTTP Basic authentication, allowing full server configuration access.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">admin</span><span class="nt-tag">default-login</span><span class="nt-tag">owncast</span><span class="nt-tag">streaming</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://owncast.online/docs/configuration/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://owncast.online/quickstart/configure/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="pahtool login panel - detect info identify web-based control panels pahtool login panel was detected. righettod panel pahtool login detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">PAHTool Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/pahtool-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">pahtool-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 9, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)PAHTool&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">PAHTool login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">pahtool</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="http://www.inovultus.com/index.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="pan-os management interface - path confusion to authentication bypass critical identify critical remote vulnerabilities a vulnerability in pan-os management interface allows authentication bypass through path confusion between nginx and apache handlers.the issue occurs due to differences in path processing between nginx and apache, where double url encoding combined with directory traversal can bypass authentication checks enforced by x-pan-authcheck header. cve-2025-0108 halencarjunior,ritikchaddha auth-bypass cve cve2025 kev panos vkev vuln cwe-287,cwe-306" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">PAN-OS Management Interface - Path Confusion to Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-0108.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-0108.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> halencarjunior,ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 13, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/287,CWE-306.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-287,CWE-306</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-0108" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-0108</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-631559155&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A vulnerability in PAN-OS management interface allows authentication bypass through path confusion between Nginx and Apache handlers.The issue occurs due to differences in path processing between Nginx and Apache, where double URL encoding combined with directory traversal can bypass authentication checks enforced by X-pan-AuthCheck header.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can exploit path confusion between Nginx and Apache to bypass authentication completely, gaining unauthorized access to the PAN-OS management interface and potentially compromising the entire firewall infrastructure.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to the patched version of PAN-OS as specified in the vendor security advisory.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">kev</span><span class="nt-tag">panos</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://slcyber.io/blog/nginx-apache-path-confusion-to-auth-bypass-in-pan-os/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="pan-os management panel - detect info identify web-based control panels pan-os management panel was detected. bhutch panel panos login detect paloaltonetworks discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">PAN-OS Management Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/panos-management-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">panos-management-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> bhutch</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 11, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;873381299&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">PAN-OS management panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">panos</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">paloaltonetworks</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://security.paloaltonetworks.com/PAN-SA-2024-0015" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="pan-os management web interface - authentication bypass critical identify critical remote vulnerabilities an authentication bypass in palo alto networks pan-os software enables an unauthenticated attacker with network access to the management web interface to gain pan-os administrator privileges to perform administrative actions, tamper with the configuration, or exploit other authenticated privilege escalation vulnerabilities cve-2024-0012 johnk3r,watchtowr cve cve2024 globalprotect kev paloalto vkev vuln cwe-306" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">PAN-OS Management Web Interface - Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-0012.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-0012.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> johnk3r,watchtowr</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 19, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/306.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-306</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-0012" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-0012</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-631559155&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator privileges to perform administrative actions, tamper with the configuration, or exploit other authenticated privilege escalation vulnerabilities</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers with network access to the management interface can bypass authentication to gain full administrator privileges, allowing them to tamper with configurations, exploit additional vulnerabilities, and completely compromise the Palo Alto firewall and connected networks.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to the latest patched version of PAN-OS as specified in the vendor security advisory.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">globalprotect</span><span class="nt-tag">kev</span><span class="nt-tag">paloalto</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://security.paloaltonetworks.com/CVE-2024-0012" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://labs.watchtowr.com/pots-and-pans-aka-an-sslvpn-palo-alto-pan-os-cve-2024-0012-and-cve-2024-9474/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-0012" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="pdf generator addon for elementor page builder &lt;= 1.7.5 - arbitrary file download high identify critical remote vulnerabilities the pdf generator addon for elementor page builder plugin for wordpress is vulnerable to path traversal in all versions up to, and including, 1.7.5 via the rtw_pgaepb_dwnld_pdf() function. this makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. cve-2024-9935 s4e-io cve cve2024 lfi pdf-generator vuln wordpress wp wp-plugin cwe-22" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">PDF Generator Addon for Elementor Page Builder &lt;= 1.7.5 - Arbitrary File Download</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-9935.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-9935.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> s4e-io</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 21, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-9935" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-9935</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)wp-content/plugins/pdf-generator-addon-for-elementor-page-builder/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The PDF Generator Addon for Elementor Page Builder plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.7.5 via the rtw_pgaepb_dwnld_pdf() function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can exploit path traversal to read arbitrary files on the server, potentially exposing sensitive configuration files, wp-config.php containing database credentials, and other critical system files.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update PDF Generator Addon for Elementor Page Builder plugin to a version later than 1.7.5 that properly validates and sanitizes file paths in the rtw_pgaepb_dwnld_pdf function.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">lfi</span><span class="nt-tag">pdf-generator</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/RandomRobbieBF/CVE-2024-9935" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://plugins.trac.wordpress.org/browser/pdf-generator-addon-for-elementor-page-builder/trunk/public/class-pdf-generator-addon-for-elementor-page-builder-public.php#L133" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/36daf2af-1db3-4b35-8849-480212660b2f?source=cve" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-9935" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="pdi intellifuel - device page low identify web-based control panels  dhiyaneshdk exposure pdi intellifuel panel discovery" data-nt-sev="low">
  <div class="nt-card-header">
    <div class="nt-title">PDI Intellifuel - Device Page</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/pdi-device-page.yaml" target="_blank" rel="noopener" class="nt-source-link">pdi-device-page.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 20, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)PDI Intellifuel&#34;</code></div>
  <div class="nt-tags"><span class="nt-tag">exposure</span><span class="nt-tag">pdi</span><span class="nt-tag">intellifuel</span><span class="nt-tag">panel</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.facebook.com/photo?fbid=629130339257489&amp;set=a.467014098802448" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="php cgi - argument injection critical identify critical remote vulnerabilities php cgi - argument injection (cve-2024-4577) is a critical argument injection flaw in php. cve-2024-4577 hüseyin tintaş,sw0rk17,s4e-io,pdresearch cgi cve cve2024 kev php rce vkev vuln cwe-78" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">PHP CGI - Argument Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-4577.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-4577.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Hüseyin TINTAŞ,sw0rk17,s4e-io,pdresearch</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 7, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/78.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-78</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-4577" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-4577</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)php warning\&#34; \\|\\| \&#34;fatal error&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">PHP CGI - Argument Injection (CVE-2024-4577) is a critical argument injection flaw in PHP.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation could lead to remote code execution on the affected system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the vendor-supplied patches or upgrade to a non-vulnerable version.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cgi</span><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">kev</span><span class="nt-tag">php</span><span class="nt-tag">rce</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://s4e.io/tools/php-cgi-code-injection-cve-2024-4577" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="http://www.openwall.com/lists/oss-security/2024/06/07/1" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://blog.orange.tw/2024/06/cve-2024-4577-yet-another-php-rce.html" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://cert.be/en/advisory/warning-php-remote-code-execution-patch-immediately" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="php ldap admin panel - detect info identify web-based control panels  ritikchaddha,dhiyaneshdk php phpldapadmin panel detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">PHP LDAP Admin Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/phpldapadmin-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">phpldapadmin-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha,DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 12, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)phpLDAPadmin&#34;})</code></div>
  <div class="nt-tags"><span class="nt-tag">php</span><span class="nt-tag">phpldapadmin</span><span class="nt-tag">panel</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="php login system 2.0.1 - cross-site scripting medium identify critical remote vulnerabilities msaad1999&#39;s php-login-system 2.0.1 contains a reflected cross-site scripting caused by unsanitized input in &#39;validator&#39; parameter in /reset-password, letting remote attackers execute arbitrary javascript in a user&#39;s browser, exploit requires attacker to craft malicious url cve-2023-38875 0x_akoko cve cve2023 php-login-system xss cwe-79" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">PHP Login System 2.0.1 - Cross-Site Scripting</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-38875.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-38875.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_Akoko</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 28, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-79</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-38875" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-38875</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)klik_loginsystem&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">msaad1999&#39;s PHP-Login-System 2.0.1 contains a reflected cross-site scripting caused by unsanitized input in &#39;validator&#39; parameter in /reset-password, letting remote attackers execute arbitrary JavaScript in a user&#39;s browser, exploit requires attacker to craft malicious URL</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can execute arbitrary JavaScript in users&#39; browsers, potentially stealing cookies or session tokens.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Implement proper input validation and output encoding for the &#39;validator&#39; parameter.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">php-login-system</span><span class="nt-tag">xss</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-38876" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/dub-flow/vulnerability-research/tree/main/CVE-2023-38875" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="phpci configuration exposure &#34;phpci.yml&#34; exposure info identify critical remote vulnerabilities phpci configuration &#34;phpci.yml&#34; file was exposed. dhiyaneshdk phpci misconfig vuln" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">PHPCI Configuration Exposure &#34;phpci.yml&#34; Exposure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposures/configs/phpci-yml.yaml" target="_blank" rel="noopener" class="nt-source-link">phpci-yml.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 16, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)phpci\\.yml&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">PHPCI Configuration &#34;phpci.yml&#34; File was exposed.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">phpci</span><span class="nt-tag">misconfig</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/dancryer/PHPCI/blob/master/.phpci.yml" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="phpcms 2008 - remote code execution via template injection critical identify critical remote vulnerabilities phpcms 2008 suffers from an unauthenticated rce via template injection in type.php, where attacker-supplied content is written into a php template cache file, which is then executable. cve-2018-19127 tomaquet18 cve cve2018 phpcms rce ssti vkev vuln cwe-94" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">PHPCMS 2008 - Remote Code Execution via Template Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2018/CVE-2018-19127.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2018-19127.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> tomaquet18</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 2, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/94.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-94</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2018-19127" target="_blank" rel="noopener" class="nt-cve-link">CVE-2018-19127</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Powered by phpcms&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">PHPCMS 2008 suffers from an unauthenticated RCE via template injection in type.php, where attacker-supplied content is written into a PHP template cache file, which is then executable.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation allows an unauthenticated attacker to achieve remote code execution on the server, potentially taking full control.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">The vendor is unresponsive and PHPCMS 2008 is no longer maintained. Users are advised to stop using this software or restrict public access to it.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2018</span><span class="nt-tag">phpcms</span><span class="nt-tag">rce</span><span class="nt-tag">ssti</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/ab1gale/phpcms-2008-CVE-2018-19127" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/advisories/GHSA-p498-q357-m3p7" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2018-19127" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="phpgurukul hospital management system 4.0 - sql injection high identify critical remote vulnerabilities phpgurukul hospital management system in php v4.0 has a sql injection vulnerability in \hms\user-login.php. remote unauthenticated users can exploit the vulnerability to obtain sensitive database information. cve-2020-22165 ritikchaddha cms cve cve2020 hms phpgurukul sqli vkev vuln cwe-89" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">PHPGurukul Hospital Management System 4.0 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2020/CVE-2020-22165.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2020-22165.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 9, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2020-22165" target="_blank" rel="noopener" class="nt-cve-link">CVE-2020-22165</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Hospital Management System&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\user-login.php. Remote unauthenticated users can exploit the vulnerability to obtain sensitive database information.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation allows attackers to access sensitive data from the database, potentially leading to data leakage and further compromise of the application.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to the latest version or apply proper input sanitization and parameterized queries to mitigate this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cms</span><span class="nt-tag">cve</span><span class="nt-tag">cve2020</span><span class="nt-tag">hms</span><span class="nt-tag">phpgurukul</span><span class="nt-tag">sqli</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/itodaro/PHPGurukul_Hospital_Management_System4.0_cve" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2020-22165" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="phpipam &lt;v1.5.1 - missing authorization medium identify critical remote vulnerabilities in phpipam 1.5.1, an unauthenticated user could download the list of high-usage ip subnets that contains sensitive information such as a subnet description, ip ranges, and usage rates via find_full_subnets.php endpoint. the bug lies in the fact that find_full_subnets.php does not verify if the user is authorized to access the data, and if the script was started from a command line. cve-2023-0678 princechaddha,ritikchaddha cve cve2023 php phpipam unauth vuln cwe-862" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">PHPIPAM &lt;v1.5.1 - Missing Authorization</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-0678.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-0678.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> princechaddha,ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 31, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/862.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-862</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-0678" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-0678</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)phpipam ip address management&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">In phpIPAM 1.5.1, an unauthenticated user could download the list of high-usage IP subnets that contains sensitive information such as a subnet description, IP ranges, and usage rates via find_full_subnets.php endpoint. The bug lies in the fact that find_full_subnets.php does not verify if the user is authorized to access the data, and if the script was started from a command line.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can access sensitive network information including IP subnet descriptions, ranges, and usage rates through the find_full_subnets.php endpoint without authorization.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update phpIPAM to version 1.5.1 or later that implements proper authorization checks in find_full_subnets.php before returning subnet information.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">php</span><span class="nt-tag">phpipam</span><span class="nt-tag">unauth</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/phpipam/phpipam/commit/1960bd24e8a55796da066237cf11272c44bb1cc4" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="phpjabbers food delivery script - sql injection critical identify critical remote vulnerabilities phpjabbers food delivery script 3.0 has a sql injection (sqli) vulnerability in the &#34;q&#34; parameter of index.php. cve-2023-40748 ritikchaddha cve cve2023 food-delivery phpjabbers sqli vkev vuln cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">PHPJabbers Food Delivery Script - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-40748.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-40748.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 22, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-40748" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-40748</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)PHPJabbers&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">PHPJabbers Food Delivery Script 3.0 has a SQL injection (SQLi) vulnerability in the &#34;q&#34; parameter of index.php.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can exploit SQL injection in the q parameter to extract sensitive database information including customer orders, payment details, delivery addresses, and admin credentials from the Food Delivery platform.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update PHPJabbers Food Delivery Script to a version newer than 3.0 that properly sanitizes the q parameter and uses parameterized queries.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">food-delivery</span><span class="nt-tag">phpjabbers</span><span class="nt-tag">sqli</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://medium.com/@tfortinsec/multiple-vulnerabilities-in-phpjabbers-part-3-40fc3565982f" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-40748" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="phpjabbers food delivery script v3.0 - sql injection critical identify critical remote vulnerabilities phpjabbers food delivery script v3.0 is vulnerable to sql injection in the &#34;column&#34; parameter of index.php. cve-2023-40749 ritikchaddha cve cve2023 food-delivery phpjabbers sqli vuln cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">PHPJabbers Food Delivery Script v3.0 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-40749.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-40749.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 22, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-40749" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-40749</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)PHPJabbers&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">PHPJabbers Food Delivery Script v3.0 is vulnerable to SQL Injection in the &#34;column&#34; parameter of index.php.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can exploit SQL injection in the column parameter to extract sensitive database information including customer orders, payment details, delivery addresses, and admin credentials from the Food Delivery platform.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update PHPJabbers Food Delivery Script to a version newer than 3.0 that properly sanitizes the column parameter and uses parameterized queries.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">food-delivery</span><span class="nt-tag">phpjabbers</span><span class="nt-tag">sqli</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://medium.com/@tfortinsec/multiple-vulnerabilities-in-phpjabbers-part-3-40fc3565982f" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-40749" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="phpjabbers shuttle booking software 1.0 - cross site scripting medium identify critical remote vulnerabilities the attacker can send to victim a link containing a malicious url in an email or instant message can perform a wide variety of actions, such as stealing the victim&#39;s session token or login credentials. cve-2023-4112 r3y3r53 cve cve2023 packetstorm phpjabbers unauth vuln xss cwe-79" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">PHPJabbers Shuttle Booking Software 1.0 - Cross Site Scripting</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-4112.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-4112.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> r3Y3r53</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 17, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-79</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-4112" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-4112</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)php jabbers\\.com&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The attacker can send to victim a link containing a malicious URL in an email or instant message can perform a wide variety of actions, such as stealing the victim&#39;s session token or login credentials.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can inject malicious JavaScript through URL parameters, potentially stealing session tokens and login credentials of shuttle booking system administrators and customers.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update PHPJabbers Shuttle Booking Software to a version newer than 1.0 that properly sanitizes URL parameters in the admin login functionality.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">packetstorm</span><span class="nt-tag">phpjabbers</span><span class="nt-tag">unauth</span><span class="nt-tag">vuln</span><span class="nt-tag">xss</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.exploitalert.com/view-details.html?id=39750" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://cxsecurity.com/ascii/WLB-2023080012" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="http://packetstormsecurity.com/files/173930/PHPJabbers-Shuttle-Booking-Software-1.0-Cross-Site-Scripting.html" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-4112" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://vuldb.com/?ctiid.235959" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="phpjabbers taxi booking 2.0 - cross site scripting medium identify critical remote vulnerabilities a vulnerability classified as problematic was found in php jabbers taxi booking 2.0. affected by this vulnerability is an unknown functionality of the file /index.php. the manipulation of the argument index leads to cross site scripting. the attack can be launched remotely. cve-2023-4116 r3y3r53 cve cve2023 packetstorm phpjabbers vuln xss cwe-79" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">PHPJabbers Taxi Booking 2.0 - Cross Site Scripting</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-4116.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-4116.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> r3Y3r53</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 17, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-79</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-4116" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-4116</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)php jabbers\\.com&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A vulnerability classified as problematic was found in PHP Jabbers Taxi Booking 2.0. Affected by this vulnerability is an unknown functionality of the file /index.php. The manipulation of the argument index leads to cross site scripting. The attack can be launched remotely.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can inject malicious JavaScript through the index parameter, potentially stealing booking information and user credentials from the Taxi Booking platform.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update PHP Jabbers Taxi Booking to a version newer than 2.0 that properly sanitizes the index parameter and encodes output to prevent XSS attacks.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">packetstorm</span><span class="nt-tag">phpjabbers</span><span class="nt-tag">vuln</span><span class="nt-tag">xss</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.exploitalert.com/view-details.html?id=39746" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://cxsecurity.com/ascii/WLB-2023080016" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="http://packetstormsecurity.com/files/173937/PHPJabbers-Taxi-Booking-2.0-Cross-Site-Scripting.html" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-4116" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://vuldb.com/?ctiid.235963" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="phpmailer panel - detect info identify web-based control panels phpmailer panel was detected. ritikchaddha discovery mailer panel php cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">PHPMailer Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/php-mailer.yaml" target="_blank" rel="noopener" class="nt-source-link">php-mailer.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)PHP Mailer&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">PHPMailer panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">mailer</span><span class="nt-tag">panel</span><span class="nt-tag">php</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="pmb 7.4.6 - cross-site scripting medium identify critical remote vulnerabilities pmb 7.4.6 contains a cross-site scripting vulnerability via the query parameter at /admin/convert/export_z3950_new.php. an attacker can inject arbitrary script in the browser of an unsuspecting user in the context of the affected site. this can allow the attacker to steal cookie-based authentication credentials and launch other attacks. cve-2023-24733 r3y3r53 cve cve2023 pmb pmb_project sigb unauth vkev vuln xss cwe-79" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">PMB 7.4.6 - Cross-Site Scripting</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-24733.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-24733.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> r3Y3r53</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-79</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-24733" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-24733</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1469328760&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">PMB 7.4.6 contains a cross-site scripting vulnerability via the query parameter at /admin/convert/export_z3950_new.php. An attacker can inject arbitrary script in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to inject malicious scripts into web pages viewed by users, leading to potential data theft, session hijacking, or defacement of the affected website.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patch or upgrade to a non-vulnerable version of PMB.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">pmb</span><span class="nt-tag">pmb_project</span><span class="nt-tag">sigb</span><span class="nt-tag">unauth</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">xss</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/AetherBlack/CVE/blob/main/PMB/readme.md" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/AetherBlack/CVE/tree/main/PMB" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-24733" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="pronote login panel - detect info identify web-based control panels pronote products was detected. righettod panel pronote login discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">PRONOTE Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/pronote-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">pronote-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 4, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)PRONOTE&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">PRONOTE products was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">pronote</span><span class="nt-tag">login</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.index-education.com/fr/logiciel-gestion-vie-scolaire.php" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="prtg network monitor - hardcoded credentials high identify default logins in web-based control panels prtg network monitor contains a hardcoded credential vulnerability. an attacker can obtain access to user accounts and access sensitive information, modify data, and/or execute unauthorized operations. johnk3r default-login prtg vuln cwe-798" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">PRTG Network Monitor - Hardcoded Credentials</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/prtg/prtg-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">prtg-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> johnk3r</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/798.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-798</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-655683626&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">PRTG Network Monitor contains a hardcoded credential vulnerability. An attacker can obtain access to user accounts and access sensitive information, modify data, and/or execute unauthorized operations.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">prtg</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.paessler.com/manuals/prtg/login" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="ptc thingworx - panel info identify web-based control panels ptc thingworx is an industrial iot (iiot) platform for building and deploying
connected industrial applications, machine monitoring, and remote service solutions.
exposed instances may provide unauthenticated access to iiot dashboards and
connected device management interfaces. rxerium discovery ics iot panel ptc thingworx" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">PTC ThingWorx - Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/ptc-thingworx-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">ptc-thingworx-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 27, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;^Thingworx&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">PTC ThingWorx is an Industrial IoT (IIoT) platform for building and deploying
connected industrial applications, machine monitoring, and remote service solutions.
Exposed instances may provide unauthenticated access to IIoT dashboards and
connected device management interfaces.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">ics</span><span class="nt-tag">iot</span><span class="nt-tag">panel</span><span class="nt-tag">ptc</span><span class="nt-tag">thingworx</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.ptc.com/en/products/thingworx" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="pair drop panel - detect info identify web-based control panels local file sharing in your browser. inspired by apple&#39;s airdrop. fork of snapdrop. rxerium panel pairdrop login discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Pair Drop Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/pairdrop-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">pairdrop-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 3, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)PairDrop&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Local file sharing in your browser. Inspired by Apple&#39;s AirDrop. Fork of Snapdrop.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">pairdrop</span><span class="nt-tag">login</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/schlagmichdoch/pairdrop" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="palo alto expedition - admin account takeover critical identify critical remote vulnerabilities missing authentication for a critical function in palo alto networks expedition can lead to an expedition admin account takeover for attackers with network access to expedition. cve-2024-5910 johnk3r auth-bypass cve cve2024 kev palo-alto vkev vuln cwe-306" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Palo Alto Expedition - Admin Account Takeover</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-5910.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-5910.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> johnk3r</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 9, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/306.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-306</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-5910" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-5910</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1499876150&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Missing authentication for a critical function in Palo Alto Networks Expedition can lead to an Expedition admin account takeover for attackers with network access to Expedition.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers with network access can exploit missing authentication to takeover Expedition admin accounts without credentials.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update Palo Alto Networks Expedition to the latest version that patches CVE-2024-5910 as specified in the Palo Alto security advisory.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">kev</span><span class="nt-tag">palo-alto</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.horizon3.ai/attack-research/palo-alto-expedition-from-n-day-to-full-compromise" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://security.paloaltonetworks.com/CVE-2024-5910" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-5910" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="palo alto expedition - sql injection high identify critical remote vulnerabilities an sql injection vulnerability in palo alto networks expedition allows an unauthenticated attacker to reveal expedition database contents, such as password hashes, usernames, device configurations, and device api keys. with this, attackers can also create and read arbitrary files on the expedition system. cve-2024-9465 dhiyaneshdk cve cve2024 kev palo-alto sqli time-based-sqli vkev vuln cwe-89" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Palo Alto Expedition - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-9465.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-9465.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 10, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-9465" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-9465</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1499876150&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An SQL injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to reveal Expedition database contents, such as password hashes, usernames, device configurations, and device API keys. With this, attackers can also create and read arbitrary files on the Expedition system.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can exploit SQL injection to reveal Expedition database contents including password hashes, usernames, device configurations, and API keys, and create or read arbitrary files on the system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply security updates from Palo Alto Networks as specified in security advisory PAN-SA-2024-0010 to address the SQL injection vulnerability in Expedition.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">kev</span><span class="nt-tag">palo-alto</span><span class="nt-tag">sqli</span><span class="nt-tag">time-based-sqli</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://security.paloaltonetworks.com/PAN-SA-2024-0010" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/horizon3ai/CVE-2024-9465/tree/main" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.horizon3.ai/attack-research/palo-alto-expedition-from-n-day-to-full-compromise/" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-9465" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="palo alto expedition project login - detect info identify web-based control panels palo alto expedition project login panel was detected. johnk3r panel expedition palo-alto login detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Palo Alto Expedition Project Login - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/paloalto-expedition-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">paloalto-expedition-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> johnk3r</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 10, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1499876150&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Palo Alto Expedition Project login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">expedition</span><span class="nt-tag">palo-alto</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="palo alto network pan-os - remote code execution critical identify critical remote vulnerabilities palo alto network pan-os and panorama before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote attackers to execute arbitrary code via vectors involving the management interface. cve-2017-15944 emadshanab,milo2012 cve cve2017 edb globalprotect kev paloaltonetworks panos rce vkev vpn vuln" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Palo Alto Network PAN-OS - Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2017/CVE-2017-15944.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2017-15944.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> emadshanab,milo2012</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2017-15944" target="_blank" rel="noopener" class="nt-cve-link">CVE-2017-15944</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-631559155&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Palo Alto Network PAN-OS and Panorama before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote attackers to execute arbitrary code via vectors involving the management interface.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches and updates provided by Palo Alto Networks.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2017</span><span class="nt-tag">edb</span><span class="nt-tag">globalprotect</span><span class="nt-tag">kev</span><span class="nt-tag">paloaltonetworks</span><span class="nt-tag">panos</span><span class="nt-tag">rce</span><span class="nt-tag">vkev</span><span class="nt-tag">vpn</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.exploit-db.com/exploits/43342" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://security.paloaltonetworks.com/CVE-2017-15944" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="http://blog.orange.tw/2019/07/attacking-ssl-vpn-part-1-preauth-rce-on-palo-alto.html" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2017-15944" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="http://www.securitytracker.com/id/1040007" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="palo alto networks pan-os default login high identify default logins in web-based control panels palo alto networks pan-os application default admin credentials were discovered. techryptic (@tech) default-login panos vuln cwe-522" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Palo Alto Networks PAN-OS Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/paloalto/panos-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">panos-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Techryptic (@Tech)</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/522.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-522</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.bodies&#34;]), {# contains &#34;window.Pan = window.Pan || {}&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Palo Alto Networks PAN-OS application default admin credentials were discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">panos</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/getting-started/integrate-the-firewall-into-your-management-network/perform-initial-configuration.html#:~:text=By%20default%2C%20the%20firewall%20has,with%20other%20firewall%20configuration%20tasks." target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="pandora fms mobile console login panel - detect info identify web-based control panels pandora fms mobile console login panel was detected. dhiyaneshdk discovery edb pandorafms panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Pandora FMS Mobile Console Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/pandora-fms-console.yaml" target="_blank" rel="noopener" class="nt-source-link">pandora-fms-console.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)pandora fms&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Pandora FMS Mobile Console login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">edb</span><span class="nt-tag">pandorafms</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.exploit-db.com/ghdb/6827" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="papercut &lt; 22.1.3 - path traversal critical identify critical remote vulnerabilities papercut ng and papercut mf before 22.1.3 are vulnerable to path traversal which enables attackers to read, delete, and upload arbitrary files. cve-2023-39143 pdteam cve cve2023 lfi papercut vkev vuln cwe-22" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">PaperCut &lt; 22.1.3 - Path Traversal</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-39143.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-39143.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pdteam</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 6, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-39143" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-39143</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)content=\&#34;papercut&#34; || service[&#34;http.body&#34;] matches &#34;(?i)papercut&#34; || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)papercut&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">PaperCut NG and PaperCut MF before 22.1.3 are vulnerable to path traversal which enables attackers to read, delete, and upload arbitrary files.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can exploit this vulnerability to access sensitive files, potentially leading to unauthorized disclosure of information or remote code execution.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade PaperCut to version 22.1.3 or later to mitigate the vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">lfi</span><span class="nt-tag">papercut</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-39143" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.horizon3.ai/cve-2023-39143-papercut-path-traversal-file-upload-rce-vulnerability/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.papercut.com/kb/Main/securitybulletinjuly2023/" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-131a" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/nomi-sec/PoC-in-GitHub" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="papercut ng unauthenticated xmlrpc functionality medium identify critical remote vulnerabilities papercut ng allows for unauthenticated xmlrpc commands to be run by default. versions 22.0.12 and below are confirmed to be affected, but later versions may also be affected due to lack of a vendor supplied patch. cve-2023-4568 dhiyaneshdk cve cve2023 papercut unauth vuln cwe-287" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">PaperCut NG Unauthenticated XMLRPC Functionality</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-4568.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-4568.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 18, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/287.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-287</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-4568" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-4568</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)content=\&#34;papercut&#34; || service[&#34;http.body&#34;] matches &#34;(?i)&#39;content=\&#34;papercut&#39;&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">PaperCut NG allows for unauthenticated XMLRPC commands to be run by default. Versions 22.0.12 and below are confirmed to be affected, but later versions may also be affected due to lack of a vendor supplied patch.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could lead to remote code execution or unauthorized access to sensitive information.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches and updates from the vendor to address this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">papercut</span><span class="nt-tag">unauth</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-4568" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.tenable.com/security/research/tra-2023-31" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="paperless-ngx panel - detect info identify web-based control panels detected paperless-ngx was a self-hosted document management platform for scanning, ocr-ing and tagging paper documents. chrisjr404 detect discovery panel paperless paperless-ngx" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Paperless-ngx Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/paperless-ngx-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">paperless-ngx-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ChrisJr404</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 6, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Paperless-ngx&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detected Paperless-ngx was a self-hosted document management platform for scanning, OCR-ing and tagging paper documents.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">paperless</span><span class="nt-tag">paperless-ngx</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/paperless-ngx/paperless-ngx" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://docs.paperless-ngx.com/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="parallels h-sphere 3.6.1713 - cross-site scripting medium identify critical remote vulnerabilities parallels h-sphere 3.6.1713 contains a cross-site scripting vulnerability via the index_en.php &#39;from&#39; parameter. cve-2022-30777 3th1c_yuk1 cve cve2022 hsphere parallels vkev vuln xss cwe-79" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Parallels H-Sphere 3.6.1713 - Cross-Site Scripting</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-30777.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-30777.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 3th1c_yuk1</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-79</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-30777" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-30777</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)h-sphere&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Parallels H-Sphere 3.6.1713 contains a cross-site scripting vulnerability via the index_en.php &#39;from&#39; parameter.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute arbitrary script code in the victim&#39;s browser, leading to session hijacking, defacement, or theft of sensitive information.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patch or upgrade to a newer version of Parallels H-Sphere to mitigate the XSS vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">hsphere</span><span class="nt-tag">parallels</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">xss</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://medium.com/@bhattronit96/cve-2022-30777-45725763ab59" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://en.wikipedia.org/wiki/H-Sphere" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-30777" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://medium.com/%40bhattronit96/cve-2022-30777-45725763ab59" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/ARPSyndicate/cvemon" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="parallels h-sphere login panel - detect info identify web-based control panels parallels h-sphere login panel was detected. ritikchaddha discovery hsphere panel parallels cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Parallels H-Sphere Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/parallels/parallels-hsphere-detect.yaml" target="_blank" rel="noopener" class="nt-source-link">parallels-hsphere-detect.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)parallels h-sphere&#34;}) || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)h-sphere&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Parallels H-Sphere login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">hsphere</span><span class="nt-tag">panel</span><span class="nt-tag">parallels</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="parse dashboard login panel - detect info identify web-based control panels parse dashboard login panel was detected. tess discovery exposure panel parse parseplatform cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Parse Dashboard Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/parse-dashboard.yaml" target="_blank" rel="noopener" class="nt-source-link">parse-dashboard.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> tess</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)parse dashboard&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Parse Dashboard login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">exposure</span><span class="nt-tag">panel</span><span class="nt-tag">parse</span><span class="nt-tag">parseplatform</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="parse server - graphql schema information disclosure medium identify critical remote vulnerabilities the parse server graphql api previously allowed public access to the graphql schema without requiring a session token or the master key. while schema introspection reveals only metadata and not actual data, this metadata can still expand the potential attack surface. securitytaters cve cve2025 exposure graphql parse vkev vuln" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Parse Server - GraphQL Schema Information Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-53364.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-53364.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> securitytaters</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 20, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)parse server\&#34; \\|\\| \&#34;parse-server&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The Parse Server GraphQL API previously allowed public access to the GraphQL schema without requiring a session token or the master key. While schema introspection reveals only metadata and not actual data, this metadata can still expand the potential attack surface.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can access GraphQL schema metadata without authentication, potentially expanding the attack surface through exposure of API structure and query capabilities.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade Parse Server to the latest version that requires authentication for GraphQL schema introspection.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">exposure</span><span class="nt-tag">graphql</span><span class="nt-tag">parse</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/parse-community/parse-server/security/advisories/GHSA-48q3-prgv-gm4w" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.miggo.io/vulnerability-database/cve/CVE-2025-53364" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53364" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="passbolt login panel info identify web-based control panels passbolt login panel was detected. righettod panel passbolt login discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Passbolt Login Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/passbolt-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">passbolt-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 5, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Passbolt \\| Open source password manager for teams&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Passbolt login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">passbolt</span><span class="nt-tag">login</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.passbolt.com/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="payroll management system web login panel - detect info identify web-based control panels payroll management system web login panel was detected. idealphase discovery panel payroll cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Payroll Management System Web Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/payroll-management-system-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">payroll-management-system-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> idealphase</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Admin \\| Employee&#39;s Payroll Management System&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Payroll Management System Web login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">payroll</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="pega infinity login panel - detect info identify web-based control panels pega infinity login panel was detected. powerexploit,righettod discovery panel pega cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Pega Infinity Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/pega-web-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">pega-web-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> powerexploit,righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)pega platform&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Pega Infinity login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">pega</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.pega.com/infinity" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="pelco sarix - default login high identify default logins in web-based control panels pelco sarix camera default login credentials (admin/admin) were discovered using digest authentication. tdiderich pelco sarix default-login cwe-798" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Pelco Sarix - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/pelco/pelco-sarix-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">pelco-sarix-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> tdiderich</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 19, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/798.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-798</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">asset[&#34;hw&#34;] matches &#34;(i)Pelco Sarix&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Pelco Sarix camera default login credentials (admin/admin) were discovered using Digest Authentication.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">pelco</span><span class="nt-tag">sarix</span><span class="nt-tag">default-login</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://support.pelco.com/s/article/Default-passwords-and-usernames-for-Digital-Sentry-DX-Endura-Sarix-and-VideoXpert-components-1538586718306?language=en_US" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="pentaho default login high identify default logins in web-based control panels pentaho default admin credentials were discovered. pussycat0x default-login pentaho vuln cwe-522" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Pentaho Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/pentaho/pentaho-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">pentaho-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/522.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-522</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;^Pentaho User Console&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Pentaho default admin credentials were discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">pentaho</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.hitachivantara.com/en-us/pdfd/training/pentaho-lesson-1-user-console-overview.pdf" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="perforce repository disclosure low identify critical remote vulnerabilities detected an exposed .p4ignore file, which could have revealed ignored files, sensitive paths, or developer-specific information useful for further enumeration. dhiyaneshdk exposure perforce repo disclosure" data-nt-sev="low">
  <div class="nt-card-header">
    <div class="nt-title">Perforce Repository Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/misconfiguration/perforce-repository.yaml" target="_blank" rel="noopener" class="nt-source-link">perforce-repository.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 21, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Perforce&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detected an exposed .p4ignore file, which could have revealed ignored files, sensitive paths, or developer-specific information useful for further enumeration.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">exposure</span><span class="nt-tag">perforce</span><span class="nt-tag">repo</span><span class="nt-tag">disclosure</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://help.perforce.com/helix-core/server-apps/cmdref/current/Content/CmdRef/P4IGNORE.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="perplexica panel - detect info identify web-based control panels perplexica is an open-source ai-powered search engine that uses searxng to search
the web and provides ai-generated answers. rxerium ai detect discovery llm panel perplexica search" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Perplexica Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/perplexica-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">perplexica-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 27, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;Perplexica&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Perplexica is an open-source AI-powered search engine that uses SearXNG to search
the web and provides AI-generated answers.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">ai</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">llm</span><span class="nt-tag">panel</span><span class="nt-tag">perplexica</span><span class="nt-tag">search</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/ItzCrazyKns/Perplexica" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="persis panel - detect info identify web-based control panels persis panel was detected, righettod discovery panel persis cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Persis Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/persis-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">persis-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Persis&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Persis panel was detected,</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">persis</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.persis.de/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="personal weather station dashboard 12 - directory traversal high identify critical remote vulnerabilities personal weather station dashboard 12_lts allows unauthenticated remote attackers to read arbitrary files via ../ directory traversal in the test parameter to /others/_test.php, as demonstrated by reading the server&#39;s private ssl key in cleartext. cve-2025-47423 pussycat0x cve cve2025 lfi pws traversal vuln cwe-24" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Personal Weather Station Dashboard 12 - Directory Traversal</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-47423.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-47423.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 18, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/24.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-24</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-47423" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-47423</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)PWS Dashboard&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Personal Weather Station Dashboard 12_lts allows unauthenticated remote attackers to read arbitrary files via ../ directory traversal in the test parameter to /others/_test.php, as demonstrated by reading the server&#39;s private SSL key in cleartext.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can read arbitrary files including private SSL keys through directory traversal in the test parameter, potentially exposing sensitive cryptographic material.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade Personal Weather Station Dashboard to a version later than 12_lts that properly validates file paths.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">lfi</span><span class="nt-tag">pws</span><span class="nt-tag">traversal</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/Haluka92/CVE-2025-47423" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://pwsdashboard.com/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="phabricator login panel - detect info identify web-based control panels phabricator login panel was detected. dhiyaneshdk discovery panel phabricator phacility cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Phabricator Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/phabricator-login.yaml" target="_blank" rel="noopener" class="nt-source-link">phabricator-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)phabricator-standard-page&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Phabricator login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">phabricator</span><span class="nt-tag">phacility</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="phoenix contact charx sec-3xxx ac charging controller panel - detect info identify web-based control panels phoenix contact charx sec-3xxx ac charging controller panel was detected. inokii panel phoenix-contact charx ics discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Phoenix Contact CHARX SEC-3XXX AC Charging Controller Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/phoenix-contact-charx-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">phoenix-contact-charx-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> inokii</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 16, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Phoenix Contact - CHARX&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Phoenix Contact CHARX SEC-3XXX AC Charging Controller panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">phoenix-contact</span><span class="nt-tag">charx</span><span class="nt-tag">ics</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.phoenixcontact.com/en-us/products/ac-charging-controllers" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="phoenix contact charx sec-3xxx ac charging controller rest api - detect info identify critical remote vulnerabilities phoenix contact charx sec-3xxx ac charging controller rest api was detected. inokii phoenix-contact charx ics api discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Phoenix Contact CHARX SEC-3XXX AC Charging Controller REST API - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposures/apis/phoenix-contact-charx-api.yaml" target="_blank" rel="noopener" class="nt-source-link">phoenix-contact-charx-api.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> inokii</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 16, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Phoenix Contact - CHARX&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Phoenix Contact CHARX SEC-3XXX AC Charging Controller REST API was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">phoenix-contact</span><span class="nt-tag">charx</span><span class="nt-tag">ics</span><span class="nt-tag">api</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.phoenixcontact.com/en-us/products/ac-charging-controllers" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="phoenix contact charx sec-3xxx ac controller &lt; 1.7.3 - multiple vulnerabilities critical identify critical remote vulnerabilities multiple vulnerabilities exist in phoenix contact charx sec-3xxx ac controller versions prior to 1.7.3. successful exploitation may allow attackers to bypass authentication, disclose sensitive information, or execute arbitrary code. inokii charx phoenix-contact vuln" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Phoenix Contact CHARX SEC-3XXX AC Controller &lt; 1.7.3 - Multiple Vulnerabilities</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/vulnerabilities/phoenix-contact/phoenix-contact-charx-multiple-vulnerabilities.yaml" target="_blank" rel="noopener" class="nt-source-link">phoenix-contact-charx-multiple-vulnerabilities.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> inokii</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 11, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Phoenix Contact - CHARX&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Multiple vulnerabilities exist in Phoenix Contact CHARX SEC-3XXX AC Controller versions prior to 1.7.3. Successful exploitation may allow attackers to bypass authentication, disclose sensitive information, or execute arbitrary code.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">charx</span><span class="nt-tag">phoenix-contact</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="phoronix test suite panel - detect info identify web-based control panels phoronix test suite panel was detected. pikpikcu panel phoronix phoronix-media discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Phoronix Test Suite Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/phoronix-pane.yaml" target="_blank" rel="noopener" class="nt-source-link">phoronix-pane.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pikpikcu</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)phoronix-test-suite&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Phoronix Test Suite panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">phoronix</span><span class="nt-tag">phoronix-media</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="photo gallery by 10web &lt; 1.6.0 - sql injection critical identify critical remote vulnerabilities the photo gallery by 10web wordpress plugin before 1.6.0 does not validate and escape the bwg_tag_id_bwg_thumbnails_0 parameter before using it in a sql statement via the bwg_frontend_data ajax action (available to unauthenticated and authenticated users), leading to an unauthenticated sql injection cve-2022-0169 ritikchaddha,princechaddha 10web cve cve2022 photo-gallery sqli vkev vuln wordpress wp wp-plugin wpscan cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Photo Gallery by 10Web &lt; 1.6.0 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-0169.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-0169.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha,princechaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 2, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-0169" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-0169</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/photo-gallery&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The Photo Gallery by 10Web WordPress plugin before 1.6.0 does not validate and escape the bwg_tag_id_bwg_thumbnails_0 parameter before using it in a SQL statement via the bwg_frontend_data AJAX action (available to unauthenticated and authenticated users), leading to an unauthenticated SQL injection</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized access, data manipulation, or data leakage.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">This is resolved in release 1.6.0.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">10web</span><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">photo-gallery</span><span class="nt-tag">sqli</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">wpscan</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wpscan.com/vulnerability/0b4d870f-eab8-4544-91f8-9c5f0538709c" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://wordpress.org/plugins/photo-gallery/advanced/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-0169" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://plugins.trac.wordpress.org/changeset/2672822/photo-gallery#file9" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="photoprism panel - detect info identify web-based control panels photoprism is an ai-powered photos app for the decentralized web. this template detects the presence of photoprism login panel. rxerium,ritikchaddha photoprism panel login detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">PhotoPrism Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/photoprism-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">photoprism-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium,ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 13, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)PhotoPrism&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">PhotoPrism is an AI-powered photos app for the decentralized web. This template detects the presence of PhotoPrism login panel.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">photoprism</span><span class="nt-tag">panel</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://docs.photoprism.app/getting-started/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="phpmyadmin - unauthenticated access high identify critical remote vulnerabilities unauthenticated access to phpmyadmin dashboard. pwnhxl misconfig phpmyadmin unauth vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">PhpMyAdmin - Unauthenticated Access</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/vulnerabilities/phpmyadmin-unauth.yaml" target="_blank" rel="noopener" class="nt-source-link">phpmyadmin-unauth.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pwnhxl</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)server_databases\\.php&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Unauthenticated Access to phpmyadmin dashboard.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">misconfig</span><span class="nt-tag">phpmyadmin</span><span class="nt-tag">unauth</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.phpmyadmin.net" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="phpmyadmin &lt;4.8.2 - local file inclusion high identify critical remote vulnerabilities phpmyadmin before version 4.8.2 is susceptible to local file inclusion that allows an attacker to include (view and potentially execute) files on the server. the vulnerability comes from a portion of code where pages are redirected and loaded within phpmyadmin, and an improper test for whitelisted pages. an attacker must be authenticated, except in the &#34;$cfg[&#39;allowarbitraryserver&#39;] = true&#34; case (where an attacker can specify any host he/she is already in control of, and execute arbitrary code on phpmyadmin) and the &#34;$cfg[&#39;serverdefault&#39;] = 0&#34; case (which bypasses the login requirement and runs the vulnerable code without any authentication). cve-2018-12613 pikpikcu cve cve2018 edb lfi phpmyadmin vkev vulhub vuln cwe-287" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">PhpMyAdmin &lt;4.8.2 - Local File Inclusion</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2018/CVE-2018-12613.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2018-12613.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pikpikcu</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/287.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-287</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2018-12613" target="_blank" rel="noopener" class="nt-cve-link">CVE-2018-12613</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)phpmyadmin&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">PhpMyAdmin before version 4.8.2 is susceptible to local file inclusion that allows an attacker to include (view and potentially execute) files on the server. The vulnerability comes from a portion of code where pages are redirected and loaded within phpMyAdmin, and an improper test for whitelisted pages. An attacker must be authenticated, except in the &#34;$cfg[&#39;AllowArbitraryServer&#39;] = true&#34; case (where an attacker can specify any host he/she is already in control of, and execute arbitrary code on phpMyAdmin) and the &#34;$cfg[&#39;ServerDefault&#39;] = 0&#34; case (which bypasses the login requirement and runs the vulnerable code without any authentication).</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can exploit this vulnerability to read arbitrary files on the server.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade PhpMyAdmin to version 4.8.2 or later to fix the vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2018</span><span class="nt-tag">edb</span><span class="nt-tag">lfi</span><span class="nt-tag">phpmyadmin</span><span class="nt-tag">vkev</span><span class="nt-tag">vulhub</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/vulhub/vulhub/tree/master/phpmyadmin/CVE-2018-12613" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.phpmyadmin.net/security/PMASA-2018-4/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.exploit-db.com/exploits/44928/" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2018-12613" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://security.gentoo.org/glsa/201904-16" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="phpmyadmin scripts - remote code execution high identify critical remote vulnerabilities phpmyadmin scripts 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 are susceptible to a remote code execution in setup.php that allows remote attackers to inject arbitrary php code into a configuration file via the save action. combined with the ability to save files on server, this can allow unauthenticated users to execute arbitrary php code. cve-2009-1151 princechaddha cve cve2009 deserialization kev phpmyadmin rce vkev vulhub vuln cwe-94" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">PhpMyAdmin Scripts - Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2009/CVE-2009-1151.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2009-1151.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> princechaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/94.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-94</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2009-1151" target="_blank" rel="noopener" class="nt-cve-link">CVE-2009-1151</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)phpmyadmin&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">PhpMyAdmin Scripts 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 are susceptible to a remote code execution in setup.php that allows remote attackers to inject arbitrary PHP code into a configuration file via the save action. Combined with the ability to save files on server, this can allow unauthenticated users to execute arbitrary PHP code.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability can lead to unauthorized access, data leakage, and potential compromise of the affected system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update PhpMyAdmin to the latest version or apply the necessary patches.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2009</span><span class="nt-tag">deserialization</span><span class="nt-tag">kev</span><span class="nt-tag">phpmyadmin</span><span class="nt-tag">rce</span><span class="nt-tag">vkev</span><span class="nt-tag">vulhub</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.phpmyadmin.net/security/PMASA-2009-3/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/vulhub/vulhub/tree/master/phpmyadmin/WooYun-2016-199433" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="http://phpmyadmin.svn.sourceforge.net/viewvc/phpmyadmin/branches/MAINT_2_11_9/phpMyAdmin/scripts/setup.php?r1=11514&amp;r2=12301&amp;pathrev=12301" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="http://www.phpmyadmin.net/home_page/security/PMASA-2009-3.php" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2009-1151" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="pichome 2.1.0 - arbitrary file read high identify critical remote vulnerabilities a vulnerability, which was classified as critical, was found in zyx0814 pichome 2.1.0. this affects an unknown part of the file /index.php?mod=textviewer. the manipulation of the argument src leads to path traversal. it is possible to initiate the attack remotely. the exploit has been disclosed to the public and may be used. cve-2025-1743 3th1c_yuk1 cve cve2025 lfi pichome vkev vuln zyx0814 cwe-22" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Pichome 2.1.0 - Arbitrary File Read</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-1743.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-1743.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 3th1c_yuk1</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 15, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-1743" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-1743</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)PicHome&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A vulnerability, which was classified as critical, was found in zyx0814 Pichome 2.1.0. This affects an unknown part of the file /index.php?mod=textviewer. The manipulation of the argument src leads to path traversal. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can read arbitrary files from the server through path traversal in the src parameter, potentially exposing sensitive configuration files, credentials, and user data.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to Pichome version 2.1.1 or later that properly validates file paths.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">lfi</span><span class="nt-tag">pichome</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">zyx0814</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/sheratan4/cve/issues/4" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-1743" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="pichome login panel - detect info identify web-based control panels pichome login panel was detected. ritikchaddha discovery panel pichome cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Pichome Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/pichome-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">pichome-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;933976300&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Pichome login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">pichome</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="pimcore admin login - panel detect info identify web-based control panels pimcore admin login interface was discovered. th3l0newolf admin discovery login panel pimcore cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Pimcore Admin Login - Panel Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/pimcore-admin-login-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">pimcore-admin-login-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Th3l0newolf</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 19, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Welcome to Pimcore!&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Pimcore admin login interface was discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">admin</span><span class="nt-tag">discovery</span><span class="nt-tag">login</span><span class="nt-tag">panel</span><span class="nt-tag">pimcore</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="piwigo - user enumeration via password reset medium identify critical remote vulnerabilities piwigo is an open source photo gallery application for the web. in version 15.5.0 and likely earlier 15.x releases, the password reset functionality in piwigo allows an unauthenticated attacker to determine whether a given username or email address exists in the system. the endpoint at password.php?action=lost returns distinct messages for valid vs. invalid accounts, enabling user enumeration. as of time of publication, no known patches are available. cve-2025-62512 dhiyaneshdk cve cve2025 exposure piwigo user-enum cwe-204" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Piwigo - User Enumeration via Password Reset</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-62512.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-62512.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 24, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/204.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-204</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-62512" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-62512</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Piwigo&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Piwigo is an open source photo gallery application for the web. In version 15.5.0 and likely earlier 15.x releases, the password reset functionality in Piwigo allows an unauthenticated attacker to determine whether a given username or email address exists in the system. The endpoint at password.php?action=lost returns distinct messages for valid vs. invalid accounts, enabling user enumeration. As of time of publication, no known patches are available.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can enumerate valid usernames or email addresses, aiding further targeted attacks.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest version when available or apply mitigations to unify response messages.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">exposure</span><span class="nt-tag">piwigo</span><span class="nt-tag">user-enum</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/Piwigo/Piwigo/security/advisories/GHSA-h4wx-7m83-xfxc" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="piwigo login panel - detect info identify web-based control panels piwigo login panel was detected. daffainfo detect discovery panel piwigo cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Piwigo Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/piwigo-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">piwigo-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> daffainfo</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;540706145&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Piwigo login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">piwigo</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="planet estream login panel - detect info identify web-based control panels planet estream login panel was detected. arafatansari discovery estream panel planet planetestream cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Planet eStream Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/planet-estream-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">planet-estream-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> arafatansari</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)login - planet estream&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Planet eStream login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">estream</span><span class="nt-tag">panel</span><span class="nt-tag">planet</span><span class="nt-tag">planetestream</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="plausible panel - detect info identify web-based control panels plausible is intuitive, lightweight and open source web analytics. rxerium panel plausible detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Plausible Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/plausible-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">plausible-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 27, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Plausible&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Plausible is intuitive, lightweight and open source web analytics.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">plausible</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://plausible.io/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/plausible/analytics" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="plesk end-of-life - detect info identify web-based control panels detected plesk versions that have reached end-of-life (eol) and no longer receive security updates. shivam kamboj tech plesk eol" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Plesk End-of-Life - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/technologies/eol/plesk-eol.yaml" target="_blank" rel="noopener" class="nt-source-link">plesk-eol.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Shivam Kamboj</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 2, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.head.xPoweredByPlesk&#34;] != &#34;&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detected Plesk versions that have reached End-of-Life (EOL) and no longer receive security updates.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">tech</span><span class="nt-tag">plesk</span><span class="nt-tag">eol</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://endoflife.date/plesk" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://docs.plesk.com/release-notes/obsidian/change-log/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="plesk login panel - detect info identify web-based control panels plesk login panel was detected. dhiyaneshdk,daffainfo,righettod discovery edb login panel plesk cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Plesk Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/plesk-onyx-login.yaml" target="_blank" rel="noopener" class="nt-source-link">plesk-onyx-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDK,daffainfo,righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)plesk onyx&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Plesk login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">edb</span><span class="nt-tag">login</span><span class="nt-tag">panel</span><span class="nt-tag">plesk</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.exploit-db.com/ghdb/6501" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.plesk.com/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="plesk obsidian login panel - detect info identify web-based control panels plesk obsidian login panel was detected. dhiyaneshdk,daffainfo discovery edb login panel plesk cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Plesk Obsidian Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/plesk-obsidian-login.yaml" target="_blank" rel="noopener" class="nt-source-link">plesk-obsidian-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDK,daffainfo</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)plesk obsidian&#34; || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)plesk obsidian&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Plesk Obsidian login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">edb</span><span class="nt-tag">login</span><span class="nt-tag">panel</span><span class="nt-tag">plesk</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="pocketbase panel - detect info identify web-based control panels pocketbase login panel was discovered. userdehghani panel pocketbase login detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">PocketBase Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/pocketbase-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">pocketbase-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> userdehghani</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 13, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;981081715&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">PocketBase Login panel was discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">pocketbase</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://pocketbase.io/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://pocketbase.io/docs/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="polarion siemens login - panel info identify web-based control panels detects the exposed polarion siemens login page. th3l0newolf polarion siemens login panel detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Polarion Siemens Login - Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/polarion-siemens-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">polarion-siemens-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Th3l0newolf</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 17, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-1135703796&#34; || service[&#34;favicon.ico.image.mmh3&#34;] == &#34;707299418&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detects the exposed Polarion Siemens login page.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">polarion</span><span class="nt-tag">siemens</span><span class="nt-tag">login</span><span class="nt-tag">panel</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://polarion.plm.automation.siemens.com/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="polycom hdx - web interface exposure low identify web-based control panels detecetd polycom hdx video conferencing system web interface, potentially allowing unauthorized access to device configuration and video calls. 0x_akoko exposure hdx iot polycom video-conferencing cwe-200" data-nt-sev="low">
  <div class="nt-card-header">
    <div class="nt-title">Polycom HDX - Web Interface Exposure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/polycom-hdx-web-exposure.yaml" target="_blank" rel="noopener" class="nt-source-link">polycom-hdx-web-exposure.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_Akoko</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 16, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Polycom HDX&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detecetd Polycom HDX video conferencing system web interface, potentially allowing unauthorized access to device configuration and video calls.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">exposure</span><span class="nt-tag">hdx</span><span class="nt-tag">iot</span><span class="nt-tag">polycom</span><span class="nt-tag">video-conferencing</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.polycom.com/products-services/hd-telepresence-video-conferencing.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://support.polycom.com/content/support/north-america/usa/en/support/video.html" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="polynote panel - detect info identify web-based control panels polynote is a polyglot notebook supporting scala, python, sql, and spark with a rich ui rxerium detect discovery notebook panel polynote python scala" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Polynote Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/polynote-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">polynote-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 27, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;^Polynote&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Polynote is a polyglot notebook supporting Scala, Python, SQL, and Spark with a rich UI</div></div></div>
  <div class="nt-tags"><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">notebook</span><span class="nt-tag">panel</span><span class="nt-tag">polynote</span><span class="nt-tag">python</span><span class="nt-tag">scala</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/polynote/polynote" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://polynote.org" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="popup-maker &lt; 1.8.12 - broken authentication critical identify critical remote vulnerabilities an issue was discovered in the popup maker plugin before 1.8.13 for wordpress. an unauthenticated attacker can partially control the arguments of the do_action function to invoke certain popmake_ or pum_ methods, as demonstrated by controlling content and delivery of popmake-system-info.txt (aka the &#34;support debug text file&#34;). cve-2019-17574 dhiyaneshdk auth-bypass code-atlantic cve cve2019 disclosure popup-maker vkev vuln wordpress wp wp-plugin wpscan cwe-639" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Popup-Maker &lt; 1.8.12 - Broken Authentication</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2019/CVE-2019-17574.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2019-17574.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 12, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/639.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-639</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2019-17574" target="_blank" rel="noopener" class="nt-cve-link">CVE-2019-17574</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/popup-maker/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An issue was discovered in the Popup Maker plugin before 1.8.13 for WordPress. An unauthenticated attacker can partially control the arguments of the do_action function to invoke certain popmake_ or pum_ methods, as demonstrated by controlling content and delivery of popmake-system-info.txt (aka the &#34;support debug text file&#34;).</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can gain administrative access to the WordPress site.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update Popup-Maker plugin to version 1.8.12 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">code-atlantic</span><span class="nt-tag">cve</span><span class="nt-tag">cve2019</span><span class="nt-tag">disclosure</span><span class="nt-tag">popup-maker</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">wpscan</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wpscan.com/vulnerability/9907" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://web.archive.org/web/20191128065954/https://blog.redyops.com/wordpress-plugin-popup-maker/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2019-17574" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/PopupMaker/Popup-Maker/blob/master/CHANGELOG.md" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://wpvulndb.com/vulnerabilities/9907" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="portainer - init deploy discovery medium identify critical remote vulnerabilities portainer initialization deployment files were discovered. princechaddha portainer exposure docker devops disclosure vuln cwe-200" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Portainer - Init Deploy Discovery</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/vulnerabilities/portainer-init-deploy.yaml" target="_blank" rel="noopener" class="nt-source-link">portainer-init-deploy.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> princechaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Portainer&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Portainer initialization deployment files were discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">portainer</span><span class="nt-tag">exposure</span><span class="nt-tag">docker</span><span class="nt-tag">devops</span><span class="nt-tag">disclosure</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://documentation.portainer.io/v2.0/deploy/initial/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="portainer login panel - detect info identify web-based control panels  ritikchaddha detect discovery panel portainer" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Portainer Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/portainer-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">portainer-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 9, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)portainer&#34;})</code></div>
  <div class="nt-tags"><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">portainer</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/portainer/portainer" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="portal do software publico brasileiro i3geo 7.0.5 - local file inclusion critical identify critical remote vulnerabilities portal do software publico brasileiro i3geo 7.0.5 is vulnerable to local file inclusion in the component codemirror.php, which allows attackers to execute arbitrary php code via a crafted http request. cve-2022-32409 pikpikcu cve cve2022 i3geo lfi softwarepublico vkev vuln cwe-22" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Portal do Software Publico Brasileiro i3geo 7.0.5 - Local File Inclusion</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-32409.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-32409.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pikpikcu</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-32409" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-32409</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)i3geo&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Portal do Software Publico Brasileiro i3geo 7.0.5 is vulnerable to local file inclusion in the component codemirror.php, which allows attackers to execute arbitrary PHP code via a crafted HTTP request.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can exploit this vulnerability to access sensitive information, such as configuration files, credentials, or other sensitive data stored on the server.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest patch or upgrade to a newer version of i3geo to fix the LFI vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">i3geo</span><span class="nt-tag">lfi</span><span class="nt-tag">softwarepublico</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/wagnerdracha/ProofOfConcept/blob/main/i3geo_proof_of_concept.txt" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://owasp.org/www-project-web-security-testing-guide/v42/4-Web_Application_Security_Testing/07-Input_Validation_Testing/11.1-Testing_for_Local_File_Inclusion" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-32409" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/ARPSyndicate/cvemon" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/ARPSyndicate/kenzer-templates" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="post grid &lt;= 2.2.50 - information exposure via rest api high identify critical remote vulnerabilities exposure of sensitive information to an unauthorized actor vulnerability in pickplugins post grid combo – 36+ gutenberg blocks.this issue affects post grid combo – 36+ gutenberg blocks: from n/a through 2.2.50. cve-2023-40211 daffainfo cve cve2023 pickplugins post-grid vkev wordpress wp wp-plugin cwe-200" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Post Grid &lt;= 2.2.50 - Information Exposure via REST API</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-40211.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-40211.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> daffainfo</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 30, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-40211" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-40211</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/post-grid-combo/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Exposure of Sensitive Information to an Unauthorized Actor vulnerability in PickPlugins Post Grid Combo – 36+ Gutenberg Blocks.This issue affects Post Grid Combo – 36+ Gutenberg Blocks: from n/a through 2.2.50.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthorized actors can access sensitive information, leading to privacy breaches and potential misuse of data.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest version beyond 2.2.50 or apply available security patches.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">pickplugins</span><span class="nt-tag">post-grid</span><span class="nt-tag">vkev</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://patchstack.com/database/vulnerability/post-grid/wordpress-post-grid-combo-plugin-2-2-50-sensitive-data-exposure-vulnerability?_s_id=cve" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://plugins.trac.wordpress.org/changeset/2947951/post-grid/trunk/src/functions-rest.php" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-40211" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="posthog login panel - detect info identify web-based control panels posthog login panel was detected. theabhinavgaur panel posthog discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">PostHog Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/posthog-admin-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">posthog-admin-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> theabhinavgaur</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)posthog&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">PostHog login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">posthog</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="poste.io admin panel - detect info identify web-based control panels poste.io login panel was detected. ritikchaddha panel poste login detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Poste.io Admin Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/posteio-admin-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">posteio-admin-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 12, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Administration login&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Poste.io login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">poste</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="powerchute network shutdown panel - detect info identify web-based control panels  dhiyaneshdk panel login powerchute detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">PowerChute Network Shutdown Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/powerchute-network-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">powerchute-network-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 11, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)PowerChute Network Shutdown&#34;</code></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">login</span><span class="nt-tag">powerchute</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="powercom network manager info identify web-based control panels  pussycat0x powercommanager login panel discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">PowerCom Network Manager</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/powercom-network-manager.yaml" target="_blank" rel="noopener" class="nt-source-link">powercom-network-manager.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)PowerCom Network Manager&#34;})</code></div>
  <div class="nt-tags"><span class="nt-tag">powercommanager</span><span class="nt-tag">login</span><span class="nt-tag">panel</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="powerjob - default login high identify default logins in web-based control panels powerjob default login credentials were discovered. j4vaovo powerjob default-login vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">PowerJob - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/powerjob-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">powerjob-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> j4vaovo</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;PowerJob&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">PowerJob default login credentials were discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">powerjob</span><span class="nt-tag">default-login</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.yuque.com/powerjob/guidence/trial" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="powerjob &lt;=4.3.2 - unauthenticated access medium identify critical remote vulnerabilities powerjob v4.3.1 is vulnerable to insecure permissions. via the list job interface. cve-2023-29923 for3stco1d cve cve2023 powerjob unauth vuln cwe-276" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">PowerJob &lt;=4.3.2 - Unauthenticated Access</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-29923.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-29923.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> For3stCo1d</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 14, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/276.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-276</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-29923" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-29923</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)powerjob&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">PowerJob V4.3.1 is vulnerable to Insecure Permissions. via the list job interface.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can exploit this vulnerability to gain unauthorized access to sensitive information or perform malicious actions.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade PowerJob to a version higher than 4.3.2 or apply the necessary patches to fix the authentication bypass issue.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">powerjob</span><span class="nt-tag">unauth</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/PowerJob/PowerJob/issues/587" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-29923" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/KayCHENvip/vulnerability-poc" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/Le1a/CVE-2023-29923" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/Threekiii/Awesome-POC" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="powerjob list - authorization bypass medium identify critical remote vulnerabilities powerjob = 5.1.2 contains a broken access control caused by missing authorization in /user/list function, letting remote attackers access unauthorized resources, exploit requires no special privileges. cve-2025-11580 dhiyaneshdk cve cve2025 powerjob auth-bypass oss cwe-862,cwe-863" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">PowerJob List - Authorization Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-11580.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-11580.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 21, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/862,CWE-863.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-862,CWE-863</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-11580" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-11580</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)PowerJob&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">PowerJob = 5.1.2 contains a broken access control caused by missing authorization in /user/list function, letting remote attackers access unauthorized resources, exploit requires no special privileges.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Remote attackers can access unauthorized resources, potentially leading to data exposure or privilege escalation.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest version beyond 5.1.2.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">powerjob</span><span class="nt-tag">auth-bypass</span><span class="nt-tag">oss</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/PowerJob/PowerJob/issues/1127" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-11580" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="powerjob login panel - detect info identify web-based control panels powerjob login panel was detected. pikpikcu discovery panel powerjob cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">PowerJob Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/powerjob-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">powerjob-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pikpikcu</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)PowerJob&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">PowerJob login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">powerjob</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="powershell universal - default login high identify default logins in web-based control panels powershell universal default admin credentials were discovered. ap3r default-login powershell-universal vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">PowerShell Universal - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/powershell/powershell-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">powershell-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ap3r</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 17, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;PowerShell Universal&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">PowerShell Universal default admin credentials were discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">powershell-universal</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://ironmansoftware.com/powershell-universal" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="powertek firmware &lt;3.30.30 - authorization bypass high identify critical remote vulnerabilities powertek firmware (multiple brands) before 3.30.30 running power distribution units are vulnerable to authorization bypass in the web interface. to exploit the vulnerability, an attacker must send an http packet to the data retrieval interface (/cgi/get_param.cgi) with the tmptoken cookie set to an empty string followed by a semicolon. this bypasses an active session authorization check. this can be then used to fetch the values of protected sys.passwd and sys.su.name fields that contain the username and password in cleartext. cve-2022-33174 pikpikcu auth-bypass cve cve2022 powertek powertekpdus vuln cwe-863" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Powertek Firmware &lt;3.30.30 - Authorization Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-33174.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-33174.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pikpikcu</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/863.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-863</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-33174" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-33174</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)powertek&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Powertek firmware (multiple brands) before 3.30.30 running Power Distribution Units are vulnerable to authorization bypass in the web interface. To exploit the vulnerability, an attacker must send an HTTP packet to the data retrieval interface (/cgi/get_param.cgi) with the tmpToken cookie set to an empty string followed by a semicolon. This bypasses an active session authorization check. This can be then used to fetch the values of protected sys.passwd and sys.su.name fields that contain the username and password in cleartext.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can bypass authentication and gain unauthorized access to the Powertek Firmware, potentially leading to further compromise of the system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade the Powertek Firmware to version 3.30.30 or higher to mitigate the vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">powertek</span><span class="nt-tag">powertekpdus</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://gynvael.coldwind.pl/?lang=en&amp;id=748" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-33174" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/Henry4E36/CVE-2022-33174" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/k0mi-tg/CVE-POC" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/nomi-sec/PoC-in-GitHub" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="pre-auth takeover of build pipelines in gocd high identify critical remote vulnerabilities gocd contains a critical information disclosure vulnerability whose exploitation allows unauthenticated attackers to leak configuration information including build secrets and encryption keys. cve-2021-43287 dhiyaneshdk cve cve2021 go gocd lfi thoughtworks vkev vuln cwe-200" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Pre-Auth Takeover of Build Pipelines in GoCD</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2021/CVE-2021-43287.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2021-43287.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2021-43287" target="_blank" rel="noopener" class="nt-cve-link">CVE-2021-43287</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Create a pipeline - Go\&#34; html:\&#34;GoCD Version&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">GoCD contains a critical information disclosure vulnerability whose exploitation allows unauthenticated attackers to leak configuration information including build secrets and encryption keys.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability can lead to unauthorized access and control over the build pipelines, potentially resulting in the execution of arbitrary code or unauthorized modifications.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to version v21.3.0. or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2021</span><span class="nt-tag">go</span><span class="nt-tag">gocd</span><span class="nt-tag">lfi</span><span class="nt-tag">thoughtworks</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://attackerkb.com/assessments/9101a539-4c6e-4638-a2ec-12080b7e3b50" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://blog.sonarsource.com/gocd-pre-auth-pipeline-takeover" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://twitter.com/wvuuuuuuuuuuuuu/status/1456316586831323140" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://www.gocd.org/releases/#21-3-0" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/gocd/gocd/commit/41abc210ac4e8cfa184483c9ff1c0cc04fb3511c" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="prestashop &lt; 1.7.6.6 - information exposure via upload directory low identify critical remote vulnerabilities prestashop versions after 1.5.0.0 and before 1.7.6.6 are vulnerable to information exposure through directory listing in the upload directory due to a missing index.php file. cve-2020-15081 0x_akoko cve cve2020 directory-listing exposure prestashop cwe-548" data-nt-sev="low">
  <div class="nt-card-header">
    <div class="nt-title">PrestaShop &lt; 1.7.6.6 - Information Exposure via Upload Directory</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2020/CVE-2020-15081.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2020-15081.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_Akoko</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 20, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/548.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-548</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2020-15081" target="_blank" rel="noopener" class="nt-cve-link">CVE-2020-15081</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;product&#34;] contains &#34;PrestaShop:PrestaShop&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">PrestaShop versions after 1.5.0.0 and before 1.7.6.6 are vulnerable to information exposure through directory listing in the upload directory due to a missing index.php file.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can enumerate uploaded files potentially exposing sensitive customer data, invoices, or internal documents.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to PrestaShop version 1.7.6.6 or later, or add an empty index.php file in the upload directory as a workaround.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2020</span><span class="nt-tag">directory-listing</span><span class="nt-tag">exposure</span><span class="nt-tag">prestashop</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15081" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/PrestaShop/PrestaShop/security/advisories/GHSA-997j-f42g-x57c" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/PrestaShop/PrestaShop/commit/bac9ea6936b073f84b1abd9864317af3713f1901" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="prestashop theme volty cms blog - sql injection critical identify critical remote vulnerabilities in the module &#39;theme volty cms blog&#39; (tvcmsblog) up to versions 4.0.1 from theme volty for prestashop, a guest can perform sql injection in affected versions. cve-2023-39650 mastercho cve cve2023 prestashop sqli time-based-sqli tvcmsblog vuln cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">PrestaShop Theme Volty CMS Blog - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-39650.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-39650.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> mastercho</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 14, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-39650" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-39650</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/tvcmsblog&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">In the module &#39;Theme Volty CMS Blog&#39; (tvcmsblog) up to versions 4.0.1 from Theme Volty for PrestaShop, a guest can perform SQL injection in affected versions.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized accessand data leakage.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches and updates from the vendor to address this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">prestashop</span><span class="nt-tag">sqli</span><span class="nt-tag">time-based-sqli</span><span class="nt-tag">tvcmsblog</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://security.friendsofpresta.org/modules/2023/08/24/tvcmsblog.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-39650" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="prestashop `tshirtecommerce` module - sql injection critical identify critical remote vulnerabilities the tshirtecommerce module for prestashop is vulnerable to unauthenticated sql injection via the designer endpoint, allowing attackers to execute arbitrary sql queries and extract sensitive information from the database. cve-2023-27637 ritikchaddha cve cve2023 prestashop sqli time-based-sqli tshirtecommerce vkev vuln cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">PrestaShop `tshirtecommerce` Module - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-27637.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-27637.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 29, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-27637" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-27637</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Prestashop&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The tshirtecommerce module for PrestaShop is vulnerable to unauthenticated SQL injection via the designer endpoint, allowing attackers to execute arbitrary SQL queries and extract sensitive information from the database.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can execute time-based SQL injection through the parent_id parameter in the designer endpoint to extract the complete PrestaShop database including user credentials and order data.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update the tshirtecommerce module to the latest version and apply all security patches.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">prestashop</span><span class="nt-tag">sqli</span><span class="nt-tag">time-based-sqli</span><span class="nt-tag">tshirtecommerce</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://security.friendsofpresta.org/module/2023/03/21/tshirtecommerce_cwe-89.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-27637" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://codecanyon.net/item/prestashop-custom-product-designer/19202018" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://tshirtecommerce.com/" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="prestashop fieldpopupnewsletter module - cross site scripting medium identify critical remote vulnerabilities fieldpopupnewsletter prestashop module v1.0.0 was discovered to contain a reflected cross-site scripting (xss) vulnerability via the callback parameter at ajax.php. cve-2023-39676 meme-lord cve cve2023 fieldthemes prestashop vuln xss cwe-79" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">PrestaShop fieldpopupnewsletter Module - Cross Site Scripting</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-39676.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-39676.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> meme-lord</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 7, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-79</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-39676" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-39676</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)fieldpopupnewsletter&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Fieldpopupnewsletter Prestashop Module v1.0.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the callback parameter at ajax.php.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to inject malicious scripts into the affected website, leading to potential theft of sensitive information, session hijacking, or defacement.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches and updates from the vendor to address this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">fieldthemes</span><span class="nt-tag">prestashop</span><span class="nt-tag">vuln</span><span class="nt-tag">xss</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://blog.sorcery.ie/posts/fieldpopupnewsletter_xss/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://sorcery.ie" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://themeforest.net/user/fieldthemes" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="prestashop productsalert - sql injection critical identify critical remote vulnerabilities in the module &#39;products alert&#39; (productsalert) up to version 1.7.4 from smart modules for prestashop, a guest can perform sql injection in affected versions. cve-2024-36683 mastercho cve cve2024 prestashop productsalert sqli time-based-sqli vuln cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">PrestaShop productsalert - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-36683.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-36683.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> mastercho</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 14, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-36683" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-36683</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/productsalert&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">In the module &#39;Products Alert&#39; (productsalert) up to version 1.7.4 from Smart Modules for PrestaShop, a guest can perform SQL injection in affected versions.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized accessand data leakage.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches and updates from the vendor to address this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">prestashop</span><span class="nt-tag">productsalert</span><span class="nt-tag">sqli</span><span class="nt-tag">time-based-sqli</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://security.friendsofpresta.org/modules/2024/06/20/productsalert.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-36683" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="prestashop xipblog - sql injection critical identify critical remote vulnerabilities in the blog module (xipblog), an anonymous user can perform sql injection. even though the module has been patched in version 2.0.1, the version number was not incremented at the time. cve-2023-27847 mastercho cve cve2023 prestashop sqli time-based-sqli vuln xipblog cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">PrestaShop xipblog - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-27847.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-27847.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> mastercho</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 14, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-27847" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-27847</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/xipblog&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">In the blog module (xipblog), an anonymous user can perform SQL injection. Even though the module has been patched in version 2.0.1, the version number was not incremented at the time.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized access and data leakage.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches and updates from the vendor to address this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">prestashop</span><span class="nt-tag">sqli</span><span class="nt-tag">time-based-sqli</span><span class="nt-tag">vuln</span><span class="nt-tag">xipblog</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://security.friendsofpresta.org/modules/2023/03/23/xipblog.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-27847" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="prestashop posstaticfooter &lt;= 1.0.0 - sql injection critical identify critical remote vulnerabilities prestashop posstaticfooter &lt;= 1.0.0 is vulnerable to sql injection via posstaticfooter::getposcurrenthook(). cve-2023-30194 daffainfo cve cve2023 poststaticfooter prestashop sqli vkev vuln cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Prestashop posstaticfooter &lt;= 1.0.0 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-30194.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-30194.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> daffainfo</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 10, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-30194" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-30194</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)posstaticfooter&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Prestashop posstaticfooter &lt;= 1.0.0 is vulnerable to SQL Injection via posstaticfooter::getPosCurrentHook().</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can execute arbitrary SQL commands to extract database contents including customer data, orders, payment information, and administrative credentials from the PrestaShop database.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to the latest version of the posstaticfooter module from posthemes.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">poststaticfooter</span><span class="nt-tag">prestashop</span><span class="nt-tag">sqli</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://friends-of-presta.github.io/security-advisories/modules/2023/05/09/posstaticfooter.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://themeforest.net/user/posthemes/portfolio" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-30194" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="prettier - ignore file disclosure info identify critical remote vulnerabilities the .prettierignore file is publicly accessible, potentially revealing project structure, sensitive file paths, and internal directory organization. ritikchaddha prettier config exposure disclosure" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Prettier - Ignore File Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposures/configs/prettier-ignore-disclosure.yaml" target="_blank" rel="noopener" class="nt-source-link">prettier-ignore-disclosure.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 26, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)\\.prettierignore&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The .prettierignore file is publicly accessible, potentially revealing project structure, sensitive file paths, and internal directory organization.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">prettier</span><span class="nt-tag">config</span><span class="nt-tag">exposure</span><span class="nt-tag">disclosure</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://prettier.io/docs/en/ignore.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="prime mover &lt; 1.9.3 - sensitive data exposure high identify critical remote vulnerabilities prime mover plugin for wordpress is vulnerable to sensitive information exposure in all versions up to, and including, 1.9.2 via directory listing in the &#39;prime-mover-export-files/1/&#39; folder. this makes it possible for unauthenticated attackers to extract sensitive data including site and configuration information, directories, files, and password hashes. cve-2023-6505 s4e-io cve cve2023 exposure listing prime-mover vuln wordpress wp wp-plugin" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Prime Mover &lt; 1.9.3 - Sensitive Data Exposure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-6505.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-6505.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> s4e-io</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 10, 2024</span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-6505" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-6505</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/prime-mover&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Prime Mover plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.9.2 via directory listing in the &#39;prime-mover-export-files/1/&#39; folder. This makes it possible for unauthenticated attackers to extract sensitive data including site and configuration information, directories, files, and password hashes.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can exploit directory listing to access export files containing sensitive site configuration data, database information, and password hashes from WordPress Prime Mover installations.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Fixed in 1.9.3</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">exposure</span><span class="nt-tag">listing</span><span class="nt-tag">prime-mover</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wpscan.com/vulnerability/eca6f099-6af0-4f42-aade-ab61dd792629" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://research.cleantalk.org/cve-2023-6505-prime-mover-poc-exploit/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-6505" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="primetek primefaces 5.x - remote code execution critical identify critical remote vulnerabilities primetek primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution. cve-2017-1000486 moritz nentwig cve cve2017 injection kev primetek rce vkev vuln cwe-326" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Primetek Primefaces 5.x - Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2017/CVE-2017-1000486.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2017-1000486.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Moritz Nentwig</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/326.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-326</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2017-1000486" target="_blank" rel="noopener" class="nt-cve-link">CVE-2017-1000486</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;product&#34;] contains &#34;Primetek:Primefaces&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches or upgrade to a newer version of the Primetek Primefaces application.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2017</span><span class="nt-tag">injection</span><span class="nt-tag">kev</span><span class="nt-tag">primetek</span><span class="nt-tag">rce</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/mogwailabs/CVE-2017-1000486" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/pimps/CVE-2017-1000486" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://blog.mindedsecurity.com/2016/02/rce-in-oracle-netbeans-opensource.html" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2017-1000486" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://cryptosense.com/weak-encryption-flaw-in-primefaces/" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="prison management system - sql injection authentication bypass high identify critical remote vulnerabilities sql injection vulnerability was found on the login page in prison management system cve-2024-33288 s4e-io cve cve2024 cms sqli vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Prison Management System - SQL Injection Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-33288.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-33288.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> s4e-io</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 16, 2024</span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-33288" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-33288</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Prison Management System&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Sql injection vulnerability was found on the login page in Prison Management System</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can bypass authentication via SQL injection to gain unauthorized administrative access to the Prison Management System.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply security patches for Prison Management System addressing SQL injection vulnerabilities.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">cms</span><span class="nt-tag">sqli</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://en.0day.today/exploit/39610" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.sourcecodester.com/sql/17287/prison-management-system.html" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="pritunl - panel info identify web-based control panels realtime website and application monitoring tool irshad ahamed discovery login panel pritunl" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Pritunl - Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/pritunl-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">pritunl-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> irshad ahamed</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 1, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Pritunl&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Realtime website and application monitoring tool</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">login</span><span class="nt-tag">panel</span><span class="nt-tag">pritunl</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/louislam/uptime-kuma" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://uptime.kuma.pet/docs/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="privategpt - detect info identify web-based control panels privategpt panel has been detected. ritikchaddha ai detect discovery panel privategpt" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">PrivateGPT - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/privategpt-detect.yaml" target="_blank" rel="noopener" class="nt-source-link">privategpt-detect.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 16, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)private gpt&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">PrivateGPT panel has been detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">ai</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">privategpt</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/zylon-ai/private-gpt" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="proftpd mod_sql - preauth user backdoor high identify critical remote vulnerabilities proftpd mod_sql before 1.3.10rc1 contains a remote code execution caused by unsafe username handling with sql backend commands in user request logging expansions, letting remote attackers execute arbitrary code, exploit requires sql backend allowing commands. cve-2026-42167 pussycat0x cve cve2026 ftp network proftpd rce sqli vkev cwe-89" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">ProFTPD mod_sql - Preauth User Backdoor</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/network/cves/2026/CVE-2026-42167.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2026-42167.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 4, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2026-42167" target="_blank" rel="noopener" class="nt-cve-link">CVE-2026-42167</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;protocol&#34;] contains &#34;ftp&#34; and service[&#34;service.transport&#34;] contains &#34;tcp&#34; and service[&#34;banner&#34;] matches &#34;(?i)ProFTPd&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">ProFTPD mod_sql before 1.3.10rc1 contains a remote code execution caused by unsafe username handling with SQL backend commands in USER request logging expansions, letting remote attackers execute arbitrary code, exploit requires SQL backend allowing commands.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Remote attackers can execute arbitrary code on the server, potentially leading to full system compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to version 1.3.10rc1 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2026</span><span class="nt-tag">ftp</span><span class="nt-tag">network</span><span class="nt-tag">proftpd</span><span class="nt-tag">rce</span><span class="nt-tag">sqli</span><span class="nt-tag">vkev</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/ZeroPathAI/proftpd-CVE-2026-42167-poc" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://zeropath.com/blog/proftpd-cve-2026-42167-auth-bypass-privesc-rce" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="processwire login - panel detect info identify web-based control panels processwire login panel was detected. ramkrishna sawant panel processwire discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">ProcessWire Login - Panel Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/processwire-login.yaml" target="_blank" rel="noopener" class="nt-source-link">processwire-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Ramkrishna Sawant</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)processwire&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">ProcessWire login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">processwire</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://processwire.com/docs/security/admin/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="procore login - panel info identify web-based control panels  rxerium panel login detect procore discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Procore Login - Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/procore-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">procore-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 14, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1952289652&#34;</code></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">procore</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="prodigy commerce &lt;= 3.3.0 - local file inclusion critical identify critical remote vulnerabilities prodigy commerce wordpress plugin &lt;= 3.2.9 contains a local file inclusion caused by improper sanitization of &#39;parameters[template_name]&#39; parameter, letting unauthenticated attackers include and execute arbitrary files remotely. cve-2026-0926 shivam kamboj cve cve2026 lfi prodigy-commerce unauth wordpress wp wp-plugin cwe-98" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Prodigy Commerce &lt;= 3.3.0 - Local File Inclusion</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2026/CVE-2026-0926.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2026-0926.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Shivam Kamboj</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 13, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/98.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-98</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2026-0926" target="_blank" rel="noopener" class="nt-cve-link">CVE-2026-0926</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/prodigy-commerce/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Prodigy Commerce WordPress plugin &lt;= 3.2.9 contains a local file inclusion caused by improper sanitization of &#39;parameters[template_name]&#39; parameter, letting unauthenticated attackers include and execute arbitrary files remotely.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can execute arbitrary PHP code, bypass access controls, and access sensitive data, potentially leading to full server compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest version beyond 3.2.9.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2026</span><span class="nt-tag">lfi</span><span class="nt-tag">prodigy-commerce</span><span class="nt-tag">unauth</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/prodigy-commerce/prodigy-commerce-329-unauthenticated-local-file-inclusion-via-parameterstemplate-name" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0926" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="profilegrid &lt;= 5.7.8 - sql injection critical identify critical remote vulnerabilities the profilegrid – user profiles, groups and communities plugin for wordpress is vulnerable to sql injection in versions up to, and including, 5.7.8 due to insufficient escaping on the user supplied &#39;search&#39; parameter and lack of sufficient preparation on the existing sql query. cve-2024-30490 shivam kamboj cve cve2024 wordpress wp wp-plugin profilegrid sqli cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">ProfileGrid &lt;= 5.7.8 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-30490.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-30490.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Shivam Kamboj</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 30, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-30490" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-30490</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/profilegrid-user-profiles-groups-and-communities/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.7.8 due to insufficient escaping on the user supplied &#39;search&#39; parameter and lack of sufficient preparation on the existing SQL query.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can execute arbitrary SQL queries, potentially leading to data theft, data tampering, or database compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to ProfileGrid version 5.7.9 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">profilegrid</span><span class="nt-tag">sqli</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/profilegrid-user-profiles-groups-and-communities/profilegrid-578-unauthenticated-sql-injection" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://wordpress.org/plugins/profilegrid-user-profiles-groups-and-communities/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-30490" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="progress kemp loadmaster - command injection critical identify critical remote vulnerabilities unauthenticated remote attackers can access the system through the loadmaster management interface, enabling arbitrary system command execution. cve-2024-1212 dhiyaneshdk cve cve2024 kev loadmaster progress rce vkev vuln cwe-78" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Progress Kemp LoadMaster - Command Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-1212.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-1212.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 20, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/78.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-78</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-1212" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-1212</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)LoadMaster&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Unauthenticated remote attackers can access the system through the LoadMaster management interface, enabling arbitrary system command execution.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can execute arbitrary system commands through the LoadMaster management interface, leading to complete system compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to LoadMaster versions 7.2.59.2, 7.2.54.8, or 7.2.48.10 depending on your current version.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">kev</span><span class="nt-tag">loadmaster</span><span class="nt-tag">progress</span><span class="nt-tag">rce</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://rhinosecuritylabs.com/research/cve-2024-1212unauthenticated-command-injection-in-progress-kemp-loadmaster" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://support.kemptechnologies.com/hc/en-us/articles/23878931058445-LoadMaster-Security-Vulnerability-CVE-2024-1212" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://support.kemptechnologies.com/hc/en-us/articles/24325072850573-Release-Notice-LMOS-7-2-59-2-7-2-54-8-7-2-48-10-CVE-2024-1212" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-1212" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://freeloadbalancer.com/" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="progress kemp loadmaster panel - detect info identify web-based control panels a progress kemp loadmaster panel was detected. rxerium login progress kemp loadmaster panel detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Progress Kemp LoadMaster Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/kemp-loadmaster-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">kemp-loadmaster-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 10, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Kemp Login Screen&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A Progress Kemp LoadMaster panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">login</span><span class="nt-tag">progress</span><span class="nt-tag">kemp</span><span class="nt-tag">loadmaster</span><span class="nt-tag">panel</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://kemptechnologies.com/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="progress sharefile storage zones controller - authentication bypass critical identify critical remote vulnerabilities customer managed sharefile storage zones controller (szc) contains an authentication bypass (execution after redirect) that allows unauthenticated attackers to access restricted configuration pages. this leads to changing system configuration and potential remote code execution. cve-2026-2699 dhiyaneshdk auth-bypass cve cve2026 progress sharefile cwe-284" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Progress ShareFile Storage Zones Controller - Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2026/CVE-2026-2699.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2026-2699.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 8, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/284.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-284</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2026-2699" target="_blank" rel="noopener" class="nt-cve-link">CVE-2026-2699</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;product&#34;] contains &#34;Progress Software:ShareFile Storage Zones Controller&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Customer Managed ShareFile Storage Zones Controller (SZC) contains an authentication bypass (Execution After Redirect) that allows unauthenticated attackers to access restricted configuration pages. This leads to changing system configuration and potential remote code execution.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can change system configuration and potentially execute remote code, leading to full system compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update ShareFile Storage Zones Controller to version 5.12.4 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2026</span><span class="nt-tag">progress</span><span class="nt-tag">sharefile</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/watchtowrlabs/watchTowr-vs-Progress-ShareFile-CVE-2026-2699" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://labs.watchtowr.com/youre-not-supposed-to-sharefile-with-everyone-progress-sharefile-pre-auth-rce-chain-cve-2026-2699-cve-2026-2701/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://docs.sharefile.com/en-us/storage-zones-controller/5-0/security-vulnerability-feb26" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="project insight login panel - detect info identify web-based control panels project insight login panel was detected. dhiyaneshdk discovery edb helpproject panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Project Insight Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/project-insight-login.yaml" target="_blank" rel="noopener" class="nt-source-link">project-insight-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)project insight - login&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Project Insight login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">edb</span><span class="nt-tag">helpproject</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.exploit-db.com/ghdb/7413" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="projectsend login panel - detect info identify web-based control panels projectsend login panel was detected. idealphase panel projectsend edb discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">ProjectSend Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/projectsend-login.yaml" target="_blank" rel="noopener" class="nt-source-link">projectsend-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> idealphase</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)provided&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">ProjectSend login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">projectsend</span><span class="nt-tag">edb</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.exploit-db.com/ghdb/7380" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/projectsend/projectsend" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="proofpoint protection server panel - detect info identify web-based control panels proofpoint protection server panel was detected. johnk3r detect discovery login panel proofpoint cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Proofpoint Protection Server Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/proofpoint-protection-server-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">proofpoint-protection-server-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> johnk3r</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 15, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;942678640&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Proofpoint Protection Server panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">login</span><span class="nt-tag">panel</span><span class="nt-tag">proofpoint</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="protect wp admin &lt; 4.0 - unauthenticated protection bypass medium identify critical remote vulnerabilities the protect wp admin wordpress plugin before version 4.0 disclosed the url of the admin panel through the redirection of a crafted url, bypassing the protection offered. cve-2023-3139 popcorn94 cve cve2023 protect-wp-admin unauth vkev vuln wordpress wp-plugin wpscan cwe-601" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Protect WP Admin &lt; 4.0 - Unauthenticated Protection Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-3139.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-3139.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> popcorn94</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 16, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/601.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-601</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-3139" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-3139</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/protect-wp-admin&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The Protect WP Admin WordPress plugin before version 4.0 disclosed the URL of the admin panel through the redirection of a crafted URL, bypassing the protection offered.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can exploit URL redirection to discover the protected admin panel URL and bypass the protection mechanism offered by the plugin.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Fixed in 4.0 or later</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">protect-wp-admin</span><span class="nt-tag">unauth</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">wpscan</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wpscan.com/vulnerability/f8a29aee-19cd-4e62-b829-afc9107f69bd/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://magos-securitas.com/txt/CVE-2023-3139.txt" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="proxmox virtual environment login panel - detect info identify web-based control panels proxmox virtual environment login panel was detected. lum8rjack discovery login panel proxmox cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Proxmox Virtual Environment Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/proxmox-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">proxmox-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> lum8rjack</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;213144638&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Proxmox Virtual Environment login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">login</span><span class="nt-tag">panel</span><span class="nt-tag">proxmox</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.proxmox.com/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="pterodactyl panel - remote code execution critical identify critical remote vulnerabilities pterodactyl is a free, open-source game server management panel. using the /locales/locale.json with the locale and namespace query parameters, a malicious actor is able to execute arbitrary code without being authenticated. cve-2025-49132 darses cve cve2025 lfi pterodactyl rce vkev vuln cwe-20,cwe-94" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Pterodactyl Panel - Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-49132.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-49132.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> darses</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 21, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/20,CWE-94.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-20,CWE-94</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-49132" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-49132</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)pterodactyl&#34;}) || service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-456405319&#34; || service[&#34;favicon.ico.image.mmh3&#34;] == &#34;846001371&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Pterodactyl is a free, open-source game server management panel. Using the /locales/locale.json with the locale and namespace query parameters, a malicious actor is able to execute arbitrary code without being authenticated.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">With the ability to execute arbitrary code, this vulnerability can be exploited in an infinite number of ways. It could be used to gain access to the Panel&#39;s server, read credentials from the Panel&#39;s config (.env or otherwise), extract sensitive information from the database (such as user details [username, email, first and last name, hashed password, ip addresses, etc]), access files of servers managed by the panel, etc.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to Pterodactyl version 1.11.11+. There are no software workarounds for this vulnerability, but use of an external Web Application Firewall (WAF) could help mitigate this attack.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">lfi</span><span class="nt-tag">pterodactyl</span><span class="nt-tag">rce</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/pterodactyl/panel/security/advisories/GHSA-24wv-6c99-f843" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/pterodactyl/panel/commit/24c82b0e335fb5d7a844226b08abf9f176e592f0" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/pterodactyl/panel/releases/tag/v1.11.11" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="pterodactyl game server - panel info identify web-based control panels detects pterodactyl game server management panel. darses detect discovery oos panel pterodactyl" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Pterodactyl game server - Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/pterodactyl-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">pterodactyl-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> darses</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 21, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Pterodactyl&#34;}) || service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-456405319&#34; || service[&#34;favicon.ico.image.mmh3&#34;] == &#34;846001371&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detects Pterodactyl game server management panel.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">oos</span><span class="nt-tag">panel</span><span class="nt-tag">pterodactyl</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/pterodactyl/panel" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="pulsar admin console panel - detect info identify web-based control panels pulsar admin console panel was detected. ritikchaddha admin apache console discovery panel pulsar cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Pulsar Admin Console Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/pulsar-admin-console.yaml" target="_blank" rel="noopener" class="nt-source-link">pulsar-admin-console.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)pulsar admin console&#34;}) || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)pulsar admin ui&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Pulsar admin console panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">admin</span><span class="nt-tag">apache</span><span class="nt-tag">console</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">pulsar</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="pulsar admin ui panel - detect info identify web-based control panels pulsar admin ui panel was detected. ritikchaddha admin apache discovery panel pulsar pulsarui cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Pulsar Admin UI Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/pulsar-adminui-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">pulsar-adminui-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)pulsar admin ui&#34;}) || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)pulsar admin console&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Pulsar admin UI panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">admin</span><span class="nt-tag">apache</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">pulsar</span><span class="nt-tag">pulsarui</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="pulsar360 admin panel - detect info identify web-based control panels pulsar360 admin panel was detected. tess panel pulsar360 pulsar admin discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Pulsar360 Admin Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/pulsar360-admin-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">pulsar360-admin-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> tess</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Pulsar Admin&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Pulsar360 admin panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">pulsar360</span><span class="nt-tag">pulsar</span><span class="nt-tag">admin</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="pulse connect secure ssl vpn arbitrary file read critical identify critical remote vulnerabilities pulse secure pulse connect secure (pcs) 8.2 before 8.2r12.1, 8.3 before 8.3r7.1, and 9.0 before 9.0r3.4 all contain an arbitrary file reading vulnerability that could allow unauthenticated remote attackers to send a specially crafted uri to gain improper access. cve-2019-11510 organiccrap cve cve2019 ivanti kev lfi packetstorm pulsesecure vkev vuln cwe-22" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Pulse Connect Secure SSL VPN Arbitrary File Read</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2019/CVE-2019-11510.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2019-11510.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> organiccrap</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2019-11510" target="_blank" rel="noopener" class="nt-cve-link">CVE-2019-11510</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)welcome\\.cgi\\?p=logo&#34; || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)ivanti connect secure&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4 all contain an arbitrary file reading vulnerability that could allow unauthenticated remote attackers to send a specially crafted URI to gain improper access.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can access sensitive information stored on the system, potentially leading to further compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches and updates provided by Pulse Secure.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2019</span><span class="nt-tag">ivanti</span><span class="nt-tag">kev</span><span class="nt-tag">lfi</span><span class="nt-tag">packetstorm</span><span class="nt-tag">pulsesecure</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://blog.orange.tw/2019/09/attacking-ssl-vpn-part-3-golden-pulse-secure-rce-chain.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44101/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2019-11510" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="http://packetstormsecurity.com/files/154176/Pulse-Secure-SSL-VPN-8.1R15.1-8.2-8.3-9.0-Arbitrary-File-Disclosure.html" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="http://packetstormsecurity.com/files/154231/Pulse-Secure-SSL-VPN-File-Disclosure-NSE.html" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="puppetboard panel - detect info identify web-based control panels puppetboard panel was detected. c-sh0,daffainfo panel puppet exposure discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Puppetboard Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/puppetboard-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">puppetboard-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> c-sh0,daffainfo</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Puppetboard&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Puppetboard panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">puppet</span><span class="nt-tag">exposure</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/voxpupuli/puppetboard" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="pure storage login panel - detect info identify web-based control panels pure storage login panel was detected. dhiyaneshdk discovery panel purestorage cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Pure Storage Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/pure-storage-login.yaml" target="_blank" rel="noopener" class="nt-source-link">pure-storage-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)pure storage login&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Pure Storage login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">purestorage</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="pyload default login high identify default logins in web-based control panels pyload default credentials were discovered. dhiyaneshdk default-login pyload vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">PyLoad Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/pyload/pyload-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">pyload-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 6, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)pyload&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">PyLoad Default Credentials were discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">pyload</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://pypi.org/project/pyload-ng/#:~:text=Default%20username%3A%20pyload%20.,Default%20password%3A%20pyload%20." target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="pyload login - panel info identify web-based control panels a pyload login was detected. dhiyaneshdk discovery login panel pyload" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">PyLoad Login - Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/pyload-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">pyload-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 6, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)login - pyload&#34;}) || service[&#34;http.body&#34;] matches &#34;(?i)pyload&#34; || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)pyload&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A Pyload Login was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">login</span><span class="nt-tag">panel</span><span class="nt-tag">pyload</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/pyload/pyload" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="python requirements file disclosure low identify critical remote vulnerabilities detected python requirements.txt file. this file contains python package dependencies and versions that could reveal technology stack, vulnerable package versions, and internal dependencies. 0x_akoko exposure python config misconfig cwe-538" data-nt-sev="low">
  <div class="nt-card-header">
    <div class="nt-title">Python Requirements File Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposures/files/python-requirements-disclosure.yaml" target="_blank" rel="noopener" class="nt-source-link">python-requirements-disclosure.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_Akoko</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 19, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/538.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-538</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)index of&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detected Python requirements.txt file. This file contains Python package dependencies and versions that could reveal technology stack, vulnerable package versions, and internal dependencies.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">exposure</span><span class="nt-tag">python</span><span class="nt-tag">config</span><span class="nt-tag">misconfig</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://pip.pypa.io/en/stable/reference/requirements-file-format/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="python setup configuration - exposure low identify critical remote vulnerabilities python setup configuration &#34;setup.py&#34; file was exposed. dhiyaneshdk python py misconfig vuln" data-nt-sev="low">
  <div class="nt-card-header">
    <div class="nt-title">Python Setup Configuration - Exposure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposures/configs/python-setup-config.yaml" target="_blank" rel="noopener" class="nt-source-link">python-setup-config.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 16, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)setup\\.py&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Python Setup Configuration &#34;setup.py&#34; File was exposed.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">python</span><span class="nt-tag">py</span><span class="nt-tag">misconfig</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.geeksforgeeks.org/python/what-is-setup-py-in-python/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="qnap hbs 3 - broken access control critical identify critical remote vulnerabilities an improper authorization vulnerability has been reported to affect qnap nas running hbs 3 (hybrid backup sync. ) if exploited, the vulnerability allows remote attackers to log in to a device. this issue affects: qnap systems inc. hbs 3 versions prior to v16.0.0415 on qts 4.5.2; versions prior to v3.0.210412 on qts 4.3.6; versions prior to v3.0.210411 on qts 4.3.4; versions prior to v3.0.210411 on qts 4.3.3; versions prior to v16.0.0419 on quts hero h4.5.1; versions prior to v16.0.0419 on qutscloud c4.5.1~c4.5.4. this issue does not affect: qnap systems inc. hbs 2 . qnap systems inc. hbs 1.3 . cve-2021-28799 daffainfo cve cve2021 hbs3 kev qnap qts qutshero rce vkev cwe-285" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">QNAP HBS 3 - Broken Access Control</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2021/CVE-2021-28799.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2021-28799.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> daffainfo</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 9, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/285.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-285</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2021-28799" target="_blank" rel="noopener" class="nt-cve-link">CVE-2021-28799</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">asset[&#34;hw&#34;] matches &#34;(?i)QNAP&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An improper authorization vulnerability has been reported to affect QNAP NAS running HBS 3 (Hybrid Backup Sync. ) If exploited, the vulnerability allows remote attackers to log in to a device. This issue affects: QNAP Systems Inc. HBS 3 versions prior to v16.0.0415 on QTS 4.5.2; versions prior to v3.0.210412 on QTS 4.3.6; versions prior to v3.0.210411 on QTS 4.3.4; versions prior to v3.0.210411 on QTS 4.3.3; versions prior to v16.0.0419 on QuTS hero h4.5.1; versions prior to v16.0.0419 on QuTScloud c4.5.1~c4.5.4. This issue does not affect: QNAP Systems Inc. HBS 2 . QNAP Systems Inc. HBS 1.3 .</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Remote attackers can log in without proper authorization, potentially leading to full system compromise or unauthorized data access.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest versions: v16.0.0415 or later for QTS 4.5.2, v3.0.210412 or later for QTS 4.3.6, v3.0.210411 or later for QTS 4.3.4 and 4.3.3, v16.0.0419 or later for QuTS hero h4.5.1, and v16.0.0419 or later for QuTScloud c4.5.1~c4.5.4.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2021</span><span class="nt-tag">hbs3</span><span class="nt-tag">kev</span><span class="nt-tag">qnap</span><span class="nt-tag">qts</span><span class="nt-tag">qutshero</span><span class="nt-tag">rce</span><span class="nt-tag">vkev</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.qnap.com/en/security-advisory/QSA-21-13" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://unit42.paloaltonetworks.com/ech0raix-ransomware-soho/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://gist.github.com/daniruiz/962ecca527b59954e619c5ae2cab680c" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2021-28799" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="qnap music station &lt; 5.4.0 - authentication bypass medium identify critical remote vulnerabilities an improper authentication vulnerability has been reported to affect music station. if exploited, the vulnerability could allow users to compromise the security of the system via a network. we have already fixed the vulnerability in the following version: music station 5.4.0 and later cve-2023-45038 daffainfo auth-bypass cve cve2023 music_station qnap vkev cwe-287" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">QNAP Music Station &lt; 5.4.0 - Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-45038.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-45038.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> daffainfo</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 2, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/287.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-287</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-45038" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-45038</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)qnap&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An improper authentication vulnerability has been reported to affect Music Station. If exploited, the vulnerability could allow users to compromise the security of the system via a network. We have already fixed the vulnerability in the following version: Music Station 5.4.0 and later</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can bypass authentication in Music Station to read arbitrary files from the QNAP system including /etc/passwd, potentially accessing sensitive configuration files and user credentials.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update QNAP Music Station to version 5.4.0 or later that implements proper authentication validation in the as_get_file_api.php endpoint.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">music_station</span><span class="nt-tag">qnap</span><span class="nt-tag">vkev</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.qnap.com/en/security-advisory/qsa-24-25" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://karzemrok.com/qnap-qsa-24-25" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-45038" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="qnap photo station - path traversal critical identify critical remote vulnerabilities qnap devices running photo station contain an external control of file name or path vulnerability allowing remote attackers to access or modify system files. cve-2019-7195 s4e-io cve cve2019 kev lfi qnap vkev vuln cwe-22" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">QNAP Photo Station - Path Traversal</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2019/CVE-2019-7195.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2019-7195.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> s4e-io</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 7, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2019-7195" target="_blank" rel="noopener" class="nt-cve-link">CVE-2019-7195</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)photo station&#34;}) || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)qnap&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">QNAP devices running Photo Station contain an external control of file name or path vulnerability allowing remote attackers to access or modify system files.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can exploit path traversal to access or modify system files, potentially reading sensitive configuration files and credentials.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to QNAP Photo Station version that addresses this vulnerability or apply vendor-provided patches.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2019</span><span class="nt-tag">kev</span><span class="nt-tag">lfi</span><span class="nt-tag">qnap</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://cycrafttechnology.medium.com/qnap-pre-auth-root-rce-affecting-312k-devices-on-the-internet-fc8af285622e" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://packetstorm.news/files/id/157857" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/cycraft-corp/cve-2019-7192-check" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/qazbnm456/awesome-cve-poc" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/th3gundy/CVE-2019-7192_QNAP_Exploit" target="_blank" rel="noopener" class="nt-ref-link">[5]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2019-7195" target="_blank" rel="noopener" class="nt-ref-link">[6]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="qnap photo station panel - detect info identify web-based control panels qnap photo station panel was detected. idealphase discovery panel photostation qnap cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">QNAP Photo Station Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/qnap/qnap-photostation-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">qnap-photostation-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> idealphase</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)photo station&#34;}) || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)qnap&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">QNAP Photo Station panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">photostation</span><span class="nt-tag">qnap</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.qnap.com/th-th/software/photo-station" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="qnap qts photo station external reference - local file inclusion critical identify critical remote vulnerabilities qnap qts photo station external reference is vulnerable to local file inclusion via an externally controlled reference to a resource vulnerability. if exploited, this could allow an attacker to modify system files. the vulnerability is fixed in the following versions: qts 5.0.1: photo station 6.1.2 and later qts 5.0.0/4.5.x: photo station 6.0.22 and later qts 4.3.6: photo station 5.7.18 and later qts 4.3.3: photo station 5.4.15 and later qts 4.2.6: photo station 5.2.14 and later. cve-2022-27593 allenwest24 cve cve2022 kev lfi qnap vkev vuln cwe-610" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">QNAP QTS Photo Station External Reference - Local File Inclusion</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-27593.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-27593.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> allenwest24</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/610.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-610</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-27593" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-27593</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)qnap&#34;}) || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)photo station&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">QNAP QTS Photo Station External Reference is vulnerable to local file inclusion via an externally controlled reference to a resource vulnerability. If exploited, this could allow an attacker to modify system files. The vulnerability is fixed in the following versions: QTS 5.0.1: Photo Station 6.1.2 and later QTS 5.0.0/4.5.x: Photo Station 6.0.22 and later QTS 4.3.6: Photo Station 5.7.18 and later QTS 4.3.3: Photo Station 5.4.15 and later QTS 4.2.6: Photo Station 5.2.14 and later.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can exploit this vulnerability to read sensitive files, execute arbitrary code, or launch further attacks.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches and updates provided by QNAP to fix the local file inclusion vulnerability in QTS Photo Station.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">kev</span><span class="nt-tag">lfi</span><span class="nt-tag">qnap</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://attackerkb.com/topics/7We3SjEYVo/cve-2022-27593" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.qnap.com/en/security-advisory/qsa-22-24" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-27593" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/20142995/sectool" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/ARPSyndicate/cvemon" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="qnap qts and photo station 6.0.3 - remote command execution critical identify critical remote vulnerabilities this improper access control vulnerability allows remote attackers to gain unauthorized access to the system. to fix these vulnerabilities, qnap recommend updating photo station to their latest versions. cve-2019-7192 dhiyaneshdk cve cve2019 kev lfi packetstorm qnap qts rce vkev vuln xss cwe-863" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">QNAP QTS and Photo Station 6.0.3 - Remote Command Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2019/CVE-2019-7192.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2019-7192.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 4, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/863.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-863</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2019-7192" target="_blank" rel="noopener" class="nt-cve-link">CVE-2019-7192</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)photo station&#34;}) || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)qnap&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">This improper access control vulnerability allows remote attackers to gain unauthorized access to the system. To fix these vulnerabilities, QNAP recommend updating Photo Station to their latest versions.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability allows remote attackers to execute arbitrary commands on the target system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patch or upgrade to a non-vulnerable version of QNAP QTS and Photo Station.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2019</span><span class="nt-tag">kev</span><span class="nt-tag">lfi</span><span class="nt-tag">packetstorm</span><span class="nt-tag">qnap</span><span class="nt-tag">qts</span><span class="nt-tag">rce</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">xss</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2019-7192" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://packetstormsecurity.com/files/157857/QNAP-QTS-And-Photo-Station-6.0.3-Remote-Command-Execution.html" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://patchstack.com/database/vulnerability/all-in-one-wp-migration/wordpress-all-in-one-wp-migration-plugin-7-62-unauthenticated-reflected-cross-site-scripting-xss-vulnerability" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-2546" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://medium.com/@cycraft_corp/qnap-pre-auth-root-rce-affecting-312k-devices-on-the-internet-fc8af285622e" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="qnap turbo nas login panel - detect info identify web-based control panels qnap qts login panel was detected. idealphase,daffainfo discovery panel qnap qts cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">QNAP Turbo NAS Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/qnap/qnap-qts-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">qnap-qts-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> idealphase,daffainfo</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)qnap turbo nas&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">QNAP QTS login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">qnap</span><span class="nt-tag">qts</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.qnap.com/qts/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="qlik sense enterprise - http request smuggling critical identify critical remote vulnerabilities an http request tunneling vulnerability found in qlik sense enterprise for windows for versions may 2023 patch 3 and earlier, february 2023 patch 7 and earlier, november 2022 patch 10 and earlier, and august 2022 patch 12 and earlier allows a remote attacker to elevate their privilege by tunneling http requests in the raw http request. this allows them to send requests that get executed by the backend server hosting the repository application. this is fixed in august 2023 ir, may 2023 patch 4, february 2023 patch 8, november 2022 patch 11, and august 2022 patch 13. cve-2023-41265 adamcrosser cve cve2023 kev qlik smuggling vkev vuln windows cwe-444" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Qlik Sense Enterprise - HTTP Request Smuggling</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-41265.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-41265.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> AdamCrosser</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 13, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/444.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-444</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-41265" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-41265</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)qlik&#34; || service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-74348711&#34; || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)qlik-sense&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An HTTP Request Tunneling vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier, November 2022 Patch 10 and earlier, and August 2022 Patch 12 and earlier allows a remote attacker to elevate their privilege by tunneling HTTP requests in the raw HTTP request. This allows them to send requests that get executed by the backend server hosting the repository application. This is fixed in August 2023 IR, May 2023 Patch 4, February 2023 Patch 8, November 2022 Patch 11, and August 2022 Patch 13.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Authenticated attackers with low privileges can exploit HTTP request tunneling to escalate privileges and execute malicious requests on the Qlik Sense repository application backend server.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update Qlik Sense Enterprise for Windows to August 2023 IR, May 2023 Patch 4, February 2023 Patch 8, November 2022 Patch 11, or August 2022 Patch 13 that fixes HTTP request smuggling in the repository application.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">kev</span><span class="nt-tag">qlik</span><span class="nt-tag">smuggling</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">windows</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.praetorian.com/blog/doubleqlik-bypassing-the-original-fix-for-cve-2023-41265/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.praetorian.com/blog/qlik-sense-technical-exploit" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.praetorian.com/blog/advisory-qlik-sense/" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://community.qlik.com/t5/Release-Notes/tkb-p/ReleaseNotes" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://community.qlik.com/t5/Official-Support-Articles/Critical-Security-fixes-for-Qlik-Sense-Enterprise-for-Windows/ta-p/2110801" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="qlik sense enterprise - path traversal medium identify critical remote vulnerabilities a path traversal vulnerability found in qlik sense enterprise for windows for versions may 2023 patch 3 and earlier, february 2023 patch 7 and earlier, november 2022 patch 10 and earlier, and august 2022 patch 12 and earlier allows an unauthenticated remote attacker to generate an anonymous session. this allows them to transmit http requests to unauthorized endpoints. this is fixed in august 2023 ir, may 2023 patch 4, february 2023 patch 8, november 2022 patch 11, and august 2022 patch 13. cve-2023-41266 adamcrosser cve cve2023 kev qlik traversal vkev vuln windows cwe-20" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Qlik Sense Enterprise - Path Traversal</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-41266.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-41266.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> AdamCrosser</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 13, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/20.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-20</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-41266" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-41266</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)qlik-sense&#34;}) || service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-74348711&#34; || service[&#34;http.body&#34;] matches &#34;(?i)qlik&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A path traversal vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier, November 2022 Patch 10 and earlier, and August 2022 Patch 12 and earlier allows an unauthenticated remote attacker to generate an anonymous session. This allows them to transmit HTTP requests to unauthorized endpoints. This is fixed in August 2023 IR, May 2023 Patch 4, February 2023 Patch 8, November 2022 Patch 11, and August 2022 Patch 13.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can exploit path traversal to generate anonymous sessions and access unauthorized API endpoints, potentially extracting sensitive business intelligence data and manipulating Qlik Sense dashboards.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update Qlik Sense Enterprise to August 2023 IR, May 2023 Patch 4, February 2023 Patch 8, November 2022 Patch 11, or August 2022 Patch 13 that properly validates resource paths and enforces authentication.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">kev</span><span class="nt-tag">qlik</span><span class="nt-tag">traversal</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">windows</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://community.qlik.com/t5/Official-Support-Articles/Critical-Security-fixes-for-Qlik-Sense-Enterprise-for-Windows/ta-p/2110801" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.praetorian.com/blog/advisory-qlik-sense/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.praetorian.com/blog/qlik-sense-technical-exploit" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://community.qlik.com/t5/Release-Notes/tkb-p/ReleaseNotes" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/Ostorlab/KEV" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="qlik sense server panel - detect info identify web-based control panels qlik sense server panel was detected. ricardomaia discovery panel qlik cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Qlik Sense Server Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/qlik-sense-server.yaml" target="_blank" rel="noopener" class="nt-source-link">qlik-sense-server.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ricardomaia</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)qlik-sense&#34;}) || service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-74348711&#34; || service[&#34;http.body&#34;] matches &#34;(?i)qlik&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Qlik Sense Server panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">qlik</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.qlik.com/us/products/qlik-sense" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="qlikview accesspoint login panel - detect info identify web-based control panels qlikview accesspoint login panel was detected. righettod panel qlikview login detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">QlikView AccessPoint Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/qlikview-accesspoint-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">qlikview-accesspoint-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 12, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)QlikView - AccessPoint&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">QlikView AccessPoint login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">qlikview</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://help.qlik.com/en-US/qlikview/May2023/Subsystems/QMC/Content/QV_QMC/QMC_System_Setup_QlikViewWebServers_AccessPoint.htm" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="qloapps 1.6.0 - sql injection high identify critical remote vulnerabilities an unauthenticated time-based sql injection found in webkul qloapps 1.6.0 via get parameters date_from, date_to, and id_product allows a remote attacker to retrieve the contents of an entire database. cve-2023-36284 ritikchaddha cve cve2023 qloapps sqli time-based-sqli vuln webkul cwe-89" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">QloApps 1.6.0 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-36284.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-36284.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 23, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-36284" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-36284</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)qloapps&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An unauthenticated Time-Based SQL injection found in Webkul QloApps 1.6.0 via GET parameters date_from, date_to, and id_product allows a remote attacker to retrieve the contents of an entire database.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation could lead to unauthorized access to sensitive data.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the vendor-supplied patch or upgrade to a non-vulnerable version.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">qloapps</span><span class="nt-tag">sqli</span><span class="nt-tag">time-based-sqli</span><span class="nt-tag">vuln</span><span class="nt-tag">webkul</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://flashy-lemonade-192.notion.site/Time-Based-SQL-injection-in-QloApps-1-6-0-be3ed1bdaf784a77b45dc6898a2de17e" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-36284" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="qmailadmin login panel - detect info identify web-based control panels qmailadmin login panel was detected. ritikchaddha discovery panel qmail qmail_project cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">QmailAdmin Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/qmail-admin-login.yaml" target="_blank" rel="noopener" class="nt-source-link">qmail-admin-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)qmailadmin&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">QmailAdmin login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">qmail</span><span class="nt-tag">qmail_project</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="qualitor itsm - detect info identify web-based control panels qualitor itsm login panel was detected. johnk3r discovery panel qualitor cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Qualitor ITSM - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/qualitor-itsm-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">qualitor-itsm-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> johnk3r</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 22, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-1217039701&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Qualitor ITSM login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">qualitor</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/projectdiscovery/nuclei-templates/blob/7ade904e3e23bde3e1f5bf721c3a0f4e3f128ae4/http/cves/2024/CVE-2024-44849.yaml" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="quest kace system management appliance 8.0.318 - remote code execution critical identify critical remote vulnerabilities the &#39;/common/download_agent_installer.php&#39; script in the quest kace system management appliance 8.0.318 is accessible by anonymous users and can be abused to execute arbitrary commands on the system. cve-2018-11138 ritikchaddha cve cve2018 kace kev passive quest rce vkev vuln cwe-78" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Quest KACE System Management Appliance 8.0.318 - Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2018/CVE-2018-11138.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2018-11138.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 13, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/78.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-78</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2018-11138" target="_blank" rel="noopener" class="nt-cve-link">CVE-2018-11138</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-463230636&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The &#39;/common/download_agent_installer.php&#39; script in the Quest KACE System Management Appliance 8.0.318 is accessible by anonymous users and can be abused to execute arbitrary commands on the system.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can execute arbitrary commands on the affected system, potentially leading to complete system compromise, data theft, or further network exploitation.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to a patched version of Quest KACE System Management Appliance or apply the necessary security patches provided by Quest Software.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2018</span><span class="nt-tag">kace</span><span class="nt-tag">kev</span><span class="nt-tag">passive</span><span class="nt-tag">quest</span><span class="nt-tag">rce</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.coresecurity.com/advisories/quest-kace-system-management-appliance-multiple-vulnerabilities" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.exploit-db.com/exploits/44950/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2018-11138" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-11138" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="quest modem configuration login - panel info identify web-based control panels quest modem configuration login panel was detected. splint3r7 panel quest login detect discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Quest Modem Configuration Login - Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/quest-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">quest-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Splint3r7</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 30, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Advanced Setup - Security - Admin User Name &amp;amp; Password&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Quest Modem Configuration login Panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">quest</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="quick.cms v6.7 - sql injection high identify critical remote vulnerabilities quick.cms version 6.7 suffers from a remote sql injection vulnerability that allows for authentication bypass. s4e-io cms packetstorm quickcms sqli vuln cwe-89" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Quick.CMS v6.7 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/vulnerabilities/other/quick-cms-sqli.yaml" target="_blank" rel="noopener" class="nt-source-link">quick-cms-sqli.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> s4e-io</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 21, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Quick\\.Cms v6\\.7&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Quick.CMS version 6.7 suffers from a remote SQL injection vulnerability that allows for authentication bypass.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cms</span><span class="nt-tag">packetstorm</span><span class="nt-tag">quickcms</span><span class="nt-tag">sqli</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://packetstormsecurity.com/files/177657/Quick.CMS-6.7-SQL-Injection.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.exploit-db.com/exploits/51910" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="quilium panel - detect info identify web-based control panels quilium cms login panel was detected. righettod panel quilium login detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Quilium Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/quilium-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">quilium-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 8, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)CMS Quilium&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Quilium CMS Login Panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">quilium</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.quilium.io/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="quiz and survey master &lt;= 8.1.4 - sql injection critical identify critical remote vulnerabilities expresstech quiz and survey master (versions up to 8.1.4) contains an sql injection caused by improper neutralization of special elements used in sql commands, letting attackers execute arbitrary sql queries, exploit requires user interaction. cve-2023-28787 shivam kamboj cve cve2023 qsm quiz-master-next sqli wordpress wp wp-plugin cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Quiz and Survey Master &lt;= 8.1.4 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-28787.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-28787.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Shivam Kamboj</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 6, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-28787" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-28787</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/quiz-master-next&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">ExpressTech Quiz And Survey Master (versions up to 8.1.4) contains an SQL injection caused by improper neutralization of special elements used in SQL commands, letting attackers execute arbitrary SQL queries, exploit requires user interaction.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can execute arbitrary SQL commands, potentially leading to data theft, data tampering, or database compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest version of Quiz And Survey Master that addresses this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">qsm</span><span class="nt-tag">quiz-master-next</span><span class="nt-tag">sqli</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://patchstack.com/articles/critical-unauthenticated-sql-injection-in-quiz-and-survey-master/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://patchstack.com/database/wordpress/plugin/quiz-master-next/vulnerability/wordpress-quiz-and-survey-master-plugin-8-1-4-unauthenticated-sql-injection-vulnerability" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-28787" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="qwik - unauthenticated rce via server$ deserialization critical identify critical remote vulnerabilities qwik &lt;=1.19.0 contains an insecure deserialization vulnerability in the server$ rpc mechanism, letting unauthenticated attackers execute arbitrary code remotely, exploit requires require() availability at runtime. cve-2026-27971 omarkurt cve cve2026 deserialization qwik rce vkev cwe-502" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Qwik - Unauthenticated RCE via server$ Deserialization</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2026/CVE-2026-27971.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2026-27971.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> omarkurt</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 4, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/502.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-502</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2026-27971" target="_blank" rel="noopener" class="nt-cve-link">CVE-2026-27971</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)q:version&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Qwik &lt;=1.19.0 contains an insecure deserialization vulnerability in the server$ RPC mechanism, letting unauthenticated attackers execute arbitrary code remotely, exploit requires require() availability at runtime.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can execute arbitrary code on the server, leading to full system compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to version 1.19.1 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2026</span><span class="nt-tag">deserialization</span><span class="nt-tag">qwik</span><span class="nt-tag">rce</span><span class="nt-tag">vkev</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/QwikDev/qwik/security/advisories/GHSA-p9x5-jp3h-96mm" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://vulnerabletarget.com/VT-2026-27971" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="ragflow panel - detect info identify web-based control panels ragflow is an open-source rag (retrieval-augmented generation) engine based on deep
document understanding. rxerium ai detect discovery llm panel rag ragflow" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">RAGFlow Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/ragflow-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">ragflow-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 27, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;RAGFlow&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine based on deep
document understanding.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">ai</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">llm</span><span class="nt-tag">panel</span><span class="nt-tag">rag</span><span class="nt-tag">ragflow</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/infiniflow/ragflow" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://ragflow.io" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="rcdevs webadm panel - detect info identify web-based control panels rcdevs webadm login panel was detected. righettod panel rcdevs webadm login detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">RCDevs WebADM Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/rcdevs-webadm-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">rcdevs-webadm-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 19, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)WebADM&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">RCDevs WebADM Login Panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">rcdevs</span><span class="nt-tag">webadm</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.rcdevs.com/solutions/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="rd web access panel - detect info identify web-based control panels rd web access panel was discovered. rxerium,sorrowx3 microsoft detect discovery login microsoft panel rdp web-access" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">RD Web Access Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/rdweb-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">rdweb-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium,sorrowx3</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 9, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)rd web access&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">RD web access panel was discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">Microsoft</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">login</span><span class="nt-tag">microsoft</span><span class="nt-tag">panel</span><span class="nt-tag">rdp</span><span class="nt-tag">web-access</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://rdweb.wvd.microsoft.com/webclient" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="rdweb remoteapp and desktop connections - web access info identify web-based control panels rdweb remoteapp and desktop connections does not display. dhiyaneshdk panel workresources discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">RDWeb RemoteApp and Desktop Connections - Web Access</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/workresources-rdp.yaml" target="_blank" rel="noopener" class="nt-source-link">workresources-rdp.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)RD Web Access&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">RDWeb RemoteApp and Desktop Connections does not display.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">workresources</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="rg-uac ruijie - password hashes leak high identify critical remote vulnerabilities multiple firewall devices from vendor ruijie networks are affected by an information leakage vulnerability where credentials are included in the source code of the web admin login interface (usernames, roles, md5 hashes and additional details of each user). attackers can use this information to illegally access into the vulnerable devices, obtain sensitive device information and change configurations. the vulnerability is identified by cnvd-2021-14536. ritikchaddha,galoget password leak ruijie exposure firewall router vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">RG-UAC Ruijie - Password Hashes Leak</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/vulnerabilities/ruijie/ruijie-password-leak.yaml" target="_blank" rel="noopener" class="nt-source-link">ruijie-password-leak.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha,galoget</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Get_Verify_Info&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Multiple Firewall Devices from vendor Ruijie Networks are affected by an information leakage vulnerability where credentials are included in the source code of the web admin login interface (usernames, roles, MD5 hashes and additional details of each user). Attackers can use this information to illegally access into the vulnerable devices, obtain sensitive device information and change configurations. The vulnerability is identified by CNVD-2021-14536.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">password</span><span class="nt-tag">leak</span><span class="nt-tag">ruijie</span><span class="nt-tag">exposure</span><span class="nt-tag">firewall</span><span class="nt-tag">router</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://forum.butian.net/share/177" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.ruijie.com.cn/gy/xw-aqtg-zw/86924/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.cnvd.org.cn/flaw/show/CNVD-2021-14536" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="rstudio sign in panel - detect info identify web-based control panels rstudio sign in panel was detected. dhiyaneshdk rstudio login panel discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">RStudio Sign In Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/rstudio-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">rstudio-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 6, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)RStudio Sign In&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">RStudio Sign In panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">rstudio</span><span class="nt-tag">login</span><span class="nt-tag">panel</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="rws worldserver - authentication bypass critical identify critical remote vulnerabilities an issue was discovered in rws worldserver before 11.7.3. adding a token parameter with the value of 02 bypasses all authentication requirements. arbitrary java code can be uploaded and executed via a .jar archive to the ws-api/v2/customizations/api endpoint. cve-2022-34267 pdresearch,iamnoooob,rootxharsh,parthmalhotra auth-bypass cve cve2022 vuln worldserver cwe-287" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">RWS WorldServer - Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-34267.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-34267.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pdresearch,iamnoooob,rootxharsh,parthmalhotra</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 22, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/287.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-287</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-34267" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-34267</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)WorldServer&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An issue was discovered in RWS WorldServer before 11.7.3. Adding a token parameter with the value of 02 bypasses all authentication requirements. Arbitrary Java code can be uploaded and executed via a .jar archive to the ws-api/v2/customizations/api endpoint.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can bypass all authentication by adding a token parameter with value 02, then upload and execute arbitrary Java code via JAR archives, potentially compromising the translation management system and accessing sensitive multilingual content.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to RWS WorldServer version 11.7.3 or later that properly validates authentication tokens and restricts API access.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">vuln</span><span class="nt-tag">worldserver</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.triskelelabs.com/vulnerabilities-in-rws-worldserver" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.rws.com/localization/products/trados-enterprise/worldserver/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/tanjiti/sec_profile" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="rabbitmq default login high identify default logins in web-based control panels rabbitmq default admin credentials were discovered. fyoorer,dwisiswant0 default-login rabbitmq vuln cwe-522" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">RabbitMQ Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/rabbitmq/rabbitmq-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">rabbitmq-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> fyoorer,dwisiswant0</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/522.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-522</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;RabbitMQ Management&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">RabbitMQ default admin credentials were discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">rabbitmq</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://onlinehelp.coveo.com/en/ces/7.0/administrator/changing_the_rabbitmq_administrator_password.htm" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="racksnet login panel - detect info identify web-based control panels racksnet login panel was detected. idealphase panel racksnet discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Racksnet Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/racksnet-login.yaml" target="_blank" rel="noopener" class="nt-source-link">racksnet-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> idealphase</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)My Datacenter - Login&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Racksnet login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">racksnet</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://racksnet.com/en/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://racksnet.com/en/product-overview/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="raidenmaild mail server v.4.9.4 - path traversal high identify critical remote vulnerabilities directory traversal vulnerability in raidenmaild mail server v.4.9.4 and before allows a remote attacker to obtain sensitive information via the /webeditor/ component. cve-2024-32399 dhiyaneshdk cve cve2024 lfi mail raiden server vuln cwe-22" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">RaidenMAILD Mail Server v.4.9.4 - Path Traversal</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-32399.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-32399.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 24, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-32399" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-32399</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)RaidenMAILD&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Directory Traversal vulnerability in RaidenMAILD Mail Server v.4.9.4 and before allows a remote attacker to obtain sensitive information via the /webeditor/ component.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can traverse directories to obtain sensitive information from the mail server.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update RaidenMAILD to a version later than 4.9.4 that patches the directory traversal vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">lfi</span><span class="nt-tag">mail</span><span class="nt-tag">raiden</span><span class="nt-tag">server</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://owasp.org/www-community/attacks/Path_Traversal" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/NN0b0dy/CVE-2024-32399/blob/main/README.md" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/NN0b0dy/c01/blob/main/01.pdf" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/NN0b0dy/CVE-2024-32399" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/nomi-sec/PoC-in-GitHub" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="railsadmin dashboard exposure high identify web-based control panels detected railsadmin dashboard was exposed without proper authentication, allowing unauthorized access to data management interface. 0x_akoko rails admin exposure misconfig panel" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">RailsAdmin Dashboard Exposure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/rails-admin-dashboard-exposure.yaml" target="_blank" rel="noopener" class="nt-source-link">rails-admin-dashboard-exposure.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_Akoko</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 26, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)RailsAdmin&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detected RailsAdmin dashboard was exposed without proper authentication, allowing unauthorized access to data management interface.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">rails</span><span class="nt-tag">admin</span><span class="nt-tag">exposure</span><span class="nt-tag">misconfig</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/railsadminteam/rails_admin" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="rainloop webmail - default admin login high identify default logins in web-based control panels rainloop webmail default admin login credentials were successful. for3stco1d default-login foss rainloop vuln webmail" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Rainloop WebMail - Default Admin Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/rainloop/rainloop-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">rainloop-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> For3stCo1d</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.bodies&#34;]), {# matches &#34;rainloop/&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Rainloop WebMail default admin login credentials were successful.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">foss</span><span class="nt-tag">rainloop</span><span class="nt-tag">vuln</span><span class="nt-tag">webmail</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/RainLoop/rainloop-webmail/issues/28" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="rallly login - panel detect info identify web-based control panels rallly login interface was discovered. th3l0newolf discovery login panel rallly cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Rallly Login - Panel Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/rallly-login-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">rallly-login-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Th3l0newolf</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 2, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches `^Login | Rally`})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Rallly login interface was discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">login</span><span class="nt-tag">panel</span><span class="nt-tag">rallly</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="rancher dashboard panel - detect info identify web-based control panels rancher dashboard was detected. ritikchaddha,righettod dashboard discovery login panel rancher cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Rancher Dashboard Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/rancher-dashboard.yaml" target="_blank" rel="noopener" class="nt-source-link">rancher-dashboard.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha,righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 16, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-1324930554&#34; || service[&#34;favicon.ico.image.mmh3&#34;] == &#34;464587962&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Rancher Dashboard was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">dashboard</span><span class="nt-tag">discovery</span><span class="nt-tag">login</span><span class="nt-tag">panel</span><span class="nt-tag">rancher</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://rancher.com/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="rancher default login high identify default logins in web-based control panels rancher default admin credentials were discovered. rancher is an open-source multi-cluster orchestration platform that lets operations teams deploy, manage and secure enterprise kubernetes. princechaddha cloud default-login devops kubernetes rancher vuln cwe-522" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Rancher Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/rancher/rancher-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">rancher-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> princechaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/522.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-522</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;464587962&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Rancher default admin credentials were discovered. Rancher is an open-source multi-cluster orchestration platform that lets operations teams deploy, manage and secure enterprise Kubernetes.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cloud</span><span class="nt-tag">default-login</span><span class="nt-tag">devops</span><span class="nt-tag">kubernetes</span><span class="nt-tag">rancher</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/rancher/rancher" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://rancher.com/docs/rancher/v2.5/en/admin-settings/authentication/local/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="rancher login panel - detect info identify web-based control panels rancher login panel was detected. princechaddha,idealphase,ritikchaddha cloud devops discovery kubernetes login panel rancher suse cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Rancher Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/rancher-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">rancher-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> princechaddha,idealphase,ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;464587962&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Rancher login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cloud</span><span class="nt-tag">devops</span><span class="nt-tag">discovery</span><span class="nt-tag">kubernetes</span><span class="nt-tag">login</span><span class="nt-tag">panel</span><span class="nt-tag">rancher</span><span class="nt-tag">suse</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/rancher/rancher" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://rancher.com/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="rapid7 nexpose vm security console - detect info identify web-based control panels rapid7 nexpose vm security console login panel was detected. johnk3r nexpose panel login detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Rapid7 Nexpose VM Security Console - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/nexpose-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">nexpose-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> johnk3r</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 2, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-516760689&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Rapid7 Nexpose VM Security Console login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">nexpose</span><span class="nt-tag">panel</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="raritan pdu - login panel info identify web-based control panels raritan intelligent pdu web interface panel has been detected. rxerium discovery ics panel pdu power raritan" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Raritan PDU - Login Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/raritan-pdu-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">raritan-pdu-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 27, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches `(?i)Raritan PDU`</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Raritan intelligent PDU web interface panel has been detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">ics</span><span class="nt-tag">panel</span><span class="nt-tag">pdu</span><span class="nt-tag">power</span><span class="nt-tag">raritan</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.raritan.com/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="raspap 2.8.7 - unauthenticated command injection critical identify critical remote vulnerabilities a command injection vulnerability in raspap 2.8.0 thru 2.8.7 allows unauthenticated attackers to execute arbitrary commands via the cfg_id parameter in /ajax/openvpn/activate_ovpncfg.php and /ajax/openvpn/del_ovpncfg.php. cve-2022-39986 dhiyaneshdk cve cve2022 packetstorm raspap rce vkev vuln cwe-77" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">RaspAP 2.8.7 - Unauthenticated Command Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-39986.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-39986.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 18, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/77.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-77</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-39986" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-39986</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-1465760059&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A Command injection vulnerability in RaspAP 2.8.0 thru 2.8.7 allows unauthenticated attackers to execute arbitrary commands via the cfg_id parameter in /ajax/openvpn/activate_ovpncfg.php and /ajax/openvpn/del_ovpncfg.php.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability can lead to remote code execution, compromising the confidentiality, integrity, and availability of the affected system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to a patched version of RaspAP or apply the vendor-supplied patch to mitigate this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">packetstorm</span><span class="nt-tag">raspap</span><span class="nt-tag">rce</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://packetstormsecurity.com/files/174190/RaspAP-2.8.7-Unauthenticated-Command-Injection.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-39986" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://medium.com/@ismael0x00/multiple-vulnerabilities-in-raspap-3c35e78809f2" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="http://packetstormsecurity.com/files/174190/RaspAP-2.8.7-Unauthenticated-Command-Injection.html" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/RaspAP/raspap-webgui/blob/master/ajax/openvpn/activate_ovpncfg.php" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="raspberrymatic login panel - detect info identify web-based control panels raspberrymatic login panel was detected. princechaddha discovery iot panel raspberrymatic cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">RaspberryMatic Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/raspberrymatic-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">raspberrymatic-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> princechaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-578216669&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">RaspberryMatic login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">iot</span><span class="nt-tag">panel</span><span class="nt-tag">raspberrymatic</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="ray api - local file inclusion high identify critical remote vulnerabilities lfi in ray&#39;s log api endpoint allows attackers to read any file on the server without authentication. cve-2023-6021 byt3bl33d3r cve cve2023 lfi oos ray ray_project vuln cwe-22,cwe-29" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Ray API - Local File Inclusion</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-6021.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-6021.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> byt3bl33d3r</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 5, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22,CWE-29.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22,CWE-29</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-6021" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-6021</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)ray dashboard&#34; || service[&#34;favicon.ico.image.mmh3&#34;] == &#34;463802404&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">LFI in Ray&#39;s log API endpoint allows attackers to read any file on the server without authentication.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can read any file on the server via the log API endpoint, potentially accessing sensitive configuration files, credentials, and application data.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update Ray to a patched version that properly validates file paths in the logs endpoint.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">lfi</span><span class="nt-tag">oos</span><span class="nt-tag">ray</span><span class="nt-tag">ray_project</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://huntr.com/bounties/5039c045-f986-4cbc-81ac-370fe4b0d3f8/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-6021" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="ray static file - local file inclusion high identify critical remote vulnerabilities lfi in ray&#39;s /static/ directory allows attackers to read any file on the server without authentication. cve-2023-6020 byt3bl33d3r cve cve2023 lfi oos ray ray_project vuln cwe-862" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Ray Static File - Local File Inclusion</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-6020.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-6020.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> byt3bl33d3r</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 5, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/862.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-862</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-6020" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-6020</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;463802404&#34; || service[&#34;http.body&#34;] matches &#34;(?i)ray dashboard&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">LFI in Ray&#39;s /static/ directory allows attackers to read any file on the server without authentication.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can read any file on the server via path traversal in the /static/ directory, potentially exposing sensitive configuration files and credentials.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update Ray to a patched version that restricts static file access.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">lfi</span><span class="nt-tag">oos</span><span class="nt-tag">ray</span><span class="nt-tag">ray_project</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://huntr.com/bounties/83dd8619-6dc3-4c98-8f1b-e620fedcd1f6/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-6020" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="rclone rc - broken access control critical identify critical remote vulnerabilities rclone &gt;= 1.45.0 and &lt; 1.73.5 contains a broken access control vulnerability caused by unauthenticated access to the rc endpoint `options/set` allowing mutation of global runtime configuration, letting unauthenticated attackers access sensitive administrative functions, exploit requires rc server started without global http authentication. cve-2026-41176 theamanrawat auth-bypass cve cve2026 rce rclone unauth vkev cwe-306" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Rclone RC - Broken Access Control</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2026/CVE-2026-41176.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2026-41176.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> theamanrawat</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 23, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/306.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-306</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2026-41176" target="_blank" rel="noopener" class="nt-cve-link">CVE-2026-41176</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.head.server&#34;] matches &#34;(?i)^rclone&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Rclone &gt;= 1.45.0 and &lt; 1.73.5 contains a broken access control vulnerability caused by unauthenticated access to the RC endpoint `options/set` allowing mutation of global runtime configuration, letting unauthenticated attackers access sensitive administrative functions, exploit requires RC server started without global HTTP authentication.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can access sensitive administrative functions, potentially leading to full control over the RC server configuration and operations.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to version 1.73.5 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2026</span><span class="nt-tag">rce</span><span class="nt-tag">rclone</span><span class="nt-tag">unauth</span><span class="nt-tag">vkev</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/rclone/rclone/security/advisories/GHSA-25qr-6mpr-f7qx" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41176" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="recrystallize server - authentication bypass high identify critical remote vulnerabilities this vulnerability allows an attacker to bypass authentication in the recrystallize server application by manipulating the &#39;adminusername&#39; cookie. this gives the attacker administrative access to the application&#39;s functionality, even when the default password has been changed. cve-2024-26331 carson chan auth-bypass cve cve2024 recrystallize vuln cwe-287" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">ReCrystallize Server - Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-26331.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-26331.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Carson Chan</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 12, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/287.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-287</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-26331" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-26331</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)ReCrystallize&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">This vulnerability allows an attacker to bypass authentication in the ReCrystallize Server application by manipulating the &#39;AdminUsername&#39; cookie. This gives the attacker administrative access to the application&#39;s functionality, even when the default password has been changed.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can bypass authentication by manipulating the AdminUsername cookie to gain administrative access to ReCrystallize Server.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update ReCrystallize Server to a patched version that addresses CVE-2024-26331.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">recrystallize</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://preview.sensepost.com/blog/2024/from-discovery-to-disclosure-recrystallize-server-vulnerabilities/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://sensepost.com/blog/2024/from-discovery-to-disclosure-recrystallize-server-vulnerabilities/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.recrystallize.com/merchant/ReCrystallize-Server-for-Crystal-Reports.htm" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/Ostorlab/KEV" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="react server components - remote code execution critical identify critical remote vulnerabilities react server components 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including react-server-dom-parcel,
react-server-dom-turbopack, and react-server-dom-webpack contain a remote code execution caused
by unsafe deserialization of payloads from http requests to server function endpoints, letting
unauthenticated attackers execute arbitrary code remotely, exploit requires no authentication. cve-2025-55182 dhiyaneshdk,princechaddha,assetnote,lachlan2k,maple3142,iamnooob cve cve2025 kev nextjs oast rce react vkev cwe-502" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">React Server Components - Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-55182.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-55182.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk,princechaddha,assetnote,lachlan2k,maple3142,iamnooob</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 4, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/502.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-502</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-55182" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-55182</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.head.xPoweredBy&#34;] matches `(?i)Next\.js`</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">React Server Components 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including react-server-dom-parcel,
react-server-dom-turbopack, and react-server-dom-webpack contain a remote code execution caused
by unsafe deserialization of payloads from HTTP requests to Server Function endpoints, letting
unauthenticated attackers execute arbitrary code remotely, exploit requires no authentication.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can execute arbitrary code remotely, potentially leading to full system compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest version that fixes the unsafe deserialization issue.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">kev</span><span class="nt-tag">nextjs</span><span class="nt-tag">oast</span><span class="nt-tag">rce</span><span class="nt-tag">react</span><span class="nt-tag">vkev</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/assetnote/react2shell-scanner" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://gist.github.com/maple3142/48bc9393f45e068cf8c90ab865c0f5f3" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.facebook.com/security/advisories/cve-2025-55182" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="http://www.openwall.com/lists/oss-security/2025/12/03/4" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://react.dev/blog/2025/12/03/critical-security-vulnerability-in-react-server-components" target="_blank" rel="noopener" class="nt-ref-link">[5]</a> <a href="https://github.com/vercel/next.js/security/advisories/GHSA-9qr9-h5gf-34mp" target="_blank" rel="noopener" class="nt-ref-link">[6]</a> <a href="https://vercel.com/changelog/cve-2025-55182" target="_blank" rel="noopener" class="nt-ref-link">[7]</a> <a href="https://github.com/Chocapikk/CVE-2025-55182" target="_blank" rel="noopener" class="nt-ref-link">[8]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="really simple security &lt; 9.1.2 - authentication bypass critical identify critical remote vulnerabilities the really simple security (free, pro, and pro multisite) plugins for wordpress are vulnerable to authentication bypass in versions 9.0.0 to 9.1.1.1. this is due to improper user check error handling in the two-factor rest api actions with the &#39;check_login_and_get_user&#39; function. this makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, when the &#34;two-factor authentication&#34; setting is enabled (disabled by default). cve-2024-10924 yaser_s auth-bypass cve cve2024 really-simple-ssl vkev vuln wordpress wp wp-plugin cwe-288,cwe-306" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Really Simple Security &lt; 9.1.2 - Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-10924.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-10924.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> yaser_s</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 19, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/288,CWE-306.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-288,CWE-306</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-10924" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-10924</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/really-simple-ssl&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The Really Simple Security (Free, Pro, and Pro Multisite) plugins for WordPress are vulnerable to authentication bypass in versions 9.0.0 to 9.1.1.1. This is due to improper user check error handling in the two-factor REST API actions with the &#39;check_login_and_get_user&#39; function. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, when the &#34;Two-Factor Authentication&#34; setting is enabled (disabled by default).</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can exploit improper error handling in the two-factor authentication REST API to bypass authentication and log in as any user including administrators when two-factor authentication is enabled.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Fixed in 9.1.2</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">really-simple-ssl</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://plugins.trac.wordpress.org/browser/really-simple-ssl/tags/9.1.1.1/security/wordpress/two-fa/class-rsssl-two-factor-on-board-api.php#L277" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://plugins.trac.wordpress.org/browser/really-simple-ssl/tags/9.1.1.1/security/wordpress/two-fa/class-rsssl-two-factor-on-board-api.php#L278" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://plugins.trac.wordpress.org/browser/really-simple-ssl/tags/9.1.1.1/security/wordpress/two-fa/class-rsssl-two-factor-on-board-api.php#L67" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://plugins.trac.wordpress.org/changeset/3188431/really-simple-ssl" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://wpscan.com/vulnerability/8e1f4374-2e41-4c27-80d4-db172015c6be/" target="_blank" rel="noopener" class="nt-ref-link">[5]</a> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/7d5d05ad-1a7a-43d2-bbbf-597e975446be?source=cve" target="_blank" rel="noopener" class="nt-ref-link">[6]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-10924" target="_blank" rel="noopener" class="nt-ref-link">[7]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="red hat jboss enterprise application platform - sensitive information disclosure medium identify critical remote vulnerabilities red hat jboss enterprise application platform 4.2 before 4.2.0.cp09 and 4.3 before 4.3.0.cp08 is susceptible to sensitive information disclosure. a remote attacker can obtain sensitive information about &#34;deployed web contexts&#34; via a request to the status servlet, as demonstrated by a full=true query string. note: this issue exists because of a cve-2008-3273 regression. cve-2010-1429 r12w4n cve cve2010 eap exposure jboss redhat tomcat vuln cwe-264" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Red Hat JBoss Enterprise Application Platform - Sensitive Information Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2010/CVE-2010-1429.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2010-1429.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> R12W4N</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/264.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-264</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2010-1429" target="_blank" rel="noopener" class="nt-cve-link">CVE-2010-1429</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)jboss&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Red Hat JBoss Enterprise Application Platform 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 is susceptible to sensitive information disclosure. A remote attacker can obtain sensitive information about &#34;deployed web contexts&#34; via a request to the status servlet, as demonstrated by a full=true query string. NOTE: this issue exists because of a CVE-2008-3273 regression.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can exploit this vulnerability to gain access to sensitive information, potentially leading to further attacks.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the necessary patches or updates provided by Red Hat to fix the vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2010</span><span class="nt-tag">eap</span><span class="nt-tag">exposure</span><span class="nt-tag">jboss</span><span class="nt-tag">redhat</span><span class="nt-tag">tomcat</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://rhn.redhat.com/errata/RHSA-2010-0377.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2010-1429" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2008-3273" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="http://marc.info/?l=bugtraq&amp;m=132698550418872&amp;w=2" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="http://securitytracker.com/id?1023918" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="red hat satellite panel - detect info identify web-based control panels  princechaddha discovery panel redhat satellite cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Red Hat Satellite Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/redhat/redhat-satellite-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">redhat-satellite-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> princechaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)redhat&#34;</code></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">redhat</span><span class="nt-tag">satellite</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="red lion hmi - login panel info identify web-based control panels red lion hmi web interface panel has been detected. rxerium discovery hmi ics panel redlion" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Red Lion HMI - Login Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/redlion-hmi-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">redlion-hmi-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 27, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches `(?i)www\.redlion\.net`</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Red Lion HMI web interface panel has been detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">hmi</span><span class="nt-tag">ics</span><span class="nt-tag">panel</span><span class="nt-tag">redlion</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.redlion.net/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="redash login panel - detect info identify web-based control panels redash login panel was detected. princechaddha panel redash discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Redash Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/redash-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">redash-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> princechaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;698624197&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Redash login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">redash</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="redash setup configuration - default secrets disclosure medium identify critical remote vulnerabilities redash setup configuration is vulnerable to default secrets disclosure (insecure default initialization of resource). if an admin sets up redash versions &lt;=10.0 and prior without explicitly specifying the `redash_cookie_secret` or `redash_secret_key` environment variables, a default value is used for both that is the same across all installations. in such cases, the instance is vulnerable to attackers being able to forge sessions using the known default value. cve-2021-41192 bananabr auth-bypass cve cve2021 hackerone redash vuln cwe-1188" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Redash Setup Configuration - Default Secrets Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2021/CVE-2021-41192.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2021-41192.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> bananabr</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/1188.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-1188</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2021-41192" target="_blank" rel="noopener" class="nt-cve-link">CVE-2021-41192</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;698624197&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Redash Setup Configuration is vulnerable to default secrets disclosure (Insecure Default Initialization of Resource). If an admin sets up Redash versions &lt;=10.0 and prior without explicitly specifying the `REDASH_COOKIE_SECRET` or `REDASH_SECRET_KEY` environment variables, a default value is used for both that is the same across all installations. In such cases, the instance is vulnerable to attackers being able to forge sessions using the known default value.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can gain unauthorized access to sensitive information and potentially compromise the Redash application.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Remove or update the default secrets in the Redash setup configuration file.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2021</span><span class="nt-tag">hackerone</span><span class="nt-tag">redash</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://hackerone.com/reports/1380121" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/getredash/redash/security/advisories/GHSA-g8xr-f424-h2rv" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2021-41192" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/getredash/redash/commit/ce60d20c4e3d1537581f2f70f1308fe77ab6a214" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/ARPSyndicate/cvemon" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="redis commander - default login high identify default logins in web-based control panels redis commander default login credentials were discovered. dhiyaneshdk default-login redis" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Redis Commander - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/redis/redis-commander-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">redis-commander-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 28, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Redis Commander&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Redis Commander Default Login credentials were discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">redis</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="redis enterprise - detect info identify web-based control panels  tess panel redis enterprise discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Redis Enterprise - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/redis-enterprise-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">redis-enterprise-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> tess</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Enterprise-Class Redis for Developers&#34;})</code></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">redis</span><span class="nt-tag">enterprise</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="redis sandbox escape - remote code execution critical identify critical remote vulnerabilities this template exploits cve-2022-0543, a lua-based redis sandbox escape. the
vulnerability was introduced by debian and ubuntu redis packages that
insufficiently sanitized the lua environment. the maintainers failed to
disable the package interface, allowing attackers to load arbitrary libraries. cve-2022-0543 dwisiswant0 cve cve2022 network redis unauth rce kev tcp vkev vuln" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Redis Sandbox Escape - Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/network/cves/2022/CVE-2022-0543.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-0543.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dwisiswant0</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-0543" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-0543</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;service.transport&#34;] == &#34;tcp&#34; and service[&#34;service.port&#34;] == &#34;6380&#34; and service[&#34;protocol&#34;] contains &#34;redis&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">This template exploits CVE-2022-0543, a Lua-based Redis sandbox escape. The
vulnerability was introduced by Debian and Ubuntu Redis packages that
insufficiently sanitized the Lua environment. The maintainers failed to
disable the package interface, allowing attackers to load arbitrary libraries.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability can lead to unauthorized access, data theft, and compromise of the affected system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the most recent versions currently available.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">network</span><span class="nt-tag">redis</span><span class="nt-tag">unauth</span><span class="nt-tag">rce</span><span class="nt-tag">kev</span><span class="nt-tag">tcp</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.ubercomp.com/posts/2022-01-20_redis_on_debian_rce" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://attackerkb.com/topics/wyA1c1HIC8/cve-2022-0543/rapid7-analysis#rapid7-analysis" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://bugs.debian.org/1005787" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://www.debian.org/security/2022/dsa-5081" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://lists.debian.org/debian-security-announce/2022/msg00048.html" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="redmine - default admin credentials high identify default logins in web-based control panels detected redmine project management application was found to have been using the default administrator credentials (admin:admin). an attacker could have gained full administrative access to manage projects, users, and system settings. 0x_akoko aut default-login redmine vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Redmine - Default Admin Credentials</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/redmine-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">redmine-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_Akoko</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 8, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;product&#34;] contains &#34;Redmine:Redmine&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detected Redmine project management application was found to have been using the default administrator credentials (admin:admin). An attacker could have gained full administrative access to manage projects, users, and system settings.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">aut</span><span class="nt-tag">default-login</span><span class="nt-tag">redmine</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.redmine.org/projects/redmine/wiki/RedmineInstall" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.simplified.guide/redmine/default-password" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="redmine login panel - detect info identify web-based control panels redmine login panel was detected. righettod panel redmine login detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Redmine Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/redmine-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">redmine-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 4, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)&#39;content=\&#34;Redmine&#39;&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Redmine login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">redmine</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.redmine.org/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="regify login panel - detect info identify web-based control panels regify login panel was detected. righettod panel regify login detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Regify Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/regify-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">regify-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 23, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1817615343&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Regify Login Panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">regify</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.regify.com/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="registrations for the events calendar &lt; 2.7.6 - sql injection critical identify critical remote vulnerabilities the registrations for the events calendar wordpress plugin before 2.7.6 does not sanitise and escape the event_id in the rtec_send_unregister_link ajax action (available to both unauthenticated and authenticated users) before using it in a sql statement, leading to an unauthenticated sql injection. cve-2021-24943 ritikchaddha cve cve2021 registrations-for-the-events-calendar roundupwp sqli time-based-sqli vkev vuln wordpress wp wp-plugin wpscan cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Registrations for the Events Calendar &lt; 2.7.6 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2021/CVE-2021-24943.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2021-24943.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 13, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2021-24943" target="_blank" rel="noopener" class="nt-cve-link">CVE-2021-24943</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/registrations-for-the-events-calendar/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The Registrations for the Events Calendar WordPress plugin before 2.7.6 does not sanitise and escape the event_id in the rtec_send_unregister_link AJAX action (available to both unauthenticated and authenticated users) before using it in a SQL statement, leading to an unauthenticated SQL injection.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can execute SQL injection through the event_id parameter, potentially extracting all Events Calendar registration data including attendee information.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Fixed in 2.7.6</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2021</span><span class="nt-tag">registrations-for-the-events-calendar</span><span class="nt-tag">roundupwp</span><span class="nt-tag">sqli</span><span class="nt-tag">time-based-sqli</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">wpscan</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wpscan.com/vulnerability/ba50c590-42ee-4523-8aa0-87ac644b77ed/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2021-24943" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://wordpress.org/plugins/registrations-for-the-events-calendar/" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="reliable controls mach-pro - login panel info identify web-based control panels reliable controls mach-prowebsys is a web-based building controller for
hvac, lighting, and energy management using bacnet/ip. these controllers
are widely deployed in commercial buildings across north america and are
often directly internet-facing with no vpn protection. rxerium bacnet bms building-automation discovery ics mach-pro panel reliable-controls" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Reliable Controls MACH-Pro - Login Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/reliable-controls-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">reliable-controls-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 27, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;Reliable Controls&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Reliable Controls MACH-ProWebSys is a web-based building controller for
HVAC, lighting, and energy management using BACnet/IP. These controllers
are widely deployed in commercial buildings across North America and are
often directly internet-facing with no VPN protection.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">bacnet</span><span class="nt-tag">bms</span><span class="nt-tag">building-automation</span><span class="nt-tag">discovery</span><span class="nt-tag">ics</span><span class="nt-tag">mach-pro</span><span class="nt-tag">panel</span><span class="nt-tag">reliable-controls</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://reliablecontrols.com/products/mach-prowebsys/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="remkon device manager login panel - detect info identify web-based control panels remkon device manager login panel was detected. pikpikcu,daffainfo discovery login panel remkon cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">RemKon Device Manager Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/remkon-manager-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">remkon-manager-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pikpikcu,daffainfo</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Remkon Device Manager&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">RemKon Device Manager login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">login</span><span class="nt-tag">panel</span><span class="nt-tag">remkon</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="remedy axis login panel - detect info identify web-based control panels  tess bmc discovery panel remedy cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Remedy Axis Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/remedy-axis-login.yaml" target="_blank" rel="noopener" class="nt-source-link">remedy-axis-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> tess</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)BMC Remedy&#34;</code></div>
  <div class="nt-tags"><span class="nt-tag">bmc</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">remedy</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="remote spark gateway configuration/credentials - exposure medium identify critical remote vulnerabilities remote spark gateway config found via /gateway.conf. domwhewell-sage config exposure remote-spark cwe-200" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Remote Spark Gateway Configuration/Credentials - Exposure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposures/configs/remote-spark-gateway-config.yaml" target="_blank" rel="noopener" class="nt-source-link">remote-spark-gateway-config.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> domwhewell-sage</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 5, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)SparkView&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Remote Spark Gateway config found via /gateway.conf.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">config</span><span class="nt-tag">exposure</span><span class="nt-tag">remote-spark</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://docs.sparkview.info/books/sparkview-admin-manual/page/31-gateway" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="remotely registration enabled high identify critical remote vulnerabilities checks if the remotely self-hosted remote desktop and collaboration web application has its user registration endpoint enabled, potentially allowing anyone to register without invitation. ritikchaddha remotely registration exposure misconfig" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Remotely Registration Enabled</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/misconfiguration/remotely-registration-enabled.yaml" target="_blank" rel="noopener" class="nt-source-link">remotely-registration-enabled.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 22, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;Remotely$&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Checks if the Remotely self-hosted remote desktop and collaboration web application has its user registration endpoint enabled, potentially allowing anyone to register without invitation.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Enabling open registration on Remotely instances may allow unauthorized users to register and gain access to the application, depending on configuration.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Disable open registration if not required by setting &#39;RequireInvitationCodeForRegistration&#39; to true in the Remotely configuration.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">remotely</span><span class="nt-tag">registration</span><span class="nt-tag">exposure</span><span class="nt-tag">misconfig</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/lucent-sea/Remotely" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/lucent-sea/Remotely/blob/master/README.md" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="reolink e1 zoom camera &lt;=3.0.0.716 - information disclosure high identify critical remote vulnerabilities reolink e1 zoom camera through 3.0.0.716 is susceptible to information disclosure. the web server discloses its configuration via the /conf/ directory that is mapped to a publicly accessible path. an attacker with network-level access to the camera can can download the entire nginx/fastcgi configurations by querying the /conf/nginx.conf or /conf/fastcgi.conf uri. cve-2021-40150 for3stco1d camera cve cve2021 exposure iot reolink vuln cwe-552" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Reolink E1 Zoom Camera &lt;=3.0.0.716 - Information Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2021/CVE-2021-40150.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2021-40150.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> For3stCo1d</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/552.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-552</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2021-40150" target="_blank" rel="noopener" class="nt-cve-link">CVE-2021-40150</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)reolink&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Reolink E1 Zoom camera through 3.0.0.716 is susceptible to information disclosure. The web server discloses its configuration via the /conf/ directory that is mapped to a publicly accessible path. An attacker with network-level access to the camera can can download the entire NGINX/FastCGI configurations by querying the /conf/nginx.conf or /conf/fastcgi.conf URI.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can exploit this vulnerability to gain access to sensitive information, potentially compromising user privacy and security.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade the Reolink E1 Zoom Camera to a version higher than 3.0.0.716 to mitigate the information disclosure vulnerability (CVE-2021-40150).</div></div></div>
  <div class="nt-tags"><span class="nt-tag">camera</span><span class="nt-tag">cve</span><span class="nt-tag">cve2021</span><span class="nt-tag">exposure</span><span class="nt-tag">iot</span><span class="nt-tag">reolink</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://dl.packetstormsecurity.net/2206-exploits/reolinke1config-disclose.txt" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/MrTuxracer/advisories/blob/master/CVEs/CVE-2021-40150.txt" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-40150" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2021-40150" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/ARPSyndicate/cvemon" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="reolink e1 zoom camera &lt;=3.0.0.716 - private key disclosure medium identify critical remote vulnerabilities reolink e1 zoom camera versions 3.0.0.716 and below suffer from a private key (rsa) disclosure vulnerability. cve-2021-40149 for3stco1d camera cve cve2021 exposure iot packetstorm reolink unauth vuln cwe-552" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Reolink E1 Zoom Camera &lt;=3.0.0.716 - Private Key Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2021/CVE-2021-40149.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2021-40149.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> For3stCo1d</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/552.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-552</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2021-40149" target="_blank" rel="noopener" class="nt-cve-link">CVE-2021-40149</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Reolink&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Reolink E1 Zoom Camera versions 3.0.0.716 and below suffer from a private key (RSA) disclosure vulnerability.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can obtain the private key, potentially leading to unauthorized access and compromise of the camera.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade the Reolink E1 Zoom Camera to a version higher than 3.0.0.716 to mitigate the vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">camera</span><span class="nt-tag">cve</span><span class="nt-tag">cve2021</span><span class="nt-tag">exposure</span><span class="nt-tag">iot</span><span class="nt-tag">packetstorm</span><span class="nt-tag">reolink</span><span class="nt-tag">unauth</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://dl.packetstormsecurity.net/2206-exploits/reolinke1key-disclose.txt" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/MrTuxracer/advisories/blob/master/CVEs/CVE-2021-40149.txt" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-40149" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="http://packetstormsecurity.com/files/167407/Reolink-E1-Zoom-Camera-3.0.0.716-Private-Key-Disclosure.html" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/MrTuxracer/advisories" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="reolink panel - detect info identify web-based control panels reolink panel was discovered. s4e-io detect discovery login panel reolink" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Reolink Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/reolink-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">reolink-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> s4e-io</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 25, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Reolink&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Reolink panel was discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">login</span><span class="nt-tag">panel</span><span class="nt-tag">reolink</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="repetier server - directory traversal high identify critical remote vulnerabilities repetier server through 1.4.10 allows ..%5c directory traversal for reading files that contain credentials, as demonstrated by connectionlost.php. cve-2023-31059 parthmalhotra,pdresearch cve cve2023 lfi repetier repetier-server vkev vuln cwe-22" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Repetier Server - Directory Traversal</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-31059.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-31059.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> parthmalhotra,pdresearch</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 9, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-31059" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-31059</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)repetier-server&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Repetier Server through 1.4.10 allows ..%5c directory traversal for reading files that contain credentials, as demonstrated by connectionLost.php.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can read, modify, or delete arbitrary files on the server, potentially leading to unauthorized access, data leakage, or system compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches or updates provided by the vendor to fix the directory traversal vulnerability in Repetier Server.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">lfi</span><span class="nt-tag">repetier</span><span class="nt-tag">repetier-server</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://cybir.com/2023/cve/poc-repetier-server-140/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.repetier-server.com/download-repetier-server/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="repetier server panel - detect info identify web-based control panels repetier server login panel detected. ritikchaddha detect discovery panel repetier repetier-server" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Repetier Server Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/repetier-server-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">repetier-server-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 13, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)repetier-server&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Repetier Server login panel detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">repetier</span><span class="nt-tag">repetier-server</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="reportico administration page - detect info identify web-based control panels create a simple report using the designer front end in seconds from a single sql statement. add expressions, user criteria, charts, groups, aggregations, page headers, page footers, hyperlinks and even custom plugin code. geeknik detect discovery login panel reportico" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Reportico Administration Page - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/reportico-admin-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">reportico-admin-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> geeknik</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 9, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)reportico administration page&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Create a simple report using the designer front end in seconds from a single SQL statement. Add expressions, user criteria, charts, groups, aggregations, page headers, page footers, hyperlinks and even custom plugin code.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">login</span><span class="nt-tag">panel</span><span class="nt-tag">reportico</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.reportico.org/site2/index.php" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/reportico-web/reportico" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="reposilite &gt;= 3.3.0, &lt; 3.5.12 - arbitrary file read high identify critical remote vulnerabilities reposilite is an open source, lightweight and easy-to-use repository manager for maven based artifacts in jvm ecosystem. reposilite v3.5.10 is affected by an arbitrary file read vulnerability via path traversal while serving expanded javadoc files. reposilite has addressed this issue in version 3.5.12. there are no known workarounds for this vulnerability. this issue was discovered and reported by the github security lab and is also tracked as ghsl-2024-074. cve-2024-36117 iamnoooob,rootxharsh,pdresearch cve cve2024 lfi reposilite vkev vuln cwe-22" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Reposilite &gt;= 3.3.0, &lt; 3.5.12 - Arbitrary File Read</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-36117.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-36117.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> iamnoooob,rootxharsh,pdresearch</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 11, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-36117" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-36117</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1212523028&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Reposilite is an open source, lightweight and easy-to-use repository manager for Maven based artifacts in JVM ecosystem. Reposilite v3.5.10 is affected by an Arbitrary File Read vulnerability via path traversal while serving expanded javadoc files. Reposilite has addressed this issue in version 3.5.12. There are no known workarounds for this vulnerability. This issue was discovered and reported by the GitHub Security lab and is also tracked as GHSL-2024-074.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can exploit path traversal to read arbitrary files including the reposilite.db database file.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update Reposilite to version 3.5.12 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">lfi</span><span class="nt-tag">reposilite</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/advisories/GHSA-82j3-hf72-7x93" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/dzikoysk/reposilite/commit/e172ae4b539c822d0d6e04cf090713c7202a79d6" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/dzikoysk/reposilite/releases/tag/3.5.12" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/dzikoysk/reposilite/security/advisories/GHSA-82j3-hf72-7x93" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-36117" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="reposilite login panel - detect info identify web-based control panels reposilite products was detected. righettod panel reposilite login discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Reposilite Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/reposilite-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">reposilite-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 27, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)reposilite&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Reposilite products was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">reposilite</span><span class="nt-tag">login</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://reposilite.com/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/dzikoysk/reposilite" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="reprise license manager 14.2 - authentication bypass critical identify critical remote vulnerabilities reprise license manager (rlm) 14.2 does not verify authentication or authorization and allows unauthenticated users to change the password of any existing user. cve-2021-44152 akincibor auth-bypass cve cve2021 packetstorm reprisesoftware rlm vuln cwe-306" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Reprise License Manager 14.2 - Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2021/CVE-2021-44152.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2021-44152.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Akincibor</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/306.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-306</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2021-44152" target="_blank" rel="noopener" class="nt-cve-link">CVE-2021-44152</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)reprise license manager&#34; || service[&#34;http.body&#34;] matches &#34;(?i)reprise license&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Reprise License Manager (RLM) 14.2 does not verify authentication or authorization and allows unauthenticated users to change the password of any existing user.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to bypass authentication and gain unauthorized access to the Reprise License Manager.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patch or upgrade to a patched version of Reprise License Manager to mitigate this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2021</span><span class="nt-tag">packetstorm</span><span class="nt-tag">reprisesoftware</span><span class="nt-tag">rlm</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://reprisesoftware.com/admin/rlm-admin-download.php?&amp;euagree=yes" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="http://packetstormsecurity.com/files/165186/Reprise-License-Manager-14.2-Unauthenticated-Password-Change.html" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2021-44152" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://www.reprisesoftware.com/RELEASE_NOTES" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/anonymous364872/Rapier_Tool" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="reprise license manager 14.2 - cross-site scripting medium identify critical remote vulnerabilities reprise license manager 14.2 contains a reflected cross-site scripting vulnerability in the /goform/login_process &#39;username&#39; parameter via get, whereby no authentication is required. cve-2022-28363 akincibor cve cve2022 packetstorm reprisesoftware rlm vkev vuln xss cwe-79" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Reprise License Manager 14.2 - Cross-Site Scripting</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-28363.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-28363.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Akincibor</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-79</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-28363" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-28363</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)reprise license&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Reprise License Manager 14.2 contains a reflected cross-site scripting vulnerability in the /goform/login_process &#39;username&#39; parameter via GET, whereby no authentication is required.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute arbitrary JavaScript code in the context of the victim&#39;s browser, leading to potential session hijacking, defacement, or theft of sensitive information.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to a patched version of Reprise License Manager or apply the vendor-supplied patch to mitigate this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">packetstorm</span><span class="nt-tag">reprisesoftware</span><span class="nt-tag">rlm</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">xss</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.reprisesoftware.com/products/software-license-management.php" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/advisories/GHSA-rpvc-qgrm-r54f" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="http://packetstormsecurity.com/files/166647/Reprise-License-Manager-14.2-Cross-Site-Scripting-Information-Disclosure.html" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-28363" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/ARPSyndicate/kenzer-templates" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="reprise license manager 14.2 - cross-site scripting medium identify critical remote vulnerabilities reprise license manager 14.2 contains a cross-site scripting vulnerability in the /goform/activate_process &#34;count&#34; parameter via get. cve-2021-45422 edoardottt cve cve2021 reprise reprisesoftware seclists vkev vuln xss cwe-79" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Reprise License Manager 14.2 - Cross-Site Scripting</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2021/CVE-2021-45422.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2021-45422.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> edoardottt</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-79</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2021-45422" target="_blank" rel="noopener" class="nt-cve-link">CVE-2021-45422</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Reprise License&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Reprise License Manager 14.2 contains a cross-site scripting vulnerability in the /goform/activate_process &#34;count&#34; parameter via GET.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute arbitrary JavaScript code in the context of the victim&#39;s browser, leading to potential session hijacking, defacement, or theft of sensitive information.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches or updates provided by the vendor to fix the XSS vulnerability in Reprise License Manager 14.2.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2021</span><span class="nt-tag">reprise</span><span class="nt-tag">reprisesoftware</span><span class="nt-tag">seclists</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">xss</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://seclists.org/fulldisclosure/2022/Jan/31" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.getinfosec.news/13202933/reprise-license-manager-142-reflected-cross-site-scripting#/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2021-45422" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="http://reprise.com" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/ARPSyndicate/kenzer-templates" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="reprise license manager 14.2 - information disclosure medium identify critical remote vulnerabilities reprise license manager 14.2 is susceptible to information disclosure via a get request to /goforms/rlminfo. no authentication is required. the information disclosed is associated with software versions, process ids, network configuration, hostname(s), system architecture and file/directory information. an attacker can possibly obtain further sensitive information, modify data, and/or execute unauthorized operations. cve-2022-28365 akincibor cve cve2022 exposure packetstorm reprisesoftware rlm vkev vuln cwe-425" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Reprise License Manager 14.2 - Information Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-28365.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-28365.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Akincibor</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/425.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-425</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-28365" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-28365</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)reprise license&#34; || service[&#34;http.body&#34;] matches &#34;(?i)reprise license manager&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Reprise License Manager 14.2 is susceptible to information disclosure via a GET request to /goforms/rlminfo. No authentication is required. The information disclosed is associated with software versions, process IDs, network configuration, hostname(s), system architecture and file/directory information. An attacker can possibly obtain further sensitive information, modify data, and/or execute unauthorized operations.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can exploit this vulnerability to gain sensitive information.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patch or upgrade to a non-vulnerable version of Reprise License Manager.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">exposure</span><span class="nt-tag">packetstorm</span><span class="nt-tag">reprisesoftware</span><span class="nt-tag">rlm</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.reprisesoftware.com/products/software-license-management.php" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/advisories/GHSA-4g2v-6x25-vr7p" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="http://packetstormsecurity.com/files/166647/Reprise-License-Manager-14.2-Cross-Site-Scripting-Information-Disclosure.html" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-28365" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://www.reprisesoftware.com/RELEASE_NOTES" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="request tracker - panel info identify web-based control panels request tracker panel was discovered. burso panel login request tracker discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Request Tracker - Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/request-tracker-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">request-tracker-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> burso</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 10, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;203612613&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Request Tracker panel was discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">login</span><span class="nt-tag">request</span><span class="nt-tag">tracker</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="residential gateway login panel - detect info identify web-based control panels residential gateway login panel was detected. idealphase panel discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Residential Gateway Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/residential-gateway-login.yaml" target="_blank" rel="noopener" class="nt-source-link">residential-gateway-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> idealphase</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Login - Residential Gateway&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Residential Gateway login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="restropress 3.0.0-3.2.1 - authentication bypass critical identify critical remote vulnerabilities restropress online food ordering system wordpress plugin 3.0.0 to 3.1.9.2 contains an authentication bypass caused by exposure of user private tokens and api data via /wp-json/wp/v2/users endpoint, letting unauthenticated attackers forge jwt tokens and authenticate as other users including administrators, exploit requires no authentication. cve-2025-9209 0x_akoko auth-bypass cve cve2025 restropress wordpress wp wp-plugin cwe-287" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">RestroPress 3.0.0-3.2.1 - Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-9209.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-9209.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_Akoko</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 23, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/287.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-287</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-9209" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-9209</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/restropress/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">RestroPress Online Food Ordering System WordPress plugin 3.0.0 to 3.1.9.2 contains an authentication bypass caused by exposure of user private tokens and API data via /wp-json/wp/v2/users endpoint, letting unauthenticated attackers forge JWT tokens and authenticate as other users including administrators, exploit requires no authentication.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can forge JWT tokens and authenticate as any user, including administrators, leading to full account takeover.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest version beyond 3.1.9.2.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">restropress</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/restropress/restropress-online-food-ordering-system-300-3192-unauthenticated-information-exposure-to-authentication-bypass-via-forged-jwt" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-9209" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="retool login panel - detect info identify web-based control panels retool login panel was detected. dhiyaneshdk discovery login panel retool cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Retool Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/retool-login.yaml" target="_blank" rel="noopener" class="nt-source-link">retool-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Retool&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Retool login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">login</span><span class="nt-tag">panel</span><span class="nt-tag">retool</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="revpi webstatus &lt;= v2.4.5 - authentication bypass critical identify critical remote vulnerabilities an unauthorized remote attacker can bypass the authentication of the affected software package by misusing an incorrect type conversion. this leads to full compromise of the device cve-2025-41646 dhiyaneshdk auth-bypass cve cve2025 kunbus revpi revpi-status vkev vuln cwe-704" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">RevPi Webstatus &lt;= v2.4.5 - Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-41646.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-41646.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 3, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/704.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-704</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-41646" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-41646</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)RevPi&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An unauthorized remote attacker can bypass the authentication of the affected software package by misusing an incorrect type conversion. This leads to full compromise of the device</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can bypass authentication through incorrect type conversion in the login mechanism, achieving complete device compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade RevPi Webstatus to version 2.4.6 or later that properly validates authentication credentials.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">kunbus</span><span class="nt-tag">revpi</span><span class="nt-tag">revpi-status</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://psirt.kunbus.com/.well-known/csaf/white/2025/kunbus-2025-0000003.json" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://x.com/win3zz/status/1940397684176904607" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41646" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="revive adserver 4.2 - remote code execution critical identify critical remote vulnerabilities revive adserver 4.2 is susceptible to remote code execution. an attacker can send a crafted payload to the xml-rpc invocation script and trigger the unserialize() call on the &#34;what&#34; parameter in the &#34;openads.spc&#34; rpc method. this can be exploited to perform various types of attacks, e.g. serialize-related php vulnerabilities or php object injection. it is possible, although unconfirmed, that the vulnerability has been used by some attackers in order to gain access to some revive adserver instances and deliver malware through them to third-party websites. cve-2019-5434 omarjezi adserver cve cve2019 edb packetstorm rce revive revive-sas vkev vuln cwe-502" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Revive Adserver 4.2 - Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2019/CVE-2019-5434.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2019-5434.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> omarjezi</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/502.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-502</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2019-5434" target="_blank" rel="noopener" class="nt-cve-link">CVE-2019-5434</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;106844876&#34; || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)revive adserver&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Revive Adserver 4.2 is susceptible to remote code execution. An attacker can send a crafted payload to the XML-RPC invocation script and trigger the unserialize() call on the &#34;what&#34; parameter in the &#34;openads.spc&#34; RPC method. This can be exploited to perform various types of attacks, e.g. serialize-related PHP vulnerabilities or PHP object injection. It is possible, although unconfirmed, that the vulnerability has been used by some attackers in order to gain access to some Revive Adserver instances and deliver malware through them to third-party websites.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the target system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches or upgrade to a newer version of Revive Adserver.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">adserver</span><span class="nt-tag">cve</span><span class="nt-tag">cve2019</span><span class="nt-tag">edb</span><span class="nt-tag">packetstorm</span><span class="nt-tag">rce</span><span class="nt-tag">revive</span><span class="nt-tag">revive-sas</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://packetstormsecurity.com/files/155559/Revive-Adserver-4.2-Remote-Code-Execution.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.exploit-db.com/exploits/47739" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.revive-adserver.com/security/revive-sa-2019-001/" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2019-5434" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="http://packetstormsecurity.com/files/155559/Revive-Adserver-4.2-Remote-Code-Execution.html" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="revive adserver &lt;5.1.0 - open redirect medium identify critical remote vulnerabilities revive adserver before 5.1.0 contains an open redirect vulnerability via the dest, oadest, and ct0 parameters of the lg.php and ck.php delivery scripts. an attacker can redirect a user to a malicious site and possibly obtain sensitive information, modify data, and/or execute unauthorized operations. cve-2021-22873 pudsec cve cve2021 hackerone packetstorm redirect revive revive-adserver seclists vkev vuln cwe-601" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Revive Adserver &lt;5.1.0 - Open Redirect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2021/CVE-2021-22873.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2021-22873.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pudsec</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/601.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-601</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2021-22873" target="_blank" rel="noopener" class="nt-cve-link">CVE-2021-22873</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;106844876&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Revive Adserver before 5.1.0 contains an open redirect vulnerability via the dest, oadest, and ct0 parameters of the lg.php and ck.php delivery scripts. An attacker can redirect a user to a malicious site and possibly obtain sensitive information, modify data, and/or execute unauthorized operations.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to redirect users to malicious websites, leading to phishing attacks or the execution of further attacks.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade Revive Adserver to version 5.1.0 or later to mitigate this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2021</span><span class="nt-tag">hackerone</span><span class="nt-tag">packetstorm</span><span class="nt-tag">redirect</span><span class="nt-tag">revive</span><span class="nt-tag">revive-adserver</span><span class="nt-tag">seclists</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://hackerone.com/reports/1081406" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/revive-adserver/revive-adserver/issues/1068" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="http://seclists.org/fulldisclosure/2021/Jan/60" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2021-22873" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="http://packetstormsecurity.com/files/161070/Revive-Adserver-5.0.5-Cross-Site-Scripting-Open-Redirect.html" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="revive adserver &lt;=5.0.3 - cross-site scripting medium identify critical remote vulnerabilities revive adserver 5.0.3 and prior contains a reflected cross-site scripting vulnerability in the publicly accessible afr.php delivery script. in older versions, it is possible to steal the session identifier and gain access to the admin interface. the query string sent to the www/delivery/afr.php script is printed back without proper escaping, allowing an attacker to execute arbitrary javascript code on the browser of the victim. cve-2020-8115 madrobot,dwisiswant0 cve cve2020 hackerone revive-adserver vkev vuln xss cwe-79" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Revive Adserver &lt;=5.0.3 - Cross-Site Scripting</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2020/CVE-2020-8115.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2020-8115.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> madrobot,dwisiswant0</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-79</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2020-8115" target="_blank" rel="noopener" class="nt-cve-link">CVE-2020-8115</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)revive adserver&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Revive Adserver 5.0.3 and prior contains a reflected cross-site scripting vulnerability in the publicly accessible afr.php delivery script. In older versions, it is possible to steal the session identifier and gain access to the admin interface. The query string sent to the www/delivery/afr.php script is printed back without proper escaping, allowing an attacker to execute arbitrary JavaScript code on the browser of the victim.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to inject malicious scripts into web pages viewed by users, leading to potential data theft, session hijacking, or defacement.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">There are currently no known exploits. As of 3.2.2, the session identifier cannot be accessed as it is stored in an http-only cookie.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2020</span><span class="nt-tag">hackerone</span><span class="nt-tag">revive-adserver</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">xss</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://hackerone.com/reports/775693" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.revive-adserver.com/security/revive-sa-2020-001/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2020-8115" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/Elsfa7-110/kenzer-templates" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/merlinepedra/nuclei-templates" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="ricoh web image monitor - detect info identify web-based control panels ricoh web image monitor device was detected. righettod panel ricoh detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Ricoh Web Image Monitor - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/ricoh-webimagemonitor-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">ricoh-webimagemonitor-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 16, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Web Image Monitor&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Ricoh Web Image Monitor device was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">ricoh</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://support.ricoh.com/bb_v1oi/pub_e/oi_view/0001082/0001082137/view/intro/int/wim.htm" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="ricoh web image monitor - reflected xss medium identify critical remote vulnerabilities a reflected cross-site scripting vulnerability exists in the laser printers and mfps (multifunction printers) which implement ricoh web image monitor. if exploited, an arbitrary script may be executed on the web browser of the user who accessed web image monitor. cve-2025-41393 jpg0mez cve cve2025 ricoh vuln web xss cwe-79" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Ricoh Web Image Monitor - Reflected XSS</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-41393.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-41393.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> jpg0mez</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 19, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-79</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-41393" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-41393</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Web Image Monitor&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A reflected cross-site scripting vulnerability exists in the laser printers and MFPs (multifunction printers) which implement Ricoh Web Image Monitor. If exploited, an arbitrary script may be executed on the web browser of the user who accessed Web Image Monitor.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can execute malicious JavaScript in user browsers through the profile parameter, potentially leading to session hijacking and credential theft.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the security patch from Ricoh for affected Web Image Monitor implementations.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">ricoh</span><span class="nt-tag">vuln</span><span class="nt-tag">web</span><span class="nt-tag">xss</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.ricoh.com/products/security/vulnerabilities/vul?id=ricoh-2025-000001" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://jvn.jp/en/jp/JVN20474768/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41393" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="riello netman 204 - sql injection critical identify critical remote vulnerabilities the three endpoints /cgi-bin/db_datalog_w.cgi, /cgi-bin/db_eventlog_w.cgi, and /cgi-bin/db_multimetr_w.cgi are vulnerable to sql injection without prior authentication. this enables an attacker to modify the collected log data in an arbitrary way. cve-2024-8877 s4e-io cve cve2024 netman sqli vkev vuln cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Riello Netman 204 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-8877.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-8877.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> s4e-io</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 4, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-8877" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-8877</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)netman 204&#34;}) || service[&#34;http.body&#34;] matches &#34;(?i)ups network management card 4&#34; || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)netman&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The three endpoints /cgi-bin/db_datalog_w.cgi, /cgi-bin/db_eventlog_w.cgi, and /cgi-bin/db_multimetr_w.cgi are vulnerable to SQL injection without prior authentication. This enables an attacker to modify the collected log data in an arbitrary way.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can exploit SQL injection to modify collected log data, extract sensitive information, and potentially gain complete control of the Netman 204 device through multiple vulnerable CGI endpoints.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply security patches from Riello for Netman 204 firmware to address the SQL injection vulnerabilities in db_datalog_w.cgi, db_eventlog_w.cgi, and db_multimetr_w.cgi endpoints.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">netman</span><span class="nt-tag">sqli</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://cyberdanube.com/en/en-multiple-vulnerabilities-in-riello-netman-204/index.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://0day.today/exploit/39757" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-8877" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="riello ups netman 204 network card - default login high identify default logins in web-based control panels default logins on riello ups netman 204 is used. attacker can access to ups and attacker can manipulate the ups settings to disrupt the onsite systems. mabdullah22 default-login netman vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Riello UPS NetMan 204 Network Card - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/riello/netman-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">netman-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> mabdullah22</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 12, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;Netman&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Default logins on Riello UPS NetMan 204 is used. Attacker can access to UPS and attacker can manipulate the UPS settings to disrupt the onsite systems.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">netman</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.riello-ups.com/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="riello ups netman 204 panel - detect info identify web-based control panels riello ups netman 204 login panel was detected. s4e-io detect discovery login netman panel" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Riello UPS NetMan 204 Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/riello-netman204-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">riello-netman204-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> s4e-io</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 4, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)netman 204&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Riello UPS NetMan 204 login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">login</span><span class="nt-tag">netman</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.riello-ups.com" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="ritecms - default login high identify default logins in web-based control panels ritecms default credentials were discovered. 0x_akoko ritecms default-login vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">RiteCMS - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/ritecms/ritecms-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">ritecms-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_Akoko</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 6, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)ritecms&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">RiteCMS Default Credentials were discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">ritecms</span><span class="nt-tag">default-login</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://ritecms.com/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="rocket.chat &lt;=3.13 - nosql injection critical identify critical remote vulnerabilities rocket.chat 3.11, 3.12 and 3.13 contains a nosql injection vulnerability which allows unauthenticated access to an api endpoint. an attacker can possibly obtain sensitive information from a database, modify data, and/or execute unauthorized administrative operations in the context of the affected site. cve-2021-22911 tess,sullo cve cve2021 hackerone nosqli packetstorm rocket.chat rocketchat sqli vkev vulhub vuln cwe-75,nvd-cwe-other" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Rocket.Chat &lt;=3.13 - NoSQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2021/CVE-2021-22911.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2021-22911.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> tess,sullo</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/75,NVD-CWE-OTHER.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-75,NVD-CWE-OTHER</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2021-22911" target="_blank" rel="noopener" class="nt-cve-link">CVE-2021-22911</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)rocket\\.chat&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Rocket.Chat 3.11, 3.12 and 3.13 contains a NoSQL injection vulnerability which allows unauthenticated access to an API endpoint. An attacker can possibly obtain sensitive information from a database, modify data, and/or execute unauthorized administrative operations in the context of the affected site.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute arbitrary NoSQL queries, leading to unauthorized access, data manipulation, or denial of service.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade Rocket.Chat to a version higher than 3.13 or apply the provided patch to mitigate the vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2021</span><span class="nt-tag">hackerone</span><span class="nt-tag">nosqli</span><span class="nt-tag">packetstorm</span><span class="nt-tag">rocket.chat</span><span class="nt-tag">rocketchat</span><span class="nt-tag">sqli</span><span class="nt-tag">vkev</span><span class="nt-tag">vulhub</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="http://packetstormsecurity.com/files/162997/Rocket.Chat-3.12.1-NoSQL-Injection-Code-Execution.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/vulhub/vulhub/tree/master/rocketchat/CVE-2021-22911" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://hackerone.com/reports/1130721" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22911" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://blog.sonarsource.com/nosql-injections-in-rocket-chat" target="_blank" rel="noopener" class="nt-ref-link">[5]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2021-22911" target="_blank" rel="noopener" class="nt-ref-link">[6]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="rocketchat login panel - detect info identify web-based control panels rocketchat login panel was detected. righettod panel rocketchat login detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">RocketChat Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/rocketchat-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">rocketchat-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 24, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Rocket\\.Chat&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">RocketChat login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">rocketchat</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.rocket.chat/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="rockmongo default login high identify default logins in web-based control panels rockmongo default admin credentials were discovered. pikpikcu default-login rockmongo vuln cwe-522" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Rockmongo Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/rockmongo/rockmongo-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">rockmongo-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pikpikcu</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/522.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-522</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;^RockMongo&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Rockmongo default admin credentials were discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">rockmongo</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://serverfault.com/questions/331315/how-to-change-the-default-admin-username-and-admin-password-in-rockmongo" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="rockwell automation factorytalk viewpoint - panel info identify web-based control panels rockwell automation factorytalk viewpoint is a web-based hmi that allows remote
monitoring and control of industrial automation systems from a browser. it provides
access to factorytalk view machine edition and site edition displays. exposed
instances may allow unauthorised access to industrial control system visualisations. rxerium discovery factorytalk ics panel rockwell scada" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Rockwell Automation FactoryTalk ViewPoint - Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/rockwell-factorytalk-viewpoint-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">rockwell-factorytalk-viewpoint-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 27, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;FactoryTalk ViewPoint&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Rockwell Automation FactoryTalk ViewPoint is a web-based HMI that allows remote
monitoring and control of industrial automation systems from a browser. It provides
access to FactoryTalk View Machine Edition and Site Edition displays. Exposed
instances may allow unauthorised access to industrial control system visualisations.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">factorytalk</span><span class="nt-tag">ics</span><span class="nt-tag">panel</span><span class="nt-tag">rockwell</span><span class="nt-tag">scada</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.rockwellautomation.com/en-us/products/software/factorytalk/operationsuite/view/factorytalk-viewpoint.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="roxy file manager - panel detect info identify web-based control panels roxy file manager panel was detected. liquidsec,dhiyaneshdk,ritikchaddha discovery fileman panel roxy roxyfileman tech cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Roxy File Manager - Panel Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/roxy-fileman.yaml" target="_blank" rel="noopener" class="nt-source-link">roxy-fileman.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> liquidsec,DhiyaneshDk,ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)roxy file manager&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Roxy File Manager panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">fileman</span><span class="nt-tag">panel</span><span class="nt-tag">roxy</span><span class="nt-tag">roxyfileman</span><span class="nt-tag">tech</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="roxy-wi - remote code execution critical identify critical remote vulnerabilities roxy-wi before 6.1.1.0 is susceptible to remote code execution. system commands can be run remotely via the ssh_command function without processing the inputs received from the user in the /app/funct.py file. cve-2022-31126 ritikchaddha cve cve2022 rce roxy roxy-wi vkev vuln cwe-74" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Roxy-WI - Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-31126.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-31126.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/74.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-74</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-31126" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-31126</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)roxy-wi&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Roxy-WI before 6.1.1.0 is susceptible to remote code execution. System commands can be run remotely via the ssh_command function without processing the inputs received from the user in the /app/funct.py file.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Users are advised to upgrade to latest version.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">rce</span><span class="nt-tag">roxy</span><span class="nt-tag">roxy-wi</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://pentest.blog/advisory-roxy-wi-unauthenticated-remote-code-executions-cve-2022-31137/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/roxy-wi/roxy-wi/security/advisories/GHSA-mh86-878h-43c9" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31126" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="roxy-wi &lt; 6.1.1.0 - remote code execution critical identify critical remote vulnerabilities roxy-wi before 6.1.1.0 is susceptible to remote code execution. system commands can be run remotely via the subprocess_execute function without processing the inputs received from the user in the /app/options.py file. cve-2022-31137 dhiyaneshdk cve cve2022 rce roxy roxy-wi vkev vuln cwe-74" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Roxy-WI &lt; 6.1.1.0 - Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-31137.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-31137.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 20, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/74.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-74</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-31137" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-31137</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)roxy-wi&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Roxy-WI before 6.1.1.0 is susceptible to remote code execution. System commands can be run remotely via the subprocess_execute function without processing the inputs received from the user in the /app/options.py file.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Users are advised to upgrade to latest version.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">rce</span><span class="nt-tag">roxy</span><span class="nt-tag">roxy-wi</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="http://packetstormsecurity.com/files/167805/Roxy-WI-Remote-Command-Execution.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.cve.org/CVERecord?id=CVE-2022-31137" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/hap-wi/roxy-wi/security/advisories/GHSA-mh86-878h-43c9" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31137" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="ruckus wireless - default login critical identify default logins in web-based control panels ruckus wireless router contains a default admin login vulnerability. an attacker can obtain access to user accounts and access sensitive information, modify data, and/or execute unauthorized operations. pussycat0x default-login router ruckus vuln cwe-1391" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Ruckus Wireless - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/ruckus/ruckus-wireless-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">ruckus-wireless-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/1391.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-1391</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)ruckus&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Ruckus Wireless router contains a default admin login vulnerability. An attacker can obtain access to user accounts and access sensitive information, modify data, and/or execute unauthorized operations.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">router</span><span class="nt-tag">ruckus</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://docs.commscope.com/bundle/fastiron-08092-securityguide/page/GUID-32D3BB01-E600-4FBE-B555-7570B5024D34.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="ruckus wireless admin login panel - detect info identify web-based control panels ruckus wireless admin login panel was detected. pussycat0x discovery exposed panel ruckus ruckuswireless cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Ruckus Wireless Admin Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/ruckus-wireless-admin-login.yaml" target="_blank" rel="noopener" class="nt-source-link">ruckus-wireless-admin-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)ruckus&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Ruckus Wireless admin login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">exposed</span><span class="nt-tag">panel</span><span class="nt-tag">ruckus</span><span class="nt-tag">ruckuswireless</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="ruckus wireless unleashed login panel - detect info identify web-based control panels ruckus wireless unleashed login panel was detected. idealphase discovery panel ruckus ruckuswireless cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Ruckus Wireless Unleashed Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/ruckus-unleashed-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">ruckus-unleashed-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> idealphase</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)unleashed login&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Ruckus Wireless Unleashed login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">ruckus</span><span class="nt-tag">ruckuswireless</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.commscope.com/ruckus/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="ruckus vriot iot controller - authentication bypass critical identify critical remote vulnerabilities ruckus vriot through 1.5.1.0.21 contains an api backdoor caused by a hardcoded token in validate_token.py,letting unauthenticated attackers interact with the api without authentication. cve-2020-26879 dhiyaneshdk api auth-bypass backdoor cve cve2020 iot ruckus vkev vriot vuln cwe-798" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Ruckus vRioT IoT Controller - Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2020/CVE-2020-26879.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2020-26879.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 11, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/798.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-798</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2020-26879" target="_blank" rel="noopener" class="nt-cve-link">CVE-2020-26879</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)RIoT Controller&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Ruckus vRioT through 1.5.1.0.21 contains an API backdoor caused by a hardcoded token in validate_token.py,letting unauthenticated attackers interact with the API without authentication.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can interact with the API without authentication via a hardcoded token, allowing complete control over the IoT controller and connected devices.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to Ruckus vRioT version 1.5.1.0.22 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">api</span><span class="nt-tag">auth-bypass</span><span class="nt-tag">backdoor</span><span class="nt-tag">cve</span><span class="nt-tag">cve2020</span><span class="nt-tag">iot</span><span class="nt-tag">ruckus</span><span class="nt-tag">vkev</span><span class="nt-tag">vriot</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://adepts.of0x.cc/ruckus-vriot-rce/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://adepts.of0x.cc" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://twitter.com/TheXC3LL" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://x-c3ll.github.io" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/alphaSeclab/sec-daily-2020" target="_blank" rel="noopener" class="nt-ref-link">[5]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2020-26879" target="_blank" rel="noopener" class="nt-ref-link">[6]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="ruijie nbr series routers - default login high identify default logins in web-based control panels ruijie nbr series routers default login username and password was discovered. pussycat0x default-login ruijie-nbr vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Ruijie NBR Series Routers - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/ruijie/ruijie-nbr-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">ruijie-nbr-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 4, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)上层网络出现异常，请检查外网线路或联系ISP运营商协助排查&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Ruijie NBR Series Routers Default Login username and password was discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">ruijie-nbr</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="ruijie rg-eg - remote code execution critical identify critical remote vulnerabilities ruijie rg-eg easy gateway web management system front-end rce has a command execution vulnerability. an attacker without identity authentication can execute arbitrary commands to control server permissions. dhiyaneshdk iot rce router ruijie vuln cwe-77" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Ruijie RG-EG - Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/vulnerabilities/ruijie/ruijie-rg-eg-web-mis-rce.yaml" target="_blank" rel="noopener" class="nt-source-link">ruijie-rg-eg-web-mis-rce.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 25, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/77.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-77</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)请输入您的RG-EG易网关的用户名和密码&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Ruijie RG-EG easy gateway WEB management system front-end RCE has a command execution vulnerability. An attacker without identity authentication can execute arbitrary commands to control server permissions.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">iot</span><span class="nt-tag">rce</span><span class="nt-tag">router</span><span class="nt-tag">ruijie</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/xinyisleep/pocscan/blob/main/%E9%94%90%E6%8D%B7/%E9%94%90%E6%8D%B7_EG%E6%98%93%E7%BD%91%E5%85%B3_WEB%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F_%E5%89%8D%E5%8F%B0RCE.py" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="ruijie rg-ew1200g router background - login bypass high identify critical remote vulnerabilities a vulnerability was found in ruijie rg-ew1200g 07161417 r483. it has been rated as critical. affected by this issue is some unknown functionality of the file /api/sys/login. the manipulation leads to improper authentication. the attack may be launched remotely. the exploit has been disclosed to the public and may be used. vdb-237518 is the identifier assigned to this vulnerability. cve-2023-4415 dhiyaneshdk cve cve2023 router ruijie ruijienetworks vuln cwe-287" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Ruijie RG-EW1200G Router Background - Login Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-4415.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-4415.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 31, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/287.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-287</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-4415" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-4415</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)app\\.2fe6356cdd1ddd0eb8d6317d1a48d379\\.css&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A vulnerability was found in Ruijie RG-EW1200G 07161417 r483. It has been rated as critical. Affected by this issue is some unknown functionality of the file /api/sys/login. The manipulation leads to improper authentication. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-237518 is the identifier assigned to this vulnerability.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can bypass authentication on the Ruijie RG-EW1200G router through improper authentication checks in the login API, potentially gaining administrative access to the router and compromising network security.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update Ruijie RG-EW1200G firmware to a version newer than 07161417 r483 that implements proper authentication validation in the login API.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">router</span><span class="nt-tag">ruijie</span><span class="nt-tag">ruijienetworks</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-4415" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/blakespire/repoforcve/tree/main/RG-EW1200G-logic" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://vuldb.com/?ctiid.237518" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://vuldb.com/?id.237518" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/thedarknessdied/Ruijie_RG-EW1200G_login_bypass-CVE-2023-4415" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="ruijie rg-nbs2009g-p - improper authentication critical identify critical remote vulnerabilities an issue in ruijie rg-nbs2009g-p rgos v.10.4(1)p2 release(9736) allows a remote attacker to gain privileges via the system/config_menu.htm. cve-2024-24116 friea bac cve cve2024 exposure ruijie vuln cwe-287" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Ruijie RG-NBS2009G-P - Improper Authentication</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-24116.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-24116.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> friea</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 29, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/287.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-287</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-24116" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-24116</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)ruijie\\.com\\.cn&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An issue in Ruijie RG-NBS2009G-P RGOS v.10.4(1)P2 Release(9736) allows a remote attacker to gain privileges via the system/config_menu.htm.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can bypass authentication to gain administrative access and control the Ruijie switch configuration.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update Ruijie RG-NBS2009G-P firmware to a version that addresses CVE-2024-24116.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">bac</span><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">exposure</span><span class="nt-tag">ruijie</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/zty-1995/RG-NBS2009G-P-switch/tree/main/Unauthorized%20Access%20Vulnerability" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://gist.github.com/zty-1995/7a5e3ad0eb3b6c44db1a6eb4092893d3" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-24116" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="ruijie rg-uac login panel - detect info identify web-based control panels ruijie rg-uac login panel was detected. princechaddha discovery firewall panel router ruijie cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Ruijie RG-UAC Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/ruijie/rg-uac-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">rg-uac-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> princechaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)get_verify_info&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Ruijie RG-UAC login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">firewall</span><span class="nt-tag">panel</span><span class="nt-tag">router</span><span class="nt-tag">ruijie</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="rundeck - default login high identify default logins in web-based control panels rundeck default login was discovered. karkis3c default-login rundeck vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Rundeck - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/rundeck/rundeck-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">rundeck-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> karkis3c</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 27, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;Rundeck - Login&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Rundeck default login was discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">rundeck</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://raw.githubusercontent.com/karkis3c/bugbounty/main/nuclei-templates/default-login/rundeck-default-login.yaml" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://docs.rundeck.com/docs/learning/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="rundeck login panel - detect info identify web-based control panels rundeck login panel was detected. dhiyaneshdk, daffainfo discovery panel rundeck cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Rundeck Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/rundeck-login.yaml" target="_blank" rel="noopener" class="nt-source-link">rundeck-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk, daffainfo</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Rundeck&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Rundeck login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">rundeck</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="rustdesk web client - default login high identify default logins in web-based control panels detected rustdesk web client admin console was using default credentials. 0x_akoko default-login rustdesk remote-access" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">RustDesk Web Client - Default login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/rustdesk-webclient-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">rustdesk-webclient-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_Akoko</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 23, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)RustDesk API Admin&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detected RustDesk Web Client Admin Console was using default credentials.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">rustdesk</span><span class="nt-tag">remote-access</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://rustdesk.com/docs/en/self-host/rustdesk-server-pro/console/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/rustdesk/rustdesk-server-pro" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="rustfs - detect info identify web-based control panels detects a rustfs server, a high-performance, distributed object storage system built in rust. icarot tech rustfs rustfs detect" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Rustfs - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/technologies/rustfs-detect.yaml" target="_blank" rel="noopener" class="nt-source-link">rustfs-detect.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> icarot</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 20, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)RustFS&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detects a Rustfs server, a high-performance, distributed object storage system built in Rust.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">tech</span><span class="nt-tag">rustfs</span><span class="nt-tag">rustfs</span><span class="nt-tag">detect</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/rustfs/rustfs" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="rustici content controller panel - detect info identify web-based control panels rustici content controller panel was detected. dhiyaneshdk panel rustici discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Rustici Content Controller Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/rustici-content-controller.yaml" target="_blank" rel="noopener" class="nt-source-link">rustici-content-controller.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Rustici Content Controller&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Rustici Content Controller panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">rustici</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="sap analytics cloud panel - detect info identify web-based control panels sap analytics cloud panel was detected. righettod panel sap cloudanalytics discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">SAP Analytics Cloud Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/sap-cloud-analytics.yaml" target="_blank" rel="noopener" class="nt-source-link">sap-cloud-analytics.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)SAP Analytics Cloud&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">SAP Analytics Cloud panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">sap</span><span class="nt-tag">cloudanalytics</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="sap knowledge warehouse &lt;=7.5.0 - cross-site scripting medium identify critical remote vulnerabilities sap knowledge warehouse 7.30, 7.31, 7.40, and 7.50 contain a reflected cross-site scripting vulnerability via the usage of one sap kw component within a web browser. cve-2021-42063 pdteam cve cve2021 packetstorm sap seclists vkev vuln xss cwe-79" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">SAP Knowledge Warehouse &lt;=7.5.0 - Cross-Site Scripting</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2021/CVE-2021-42063.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2021-42063.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pdteam</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-79</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2021-42063" target="_blank" rel="noopener" class="nt-cve-link">CVE-2021-42063</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-266008933&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">SAP Knowledge Warehouse 7.30, 7.31, 7.40, and 7.50 contain a reflected cross-site scripting vulnerability via the usage of one SAP KW component within a web browser.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to inject malicious scripts into web pages viewed by users, leading to potential data theft, session hijacking, or defacement.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to a patched version of SAP Knowledge Warehouse (&gt;=7.5.1) to mitigate the XSS vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2021</span><span class="nt-tag">packetstorm</span><span class="nt-tag">sap</span><span class="nt-tag">seclists</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">xss</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://seclists.org/fulldisclosure/2022/Mar/32" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://packetstormsecurity.com/files/166369/SAP-Knowledge-Warehouse-7.50-7.40-7.31-7.30-Cross-Site-Scripting.html" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://twitter.com/MrTuxracer/status/1505934549217382409" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2021-42063" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="http://packetstormsecurity.com/files/166369/SAP-Knowledge-Warehouse-7.50-7.40-7.31-7.30-Cross-Site-Scripting.html" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="sap management console - panel info identify web-based control panels detected the sap management console (sap mc) web panel by requesting /sapmc/sapmc.html and checking for a gsoap server header the page title. lrvt,l4rm4nd panel sap sapmc ui discovery login" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">SAP Management Console - Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/sap-management-console-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">sap-management-console-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> LRVT,l4rm4nd</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 4, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)SAP Management Console&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detected the SAP Management Console (SAP MC) web panel by requesting /sapmc/sapmc.html and checking for a gSOAP server header the page title.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">sap</span><span class="nt-tag">sapmc</span><span class="nt-tag">ui</span><span class="nt-tag">discovery</span><span class="nt-tag">login</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="sap memory pipes (mpi) desynchronization critical identify critical remote vulnerabilities sap netweaver application server abap, sap netweaver application server java, abap platform, sap content server 7.53 and sap web dispatcher are vulnerable to request smuggling and request concatenation attacks. an unauthenticated attacker can prepend a victim&#39;s request with arbitrary data. this way, the attacker can execute functions impersonating the victim or poison intermediary web caches. a successful attack could result in complete compromise of confidentiality, integrity and availability of the system. cve-2022-22536 pdteam cve cve2022 kev memory-pipes netweaver sap smuggling vkev vuln web-dispatcher cwe-444" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">SAP Memory Pipes (MPI) Desynchronization</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-22536.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-22536.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pdteam</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/444.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-444</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-22536" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-22536</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-266008933&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and SAP Web Dispatcher are vulnerable to request smuggling and request concatenation attacks. An unauthenticated attacker can prepend a victim&#39;s request with arbitrary data. This way, the attacker can execute functions impersonating the victim or poison intermediary web caches. A successful attack could result in complete compromise of Confidentiality, Integrity and Availability of the system.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability can result in unauthorized access to sensitive data and potential data leakage.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches and updates provided by SAP to mitigate this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">kev</span><span class="nt-tag">memory-pipes</span><span class="nt-tag">netweaver</span><span class="nt-tag">sap</span><span class="nt-tag">smuggling</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">web-dispatcher</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-22536" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://wiki.scn.sap.com/wiki/display/PSR/SAP+Security+Patch+Day+-+February+2022" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/Onapsis/onapsis_icmad_scanner" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://blogs.sap.com/2022/02/11/remediation-of-cve-2022-22536-request-smuggling-and-request-concatenation-in-sap-netweaver-sap-content-server-and-sap-web-dispatcher/" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://launchpad.support.sap.com/#/notes/3123396" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="sap netweaver - backdoor detection critical identify critical remote vulnerabilities detected a potential backdoor in sap netweaver allowing unauthorized command execution. dhiyaneshdk sap netweaver backdoor vuln" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">SAP NetWeaver - Backdoor Detection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/vulnerabilities/backdoor/sap-netweaver-backdoor.yaml" target="_blank" rel="noopener" class="nt-source-link">sap-netweaver-backdoor.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 26, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)SAP NetWeaver Application Server Java&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detected a potential backdoor in SAP NetWeaver allowing unauthorized command execution.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">sap</span><span class="nt-tag">netweaver</span><span class="nt-tag">backdoor</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.bleepingcomputer.com/news/security/sap-fixes-suspected-netweaver-zero-day-exploited-in-attacks/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="sap netweaver application server java 7.5 - local file inclusion high identify critical remote vulnerabilities sap netweaver application server java 7.5 is susceptible to local file inclusion in scheduler/ui/js/ffffffffbca41eb4/uiutiljavascriptjs. this can allow remote attackers to read arbitrary files via a .. (dot dot) in the query string, as exploited in the wild in august 2017, aka sap security note 2486657. cve-2017-12637 apt-mirror cve cve2017 java kev lfi sap traversal vkev vuln cwe-22" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">SAP NetWeaver Application Server Java 7.5 - Local File Inclusion</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2017/CVE-2017-12637.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2017-12637.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> apt-mirror</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2017-12637" target="_blank" rel="noopener" class="nt-cve-link">CVE-2017-12637</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-266008933&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">SAP NetWeaver Application Server Java 7.5 is susceptible to local file inclusion in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS. This can allow remote attackers to read arbitrary files via a .. (dot dot) in the query string, as exploited in the wild in August 2017, aka SAP Security Note 2486657.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to read sensitive files on the server, leading to unauthorized access, data leakage, and potential system compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches and updates provided by SAP to fix the LFI vulnerability in SAP NetWeaver Application Server Java 7.5.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2017</span><span class="nt-tag">java</span><span class="nt-tag">kev</span><span class="nt-tag">lfi</span><span class="nt-tag">sap</span><span class="nt-tag">traversal</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://download.ernw-insight.de/troopers/tr18/slides/TR18_SAP_SAP-Bugs-The-Phantom-Security.pdf" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://web.archive.org/web/20170807202056/http://www.sh0w.top/index.php/archives/7/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2017-12637" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="http://www.sh0w.top/index.php/archives/7/" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/ARPSyndicate/cvemon" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="sap netweaver composition environment tools - detect info identify web-based control panels detects the presence of the sap netweaver process integration / composition environment tools page ap3r sap netweaver cet detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">SAP NetWeaver Composition Environment Tools - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/sap-netweaver-cet-detect.yaml" target="_blank" rel="noopener" class="nt-source-link">sap-netweaver-cet-detect.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ap3r</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 14, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-266008933&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detects the presence of the SAP NetWeaver Process Integration / Composition Environment Tools page</div></div></div>
  <div class="nt-tags"><span class="nt-tag">sap</span><span class="nt-tag">netweaver</span><span class="nt-tag">cet</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://help.sap.com/doc/saphelp_scm700_ehp02/7.0.2/en-US/f6/2a7cb018bc4b239ea5b7af675a18ef/content.htm?no_cache=true" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="sap netweaver sql injection vulnerability critical identify critical remote vulnerabilities sql injection vulnerability in the uddi server of the sap netweaver j2ee engine 7.40 allows remote attackers to
execute arbitrary sql commands via unspecified vectors, as documented within sap security note 2101079. cve-2016-2386 n3integration cve cve2016 kev vuln sqli cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">SAP NetWeaver SQL Injection Vulnerability</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2016/CVE-2016-2386.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2016-2386.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> n3integration</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 25, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2016-2386" target="_blank" rel="noopener" class="nt-cve-link">CVE-2016-2386</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;product&#34;] contains &#39;SAP:NetWeaver Application Server&#39;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">SQL injection vulnerability in the UDDI server of the SAP NetWeaver J2EE Engine 7.40 allows remote attackers to
execute arbitrary SQL commands via unspecified vectors, as documented within SAP Security Note 2101079.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply updates per vendor instructions.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2016</span><span class="nt-tag">kev</span><span class="nt-tag">vuln</span><span class="nt-tag">sqli</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="http://seclists.org/fulldisclosure/2016/May/56" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-2386" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.cve.org/CVERecord?id=CVE-2016-2386" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="sap solution manager 7.2 - remote command execution critical identify critical remote vulnerabilities sap solution manager (solman) running version 7.2 has a remote command execution vulnerability within the sap eem servlet (tc~smd~agent~application~eem). the vulnerability occurs due to missing authentication checks when submitting soap requests to the /eemadminservice/eemadmin page to get information about connected smdagents, send http request (ssrf), and execute os commands on connected smdagent. cve-2020-6207 _generic_human_ cve cve2020 kev rce sap solman vkev vuln cwe-306" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">SAP Solution Manager 7.2 - Remote Command Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2020/CVE-2020-6207.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2020-6207.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> _generic_human_</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/306.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-306</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2020-6207" target="_blank" rel="noopener" class="nt-cve-link">CVE-2020-6207</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.images.mmh3&#34;] == &#34;694811822&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">SAP Solution Manager (SolMan) running version 7.2 has a remote command execution vulnerability within the SAP EEM servlet (tc~smd~agent~application~eem). The vulnerability occurs due to missing authentication checks when submitting SOAP requests to the /EemAdminService/EemAdmin page to get information about connected SMDAgents, send HTTP request (SSRF), and execute OS commands on connected SMDAgent.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute arbitrary commands on the affected system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches provided by SAP to mitigate this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2020</span><span class="nt-tag">kev</span><span class="nt-tag">rce</span><span class="nt-tag">sap</span><span class="nt-tag">solman</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://launchpad.support.sap.com/#/notes/2890213" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=540935305" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://i.blackhat.com/USA-20/Wednesday/us-20-Artuso-An-Unauthenticated-Journey-To-Root-Pwning-Your-Companys-Enterprise-Software-Servers-wp.pdf" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/chipik/SAP_EEM_CVE-2020-6207" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://www.rapid7.com/db/modules/auxiliary/admin/sap/cve_2020_6207_solman_rce/" target="_blank" rel="noopener" class="nt-ref-link">[5]</a> <a href="https://www.rapid7.com/db/modules/exploit/multi/sap/cve_2020_6207_solman_rs/" target="_blank" rel="noopener" class="nt-ref-link">[6]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2020-6207" target="_blank" rel="noopener" class="nt-ref-link">[7]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="sap successfactors login panel - detect info identify web-based control panels sap successfactors login panel was detected. tess detect discovery panel sap cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">SAP SuccessFactors Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/sap-successfactors-detect.yaml" target="_blank" rel="noopener" class="nt-source-link">sap-successfactors-detect.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> tess</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)login - sap successfactors&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">SAP SuccessFactors login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">sap</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="sap xmii 15.0 for sap netweaver 7.4 - local file inclusion high identify critical remote vulnerabilities sap xmii 15.0 for sap netweaver 7.4 is susceptible to a local file inclusion vulnerability in the getfilelist function. this can allow remote attackers to read arbitrary files via a .. (dot dot) in the path parameter to /catalog, aka sap security note 2230978. cve-2016-2389 daffainfo cve cve2016 edb lfi packetstorm sap seclists vkev vuln cwe-22" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">SAP xMII 15.0 for SAP NetWeaver 7.4 - Local File Inclusion</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2016/CVE-2016-2389.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2016-2389.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> daffainfo</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2016-2389" target="_blank" rel="noopener" class="nt-cve-link">CVE-2016-2389</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-266008933&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">SAP xMII 15.0 for SAP NetWeaver 7.4 is susceptible to a local file inclusion vulnerability in the GetFileList function. This can allow remote attackers to read arbitrary files via a .. (dot dot) in the path parameter to /Catalog, aka SAP Security Note 2230978.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to read sensitive files on the server, leading to unauthorized access and potential data leakage.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches and updates provided by SAP to mitigate the vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2016</span><span class="nt-tag">edb</span><span class="nt-tag">lfi</span><span class="nt-tag">packetstorm</span><span class="nt-tag">sap</span><span class="nt-tag">seclists</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://web.archive.org/web/20211209003818/https://erpscan.io/advisories/erpscan-16-009-sap-xmii-directory-traversal-vulnerability/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="http://packetstormsecurity.com/files/137046/SAP-MII-15.0-Directory-Traversal.html" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.exploit-db.com/exploits/39837/" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2016-2389" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="http://seclists.org/fulldisclosure/2016/May/40" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="sas login panel - detect info identify web-based control panels sas login panel has been detected. ritikchaddha discovery panel sas cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">SAS Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/sas-login-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">sas-login-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;957255151&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">SAS login panel has been detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">sas</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="sauter moduweb vision panel - detect info identify web-based control panels sauter moduweb vision was detected. righettod discovery login moduweb panel sauter" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">SAUTER moduWeb Vision Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/sauter-moduwebvision-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">sauter-moduwebvision-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 30, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-1663319756&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Sauter moduWeb Vision was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">login</span><span class="nt-tag">moduweb</span><span class="nt-tag">panel</span><span class="nt-tag">sauter</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.sauter-controls.com" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="seh utnserver pro/promax/inu-100 20.1.22 - cross-site scripting high identify critical remote vulnerabilities a vulnerability was found in utnserver pro, utnserver promax, and inu-100 version 20.1.22 and earlier, affecting the device description parameter in the web interface. this flaw allows stored cross-site scripting (xss), enabling attackers to inject javascript code. the attack can be executed remotely by tricking victims into visiting a malicious website, potentially leading to session hijacking. this vulnerability is publicly disclosed and identified as cve-2024-5420. cve-2024-5420 bl4ckp4r4d1s3 cve cve2024 seclists seh utnserver vuln xss cwe-79" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">SEH utnserver Pro/ProMAX/INU-100 20.1.22 - Cross-Site Scripting</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-5420.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-5420.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> bl4ckp4r4d1s3</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 14, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-79</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-5420" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-5420</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)utnserver Control Center&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A vulnerability was found in utnserver Pro, utnserver ProMAX, and INU-100 version 20.1.22 and earlier, affecting the device description parameter in the web interface. This flaw allows stored cross-site scripting (XSS), enabling attackers to inject JavaScript code. The attack can be executed remotely by tricking victims into visiting a malicious website, potentially leading to session hijacking. This vulnerability is publicly disclosed and identified as CVE-2024-5420.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Authenticated attackers can inject malicious JavaScript into the device description field, leading to stored XSS that can hijack user sessions when victims access the interface.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update SEH utnserver Pro/ProMAX/INU-100 to a version later than 20.1.22 that addresses the XSS vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">seclists</span><span class="nt-tag">seh</span><span class="nt-tag">utnserver</span><span class="nt-tag">vuln</span><span class="nt-tag">xss</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://cyberdanube.com/en/en-multiple-vulnerabilities-in-seh-untserver-pro/index.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://seclists.org/fulldisclosure/2024/Jun/4" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-5420" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="http://seclists.org/fulldisclosure/2024/Jun/4" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://cyberdanube.com/en/en-multiple-vulnerabilities-in-oring-iap420/index.html" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="sel real-time automation controller - login panel info identify web-based control panels schweitzer engineering laboratories (sel) real-time automation controller (rtac)
is a programmable automation controller used in electric utility and industrial
automation environments for protection, control, and automation. the web interface
exposes a management panel for configuration and monitoring. rxerium discovery energy ics panel rtac scada schweitzer sel utilities" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">SEL Real-Time Automation Controller - Login Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/sel-rtac-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">sel-rtac-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 27, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;^SEL-RTAC&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Schweitzer Engineering Laboratories (SEL) Real-Time Automation Controller (RTAC)
is a programmable automation controller used in electric utility and industrial
automation environments for protection, control, and automation. The web interface
exposes a management panel for configuration and monitoring.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">energy</span><span class="nt-tag">ics</span><span class="nt-tag">panel</span><span class="nt-tag">rtac</span><span class="nt-tag">scada</span><span class="nt-tag">schweitzer</span><span class="nt-tag">sel</span><span class="nt-tag">utilities</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://selinc.com/products/3530/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://selinc.com/products/3555/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="sgp login panel - detect info identify web-based control panels sgp login panel was detected. dhiyaneshdk panel sgp discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">SGP Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/sgp-login-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">sgp-login-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)SGP&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">SGP login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">sgp</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="shoutcast server panel - detect info identify web-based control panels shoutcast server panel was detected. dhiyaneshdk discovery panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">SHOUTcast Server Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/shoutcast-server.yaml" target="_blank" rel="noopener" class="nt-source-link">shoutcast-server.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)SHOUTcast Server&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">SHOUTcast Server panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="skysea client view panel - detect info identify web-based control panels skysea client view panel was detected. rxerium panel skysea detect login discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">SKYSEA Client View Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/skysea-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">skysea-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 15, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;385597939&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">SKYSEA Client View panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">skysea</span><span class="nt-tag">detect</span><span class="nt-tag">login</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.skyseaclientview.net/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="soplanning - default login high identify default logins in web-based control panels soplanning contains default credentials. an attacker can obtain access to user accounts and access sensitive information, modify data, and/or execute unauthorized operations. s4e-io default-login soplanning vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">SOPlanning - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/soplanning/soplanning-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">soplanning-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> s4e-io</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 7, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)soplanning&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">SOPlanning contains default credentials. An attacker can obtain access to user accounts and access sensitive information, modify data, and/or execute unauthorized operations.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">soplanning</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.soplanning.org/en/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="sound4 impact/first/pulse/eco &lt;= 2.x - authentication bypass high identify critical remote vulnerabilities the application suffers from an sql injection vulnerability. input passed through the &#39;username&#39; post parameter in &#39;index.php&#39; is not properly sanitised before being returned to the user or used in sql queries. this can be exploited to manipulate sql queries by injecting arbitrary sql code and bypass the authentication mechanism. r3y3r53 auth-bypass sound4 sqli vuln zeroscience cwe-89" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">SOUND4 IMPACT/FIRST/PULSE/Eco &lt;= 2.x - Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/vulnerabilities/other/sound4-impact-auth-bypass.yaml" target="_blank" rel="noopener" class="nt-source-link">sound4-impact-auth-bypass.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> r3Y3r53</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 17, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-1548359600&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The application suffers from an SQL Injection vulnerability. Input passed through the &#39;username&#39; POST parameter in &#39;index.php&#39; is not properly sanitised before being returned to the user or used in SQL queries. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code and bypass the authentication mechanism.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">sound4</span><span class="nt-tag">sqli</span><span class="nt-tag">vuln</span><span class="nt-tag">zeroscience</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.zeroscience.mk/en/vulnerabilities/ZSL-2022-5727.php" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="sound4 impact/first/pulse/eco &lt;=2.x (phptail) unauthenticated file disclosure medium identify critical remote vulnerabilities the application suffers from an unauthenticated file disclosure vulnerability. using the &#39;file&#39; get parameter attackers can disclose arbitrary files on the affected device and disclose sensitive and system information. arafatansari packetstorm lfi sound4 unauth disclosure vuln" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">SOUND4 IMPACT/FIRST/PULSE/Eco &lt;=2.x (PHPTail) Unauthenticated File Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/vulnerabilities/other/sound4-file-disclosure.yaml" target="_blank" rel="noopener" class="nt-source-link">sound4-file-disclosure.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> arafatansari</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)SOUND4&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The application suffers from an unauthenticated file disclosure vulnerability. Using the &#39;file&#39; GET parameter attackers can disclose arbitrary files on the affected device and disclose sensitive and system information.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">packetstorm</span><span class="nt-tag">lfi</span><span class="nt-tag">sound4</span><span class="nt-tag">unauth</span><span class="nt-tag">disclosure</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://packetstormsecurity.com/files/170263/SOUND4-IMPACT-FIRST-PULSE-Eco-2.x-Unauthenticated-File-Disclosure.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.zeroscience.mk/en/vulnerabilities/ZSL-2022-5736.php" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="spip - remote command execution critical identify critical remote vulnerabilities spip before 4.2.1 allows remote code execution via form values in the public area because serialization is mishandled. the fixed versions are 3.2.18, 4.0.10, 4.1.8, and 4.2.1. cve-2023-27372 dhiyaneshdk,nuts7 cve cve2023 packetstorm rce spip vkev vuln" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">SPIP - Remote Command Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-27372.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-27372.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK,nuts7</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 22, 2023</span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-27372" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-27372</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)spip\\.php\\?page=backend&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. The fixed versions are 3.2.18, 4.0.10, 4.1.8, and 4.2.1.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute arbitrary commands on the target system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches or upgrade to a patched version of SPIP.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">packetstorm</span><span class="nt-tag">rce</span><span class="nt-tag">spip</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://packetstormsecurity.com/files/171921/SPIP-Remote-Command-Execution.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-27372" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/nuts7/CVE-2023-27372" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="http://packetstormsecurity.com/files/171921/SPIP-Remote-Command-Execution.html" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="http://packetstormsecurity.com/files/173044/SPIP-4.2.1-Remote-Code-Execution.html" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="sql buddy login panel - detect info identify web-based control panels sql buddy login panel was detected. nullfuzz discovery panel sqlbuddy cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">SQL Buddy Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/sqlbuddy-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">sqlbuddy-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> nullfuzz</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)SQL Buddy&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">SQL Buddy login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">sqlbuddy</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="http://sqlbuddy.com/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="sql monitor - discovery info identify web-based control panels sql monitor was discovered. dhiyaneshdk discovery panel red-gate cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">SQL Monitor - Discovery</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/sql-monitor.yaml" target="_blank" rel="noopener" class="nt-source-link">sql-monitor.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)sql monitor&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">SQL Monitor was discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">red-gate</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="ssh privx login panel - detect info identify web-based control panels ssh privx login panel was detected. korteke discovery panel privx cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">SSH PrivX Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/privx-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">privx-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> korteke</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)PrivX&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">SSH PrivX login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">privx</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.ssh.com/products/privx/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="ssl vpn session hijacking critical identify critical remote vulnerabilities an improper authentication vulnerability in the sslvpn authentication mechanism allows a remote attacker to bypass authentication. cve-2024-53704 johnk3r cve cve2024 kev sonicwall vkev vuln cwe-287" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">SSL VPN Session Hijacking</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-53704.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-53704.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> johnk3r</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 11, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/287.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-287</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-53704" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-53704</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body.mmh3&#34;] == &#34;-1466805544&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can hijack SSL VPN sessions by bypassing authentication mechanisms and gaining unauthorized access to the VPN.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update SonicWall to a version that patches CVE-2024-53704 as specified in PSIRT advisory SNWLID-2025-0003.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">kev</span><span class="nt-tag">sonicwall</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://bishopfox.com/blog/sonicwall-cve-2024-53704-ssl-vpn-session-hijacking" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0003" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="stagil navigation for jira menu &amp; themes &lt;2.0.52 - local file inclusion high identify critical remote vulnerabilities stagil navigation for jira menu &amp; themes plugin before 2.0.52 is susceptible to local file inclusion via modifying the filename parameter to the snjcustomdesignconfig endpoint. an attacker can inject arbitrary script in the browser of an unsuspecting user in the context of the affected site. this can potentially allow the attacker to steal cookie-based authentication credentials and launch other attacks. cve-2023-26255 dhiyaneshdk atlassian cms cve cve2023 jira lfi stagil vkev vuln cwe-22" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">STAGIL Navigation for Jira Menu &amp; Themes &lt;2.0.52 - Local File Inclusion</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-26255.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-26255.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-26255" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-26255</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)jira&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">STAGIL Navigation for Jira Menu &amp; Themes plugin before 2.0.52 is susceptible to local file inclusion via modifying the fileName parameter to the snjCustomDesignConfig endpoint. An attacker can inject arbitrary script in the browser of an unsuspecting user in the context of the affected site. This can potentially allow the attacker to steal cookie-based authentication credentials and launch other attacks.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can exploit this vulnerability to read sensitive files on the server.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade STAGIL Navigation for Jira Menu &amp; Themes to version 2.0.52 or higher to fix the Local File Inclusion vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">atlassian</span><span class="nt-tag">cms</span><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">jira</span><span class="nt-tag">lfi</span><span class="nt-tag">stagil</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/1nters3ct/CVEs/blob/main/CVE-2023-26255.md" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://marketplace.atlassian.com/apps/1216090/stagil-navigation-for-jira-menus-themes?tab=overview&amp;hosting=cloud" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-26255" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/nomi-sec/PoC-in-GitHub" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/tucommenceapousser/CVE-2023-26255-Exp" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="stagil navigation for jira menu &amp; themes &lt;2.0.52 - local file inclusion high identify critical remote vulnerabilities stagil navigation for jira menu &amp; themes plugin before 2.0.52 is susceptible to local file inclusion via modifying the filename parameter to the snjfooternavigationconfig endpoint. an attacker can inject arbitrary script in the browser of an unsuspecting user in the context of the affected site. this can potentially allow the attacker to steal cookie-based authentication credentials and launch other attacks. cve-2023-26256 pikpikcu atlassian cms cve cve2023 jira lfi stagil vkev vuln cwe-22" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">STAGIL Navigation for Jira Menu &amp; Themes &lt;2.0.52 - Local File Inclusion</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-26256.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-26256.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pikpikcu</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-26256" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-26256</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)jira&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">STAGIL Navigation for Jira Menu &amp; Themes plugin before 2.0.52 is susceptible to local file inclusion via modifying the fileName parameter to the snjFooterNavigationConfig endpoint. An attacker can inject arbitrary script in the browser of an unsuspecting user in the context of the affected site. This can potentially allow the attacker to steal cookie-based authentication credentials and launch other attacks.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can exploit this vulnerability to read sensitive files on the server.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade STAGIL Navigation for Jira Menu &amp; Themes to version 2.0.52 or higher to fix the Local File Inclusion vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">atlassian</span><span class="nt-tag">cms</span><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">jira</span><span class="nt-tag">lfi</span><span class="nt-tag">stagil</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/1nters3ct/CVEs/blob/main/CVE-2023-26256.md" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://marketplace.atlassian.com/apps/1216090/stagil-navigation-for-jira-menus-themes?tab=overview&amp;hosting=cloud" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-26256" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/0x7eTeam/CVE-2023-26256" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/ARPSyndicate/cvemon" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="sungrow logger1000 panel - detect info identify web-based control panels sungrow (solar energy inverter monitoring devices) logger1000 panel was detected. gy741 panel logger1000 sungrow discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">SUNGROW Logger1000 Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/sungrow-logger1000-detect.yaml" target="_blank" rel="noopener" class="nt-source-link">sungrow-logger1000-detect.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> gy741</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)logger&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">SUNGROW (Solar Energy Inverter Monitoring Devices) Logger1000 panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">logger1000</span><span class="nt-tag">sungrow</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.europe-solarstore.com/download/Sungrow/Sungrow-data-logger-1000_1000B-usert-manual.pdf" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="suse manager server - panel info identify web-based control panels suse manager login panel detected. darses detect discovery login panel suse" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">SUSE Manager Server - Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/suse-manager-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">suse-manager-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> darses</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 30, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)SUSE Manager - Sign In&#34;}) || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)SUSE Multi-Linux Manager - Sign In&#34;}) || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Uyuni - Sign In&#34;}) || service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1158194469&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">SUSE Manager login panel detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">login</span><span class="nt-tag">panel</span><span class="nt-tag">suse</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="safenet authentication login panel - detect info identify web-based control panels safenet authentication service self enrollment login panel was detected. righettod panel safenet thales login detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">SafeNet Authentication Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/safenet-authentication-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">safenet-authentication-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 25, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Self Enrollment&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">SafeNet Authentication Service Self Enrollment login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">safenet</span><span class="nt-tag">thales</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://cpl.thalesgroup.com/access-management/safenet-trusted-access" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="sage x3 login panel - detect info identify web-based control panels sage x3 login panel was detected. pikpikcu,daffainfo discovery login panel sage cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Sage X3 Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/sage-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">sage-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pikpikcu,daffainfo</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)sage x3&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Sage X3 login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">login</span><span class="nt-tag">panel</span><span class="nt-tag">sage</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="saia pcd web server panel - detect info identify web-based control panels saia pcd web server panel was detected. dhiyaneshdk saia login panel pcd discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Saia PCD Web Server Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/saia-pcd-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">saia-pcd-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 7, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Saia PCD Web Server&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Saia PCD Web Server panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">saia</span><span class="nt-tag">login</span><span class="nt-tag">panel</span><span class="nt-tag">pcd</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="saltstack &lt;=3002 - shell injection critical identify critical remote vulnerabilities saltstack salt through 3002 allows an unauthenticated user with network access to the salt api to use shell injections to run code on the salt-api using the ssh client. cve-2020-16846 dwisiswant0 cve cve2020 kev saltstack vkev vulhub vuln cwe-78" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">SaltStack &lt;=3002 - Shell Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2020/CVE-2020-16846.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2020-16846.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dwisiswant0</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/78.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-78</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2020-16846" target="_blank" rel="noopener" class="nt-cve-link">CVE-2020-16846</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;json.return&#34;] == &#34;Welcome&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">SaltStack Salt through 3002 allows an unauthenticated user with network access to the Salt API to use shell injections to run code on the Salt-API using the SSH client.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can execute arbitrary shell commands via the Salt API, leading to complete server compromise and access to all managed systems.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to a patched version of SaltStack (&gt;=3003) to mitigate this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2020</span><span class="nt-tag">kev</span><span class="nt-tag">saltstack</span><span class="nt-tag">vkev</span><span class="nt-tag">vulhub</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://saltproject.io/on-november-3-2020-saltstack-publicly-disclosed-three-new-cves/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://mp.weixin.qq.com/s/R8qw_lWizGyeJS0jOcYXag" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/vulhub/vulhub/tree/master/saltstack/CVE-2020-16846" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2020-16846" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00029.html" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="saltstack config panel - detect info identify web-based control panels saltstack config panel was detected. pussycat0x discovery login panel saltstack vmware cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">SaltStack Config Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/saltstack-config-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">saltstack-config-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)SaltStack Config&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">SaltStack config panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">login</span><span class="nt-tag">panel</span><span class="nt-tag">saltstack</span><span class="nt-tag">vmware</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="samsung magicinfo panel - detect info identify web-based control panels samsung magicinfo panel was discovered. s4e-io panel login magicinfo detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Samsung MagicINFO Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/magicinfo-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">magicinfo-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> s4e-io</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 22, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)MagicINFO&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Samsung MagicINFO panel was discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">login</span><span class="nt-tag">magicinfo</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.samsung.com/de/business/display-solutions/magicinfo/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="samsung printer - default login high identify default logins in web-based control panels samsung printers contain a default admin login vulnerability. an attacker can obtain access to user accounts and access sensitive information, modify data, and/or execute unauthorized operations. gy741 default-login iot printer samsung vuln cwe-522" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Samsung Printer - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/samsung/samsung-printer-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">samsung-printer-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> gy741</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/522.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-522</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;SyncThru Web Service&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Samsung printers contain a default admin login vulnerability. An attacker can obtain access to user accounts and access sensitive information, modify data, and/or execute unauthorized operations.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">iot</span><span class="nt-tag">printer</span><span class="nt-tag">samsung</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://support.hp.com/gb-en/document/c05591673" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="sanity studio panel - detect info identify web-based control panels sanity studio panel was detected. sanity is a headless cms platform. shivam kamboj panel sanity tech discovery detect" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Sanity Studio Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/sanity-studio-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">sanity-studio-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Shivam Kamboj</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 12, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Sanity Studio&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Sanity Studio panel was detected. Sanity is a headless CMS platform.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">sanity</span><span class="nt-tag">tech</span><span class="nt-tag">discovery</span><span class="nt-tag">detect</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.sanity.io/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="sante pacs server.exe - path traversal information disclosure high identify critical remote vulnerabilities a path traversal information disclosure vulnerability exists in &#34;sante pacs server.exe&#34;. an unauthenticated remote attacker can exploit it to download arbitrary files on the disk drive where the application is installed. cve-2025-2264 dhiyaneshdk cve cve2025 lfi pacs sante vkev vuln cwe-22" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Sante PACS Server.exe - Path Traversal Information Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-2264.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-2264.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 9, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-2264" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-2264</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1185161484&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A Path Traversal Information Disclosure vulnerability exists in &#34;Sante PACS Server.exe&#34;. An unauthenticated remote attacker can exploit it to download arbitrary files on the disk drive where the application is installed.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can exploit path traversal to download arbitrary files from the server, potentially exposing sensitive patient data, credentials, and configuration files.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to Sante PACS Server version 4.1.1 or later that properly validates file paths.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">lfi</span><span class="nt-tag">pacs</span><span class="nt-tag">sante</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.tenable.com/security/research/tra-2025-08" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="satellian intellian aptus web &lt;= 1.24 - remote command execution critical identify critical remote vulnerabilities intellian aptus web 1.24 allows remote attackers to execute arbitrary os commands via the q field within json data to the cgi-bin/libagent.cgi uri. note: a valid sid cookie for a login to the intellian default account might be needed. cve-2020-7980 ritikchaddha aptus cve cve2020 intellian intelliantech packetstorm rce satellian vkev vuln cwe-78" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Satellian Intellian Aptus Web &lt;= 1.24 - Remote Command Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2020/CVE-2020-7980.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2020-7980.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/78.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-78</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2020-7980" target="_blank" rel="noopener" class="nt-cve-link">CVE-2020-7980</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)intellian aptus web&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Intellian Aptus Web 1.24 allows remote attackers to execute arbitrary OS commands via the Q field within JSON data to the cgi-bin/libagent.cgi URI. NOTE: a valid sid cookie for a login to the intellian default account might be needed.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability allows remote attackers to execute arbitrary commands on the target system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to a patched version of Satellian Intellian Aptus Web (version &gt; 1.24).</div></div></div>
  <div class="nt-tags"><span class="nt-tag">aptus</span><span class="nt-tag">cve</span><span class="nt-tag">cve2020</span><span class="nt-tag">intellian</span><span class="nt-tag">intelliantech</span><span class="nt-tag">packetstorm</span><span class="nt-tag">rce</span><span class="nt-tag">satellian</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2020-7980" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://sku11army.blogspot.com/2020/01/intellian-aptus-web-rce-intellian.html" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/Xh4H/Satellian-CVE-2020-7980" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="http://packetstormsecurity.com/files/156143/Satellian-1.12-Remote-Code-Execution.html" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/0xT11/CVE-POC" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="satis composer repository - detect info identify web-based control panels satis composer repository was detected florianmaak panel exposure composer satis discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Satis Composer Repository - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/satis-repository.yaml" target="_blank" rel="noopener" class="nt-source-link">satis-repository.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> FlorianMaak</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 14, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)&lt;a href=\\\\&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Satis composer repository was detected</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">exposure</span><span class="nt-tag">composer</span><span class="nt-tag">satis</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/composer/satis" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="sato - default login high identify default logins in web-based control panels sato using default credentials was discovered. y0no default-login printer sato vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Sato - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/sato/sato-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">sato-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> y0no</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 21, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;Sato&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Sato using default credentials was discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">printer</span><span class="nt-tag">sato</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="sawtoothsoftware lighthouse studio &lt; 9.16.14 - pre-auth remote code execution critical identify critical remote vulnerabilities a pre-authentication remote code execution vulnerability exists in sawtooth software’s lighthouse studio versions prior to 9.16.14. the issue arises from the unsafe use of the `eval` function within the perl cgi component `ciwweb.pl`, where attacker-supplied input inside `hid_random_acarat` is directly passed to `eval`. this allows remote unauthenticated attackers to execute arbitrary perl code on the server. cve-2025-34300 assetnote,dhiyaneshdk,iamnoooob cve cve2025 lighthouse-studio rce sawtoothsoftware ssti vkev vuln cwe-1336,cwe-20" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">SawtoothSoftware Lighthouse Studio &lt; 9.16.14 - Pre-Auth Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-34300.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-34300.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> assetnote,DhiyaneshDK,iamnoooob</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 16, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/1336,CWE-20.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-1336,CWE-20</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-34300" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-34300</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Lighthouse Studio&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A pre-authentication remote code execution vulnerability exists in Sawtooth Software’s Lighthouse Studio versions prior to 9.16.14. The issue arises from the unsafe use of the `eval` function within the Perl CGI component `ciwweb.pl`, where attacker-supplied input inside `hid_Random_ACARAT` is directly passed to `eval`. This allows remote unauthenticated attackers to execute arbitrary Perl code on the server.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can execute arbitrary Perl code through the hid_Random_ACARAT parameter due to unsafe eval usage, achieving complete server compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to Sawtooth Software Lighthouse Studio version 9.16.14 or later that removes unsafe eval usage in ciwweb.pl.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">lighthouse-studio</span><span class="nt-tag">rce</span><span class="nt-tag">sawtoothsoftware</span><span class="nt-tag">ssti</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://slcyber.io/assetnote-security-research-center/rce-in-the-most-popular-survey-software-youve-never-heard-of/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://sawtoothsoftware.com/resources/software-downloads/lighthouse-studio" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-34300" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="scadabr - login panel info identify web-based control panels scadabr is an open-source scada system based on mango automation, widely
used in brazil and latin america for industrial monitoring. the &#34;powered by
mango&#34; tagline in the title is a unique identifier. instances are often
internet-facing without authentication controls. rxerium discovery ics latin-america mango open-source panel scada scadabr" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">ScadaBR - Login Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/scadabr-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">scadabr-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 27, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)ScadaBR Software&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">ScadaBR is an open-source SCADA system based on Mango Automation, widely
used in Brazil and Latin America for industrial monitoring. The &#34;powered by
Mango&#34; tagline in the title is a unique identifier. Instances are often
internet-facing without authentication controls.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">ics</span><span class="nt-tag">latin-america</span><span class="nt-tag">mango</span><span class="nt-tag">open-source</span><span class="nt-tag">panel</span><span class="nt-tag">scada</span><span class="nt-tag">scadabr</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.scadabr.com.br/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/ScadaBR/ScadaBR" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="scan2net - panel info identify web-based control panels scan2net login was detected. this software is used to manage imageaccess devices.universities and public institutions often use imageaccess devices. matejsmycka panel scan2net login discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Scan2Net - Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/scan2net-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">scan2net-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> matejsmycka</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 18, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1780061475&#34; || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Scan2Net&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Scan2Net Login was detected. This software is used to manage ImageAccess devices.Universities and public institutions often use ImageAccess devices.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">scan2net</span><span class="nt-tag">login</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="schneider electric clearscada - panel info identify web-based control panels clearscada (now branded as ecostruxure geo scada expert) is a schneider electric
scada platform used in water, oil and gas, and utilities sectors. exposed instances
may provide unauthenticated access to industrial process data and control interfaces. rxerium clearscada discovery ics panel scada schneider" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Schneider Electric ClearSCADA - Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/clearscada-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">clearscada-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 27, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches `(?:ClearSCADA|Geo SCADA Expert) Home`</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">ClearSCADA (now branded as EcoStruxure Geo SCADA Expert) is a Schneider Electric
SCADA platform used in water, oil and gas, and utilities sectors. Exposed instances
may provide unauthenticated access to industrial process data and control interfaces.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">clearscada</span><span class="nt-tag">discovery</span><span class="nt-tag">ics</span><span class="nt-tag">panel</span><span class="nt-tag">scada</span><span class="nt-tag">schneider</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.se.com/ww/en/work/products/product-launch/scada/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.se.com/us/en/faqs/FA298792/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="schneider electric ecostruxure link150 default login high identify default logins in web-based control panels schneider electric ecostruxure link150 ethernet gateway with default administrator credentials discovered. vincent bouvier default-login schneider-electric ecostruxure link150 iot runzero cwe-1392" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Schneider Electric EcoStruxure Link150 Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/schneider-electric/ecostruxure-link150_v2.yaml" target="_blank" rel="noopener" class="nt-source-link">ecostruxure-link150_v2.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Vincent Bouvier</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 2, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/1392.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-1392</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">asset[&#34;hw_product&#34;] matches `LINK150` || any(each(service[&#34;html.titles&#34;]), {# matches `Schneider Electric`}) &amp;&amp; any(each(service[&#34;vscan.technologies&#34;]), {# matches `schneider-electric-ecostruxure`})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Schneider Electric EcoStruxure Link150 Ethernet Gateway with default administrator credentials discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">schneider-electric</span><span class="nt-tag">ecostruxure</span><span class="nt-tag">link150</span><span class="nt-tag">iot</span><span class="nt-tag">runzero</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.se.com/uk/en/product-range/63423-ecostruxure-link150/#overview" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.se.com/ww/en/product/TCSEGLA23F14F/ecostruxure-link150-application" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="schneider electric pelco videoxpert enterprise 2.0 - path traversal medium identify critical remote vulnerabilities schneider electric pelco videoxpert enterprise versions 2.0 and prior contain a directory traversal caused by insufficient input validation, letting unauthorized persons view web server files, exploit requires no authentication. cve-2017-9965 0x_akoko cve cve2017 lfi packetstorm pelco schneider videoxpert vuln cwe-22" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Schneider Electric Pelco VideoXpert Enterprise 2.0 - Path Traversal</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2017/CVE-2017-9965.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2017-9965.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_akoko</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 5, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2017-9965" target="_blank" rel="noopener" class="nt-cve-link">CVE-2017-9965</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)VideoXpert&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Schneider Electric Pelco VideoXpert Enterprise versions 2.0 and prior contain a directory traversal caused by insufficient input validation, letting unauthorized persons view web server files, exploit requires no authentication.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can view web server files and directories, potentially exposing sensitive configuration files, credentials, and system information.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply security updates provided by Schneider Electric or upgrade to a non-vulnerable version.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2017</span><span class="nt-tag">lfi</span><span class="nt-tag">packetstorm</span><span class="nt-tag">pelco</span><span class="nt-tag">schneider</span><span class="nt-tag">videoxpert</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://packetstormsecurity.com/files/143317/Schneider-Electric-Pelco-VideoXpert-Core-Admin-Portal-Directory-Traversal.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.zeroscience.mk/en/vulnerabilities/ZSL-2017-5419.php" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://ics-cert.us-cert.gov/advisories/ICSA-17-355-02" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://www.schneider-electric.com/en/download/document/SEVD-2017-339-01/" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="schneider electric powerlogic pm8000 default login high identify default logins in web-based control panels schneider electric powerlogic pm8000 power quality meter with default user1/0 credentials discovered. vincent bouvier default-login schneider-electric powerlogic pm8000 ics scada iot runzero cwe-1392" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Schneider Electric PowerLogic PM8000 Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/schneider-electric/pm8000.yaml" target="_blank" rel="noopener" class="nt-source-link">pm8000.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Vincent Bouvier</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 2, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/1392.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-1392</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;tls.cn&#34;]), {# matches `(?i)PM8000-`}) || any(each(service[&#34;tls.names&#34;]), {# matches `(?i)pm8000-`}) || any(each(service[&#34;service.vhost&#34;]), {# matches `(?i)PM8000-`}) || (asset[&#34;hw&#34;] matches `Schneider\s+Electric\s+PowerLogic\s+Power\s+Meter` &amp;&amp; any(each(service[&#34;http.head.location&#34;]), {# matches `/web/resources/monitoring.html`}))</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Schneider Electric PowerLogic PM8000 Power Quality Meter with default User1/0 credentials discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">schneider-electric</span><span class="nt-tag">powerlogic</span><span class="nt-tag">pm8000</span><span class="nt-tag">ics</span><span class="nt-tag">scada</span><span class="nt-tag">iot</span><span class="nt-tag">runzero</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.se.com/us/en/faqs/FA243275/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.se.com/ww/en/product-range/61102-powerlogic-pm8000/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.productinfo.schneider-electric.com/nadigest/5c51d645347bdf0001f1f280/Master/17704_MAIN%20(bookmap)_0000041932.xml/$/PowerQualityMeters-PM8000CPT_0000083065" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="schneider tac vista - login panel info identify web-based control panels schneider tac vista building automation panel has been detected. rxerium bms discovery ics panel schneider tac vista" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Schneider TAC Vista - Login Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/schneider-tac-vista-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">schneider-tac-vista-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 27, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;TAC Vista Webstation&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Schneider TAC Vista building automation panel has been detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">bms</span><span class="nt-tag">discovery</span><span class="nt-tag">ics</span><span class="nt-tag">panel</span><span class="nt-tag">schneider</span><span class="nt-tag">tac</span><span class="nt-tag">vista</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.se.com/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="scramble laravel - remote code execution critical identify critical remote vulnerabilities scramble for laravel &gt;= 0.13.2 and &lt; 0.13.22 contains a remote code execution caused by evaluation of user-controlled input in validation rules during documentation generation, letting remote attackers execute arbitrary php code, exploit requires publicly accessible documentation endpoints. cve-2026-44262 joshuavanderpoll cve cve2026 laravel php rce scramble cwe-94" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Scramble Laravel - Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2026/CVE-2026-44262.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2026-44262.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> joshuavanderpoll</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 4, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/94.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-94</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2026-44262" target="_blank" rel="noopener" class="nt-cve-link">CVE-2026-44262</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches `(?i)Login\s*[\p{Pd}|]?\s*Laravel`})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Scramble for Laravel &gt;= 0.13.2 and &lt; 0.13.22 contains a remote code execution caused by evaluation of user-controlled input in validation rules during documentation generation, letting remote attackers execute arbitrary PHP code, exploit requires publicly accessible documentation endpoints.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Remote attackers can execute arbitrary PHP code, potentially leading to full application compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to version 0.13.22 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2026</span><span class="nt-tag">laravel</span><span class="nt-tag">php</span><span class="nt-tag">rce</span><span class="nt-tag">scramble</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/advisories/GHSA-4rm2-28vj-fj39" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/joshuavanderpoll/CVE-2026-44262" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44262" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="scribble diffusion panel - detect info identify web-based control panels a tool to turn your rough sketch into a refined image using ai. rxerium panel scribble detect discovery ai" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Scribble Diffusion Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/scribble-diffusion-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">scribble-diffusion-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 27, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Scribble Diffusion&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A tool to turn your rough sketch into a refined image using AI.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">scribble</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">ai</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://scribblediffusion.com/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/replicate/scribble-diffusion" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="scriptcase panel detect info identify web-based control panels  ricardo maia (brainfork) panel scriptcase discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">ScriptCase Panel Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/scriptcase/scriptcase-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">scriptcase-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Ricardo Maia (Brainfork)</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)ScriptCase&#34;})</code></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">scriptcase</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.scriptcase.com.br" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.scriptcase.net" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="scriptcase production environment login info identify web-based control panels  ricardo maia (brainfork) panel scriptcase discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">ScriptCase Production Environment Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/scriptcase/scriptcase-prod-login.yaml" target="_blank" rel="noopener" class="nt-source-link">scriptcase-prod-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Ricardo Maia (Brainfork)</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)ScriptCase&#34;})</code></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">scriptcase</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.scriptcase.com.br" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.scriptcase.net" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="seafile panel - detect info identify web-based control panels seafile panel was detected. techbrunchfr,righettod sefile panel login seafile discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Seafile Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/seafile-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">seafile-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> TechbrunchFR,righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1552322396&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Seafile panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">sefile</span><span class="nt-tag">panel</span><span class="nt-tag">login</span><span class="nt-tag">seafile</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.seafile.com/en/home/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/haiwen/seafile" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="seagate nas login - detect info identify web-based control panels seagate nas - seagate login was detected. justaacat discovery login panel seagate" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Seagate NAS Login - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/seagate-nas-login.yaml" target="_blank" rel="noopener" class="nt-source-link">seagate-nas-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> JustaAcat</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)seagate nas - seagate&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Seagate NAS - SEAGATE Login was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">login</span><span class="nt-tag">panel</span><span class="nt-tag">seagate</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="seagate nas os 4.3.15.1 - server information disclosure high identify critical remote vulnerabilities seagate nas os version 4.3.15.1 has insufficient access control which allows attackers to obtain information about the nas without authentication via empty post requests in /api/external/7.0/system.system.get_infos. cve-2018-12296 princechaddha cve cve2018 disclosure nasos seagate unauth vkev vuln cwe-732" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Seagate NAS OS 4.3.15.1 - Server Information Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2018/CVE-2018-12296.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2018-12296.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> princechaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/732.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-732</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2018-12296" target="_blank" rel="noopener" class="nt-cve-link">CVE-2018-12296</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)seagate nas - seagate&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Seagate NAS OS version 4.3.15.1 has insufficient access control which allows attackers to obtain information about the NAS without authentication via empty POST requests in /api/external/7.0/system.System.get_infos.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can gain sensitive information about the server, potentially leading to further attacks.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to a patched version of Seagate NAS OS.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2018</span><span class="nt-tag">disclosure</span><span class="nt-tag">nasos</span><span class="nt-tag">seagate</span><span class="nt-tag">unauth</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://blog.securityevaluators.com/invading-your-personal-cloud-ise-labs-exploits-the-seagate-stcr3000101-ecf89de2170" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2018-12296" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/ARPSyndicate/kenzer-templates" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="securenvoy login panel - detect info identify web-based control panels securenvoy login panel was detected. 0xrod,righettod panel securenvoy discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">SecurEnvoy Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/securenvoy-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">securenvoy-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0xrod,righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)securenvoy&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">SecurEnvoy login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">securenvoy</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://securenvoy.com/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="securenvoy two factor authentication - ldap injection critical identify critical remote vulnerabilities multiple ldap injections vulnerabilities exist in securenvoy mfa before 9.4.514 due to improper validation of user-supplied input. an unauthenticated remote attacker could exfiltrate data from active directory through blind ldap injection attacks against the desktop service exposed on the /secserver http endpoint. this may include ms-mcs-admpwd, which has a cleartext password for the local administrator password solution (laps) feature. cve-2024-37393 s4e-io cve cve2024 ldap securenvoy vkev vuln cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">SecurEnvoy Two Factor Authentication - LDAP Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-37393.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-37393.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> s4e-io</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 11, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-37393" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-37393</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)SecurEnvoy&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Multiple LDAP injections vulnerabilities exist in SecurEnvoy MFA before 9.4.514 due to improper validation of user-supplied input. An unauthenticated remote attacker could exfiltrate data from Active Directory through blind LDAP injection attacks against the DESKTOP service exposed on the /secserver HTTP endpoint. This may include ms-Mcs-AdmPwd, which has a cleartext password for the Local Administrator Password Solution (LAPS) feature.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can exploit LDAP injection to exfiltrate sensitive Active Directory data including cleartext LAPS passwords.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update SecurEnvoy MFA to version 9.4.514 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">ldap</span><span class="nt-tag">securenvoy</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.tenable.com/cve/CVE-2024-37393" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.optistream.io/blogs/tech/securenvoy-cve-2024-37393" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://securenvoy.com" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="securden unified pam - authentication bypass critical identify critical remote vulnerabilities an authentication bypass vulnerability exists which allows an unauthenticated attacker to control administrator backup functions, leading to compromise of passwords, secrets, and application session tokens stored by the unified pam. dhiyaneshdk,pussycat0x,iamnoooob,pdresearch auth-bypass cve cve2025 pam securden vkev vuln" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Securden Unified PAM - Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-53118.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-53118.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk,pussycat0x,iamnoooob,pdresearch</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 28, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1798893256&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An authentication bypass vulnerability exists which allows an unauthenticated attacker to control administrator backup functions, leading to compromise of passwords, secrets, and application session tokens stored by the Unified PAM.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can control administrator backup functions to compromise passwords, secrets, and application session tokens stored in Unified PAM.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade Securden Unified PAM to the latest version that implements proper authentication checks on backup functions.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">pam</span><span class="nt-tag">securden</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.rapid7.com/blog/post/securden-unified-pam-multiple-critical-vulnerabilities-fixed/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53118" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="secure login service login panel - detect info identify web-based control panels secure login service login panel was detected. dhiyaneshdk panel sls login service discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Secure Login Service Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/secure-login-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">secure-login-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Secure Login Service&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Secure Login Service login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">sls</span><span class="nt-tag">login</span><span class="nt-tag">service</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="securepoint utm 12.x session id leak high identify critical remote vulnerabilities an issue was discovered in securepoint utm before 12.2.5.1. the firewall&#39;s endpoint at /spcgi.cgi allows sessionid information disclosure via an invalid authentication attempt. this can afterwards be used to bypass the device&#39;s authentication and get access to the administrative interface. cve-2023-22620 dhiyaneshdk cve cve2023 leak memory packetstorm securepoint utm vkev vuln cwe-863" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">SecurePoint UTM 12.x Session ID Leak</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-22620.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-22620.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/863.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-863</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-22620" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-22620</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)securepoint utm&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An issue was discovered in SecurePoint UTM before 12.2.5.1. The firewall&#39;s endpoint at /spcgi.cgi allows sessionid information disclosure via an invalid authentication attempt. This can afterwards be used to bypass the device&#39;s authentication and get access to the administrative interface.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could lead to unauthorized access to sensitive information or perform actions on behalf of the user.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to version 12.2.5.1 or newer</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">leak</span><span class="nt-tag">memory</span><span class="nt-tag">packetstorm</span><span class="nt-tag">securepoint</span><span class="nt-tag">utm</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-22620" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/MrTuxracer/advisories/blob/master/CVEs/CVE-2023-22620.txt" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.rcesecurity.com/2023/04/securepwn-part-1-bypassing-securepoint-utms-authentication-cve-2023-22620/" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://packetstormsecurity.com/files/171924/SecurePoint-UTM-12.x-Session-ID-Leak.html" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://rcesecurity.com" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="securepoint utm - leaking remote memory contents medium identify critical remote vulnerabilities an issue was discovered in securepoint utm before 12.2.5.1. the firewall&#39;s endpoint at /spcgi.cgi allows information disclosure of memory contents to be achieved by an authenticated user. essentially, uninitialized data can be retrieved via an approach in which a sessionid is obtained but not used. cve-2023-22897 dhiyaneshdk cve cve2023 exposure memory securepoint utm vkev vuln cwe-908" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Securepoint UTM - Leaking Remote Memory Contents</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-22897.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-22897.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/908.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-908</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-22897" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-22897</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)securepoint utm&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An issue was discovered in SecurePoint UTM before 12.2.5.1. The firewall&#39;s endpoint at /spcgi.cgi allows information disclosure of memory contents to be achieved by an authenticated user. Essentially, uninitialized data can be retrieved via an approach in which a sessionid is obtained but not used.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can exploit this vulnerability to gain access to sensitive information stored in the device&#39;s memory.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches and updates provided by Securepoint to fix the memory leakage issue.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">exposure</span><span class="nt-tag">memory</span><span class="nt-tag">securepoint</span><span class="nt-tag">utm</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-22897" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/MrTuxracer/advisories/blob/master/CVEs/CVE-2023-22897.txt" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.rcesecurity.com/2023/04/securepwn-part-2-leaking-remote-memory-contents-cve-2023-22897/" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://rcesecurity.com" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/MrTuxracer/advisories" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="security onion panel - detect info identify web-based control panels security onion is a free and open source linux distribution for intrusion detection, security monitoring, and log management. it includes cyberchef, networkminer, and many other security tools. rxerium detect discovery onion panel security securityonionsolutions" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Security Onion Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/security-onion-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">security-onion-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 27, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)security onion&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Security Onion is a free and open source Linux distribution for intrusion detection, security monitoring, and log management. It includes CyberChef, NetworkMiner, and many other security tools.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">onion</span><span class="nt-tag">panel</span><span class="nt-tag">security</span><span class="nt-tag">securityonionsolutions</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://securityonionsolutions.com/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/Security-Onion-Solutions/securityonion" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="securityspy camera panel - detect info identify web-based control panels securityspy camera panel was detected. pussycat0x unauth iot securityspy panel camera discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">SecuritySpy Camera Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/securityspy-detect.yaml" target="_blank" rel="noopener" class="nt-source-link">securityspy-detect.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)SecuritySpy&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">SecuritySpy Camera panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">unauth</span><span class="nt-tag">iot</span><span class="nt-tag">securityspy</span><span class="nt-tag">panel</span><span class="nt-tag">camera</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="seeddms default login high identify default logins in web-based control panels seeddms default admin credentials were discovered. alifathi-h1 default-login seeddms vuln cwe-522" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">SeedDMS Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/seeddms/seeddms-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">seeddms-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> alifathi-h1</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/522.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-522</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;SeedDMS&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">SeedDMS default admin credentials were discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">seeddms</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.seeddms.org/index.php?id=2" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.redhat.com/sysadmin/install-seeddms" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="seeddms login panel - detect info identify web-based control panels seeddms login panel was detected. pussycat0x,daffainfo discovery login panel seeddms cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">SeedDMS Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/seeddms-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">seeddms-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x,daffainfo</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)seeddms&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">SeedDMS login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">login</span><span class="nt-tag">panel</span><span class="nt-tag">seeddms</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="seeyon oa a6 setextno.jsp - sql injection high identify critical remote vulnerabilities seeyon oa a6 initdataassess.jsp has leaked user sensitive information,you can blast the user password through the obtained username to enter the background for further attacks sleepingbag945 oa seeyon sqli vuln cwe-89" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Seeyon OA A6 setextno.jsp - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/vulnerabilities/seeyon/seeyon-oa-setextno-sqli.yaml" target="_blank" rel="noopener" class="nt-source-link">seeyon-oa-setextno-sqli.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> SleepingBag945</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 5, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)yyoa&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Seeyon OA A6 initDataAssess.jsp has leaked user sensitive information,You can blast the user password through the obtained username to enter the background for further attacks</div></div></div>
  <div class="nt-tags"><span class="nt-tag">oa</span><span class="nt-tag">seeyon</span><span class="nt-tag">sqli</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/achuna33/MYExploit/blob/8ffbf7ee60cbd77ad90b0831b93846aba224ab29/src/main/java/com/achuna33/Controllers/SeeyonController.java" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="http://wiki.peiqi.tech/wiki/oa/致远OA/致远OA%20A6%20setextno.jsp%20SQL注入漏洞.html" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/Threekiii/Awesome-POC/blob/master/OA%E4%BA%A7%E5%93%81%E6%BC%8F%E6%B4%9E/%E8%87%B4%E8%BF%9COA%20A6%20setextno.jsp%20SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="selenium grid panel - detect info identify web-based control panels selenium grid panel was detected. pussycat0x discovery panel selenium unauth cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Selenium Grid Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/selenium-grid.yaml" target="_blank" rel="noopener" class="nt-source-link">selenium-grid.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Selenium Grid&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Selenium Grid panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">selenium</span><span class="nt-tag">unauth</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="selfcheck system manager - panel info identify web-based control panels  dhiyaneshdk panel login selfcheck systemmanager discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">SelfCheck System Manager - Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/selfcheck-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">selfcheck-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 20, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)SelfCheck System Manager&#34;})</code></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">login</span><span class="nt-tag">selfcheck</span><span class="nt-tag">systemmanager</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.facebook.com/photo/?fbid=607747024729154&amp;set=a.467014098802448" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="sensei lms &lt; 4.24.2 - email template leak high identify critical remote vulnerabilities the sensei lms wordpress plugin before 4.24.2 does not properly protect some its rest api routes, allowing unauthenticated attackers to leak email templates. cve-2024-7786 s4e-io cve cve2024 exposure sensei-lms vkev vuln wordpress wp wp-plugin wpscan" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Sensei LMS &lt; 4.24.2 - Email Template Leak</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-7786.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-7786.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> s4e-io</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 5, 2024</span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-7786" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-7786</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/sensei-lms&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The Sensei LMS WordPress plugin before 4.24.2 does not properly protect some its REST API routes, allowing unauthenticated attackers to leak email templates.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can access and leak email templates through unprotected REST API endpoints, potentially exposing sensitive information included in email communications and template configurations.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update Sensei LMS plugin to version 4.24.2 or later to address the REST API protection issue.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">exposure</span><span class="nt-tag">sensei-lms</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">wpscan</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wpscan.com/vulnerability/f44e6f8f-3ef2-45c9-ae9c-9403305a548a/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-7786" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.usom.gov.tr/bildirim/tr-24-1387" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="sensu by sumo logic login panel - detect info identify web-based control panels sensu by sumo logic login panel was detected. ja1sh panel sensu sumo detect discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Sensu by Sumo Logic Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/sensu-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">sensu-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ja1sh</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-749942143&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Sensu by Sumo Logic login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">sensu</span><span class="nt-tag">sumo</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="sentinelone management console login panel - detect info identify web-based control panels sentinelone management console login panel was detected. dhiyaneshdk panel sentinelone discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">SentinelOne Management Console Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/sentinelone-console.yaml" target="_blank" rel="noopener" class="nt-source-link">sentinelone-console.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)SentinelOne - Management Console&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">SentinelOne Management Console login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">sentinelone</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="sentry login panel info identify web-based control panels sentry login panel was detected. righettod discovery login panel sentry" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Sentry Login Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/sentry-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">sentry-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 2, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)login \\| sentry&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Sentry login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">login</span><span class="nt-tag">panel</span><span class="nt-tag">sentry</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://sentry.io/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="sequoiadb login panel - detect info identify web-based control panels sequoiadb login panel was detected. dhiyaneshdk sequoiadb panel login discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">SequoiaDB Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/sequoiadb-login.yaml" target="_blank" rel="noopener" class="nt-source-link">sequoiadb-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)SequoiaDB&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">SequoiaDB login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">sequoiadb</span><span class="nt-tag">panel</span><span class="nt-tag">login</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="serge panel - detect info identify web-based control panels serge is a web interface for chatting with alpaca through llama.cpp. this template detects the presence of a serge chat interface. rxerium ai chat detect discovery llm panel serge" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Serge Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/serge-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">serge-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 27, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;Serge - Powered by LLaMa&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Serge is a web interface for chatting with Alpaca through llama.cpp. This template detects the presence of a Serge chat interface.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">ai</span><span class="nt-tag">chat</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">llm</span><span class="nt-tag">panel</span><span class="nt-tag">serge</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/serge-chat/serge" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://serge.chat" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="server backup manager se panel - detect info identify web-based control panels server backup manager se login panel was detected. dhiyaneshdk panel server backup manager discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Server Backup Manager SE Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/server-backup-manager-se.yaml" target="_blank" rel="noopener" class="nt-source-link">server-backup-manager-se.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Server Backup Manager SE&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Server Backup Manager SE login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">server</span><span class="nt-tag">backup</span><span class="nt-tag">manager</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="service finder bookings - authentication bypass critical identify critical remote vulnerabilities service finder bookings wordpress plugin &lt;= 6.0 contains a privilege escalation caused by improper validation of user cookie in service_finder_switch_back() function, letting unauthenticated attackers login as any user including admins. cve-2025-5947 sedat4ras auth-bypass cookie-spoofing cve cve2025 sf-booking vkev vuln wordpress wp wp-plugin cwe-639" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Service Finder Bookings - Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-5947.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-5947.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> sedat4ras</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 8, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/639.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-639</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-5947" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-5947</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] contains &#34;/wp-content/plugins/sf-booking&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Service Finder Bookings WordPress plugin &lt;= 6.0 contains a privilege escalation caused by improper validation of user cookie in service_finder_switch_back() function, letting unauthenticated attackers login as any user including admins.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can login as any user, including administrators, leading to full system compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest version beyond 6.0.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">cookie-spoofing</span><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">sf-booking</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://patchstack.com/database/wordpress/plugin/sf-booking/vulnerability/wordpress-service-finder-bookings-plugin-6-0-authentication-bypass-via-user-switch-cookie-vulnerability" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/advisories/GHSA-x2xx-4qhp-2vqx" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/M4rgs/CVE-2025-5947_Exploit" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-5947" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="servicenow - incomplete input validation critical identify critical remote vulnerabilities servicenow has addressed an input validation vulnerability that was identified in the washington dc, vancouver, and earlier now platform releases. this vulnerability could enable an unauthenticated user to remotely execute code within the context of the now platform. the vulnerability is addressed in the listed patches and hot fixes below, which were released during the june 2024 patching cycle. if you have not done so already, we recommend applying security patches relevant to your instance as soon as possible. cve-2024-5217 dhiyaneshdk,ritikchaddha cve cve2024 kev rce servicenow vkev vuln cwe-697" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">ServiceNow - Incomplete Input Validation</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-5217.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-5217.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk,ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 11, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/697.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-697</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-5217" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-5217</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1701804003&#34; || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)servicenow&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">ServiceNow has addressed an input validation vulnerability that was identified in the Washington DC, Vancouver, and earlier Now Platform releases. This vulnerability could enable an unauthenticated user to remotely execute code within the context of the Now Platform. The vulnerability is addressed in the listed patches and hot fixes below, which were released during the June 2024 patching cycle. If you have not done so already, we recommend applying security patches relevant to your instance as soon as possible.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can exploit this vulnerability to compromise system security.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply security patches to address CVE-2024-5217.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">kev</span><span class="nt-tag">rce</span><span class="nt-tag">servicenow</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.assetnote.io/resources/research/chaining-three-bugs-to-access-all-your-servicenow-data" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://support.servicenow.com/kb?id=kb_article_view&amp;sysparm_article=KB1644293" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://support.servicenow.com/kb?id=kb_article_view&amp;sysparm_article=KB1648313" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-5217" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="servicenow login panel - detect info identify web-based control panels servicenow login panel was detected. righettod detect discovery login panel servicenow" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">ServiceNow Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/servicenow-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">servicenow-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 1, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1701804003&#34; || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)servicenow&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">ServiceNow Login Panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">login</span><span class="nt-tag">panel</span><span class="nt-tag">servicenow</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.servicenow.com/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="servicenow ui macros - template injection critical identify critical remote vulnerabilities servicenow has addressed an input validation vulnerability that was identified in vancouver and washington dc now platform releases. this vulnerability could enable an unauthenticated user to remotely execute code within the context of the now platform. servicenow applied an update to hosted instances, and servicenow released the update to our partners and self-hosted customers. listed below are the patches and hot fixes that address the vulnerability. if you have not done so already, we recommend applying security patches relevant to your instance as soon as possible. cve-2024-4879 dhiyaneshdk,ritikchaddha cve cve2024 kev servicenow ssti vkev vuln cwe-1287" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">ServiceNow UI Macros - Template Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-4879.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-4879.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk,ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 11, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/1287.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-1287</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-4879" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-4879</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1701804003&#34; || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)servicenow&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">ServiceNow has addressed an input validation vulnerability that was identified in Vancouver and Washington DC Now Platform releases. This vulnerability could enable an unauthenticated user to remotely execute code within the context of the Now Platform. ServiceNow applied an update to hosted instances, and ServiceNow released the update to our partners and self-hosted customers. Listed below are the patches and hot fixes that address the vulnerability. If you have not done so already, we recommend applying security patches relevant to your instance as soon as possible.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can exploit SSTI to execute arbitrary code on ServiceNow servers.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply security patches for ServiceNow as per KB1644293 and KB1645154.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">kev</span><span class="nt-tag">servicenow</span><span class="nt-tag">ssti</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.assetnote.io/resources/research/chaining-three-bugs-to-access-all-your-servicenow-data" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://support.servicenow.com/kb?id=kb_article_view&amp;sysparm_article=KB1644293" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://support.servicenow.com/kb?id=kb_article_view&amp;sysparm_article=KB1645154" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-4879" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="sevone nms network manager info identify web-based control panels  pussycat0x sevone manager login panel discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">SevOne NMS Network Manager</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/sevone-nms-network-manager.yaml" target="_blank" rel="noopener" class="nt-source-link">sevone-nms-network-manager.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)SevOne NMS - Network Manager&#34;})</code></div>
  <div class="nt-tags"><span class="nt-tag">sevone</span><span class="nt-tag">manager</span><span class="nt-tag">login</span><span class="nt-tag">panel</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="shardingsphere elasticjob ui panel info identify web-based control panels an shardingsphere elasticjob ui panel was detected. dhiyaneshdk apache discovery login panel shardingsphere cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">ShardingSphere ElasticJob UI Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/shardingsphere-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">shardingsphere-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 18, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;816588900&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An ShardingSphere ElasticJob UI panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">apache</span><span class="nt-tag">discovery</span><span class="nt-tag">login</span><span class="nt-tag">panel</span><span class="nt-tag">shardingsphere</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="sharefile login - panel info identify web-based control panels sharefile is a cloud-based file sharing and collaboration platform that provides secure access to files from anywhere. irshad ahamed citrix detect discovery login panel sharefile" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Sharefile Login - Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/sharefile-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">sharefile-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> irshad ahamed</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 11, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)sharefile login&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">ShareFile is a cloud-based file sharing and collaboration platform that provides secure access to files from anywhere.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">citrix</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">login</span><span class="nt-tag">panel</span><span class="nt-tag">sharefile</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.sharefile.com/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="shell in a box - detect info identify web-based control panels shell in a box implements a web server that can export arbitrary command line tools to a web based terminal emulator irshad ahamed detect discovery emulator login panel shell shellinabox_project" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Shell In A Box - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/shell-box.yaml" target="_blank" rel="noopener" class="nt-source-link">shell-box.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> irshad ahamed</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 1, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-629968763&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Shell In A Box implements a web server that can export arbitrary command line tools to a web based terminal emulator</div></div></div>
  <div class="nt-tags"><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">emulator</span><span class="nt-tag">login</span><span class="nt-tag">panel</span><span class="nt-tag">shell</span><span class="nt-tag">shellinabox_project</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/shellinabox/shellinabox" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.cvedetails.com/vulnerability-list/vendor_id-15771/product_id-33062/Shellinabox-Project-Shellinabox.html" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="shield security wp plugin &lt;= 18.5.9 - local file inclusion critical identify critical remote vulnerabilities the shield security smart bot blocking &amp; intrusion prevention security plugin for wordpress is vulnerable to local file inclusion in all versions up to, and including, 18.5.9 via the render_action_template parameter. this makes it possible for unauthenticated attacker to include and execute php files on the server, allowing the execution of any php code in those files. cve-2023-6989 s4e-io cve cve2023 getshieldsecurity lfi shield-security vuln wordpress wp wp-plugin wpscan cwe-22" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Shield Security WP Plugin &lt;= 18.5.9 - Local File Inclusion</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-6989.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-6989.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> s4e-io</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 30, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-6989" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-6989</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/wp-simple-firewall&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The Shield Security Smart Bot Blocking &amp; Intrusion Prevention Security plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 18.5.9 via the render_action_template parameter. This makes it possible for unauthenticated attacker to include and execute PHP files on the server, allowing the execution of any PHP code in those files.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can exploit local file inclusion via render_action_template to execute arbitrary PHP code, potentially compromising the entire WordPress installation.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update Shield Security plugin to version 18.5.10 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">getshieldsecurity</span><span class="nt-tag">lfi</span><span class="nt-tag">shield-security</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">wpscan</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wpscan.com/vulnerability/a485aee7-39a0-418c-9699-9afc53e28f55/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-6989" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/fkie-cad/nvd-json-data-feeds" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="shiziyu cms api controller - sql injection high identify critical remote vulnerabilities shiziyu cms apicontroller.class.php parameter filtering is not rigorous, resulting in sql injection vulnerability. sleepingbag945 sqli vuln cwe-89" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Shiziyu CMS Api Controller - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/vulnerabilities/shiziyu-cms/shiziyu-cms-apicontroller-sqli.yaml" target="_blank" rel="noopener" class="nt-source-link">shiziyu-cms-apicontroller-sqli.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> SleepingBag945</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 18, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/seller\\.php\\?s=/Public/login&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Shiziyu CMS ApiController.class.php parameter filtering is not rigorous, resulting in SQL injection vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">sqli</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="shokoserver system - local file inclusion (lfi) high identify critical remote vulnerabilities shokoserver is a media server which specializes in organizing anime. in affected versions the `/api/image/withpath` endpoint is accessible without authentication and is supposed to return default server images. the endpoint accepts the parameter `serverimagepath`, which is not sanitized in any way before being passed to `system.io.file.openread`, which results in an arbitrary file read. cve-2023-43662 pussycat0x cve cve2023 lfi shoko vuln web-aui cwe-22" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">ShokoServer System - Local File Inclusion (LFI)</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-43662.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-43662.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 17, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-43662" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-43662</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Shoko WEB UI&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">ShokoServer is a media server which specializes in organizing anime. In affected versions the `/api/Image/WithPath` endpoint is accessible without authentication and is supposed to return default server images. The endpoint accepts the parameter `serverImagePath`, which is not sanitized in any way before being passed to `System.IO.File.OpenRead`, which results in an arbitrary file read.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">This issue may lead to an arbitrary file read which is exacerbated in the windows installer which installs the ShokoServer as administrator. Any unauthenticated attacker may be able to access sensitive information and read files stored on the server.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">The `/api/Image/WithPath` endpoint has been removed in commit `6c57ba0f0` which will be included in subsequent releases. Users should limit access to the `/api/Image/WithPath` endpoint or manually patch their installations until a patched release is made. This issue was discovered by the GitHub Security lab and is also indexed as GHSL-2023-191.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">lfi</span><span class="nt-tag">shoko</span><span class="nt-tag">vuln</span><span class="nt-tag">web-aui</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/wy876/POC/blob/main/Ncast%E9%AB%98%E6%B8%85%E6%99%BA%E8%83%BD%E5%BD%95%E6%92%AD%E7%B3%BB%E7%BB%9F%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/ShokoAnime/ShokoServer/commit/6c57ba0f073d6be5a4f508c46c2ce36727cbce80" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="shortpixel adaptive images &lt; 3.6.3 - cross site scripting medium identify critical remote vulnerabilities the plugin does not sanitise and escape a parameter before outputting it back in the page, leading to a reflected cross-site scripting which could be used against any high privilege users such as admin cve-2023-0334 r3y3r53 cve cve2023 shortpixel shortpixel-adaptive-images vuln wordpress wp wp-plugin wpscan xss cwe-79" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">ShortPixel Adaptive Images &lt; 3.6.3 - Cross Site Scripting</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-0334.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-0334.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> r3Y3r53</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 17, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-79</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-0334" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-0334</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/shortpixel-adaptive-images/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The plugin does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against any high privilege users such as admin</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can inject malicious JavaScript to steal high-privilege user session cookies including administrator credentials.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Fixed in version 3.6.3</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">shortpixel</span><span class="nt-tag">shortpixel-adaptive-images</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">wpscan</span><span class="nt-tag">xss</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wpscan.com/vulnerability/b027a8db-0fd6-444d-b14a-0ae58f04f931" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-0334" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="showdoc panel detection info identify web-based control panels showdoc panel was detected. showdoc was a tool for documenting apis and interfaces. rxerium discovery panel showdoc tech cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">ShowDoc Panel Detection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/showdoc-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">showdoc-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 14, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)showdoc&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">ShowDoc panel was detected. ShowDoc was a tool for documenting APIs and interfaces.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">showdoc</span><span class="nt-tag">tech</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="sidekiq &lt; 7.0.8 - cross-site scripting critical identify critical remote vulnerabilities an xss vulnerability on a sidekiq admin panel can pose serious risks to the security and functionality of the system. cve-2023-1892 ritikchaddha,princechaddha contribsys cve cve2023 sidekiq vuln xss cwe-79" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Sidekiq &lt; 7.0.8 - Cross-Site Scripting</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-1892.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-1892.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha,princechaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 25, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-79</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-1892" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-1892</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)sidekiq&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An XSS vulnerability on a Sidekiq admin panel can pose serious risks to the security and functionality of the system.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can inject malicious JavaScript through the period parameter in Sidekiq metrics endpoints, potentially stealing administrator session cookies and accessing sensitive job queue information and worker statistics.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update Sidekiq to version 7.0.8 or later that properly sanitizes the period parameter and encodes output in the metrics dashboard.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">contribsys</span><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">sidekiq</span><span class="nt-tag">vuln</span><span class="nt-tag">xss</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://huntr.com/bounties/e35e5653-c429-4fb8-94a3-cbc123ae4777" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/sidekiq/sidekiq/commit/458fdf74176a9881478c48dc5cf0269107b22214" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-1892" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="sidekiq dashboard panel - detect medium identify web-based control panels sidekiq dashboard panel was detected. dhiyaneshdk,amirmsafari unauth panel sidekiq contribsys discovery cwe-200" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Sidekiq Dashboard Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/sidekiq-dashboard.yaml" target="_blank" rel="noopener" class="nt-source-link">sidekiq-dashboard.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDK,AmirMSafari</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)sidekiq&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Sidekiq Dashboard panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">unauth</span><span class="nt-tag">panel</span><span class="nt-tag">sidekiq</span><span class="nt-tag">contribsys</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://sidekiq.org" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/mperham/sidekiq" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/mperham/sidekiq/wiki/Monitoring" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="siemens simatic hmi miniweb - default login high identify default logins in web-based control panels identified siemens simatic hmi miniweb interfaces that were accessible using default credentials.these interfaces are used to remotely monitor and control human-machine interface (hmi) panels deployed in industrial environments. leaving the default login in place posed a significant risk to operational technology (ot) systems. biero-el-corridor default-login ics siemens vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Siemens SIMATIC HMI Miniweb - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/siemens/siemens-simatic-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">siemens-simatic-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> biero-el-corridor</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 2, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;Miniweb Start Page&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Identified Siemens SIMATIC HMI MiniWeb interfaces that were accessible using default credentials.These interfaces are used to remotely monitor and control Human-Machine Interface (HMI) panels deployed in industrial environments. Leaving the default login in place posed a significant risk to operational technology (OT) systems.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">ics</span><span class="nt-tag">siemens</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="signet explorer dashboard - detect info identify web-based control panels signet explorer dashboard was detected. ritikchaddha panel signet bitcoin dashboard discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Signet Explorer Dashboard - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/signet-explorer-dashboard.yaml" target="_blank" rel="noopener" class="nt-source-link">signet-explorer-dashboard.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)mempool-space&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Signet Explorer Dashboard was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">signet</span><span class="nt-tag">bitcoin</span><span class="nt-tag">dashboard</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/mempool/mempool" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="sillytavern panel - detect info identify web-based control panels sillytavern was detected. sillytavern is a character-based ai roleplay and chat frontend that connects to local or remote llm backends. exposed instances may allow unauthenticated access to ai models and conversation history. rxerium ai detect discovery llm panel sillytavern" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">SillyTavern Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/sillytavern-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">sillytavern-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 14, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)SillyTavern&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">SillyTavern was detected. SillyTavern is a character-based AI roleplay and chat frontend that connects to local or remote LLM backends. Exposed instances may allow unauthenticated access to AI models and conversation history.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">ai</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">llm</span><span class="nt-tag">panel</span><span class="nt-tag">sillytavern</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/SillyTavern/SillyTavern" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://docs.sillytavern.app/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="simplehelp &lt;= 5.5.7 - unauthenticated path traversal high identify critical remote vulnerabilities simplehelp remote support software v5.5.7 and before is vulnerable to multiple path traversal vulnerabilities that enable unauthenticated remote attackers to download arbitrary files from the simplehelp host via crafted http requests. these files include server configuration files containing various secrets and hashed user passwords. cve-2024-57727 iamnoooob,rootxharsh,pdresearch,3th1cyuk1 cve cve2024 kev lfi simplehelp vkev vuln cwe-22" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">SimpleHelp &lt;= 5.5.7 - Unauthenticated Path Traversal</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-57727.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-57727.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> iamnoooob,rootxharsh,pdresearch,3th1cyuk1</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 19, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-57727" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-57727</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)SimpleHelp&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">SimpleHelp remote support software v5.5.7 and before is vulnerable to multiple path traversal vulnerabilities that enable unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted HTTP requests. These files include server configuration files containing various secrets and hashed user passwords.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can exploit path traversal to download server configuration files containing secrets, hashed passwords, and other sensitive information.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update SimpleHelp to version 5.5.8 or later to address the path traversal vulnerabilities.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">kev</span><span class="nt-tag">lfi</span><span class="nt-tag">simplehelp</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://simple-help.com/kb---security-vulnerabilities-01-2025#security-vulnerabilities-in-simplehelp-5-5-7-and-earlier" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.horizon3.ai/attack-research/disclosures/critical-vulnerabilities-in-simplehelp-remote-support-software/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="sitecore - remote code execution critical identify critical remote vulnerabilities multiple sitecore products allow remote code execution. this affects experience manager, experience platform, and experience commerce through 10.3. cve-2023-35813 dhiyaneshdk,iamnoooob cve cve2023 rce sitecore vkev vuln cwe-22,cwe-23" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Sitecore - Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-35813.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-35813.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk,iamnoooob</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 10, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22,CWE-23.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22,CWE-23</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-35813" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-35813</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)sitecore&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Multiple Sitecore products allow remote code execution. This affects Experience Manager, Experience Platform, and Experience Commerce through 10.3.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can execute arbitrary code on Sitecore servers through the XAML parser by injecting malicious ASP.NET markup, potentially compromising the entire content management system and accessing sensitive customer data.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply Sitecore security patches as outlined in KB1002979 for Experience Manager, Experience Platform, and Experience Commerce versions through 10.3.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">rce</span><span class="nt-tag">sitecore</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://support.sitecore.com/kb?id=kb_article_view\u0026sysparm_article=KB1002979" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://code-white.com/blog/exploiting-asp.net-templateparser-part-1/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-35813" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://support.sitecore.com/kb?id=kb_article_view&amp;sysparm_article=KB1002979" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/BagheeraAltered/CVE-2023-35813-PoC" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="sitecore cms - cross-site scripting medium identify critical remote vulnerabilities sitecore cms contains a cross-site scripting vulnerability via the &#34;special way&#34; of displaying xml controls directly, which allows for a cross site scripting attack. cve-2014-100004 dhiyaneshdk cms cve cve2014 sitecore vuln xss cwe-79" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Sitecore CMS - Cross-Site Scripting</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2014/CVE-2014-100004.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2014-100004.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 13, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-79</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2014-100004" target="_blank" rel="noopener" class="nt-cve-link">CVE-2014-100004</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Sitecore&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Sitecore CMS contains a cross-site scripting vulnerability via the &#34;special way&#34; of displaying XML Controls directly, which allows for a Cross Site Scripting Attack.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can execute arbitrary JavaScript in victims&#39; browsers, potentially stealing session cookies, credentials, or performing actions on behalf of users.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to a patched version of Sitecore CMS or apply vendor security updates.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cms</span><span class="nt-tag">cve</span><span class="nt-tag">cve2014</span><span class="nt-tag">sitecore</span><span class="nt-tag">vuln</span><span class="nt-tag">xss</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://vulners.com/securityvulns/SECURITYVULNS:DOC:30273" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://web.archive.org/web/20151016072340/http://www.securityfocus.com/archive/1/530901/100/0/threaded" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2014-100004" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="sitecore experience manager (xm) and experience platform (xp) - hardcoded credentials high identify critical remote vulnerabilities sitecore experience manager (xm) and experience platform (xp) versions 10.1 to 10.1.4 rev. 011974 pre, all versions of 10.2, 10.3 to 10.3.3 rev. 011967 pre, and 10.4 to 10.4.1 rev. 011941 pre contain a hardcoded user account. unauthenticated and remote attackers can use this account to access administrative api over http. cve-2025-34509 daffainfo cve cve2025 experience_commerce experience_platform sitecore vkev cwe-798" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Sitecore Experience Manager (XM) and Experience Platform (XP) - Hardcoded Credentials</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-34509.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-34509.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> daffainfo</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 23, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/798.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-798</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-34509" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-34509</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)sitecore&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Sitecore Experience Manager (XM) and Experience Platform (XP) versions 10.1 to 10.1.4 rev. 011974 PRE, all versions of 10.2, 10.3 to 10.3.3 rev. 011967 PRE, and 10.4 to 10.4.1 rev. 011941 PRE contain a hardcoded user account. Unauthenticated and remote attackers can use this account to access administrative API over HTTP.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can use hardcoded credentials to access administrative API endpoints over HTTP, potentially compromising the entire Sitecore platform.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the security patch as described in Sitecore KB1003667 and change all default credentials immediately.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">experience_commerce</span><span class="nt-tag">experience_platform</span><span class="nt-tag">sitecore</span><span class="nt-tag">vkev</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://labs.watchtowr.com/is-b-for-backdoor-pre-auth-rce-chain-in-sitecore-experience-platform/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://support.sitecore.com/kb?id=kb_article_view&amp;sysparm_article=KB1003667" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-34509" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="sitecore experience platform &lt;= 10.4 - arbitrary file read high identify critical remote vulnerabilities an issue was discovered in sitecore experience platform (xp), experience manager (xm), and experience commerce (xc) 8.0 initial release through 10.4 initial release. an unauthenticated attacker can read arbitrary files. cve-2024-46938 dhiyaneshdk cve cve2024 lfi rce sitecore vkev vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Sitecore Experience Platform &lt;= 10.4 - Arbitrary File Read</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-46938.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-46938.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 22, 2024</span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-46938" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-46938</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)sitecore&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An issue was discovered in Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) 8.0 Initial Release through 10.4 Initial Release. An unauthenticated attacker can read arbitrary files.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can read arbitrary files from the Sitecore server, potentially exposing sensitive configuration and credentials.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update Sitecore Experience Platform to a version that patches CVE-2024-46938.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">lfi</span><span class="nt-tag">rce</span><span class="nt-tag">sitecore</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.assetnote.io/resources/research/leveraging-an-order-of-operations-bug-to-achieve-rce-in-sitecore-8-x---10-x" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-46938" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="sitecore login panel - detect info identify web-based control panels sitecore login panel was detected. dhiyaneshdk discovery panel sitecore cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Sitecore Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/sitecore-login.yaml" target="_blank" rel="noopener" class="nt-source-link">sitecore-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Welcome to Sitecore&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Sitecore login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">sitecore</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="sitefinity login info identify web-based control panels this template identifies the sitefinity login page. dhiyaneshdk sitefinity edb panel progress discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Sitefinity Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/sitefinity-login.yaml" target="_blank" rel="noopener" class="nt-source-link">sitefinity-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;product&#34;] contains &#34;Progress:Sitefinity&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">This template identifies the Sitefinity login page.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">sitefinity</span><span class="nt-tag">edb</span><span class="nt-tag">panel</span><span class="nt-tag">progress</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.exploit-db.com/ghdb/6722" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="skeepers login panel - detect info identify web-based control panels skeepers login panel was detected. righettod panel skeepers login detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Skeepers Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/skeepers-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">skeepers-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 13, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Skeepers&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Skeepers login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">skeepers</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://skeepers.io" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="skyvern panel - detect info identify web-based control panels skyvern is an open-source ai agent that automates browser-based workflows using
llms and computer vision rxerium agents ai automation detect discovery llm panel skyvern" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Skyvern Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/skyvern-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">skyvern-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 27, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;Skyvern&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Skyvern is an open-source AI agent that automates browser-based workflows using
LLMs and computer vision</div></div></div>
  <div class="nt-tags"><span class="nt-tag">agents</span><span class="nt-tag">ai</span><span class="nt-tag">automation</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">llm</span><span class="nt-tag">panel</span><span class="nt-tag">skyvern</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/Skyvern-AI/skyvern" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://skyvern.com" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="smart s200 management platform v.s200 - sql injection high identify critical remote vulnerabilities sql injection vulnerability in baizhuo network smart s200 management platform v.s200 allows a local attacker to obtain sensitive information and escalate privileges via the /importexport.php component. cve-2024-27718 dhiyaneshdk cve cve2024 smart-s45f sqli vuln cwe-89" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Smart s200 Management Platform v.S200 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-27718.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-27718.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 18, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-27718" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-27718</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Smart管理平台&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">SQL Injection vulnerability in Baizhuo Network Smart s200 Management Platform v.S200 allows a local attacker to obtain sensitive information and escalate privileges via the /importexport.php component.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Authenticated attackers can extract sensitive database information via SQL injection in the importexport.php component.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update Smart s200 Management Platform to a version that addresses CVE-2024-27718.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">smart-s45f</span><span class="nt-tag">sqli</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/tldjgggg/cve/blob/main/sql.md" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="smartping dashboard panel - detect info identify web-based control panels smartping dashboard panel was detected. dhiyaneshdk panel misconfig unauth smartping discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">SmartPing Dashboard Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/smartping-dashboard.yaml" target="_blank" rel="noopener" class="nt-source-link">smartping-dashboard.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)SmartPing Dashboard&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">SmartPing Dashboard panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">misconfig</span><span class="nt-tag">unauth</span><span class="nt-tag">smartping</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="smartsearchwp &lt; 2.4.6 - openai key disclosure medium identify critical remote vulnerabilities the plugin does not have proper authorization in one of its rest endpoint, allowing unauthenticated users to retrieve the encoded key and then decode it, thereby leaking the openai api key. cve-2024-6845 s4e-io cve cve2024 exposure smartsearchwp vuln wordpress wp wp-plugin cwe-862" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">SmartSearchWP &lt; 2.4.6 - OpenAI Key Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-6845.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-6845.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> s4e-io</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 25, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/862.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-862</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-6845" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-6845</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/smartsearchwp&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The plugin does not have proper authorization in one of its REST endpoint, allowing unauthenticated users to retrieve the encoded key and then decode it, thereby leaking the OpenAI API key.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can retrieve and decode the OpenAI API key through an unsecured REST endpoint, potentially incurring API usage costs and data exposure.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update SmartSearchWP plugin to version 2.4.6 or later to address the API key disclosure vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">exposure</span><span class="nt-tag">smartsearchwp</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wpscan.com/vulnerability/cfaaa843-d89e-42d4-90d9-988293499d26/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-6845" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="smartermail login panel - detect info identify web-based control panels smartermail login panel was detected. rxerium panel smartermail login detect discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">SmarterMail Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/smartermail-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">smartermail-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 28, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)SmarterMail&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">SmarterMail login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">smartermail</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.smartertools.com/smartermail/business-email-server" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="social auto poster &lt;= 5.3.14 - stored cross-site scripting high identify critical remote vulnerabilities social auto poster plugin for wordpress versions up to 5.3.14 contains a stored cross-site scripting caused by insufficient sanitization and escaping of &#39;maptypes&#39; parameter in the &#39;wpw_auto_poster_map_wordpress_post_type&#39; ajax function, letting unauthenticated attackers inject and execute arbitrary scripts when users access affected pages. cve-2024-6753 shivam kamboj cve cve2024 social-auto-poster vkev wordpress wp wp-plugin xss cwe-79" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Social Auto Poster &lt;= 5.3.14 - Stored Cross-Site Scripting</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-6753.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-6753.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Shivam Kamboj</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 26, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-79</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-6753" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-6753</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;product&#34;] contains &#34;WPWeb Infotech:Social Auto Poster&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Social Auto Poster plugin for WordPress versions up to 5.3.14 contains a stored cross-site scripting caused by insufficient sanitization and escaping of &#39;mapTypes&#39; parameter in the &#39;wpw_auto_poster_map_wordpress_post_type&#39; AJAX function, letting unauthenticated attackers inject and execute arbitrary scripts when users access affected pages.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can execute arbitrary scripts in users&#39; browsers, potentially leading to session hijacking, defacement, or redirection.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest version of the plugin where the vulnerability is fixed.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">social-auto-poster</span><span class="nt-tag">vkev</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">xss</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/3c268a6d-dfb4-4a9d-802e-80e5c1c53ca2" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://patchstack.com/database/vulnerability/social-auto-poster/wordpress-social-auto-poster-plugin-5-3-14-unauthenticated-stored-cross-site-scripting-vulnerability" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-6753" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="softether vpn admin console - default login high identify default logins in web-based control panels the administrative password for the softether vpn server is blank. bhutch default-login misconfig softether vpn vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">SoftEther VPN Admin Console - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/softether/softether-vpn-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">softether-vpn-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> bhutch</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 14, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;SoftEther VPN Server&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The administrative password for the SoftEther VPN Server is blank.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">misconfig</span><span class="nt-tag">softether</span><span class="nt-tag">vpn</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.softether.org/4-docs/1-manual/3._SoftEther_VPN_Server_Manual/3.3_VPN_Server_Administration#Administration_Authority_for_the_Entire_SoftEther_VPN_Server" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="softether vpn panel - detect info identify web-based control panels softether vpn panel was detected. bhutch panel vpn softether discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">SoftEther VPN Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/softether-vpn-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">softether-vpn-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> bhutch</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 20, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)SoftEther VPN Server&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">SoftEther VPN panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">vpn</span><span class="nt-tag">softether</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="solar-log - monitoring panel info identify web-based control panels solar-log is a solar plant monitoring system by solare datensysteme gmbh (germany)
used for pv system monitoring, yield optimisation, and fault detection. the web
interface is commonly exposed on port 80, 81, or non-standard ports. rxerium discovery energy ics monitoring ot panel solar solar-log" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Solar-Log - Monitoring Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/solar-log-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">solar-log-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 27, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;Solar-Log&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Solar-Log is a solar plant monitoring system by Solare Datensysteme GmbH (Germany)
used for PV system monitoring, yield optimisation, and fault detection. The web
interface is commonly exposed on port 80, 81, or non-standard ports.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">energy</span><span class="nt-tag">ics</span><span class="nt-tag">monitoring</span><span class="nt-tag">ot</span><span class="nt-tag">panel</span><span class="nt-tag">solar</span><span class="nt-tag">solar-log</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.solar-log.com/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="solaredge monitoring - login panel info identify web-based control panels solaredge telematics monitoring panel has been detected. rxerium discovery ics panel solar solaredge" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">SolarEdge Monitoring - Login Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/solaredge-monitoring-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">solaredge-monitoring-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 27, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;^SolarEdge&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">SolarEdge Telematics monitoring panel has been detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">ics</span><span class="nt-tag">panel</span><span class="nt-tag">solar</span><span class="nt-tag">solaredge</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.solaredge.com/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="solarview 6.00 - remote command execution critical identify critical remote vulnerabilities solarview compact 6.00 is vulnerable to a command injection via network_test.php. cve-2022-40881 for3stco1d contec cve cve2022 lfi rce solarview vkev vuln cwe-77" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">SolarView 6.00 - Remote Command Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-40881.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-40881.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> For3stCo1d</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/77.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-77</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-40881" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-40881</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-244067125&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">SolarView Compact 6.00 is vulnerable to a command injection via network_test.php.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability allows an attacker to execute arbitrary commands on the target system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest patch or upgrade to a non-vulnerable version of SolarView.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">contec</span><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">lfi</span><span class="nt-tag">rce</span><span class="nt-tag">solarview</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/Timorlover/SolarView_Compact_6.0_rce_via_network_test.php" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/advisories/GHSA-wx3r-88rg-whxq" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-40881" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/KayCHENvip/vulnerability-poc" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/Threekiii/Awesome-POC" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="solarview compact 6.00 - os command injection critical identify critical remote vulnerabilities solarview compact 6.00 was discovered to contain a command injection vulnerability, attackers can execute commands by bypassing internal restrictions through downloader.php. cve-2023-23333 mr-xn contec cve cve2023 packetstorm rce solarview vkev vuln cwe-77" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">SolarView Compact 6.00 - OS Command Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-23333.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-23333.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Mr-xn</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 16, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/77.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-77</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-23333" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-23333</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)solarview compact&#34; || service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-244067125&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">SolarView Compact 6.00 was discovered to contain a command injection vulnerability, attackers can execute commands by bypassing internal restrictions through downloader.php.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability can lead to unauthorized remote code execution, potentially compromising the confidentiality, integrity, and availability of the system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest patch or update provided by the vendor to fix the OS command injection vulnerability in SolarView Compact 6.00.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">contec</span><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">packetstorm</span><span class="nt-tag">rce</span><span class="nt-tag">solarview</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/Timorlover/CVE-2023-23333" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/Mr-xn/CVE-2023-23333" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-23333" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="http://packetstormsecurity.com/files/174537/SolarView-Compact-6.00-Remote-Command-Execution.html" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/h00die-gr3y/Metasploit" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="solarview compact 6.00 - os command injection critical identify critical remote vulnerabilities solarview compact 6.00 was discovered to contain a command injection vulnerability via conf_mail.php. cve-2022-29303 badboycxcc contec cve cve2022 edb injection kev packetstorm rce solarview vkev vuln cwe-78" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">SolarView Compact 6.00 - OS Command Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-29303.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-29303.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> badboycxcc</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/78.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-78</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-29303" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-29303</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)solarview compact&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">SolarView Compact 6.00 was discovered to contain a command injection vulnerability via conf_mail.php.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability can lead to unauthorized remote code execution, potentially compromising the confidentiality, integrity, and availability of the system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest patch or update provided by the vendor to fix the OS command injection vulnerability in SolarView Compact 6.00.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">contec</span><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">edb</span><span class="nt-tag">injection</span><span class="nt-tag">kev</span><span class="nt-tag">packetstorm</span><span class="nt-tag">rce</span><span class="nt-tag">solarview</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.exploit-db.com/exploits/50940" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-29303" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://drive.google.com/drive/folders/1tGr-WExbpfvhRg31XCoaZOFLWyt3r60g?usp=sharing" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="http://packetstormsecurity.com/files/167183/SolarView-Compact-6.0-Command-Injection.html" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/ARPSyndicate/cvemon" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="solarview compact &lt;= 6.00 - local file inclusion critical identify critical remote vulnerabilities there is an arbitrary read file vulnerability in solarview compact 6.00 and below, attackers can bypass authentication to read files through texteditor.php cve-2023-29919 for3stco1d contec cve cve2023 edb lfi solarview vkev vuln cwe-276" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">SolarView Compact &lt;= 6.00 - Local File Inclusion</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-29919.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-29919.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> For3stCo1d</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 19, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/276.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-276</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-29919" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-29919</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)solarview compact&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">There is an arbitrary read file vulnerability in SolarView Compact 6.00 and below, attackers can bypass authentication to read files through texteditor.php</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can exploit this vulnerability to read sensitive files on the server, potentially leading to unauthorized access or information disclosure.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to a patched version of SolarView Compact or apply the vendor-provided security patch to mitigate the LFI vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">contec</span><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">edb</span><span class="nt-tag">lfi</span><span class="nt-tag">solarview</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/xiaosed/CVE-2023-29919" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-29919" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.solarview.io/" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/nomi-sec/PoC-in-GitHub" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="solarview compact panel - detect info identify web-based control panels solarview compact panel was detected. princechaddha contec discovery iot panel solarview cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">SolarView Compact Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/solarview-compact-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">solarview-compact-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> princechaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)solarview compact&#34; || service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-244067125&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">SolarView Compact panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">contec</span><span class="nt-tag">discovery</span><span class="nt-tag">iot</span><span class="nt-tag">panel</span><span class="nt-tag">solarview</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="solarwinds arm (access rights manager) - detect info identify web-based control panels solarwinds arm login panel was detected. bhutch discovery panel solarwinds cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">SolarWinds ARM (Access Rights Manager) - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/solarwinds-arm-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">solarwinds-arm-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> bhutch</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 24, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-1416464161&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">SolarWinds ARM login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">solarwinds</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.solarwinds.com/access-rights-manager" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="solarwinds orion api - auth bypass critical identify critical remote vulnerabilities solarwinds orion api is vulnerable to an authentication bypass vulnerability that could allow a remote attacker to execute api commands. this vulnerability could allow a remote attacker to bypass authentication and execute api commands which may result in a compromise of the solarwinds instance. solarwinds orion platform versions 2019.4 hf 5, 2020.2 with no hotfix installed, and 2020.2 hf 1 are affected. cve-2020-10148 dwisiswant0 auth-bypass cve cve2020 kev rce solarwinds vkev vuln cwe-287,cwe-288" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">SolarWinds Orion API - Auth Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2020/CVE-2020-10148.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2020-10148.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dwisiswant0</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/287,CWE-288.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-287,CWE-288</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2020-10148" target="_blank" rel="noopener" class="nt-cve-link">CVE-2020-10148</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;product&#34;] contains &#34;SolarWinds:Orion&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">SolarWinds Orion API is vulnerable to an authentication bypass vulnerability that could allow a remote attacker to execute API commands. This vulnerability could allow a remote attacker to bypass authentication and execute API commands which may result in a compromise of the SolarWinds instance. SolarWinds Orion Platform versions 2019.4 HF 5, 2020.2 with no hotfix installed, and 2020.2 HF 1 are affected.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability can lead to unauthorized access to sensitive information and potential compromise of the SolarWinds Orion system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the necessary patches or updates provided by SolarWinds to fix the authentication bypass vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2020</span><span class="nt-tag">kev</span><span class="nt-tag">rce</span><span class="nt-tag">solarwinds</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://kb.cert.org/vuls/id/843464" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/jaeles-project/jaeles-signatures/blob/master/cves/solarwinds-lfi-cve-2020-10148.yaml" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://gist.github.com/0xsha/75616ef6f24067c4fb5b320c5dfa4965" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://twitter.com/0xsha/status/1343800953946787847" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2020-10148" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="solarwinds orion default login high identify default logins in web-based control panels solarwinds orion default admin credentials were discovered. dwisiswant0 default-login solarwinds vuln cwe-522" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">SolarWinds Orion Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/solarwinds/solarwinds-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">solarwinds-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dwisiswant0</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/522.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-522</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;SolarWinds Orion&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">SolarWinds Orion default admin credentials were discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">solarwinds</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/solarwinds/OrionSDK/wiki/REST" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="solarwinds security event manager - unauthenticated rce high identify critical remote vulnerabilities the solarwinds security event manager was susceptible to remote code execution vulnerability. this vulnerability allows an unauthenticated user to abuse solarwinds’ service, resulting in remote code execution. cve-2024-0692 dhiyaneshdk cisa cve cve2024 event-manager solarwinds vkev vuln cwe-502" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">SolarWinds Security Event Manager - Unauthenticated RCE</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-0692.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-0692.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 4, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/502.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-502</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-0692" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-0692</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)SolarWinds Security Event Manager&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The SolarWinds Security Event Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows an unauthenticated user to abuse SolarWinds’ service, resulting in remote code execution.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers on the adjacent network can execute arbitrary code remotely on the SolarWinds Security Event Manager, leading to complete system compromise and potential access to all security event data.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to SolarWinds Security Event Manager version 2023.4.1 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cisa</span><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">event-manager</span><span class="nt-tag">solarwinds</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://documentation.solarwinds.com/en/success_center/sem/content/release_notes/sem_2023-4-1_release_notes.htm" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="solarwinds serv-u - directory traversal high identify critical remote vulnerabilities solarwinds serv-u was susceptible to a directory transversal vulnerability that would allow access to read sensitive files on the host machine. cve-2024-28995 dhiyaneshdk cve cve2024 kev lfi serv-u solarwinds vkev vuln cwe-22" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">SolarWinds Serv-U - Directory Traversal</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-28995.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-28995.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 13, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-28995" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-28995</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Serv-U&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">SolarWinds Serv-U was susceptible to a directory transversal vulnerability that would allow access to read sensitive files on the host machine.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can traverse directories and access sensitive files outside the intended directory structure.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update SolarWinds Serv-U to a version that patches the directory traversal vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">kev</span><span class="nt-tag">lfi</span><span class="nt-tag">serv-u</span><span class="nt-tag">solarwinds</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://attackerkb.com/topics/2k7UrkHyl3/cve-2024-28995/rapid7-analysis" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-28995" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://x.com/stephenfewer/status/1801191416741130575" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="solarwinds web help desk - authentication bypass critical identify critical remote vulnerabilities solarwinds web help desk 12.8.8 hf1 and earlier contains an authentication bypass vulnerability in the webobjects session handling. by crafting a request with a manipulated path component to an internal admin page endpoint, an unauthenticated attacker can access privileged administrative functions including authentication configuration settings, saml/cas setup, and api key management. cve-2025-40554 bushi-gg auth-bypass cve cve2025 solarwinds vkev vuln whd cwe-1390" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">SolarWinds Web Help Desk - Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-40554.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-40554.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Bushi-gg</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 16, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/1390.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-1390</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-40554" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-40554</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;product&#34;] contains &#34;SolarWinds:Web Help Desk&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">SolarWinds Web Help Desk 12.8.8 HF1 and earlier contains an authentication bypass vulnerability in the WebObjects session handling. By crafting a request with a manipulated path component to an internal admin page endpoint, an unauthenticated attacker can access privileged administrative functions including authentication configuration settings, SAML/CAS setup, and API key management.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can bypass authentication and access administrative configuration pages, potentially leading to full system compromise through authentication method manipulation.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to Web Help Desk version 2026.1 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">solarwinds</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">whd</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.solarwinds.com/trust-center/security-advisories/CVE-2025-40554" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://documentation.solarwinds.com/en/success_center/whd/content/release_notes/whd_2026-1_release_notes.htm" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.rapid7.com/blog/post/etr-multiple-critical-solarwinds-web-help-desk-vulnerabilities-cve-2025-40551-40552-40553-40554/" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-40554" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="solarwinds web help desk - authentication bypass critical identify critical remote vulnerabilities solarwinds web help desk contains an authentication bypass vulnerability caused by improper access control, letting attackers execute protected actions without authentication, exploit requires no special conditions. cve-2025-40552 watchtowr,dhiyaneshdk auth-bypass cve cve2025 solarwinds web-help-desk cwe-1390" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">SolarWinds Web Help Desk - Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-40552.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-40552.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> watchTowr,DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 26, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/1390.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-1390</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-40552" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-40552</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1895809524&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">SolarWinds Web Help Desk contains an authentication bypass vulnerability caused by improper access control, letting attackers execute protected actions without authentication, exploit requires no special conditions.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can execute protected actions without authentication, potentially compromising system integrity and data security.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest version of SolarWinds Web Help Desk.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">solarwinds</span><span class="nt-tag">web-help-desk</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/watchtowrlabs/watchTowr-vs-SolarWinds-WebHelpDesk-CVE-2025-40552-CVE-2025-40553" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.solarwinds.com/trust-center/security-advisories/CVE-2025-40552" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://documentation.solarwinds.com/en/success_center/whd/content/release_notes/whd_2026-1_release_notes.htm" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-40552" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="solarwinds web help desk - hardcoded credential critical identify critical remote vulnerabilities the solarwinds web help desk (whd) software is affected by a hardcoded credential vulnerability, allowing remote unauthenticated user to access internal functionality and modify data. cve-2024-28987 iamnoooob,rootxharsh,pdresearch cve cve2024 exposure help-desk kev solarwinds vkev vuln cwe-798" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">SolarWinds Web Help Desk - Hardcoded Credential</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-28987.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-28987.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> iamnoooob,rootxharsh,pdresearch</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 31, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/798.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-798</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-28987" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-28987</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1895809524&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The SolarWinds Web Help Desk (WHD) software is affected by a hardcoded credential vulnerability, allowing remote unauthenticated user to access internal functionality and modify data.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers with knowledge of the hardcoded credentials can gain unauthorized access to the SolarWinds Web Help Desk system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update SolarWinds Web Help Desk to a version that removes the hardcoded credentials.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">exposure</span><span class="nt-tag">help-desk</span><span class="nt-tag">kev</span><span class="nt-tag">solarwinds</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://support.solarwinds.com/SuccessCenter/s/article/SolarWinds-Web-Help-Desk-12-8-3-Hotfix-2" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.solarwinds.com/trust-center/security-advisories/cve-2024-28987" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-28987" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="solarwinds web help desk &lt; 12.8.3 - insecure deserialization critical identify critical remote vulnerabilities solarwinds web help desk before version 12.8.3 contain a critical java deserialization vulnerability that enables remote code execution. attackers can exploit this flaw to execute arbitrary commands on the host machine. initially reported as unauthenticated, solarwinds was unable to reproduce without authentication but still recommended immediate patching. with a cvss score of 9.8, this vulnerability was discovered by inmarsat government researchers and added to cisa&#39;s known exploited vulnerabilities catalog due to active exploitation in the wild. the complete attack vector requires low complexity and has high impact on confidentiality, integrity, and availability. this vulnerability was later bypassed, leading to cve-2024-28988 and subsequently cve-2025-26399. fixed in version 12.8.3 hotfix 1. cve-2024-28986 rxerium cve cve2024 deserialization kev rce solarwinds vkev webhelpdesk cwe-502" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">SolarWinds Web Help Desk &lt; 12.8.3 - Insecure Deserialization</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-28986.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-28986.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 22, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/502.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-502</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-28986" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-28986</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;product&#34;] contains &#34;SolarWinds:Web Help Desk&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">SolarWinds Web Help Desk before version 12.8.3 contain a critical Java deserialization vulnerability that enables remote code execution. Attackers can exploit this flaw to execute arbitrary commands on the host machine. Initially reported as unauthenticated, SolarWinds was unable to reproduce without authentication but still recommended immediate patching. With a CVSS score of 9.8, this vulnerability was discovered by Inmarsat Government researchers and added to CISA&#39;s Known Exploited Vulnerabilities Catalog due to active exploitation in the wild. The complete attack vector requires low complexity and has high impact on confidentiality, integrity, and availability. This vulnerability was later bypassed, leading to CVE-2024-28988 and subsequently CVE-2025-26399. Fixed in version 12.8.3 Hotfix 1.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can execute arbitrary commands on the host machine, potentially leading to full system compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the available patch provided by SolarWinds.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">deserialization</span><span class="nt-tag">kev</span><span class="nt-tag">rce</span><span class="nt-tag">solarwinds</span><span class="nt-tag">vkev</span><span class="nt-tag">webhelpdesk</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.helpnetsecurity.com/2024/08/15/cve-2024-28986/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://threatprotect.qualys.com/2024/08/18/solarwinds-web-help-desk-whd-java-deserialization-vulnerability-cve-2024-28986/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://thehackernews.com/2024/08/solarwinds-releases-patch-for-critical.html" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="solarwinds web help desk &lt; 12.8.8 hotfix 1 (hf1) - security control bypass high identify critical remote vulnerabilities solarwinds web help desk was found to be susceptible to a security control bypass vulnerability that if exploited, could allow an unauthenticated attacker to gain access to certain restricted functionality. cve-2025-40536 inokii cve cve2025 kev passive solarwinds vkev webhelpdesk cwe-693" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">SolarWinds Web Help Desk &lt; 12.8.8 Hotfix 1 (HF1) - Security Control Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-40536.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-40536.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> inokii</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 16, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/693.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-693</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-40536" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-40536</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;product&#34;] contains &#34;SolarWinds:Web Help Desk&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">SolarWinds Web Help Desk was found to be susceptible to a security control bypass vulnerability that if exploited, could allow an unauthenticated attacker to gain access to certain restricted functionality.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can gain access to certain restricted functionality.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the available 12.8.8 Hotfix 1 (HF1) or upgrade to version 2026.1.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">kev</span><span class="nt-tag">passive</span><span class="nt-tag">solarwinds</span><span class="nt-tag">vkev</span><span class="nt-tag">webhelpdesk</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.solarwinds.com/trust-center/security-advisories/cve-2025-40536" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://documentation.solarwinds.com/en/success_center/whd/content/release_notes/whd_2026-1_release_notes.htm" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://horizon3.ai/attack-research/cve-2025-40551-another-solarwinds-web-help-desk-deserialization-issue/" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="solara &lt;1.35.1 - local file inclusion high identify critical remote vulnerabilities a local file inclusion (lfi) vulnerability was identified in widgetti/solara, in version &lt;1.35.1, which was fixed in version 1.35.1. this vulnerability arises from the application&#39;s failure to properly validate uri fragments for directory traversal sequences such as &#39;../&#39; when serving static files. an attacker can exploit this flaw by manipulating the fragment part of the uri to read arbitrary files on the local file system. cve-2024-39903 iamnoooob,rootxharsh,pdresearch cve cve2024 lfi solara vuln cwe-22" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Solara &lt;1.35.1 - Local File Inclusion</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-39903.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-39903.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> iamnoooob,rootxharsh,pdresearch</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 25, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-39903" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-39903</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-223126228&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A Local File Inclusion (LFI) vulnerability was identified in widgetti/solara, in version &lt;1.35.1, which was fixed in version 1.35.1. This vulnerability arises from the application&#39;s failure to properly validate URI fragments for directory traversal sequences such as &#39;../&#39; when serving static files. An attacker can exploit this flaw by manipulating the fragment part of the URI to read arbitrary files on the local file system.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can exploit LFI to read arbitrary files from the local filesystem.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update Solara to version 1.35.1 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">lfi</span><span class="nt-tag">solara</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-39903" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/widgetti/solara/commit/df2fd66a7f4e8ffd36e8678697a8a4f76760dc54" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/widgetti/solara/security/advisories/GHSA-9794-pc4r-438w" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="somansa dlp login panel - detect info identify web-based control panels somansa dlp login panel was detected. gy741,ritikchaddha panel somansa dlp discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Somansa DLP Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/somansa-dlp-detect.yaml" target="_blank" rel="noopener" class="nt-source-link">somansa-dlp-detect.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> gy741,ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)DLP system&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Somansa DLP login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">somansa</span><span class="nt-tag">dlp</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.somansa.com/solution/integrated_solution/dlp/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="sonar poller login - panel detect info identify web-based control panels sonar poller login/interface was discovered. th3l0newolf discovery login panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Sonar Poller Login - Panel Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/sonar-poller-login.yaml" target="_blank" rel="noopener" class="nt-source-link">sonar-poller-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Th3l0newolf</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 14, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Sonar Poller&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Sonar Poller login/interface was discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">login</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="sonarqube default login - detect high identify default logins in web-based control panels sonarqube contains a default login vulnerability. an attacker can obtain access to user accounts and access sensitive information, modify data, and/or execute unauthorized operations. ep1csage default-login sonarqube vuln cwe-522" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">SonarQube Default Login - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/sonarqube/sonarqube-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">sonarqube-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Ep1cSage</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 12, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/522.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-522</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;SonarQube&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">SonarQube contains a default login vulnerability. An attacker can obtain access to user accounts and access sensitive information, modify data, and/or execute unauthorized operations.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">sonarqube</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://docs.sonarsource.com/sonarqube/9.6/instance-administration/security/#:~:text=When%20installing%20SonarQube%2C%20a%20default,Password%3A%20admin" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="sonatype nexus repository manager  &lt;3.15.0 - remote code execution critical identify critical remote vulnerabilities sonatype nexus repository manager before 3.15.0 is susceptible to remote code execution. cve-2019-7238 pikpikcu cve cve2019 kev nexus rce sonatype vkev vuln" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Sonatype Nexus Repository Manager  &lt;3.15.0 - Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2019/CVE-2019-7238.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2019-7238.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pikpikcu</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2019-7238" target="_blank" rel="noopener" class="nt-cve-link">CVE-2019-7238</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)nexus repository manager&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Sonatype Nexus Repository Manager before 3.15.0 is susceptible to remote code execution.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade Sonatype Nexus Repository Manager to a version higher than 3.15.0.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2019</span><span class="nt-tag">kev</span><span class="nt-tag">nexus</span><span class="nt-tag">rce</span><span class="nt-tag">sonatype</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/jas502n/CVE-2019-7238" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://support.sonatype.com/hc/en-us/articles/360017310793-CVE-2019-7238-Nexus-Repository-Manager-3-Missing-Access-Controls-and-Remote-Code-Execution-February-5th-2019" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2019-7238" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/ycdxsb/Exploits" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/zhangchi991022/Comprehensive-experiment-of-infomation-security" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="sonatype nexus repository manager 3 - local file inclusion high identify critical remote vulnerabilities path traversal in sonatype nexus repository 3 allows an unauthenticated attacker to read system files. fixed in version 3.68.1. cve-2024-4956 ritikchaddha cve cve2024 lfi nexus sonatype vuln cwe-22" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Sonatype Nexus Repository Manager 3 - Local File Inclusion</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-4956.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-4956.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 23, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-4956" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-4956</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)nexus repository manager&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Path Traversal in Sonatype Nexus Repository 3 allows an unauthenticated attacker to read system files. Fixed in version 3.68.1.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can read arbitrary system files via path traversal in Sonatype Nexus Repository.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update Sonatype Nexus Repository 3 to version 3.68.1 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">lfi</span><span class="nt-tag">nexus</span><span class="nt-tag">sonatype</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://x.com/phithon_xg/status/1793517567560335428?s=46&amp;t=GMMfJwV8rhJHdcj2TUympg" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-4956" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://support.sonatype.com/hc/en-us/articles/29416509323923" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/fkie-cad/nvd-json-data-feeds" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="sonatype nexus repository manager 3 - remote code execution high identify critical remote vulnerabilities sonatype nexus repository before 3.21.2 allows javael injection cve-2020-10199 rootxharsh,iamnoooob,pdresearch cve cve2020 kev nexus packetstorm rce sonatype vkev vuln cwe-917" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Sonatype Nexus Repository Manager 3 - Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2020/CVE-2020-10199.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2020-10199.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rootxharsh,iamnoooob,pdresearch</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/917.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-917</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2020-10199" target="_blank" rel="noopener" class="nt-cve-link">CVE-2020-10199</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)nexus repository manager&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches or upgrade to a non-vulnerable version of Sonatype Nexus Repository Manager 3.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2020</span><span class="nt-tag">kev</span><span class="nt-tag">nexus</span><span class="nt-tag">packetstorm</span><span class="nt-tag">rce</span><span class="nt-tag">sonatype</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://twitter.com/iamnoooob/status/1246182773427240967" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://securitylab.github.com/advisories/GHSL-2020-011-nxrm-sonatype" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2020-10199" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="http://packetstormsecurity.com/files/157261/Nexus-Repository-Manager-3.21.1-01-Remote-Code-Execution.html" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://cwe.mitre.org/data/definitions/917.html" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="sonicwall analyzer login panel - detect info identify web-based control panels sonicwall analyzer login panel was detected. dhiyaneshdk discovery panel sonicwall cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">SonicWall Analyzer Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/sonicwall-analyzer-login.yaml" target="_blank" rel="noopener" class="nt-source-link">sonicwall-analyzer-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)sonicwall analyzer login&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">SonicWall Analyzer login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">sonicwall</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="sonicwall appliance management console login panel - detect info identify web-based control panels sonicwall appliance management console login panel was detected. dhiyaneshdk,tess discovery login panel sonicwall cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">SonicWall Appliance Management Console Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/sonic-wall-application.yaml" target="_blank" rel="noopener" class="nt-source-link">sonic-wall-application.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk,Tess</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)appliance management console login&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">SonicWall Appliance Management Console login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">login</span><span class="nt-tag">panel</span><span class="nt-tag">sonicwall</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="sonicwall gms and analytics - sql injection high identify critical remote vulnerabilities improper neutralization of special elements used in an sql command (&#39;sql injection&#39;) vulnerability in sonicwall gms and analytics allows an unauthenticated attacker to extract sensitive information from the application database. this issue affects gms: 9.3.2-sp1 and earlier versions; analytics: 2.5.0.4-r7 and earlier versions. cve-2023-34133 theamanrawat cve cve2023 injection sonicwall sqli vkev vuln cwe-89" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">SonicWall GMS and Analytics - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-34133.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-34133.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> theamanrawat</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 14, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-34133" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-34133</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-1381126564&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Improper Neutralization of Special Elements used in an SQL Command (&#39;SQL Injection&#39;) vulnerability in SonicWall GMS and Analytics allows an unauthenticated attacker to extract sensitive information from the application database. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability can lead to unauthorized access, data leakage, and potential compromise of the target system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches or updates provided by SonicWall to mitigate this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">injection</span><span class="nt-tag">sonicwall</span><span class="nt-tag">sqli</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://raw.githubusercontent.com/rapid7/metasploit-framework/4b130f5be7590d04878f3bda37555e59e733324d/modules/exploits/multi/http/sonicwall_shell_injection_cve_2023_34124.rb" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.sonicwall.com/support/product-notification/urgent-security-notice-sonicwall-gms-analytics-impacted-by-suite-of-vulnerabilities/230710150218060/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/getdrive/PoC/blob/main/2023/Sonicwall_Shell_Injection/sonicwall_shell_injection_cve_2023_34124.rb" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-34133" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="http://packetstormsecurity.com/files/174571/Sonicwall-GMS-9.9.9320-Remote-Code-Execution.html" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="sonicwall network security login - detect info identify web-based control panels sonicwall network security login panel was detected. justaacat discovery login panel sonicwall" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">SonicWall Network Security Login - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/sonic-wall-login.yaml" target="_blank" rel="noopener" class="nt-source-link">sonic-wall-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> JustaAcat</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)sonicwall network security login&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">SonicWall Network Security Login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">login</span><span class="nt-tag">panel</span><span class="nt-tag">sonicwall</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="sonicwall sma1000 lfi high identify critical remote vulnerabilities pre-authentication path traversal vulnerability in sma1000 firmware version 12.4.2, which allows an unauthenticated attacker to access arbitrary files and directories stored outside the web root directory. cve-2023-0126 tess cve cve2023 lfi sma1000 sonicwall vuln cwe-22" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">SonicWall SMA1000 LFI</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-0126.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-0126.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> tess</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 28, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-0126" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-0126</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Appliance Management Console Login&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Pre-authentication path traversal vulnerability in SMA1000 firmware version 12.4.2, which allows an unauthenticated attacker to access arbitrary files and directories stored outside the web root directory.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to read sensitive files on the affected device, potentially leading to unauthorized access or information disclosure.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches or firmware updates provided by SonicWall to mitigate this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">lfi</span><span class="nt-tag">sma1000</span><span class="nt-tag">sonicwall</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-0126" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/advisories/GHSA-mr28-27qx-phg3" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0001" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/Gerxnox/One-Liner-Collections" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/thecybertix/One-Liner-Collections" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="sonicwall - pre-authentication arbitrary file read critical identify critical remote vulnerabilities improper escaping of output in mod_rewrite in apache http server 2.4.59 and earlier allows an attacker to map urls to filesystem locations that are permitted to be served by the server but are not intentionally/directly reachable by any url, resulting in code execution or source code disclosure. substitutions in server context that use a backreferences or variables as the first segment of the substitution are affected.  some unsafe rewiterules will be broken by this change and the rewrite flag &#34;unsafeprefixstat&#34; can be used to opt back in once ensuring the substitution is appropriately constrained. cve-2024-38475 shaikhyaser cve cve2024 kev lfi sma-100 sonicwal vkev vuln cwe-116" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Sonicwall - Pre-Authentication Arbitrary File Read</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-38475.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-38475.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> shaikhyaser</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 2, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/116.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-116</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-38475" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-38475</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)SonicWall\&#34; html:\&#34;SMA&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Improper escaping of output in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to map URLs to filesystem locations that are permitted to be served by the server but are not intentionally/directly reachable by any URL, resulting in code execution or source code disclosure. Substitutions in server context that use a backreferences or variables as the first segment of the substitution are affected.  Some unsafe RewiteRules will be broken by this change and the rewrite flag &#34;UnsafePrefixStat&#34; can be used to opt back in once ensuring the substitution is appropriately constrained.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can read arbitrary files from the SonicWall SMA100 filesystem including configuration files, logs, and sensitive data, potentially leading to further exploitation or complete system compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to the latest patched version of SonicWall SMA100 or apply vendor-provided security updates.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">kev</span><span class="nt-tag">lfi</span><span class="nt-tag">sma-100</span><span class="nt-tag">sonicwal</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/watchtowrlabs/watchTowr-vs-SonicWall-PreAuth-RCE-Chain/blob/main/watchTowr-vs-SonicWall-PreAuth-RCE-Chain.py" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://labs.watchtowr.com/sonicboom-from-stolen-tokens-to-remote-shells-sonicwall-sma100-cve-2023-44221-cve-2024-38475/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-38475" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="sophos firewall &lt;=18.5 mr3 - remote code execution critical identify critical remote vulnerabilities sophos firewall version v18.5 mr3 and older contains an authentication bypass vulnerability in the user portal and webadmin which could allow a remote attacker to execute code. cve-2022-1040 for3stco1d auth-bypass cve cve2022 firewall kev rce sophos vkev vuln cwe-287" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Sophos Firewall &lt;=18.5 MR3 - Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-1040.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-1040.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> For3stCo1d</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/287.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-287</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-1040" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-1040</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)sophos&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Sophos Firewall version v18.5 MR3 and older contains an authentication bypass vulnerability in the User Portal and Webadmin which could allow a remote attacker to execute code.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected system, potentially leading to complete compromise of the firewall.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to a patched version of Sophos Firewall (&gt;=18.5 MR4) to mitigate this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">firewall</span><span class="nt-tag">kev</span><span class="nt-tag">rce</span><span class="nt-tag">sophos</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/killvxk/CVE-2022-1040" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/CronUp/Vulnerabilidades/blob/main/CVE-2022-1040_checker" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-1040" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://www.sophos.com/en-us/security-advisories/sophos-sa-20220325-sfos-rce" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/Mr-xn/Penetration_Testing_POC" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="sophos firewall login panel - detect info identify web-based control panels sophos firewall login panel was detected. organiccrap,daffainfo discovery panel sophos cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Sophos Firewall Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/sophos-fw-version-detect.yaml" target="_blank" rel="noopener" class="nt-source-link">sophos-fw-version-detect.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> organiccrap,daffainfo</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)sophos&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Sophos Firewall login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">sophos</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="sophos mobile panel - detect info identify web-based control panels sophos mobile panel was detected. adam crosser,idealphase discovery panel sophos cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Sophos Mobile Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/sophos-mobile-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">sophos-mobile-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Adam Crosser,idealphase</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)sophos mobile&#34;}) || service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-1274798165&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Sophos Mobile panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">sophos</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.sophos.com/en-us/products/mobile-control" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.sophos.com/en-us/support/downloads/sophos-mobile" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="sophos web appliance info identify web-based control panels  dhiyaneshdk discovery login panel sophos" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Sophos Web Appliance</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/sophos-web-appliance.yaml" target="_blank" rel="noopener" class="nt-source-link">sophos-web-appliance.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-893681401&#34; || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)sophos web appliance&#34;})</code></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">login</span><span class="nt-tag">panel</span><span class="nt-tag">sophos</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://docs.sophos.com/nsg/swa/help/en-us/nsg/swa/concepts/AboutYourAppliance.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="sound4 impact/first/pulse/eco &lt;=2.x - authentication bypass high identify critical remote vulnerabilities the application suffers from an sql injection vulnerability. input passed through the &#39;password&#39; post parameter in &#39;index.php&#39; is not properly sanitised before being returned to the user or used in sql queries. this can be exploited to manipulate sql queries by injecting arbitrary sql code and bypass the authentication mechanism. r3y3r53 sound4 auth-bypass sqli misconfig vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Sound4 IMPACT/FIRST/PULSE/Eco &lt;=2.x - Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/vulnerabilities/other/sound4-impact-password-auth-bypass.yaml" target="_blank" rel="noopener" class="nt-source-link">sound4-impact-password-auth-bypass.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> r3Y3r53</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 17, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)SOUND4&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The application suffers from an SQL Injection vulnerability. Input passed through the &#39;password&#39; POST parameter in &#39;index.php&#39; is not properly sanitised before being returned to the user or used in SQL queries. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code and bypass the authentication mechanism.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">sound4</span><span class="nt-tag">auth-bypass</span><span class="nt-tag">sqli</span><span class="nt-tag">misconfig</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.zeroscience.mk/en/vulnerabilities/ZSL-2022-5727.php" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="spacelogic c-bus home controller &lt;=1.31.460 - remote command execution high identify critical remote vulnerabilities spacelogic c-bus home controller through 1.31.460 is susceptible to remote command execution via improper neutralization of special elements. remote root exploit can be enabled when the command is compromised, and an attacker can potentially execute malware, obtain sensitive information, modify data, and/or gain full control without entering necessary credentials. cve-2022-34753 gy741 cve cve2022 iot oast packetstorm rce schneider-electric spacelogic vkev vuln cwe-78" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">SpaceLogic C-Bus Home Controller &lt;=1.31.460 - Remote Command Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-34753.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-34753.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> gy741</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/78.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-78</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-34753" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-34753</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)spacelogic c-bus&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">SpaceLogic C-Bus Home Controller through 1.31.460 is susceptible to remote command execution via improper neutralization of special elements. Remote root exploit can be enabled when the command is compromised, and an attacker can potentially execute malware, obtain sensitive information, modify data, and/or gain full control without entering necessary credentials.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability allows remote attackers to execute arbitrary commands on the affected system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade SpaceLogic C-Bus Home Controller to a version higher than 1.31.460 to mitigate this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">iot</span><span class="nt-tag">oast</span><span class="nt-tag">packetstorm</span><span class="nt-tag">rce</span><span class="nt-tag">schneider-electric</span><span class="nt-tag">spacelogic</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.zeroscience.mk/codes/SpaceLogic.txt" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://download.schneider-electric.com/files?p_enDocType=Security+and+Safety+Notice&amp;p_File_Name=SEVD-2022-193-02_SpaceLogic-C-Bus-Home-Controller-Wiser_MK2_Security_Notification.pdf" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="http://packetstormsecurity.com/files/167783/Schneider-Electric-SpaceLogic-C-Bus-Home-Controller-5200WHC2-Remote-Root.html" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-34753" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/nomi-sec/PoC-in-GitHub" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="spacelogic c-bus home panel - detect info identify web-based control panels  ritikchaddha discovery login panel schneider-electric spacelogic" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">SpaceLogic C-Bus Home Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/spacelogic-cbus-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">spacelogic-cbus-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)spacelogic c-bus&#34;</code></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">login</span><span class="nt-tag">panel</span><span class="nt-tag">schneider-electric</span><span class="nt-tag">spacelogic</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="spam protection, antispam, firewall by cleantalk &lt; 5.153.4 - unauthenticated blind sql injection high identify critical remote vulnerabilities it was possible to exploit an unauthenticated time-based blind sql injection vulnerability in the spam protection, antispam, firewall by cleantalk wordpress plugin before 5.153.4. the update_log function in lib/cleantalk/apbctwp/firewall/sfw.php included a vulnerable query that could be injected via the user-agent header by manipulating the cookies set by the spam protection, antispam, firewall by cleantalk wordpress plugin before 5.153.4, sending an initial request to obtain a ct_sfw_pass_key cookie and then manually setting a separate ct_sfw_passed cookie and disallowing it from being reset. cve-2021-24295 dhiyaneshdk cleantalk-spam-protect cve cve2021 passive sqli vkev vuln wordpress wp wp-plugin wpscan cwe-89" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Spam protection, AntiSpam, FireWall by CleanTalk &lt; 5.153.4 - Unauthenticated Blind SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2021/CVE-2021-24295.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2021-24295.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 24, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2021-24295" target="_blank" rel="noopener" class="nt-cve-link">CVE-2021-24295</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/plugin/cleantalk-spam-protect/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">It was possible to exploit an Unauthenticated Time-Based Blind SQL Injection vulnerability in the Spam protection, AntiSpam, FireWall by CleanTalk WordPress Plugin before 5.153.4. The update_log function in lib/Cleantalk/ApbctWP/Firewall/SFW.php included a vulnerable query that could be injected via the User-Agent Header by manipulating the cookies set by the Spam protection, AntiSpam, FireWall by CleanTalk WordPress plugin before 5.153.4, sending an initial request to obtain a ct_sfw_pass_key cookie and then manually setting a separate ct_sfw_passed cookie and disallowing it from being reset.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can extract database contents via time-based blind SQL injection through User-Agent header manipulation, potentially exposing all WordPress user data.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Fixed in 5.153.4</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cleantalk-spam-protect</span><span class="nt-tag">cve</span><span class="nt-tag">cve2021</span><span class="nt-tag">passive</span><span class="nt-tag">sqli</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">wpscan</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wpscan.com/vulnerability/152171fc-888c-4275-a118-5a1e664ef28b" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/20142995/nuclei-templates" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="speedtest panel - detection info identify web-based control panels speedtest panel was discovered rxerium speedtest tracker panel login discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Speedtest Panel - Detection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/speedtest-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">speedtest-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 27, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Speedtest Tracker&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Speedtest panel was discovered</div></div></div>
  <div class="nt-tags"><span class="nt-tag">speedtest</span><span class="nt-tag">tracker</span><span class="nt-tag">panel</span><span class="nt-tag">login</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/alexjustesen/speedtest-tracker" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://docs.speedtest-tracker.dev/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="sphinxonline panel - detect info identify web-based control panels sphinxonline login panel was detected. righettod panel sphinxonline login detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">SphinxOnline Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/sphinxonline-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">sphinxonline-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 3, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Connection - SphinxOnline&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">SphinxOnline Login Panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">sphinxonline</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.lesphinx-developpement.fr/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="splunk - default password high identify default logins in web-based control panels splunk default password vulnerability exposes systems to unauthorized access, compromising data integrity and security. pussycat0x default-login splunk vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Splunk - Default Password</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/splunk/splunk-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">splunk-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 1, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;Splunk&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Splunk Default Password Vulnerability exposes systems to unauthorized access, compromising data integrity and security.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">splunk</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="splunk &lt;=7.0.1 - information disclosure medium identify critical remote vulnerabilities splunk through 7.0.1 is susceptible to information disclosure by appending __raw/services/server/info/server-info?output_mode=json to a query, as demonstrated by discovering a license key. cve-2018-11409 harshbothra_ cve cve2018 edb splunk vkev vuln cwe-200" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Splunk &lt;=7.0.1 - Information Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2018/CVE-2018-11409.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2018-11409.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> harshbothra_</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2018-11409" target="_blank" rel="noopener" class="nt-cve-link">CVE-2018-11409</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)login - splunk&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Splunk through 7.0.1 is susceptible to information disclosure by appending __raw/services/server/info/server-info?output_mode=json to a query, as demonstrated by discovering a license key.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can exploit this vulnerability to gain unauthorized access to sensitive information.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade Splunk to a version higher than 7.0.1 to mitigate the vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2018</span><span class="nt-tag">edb</span><span class="nt-tag">splunk</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/kofa2002/splunk" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.exploit-db.com/exploits/44865/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="http://web.archive.org/web/20211208114213/https://securitytracker.com/id/1041148" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2018-11409" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="http://www.securitytracker.com/id/1041148" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="splunk enterprise - local file inclusion high identify critical remote vulnerabilities in splunk enterprise on windows versions below 9.2.2, 9.1.5, and 9.0.10, an attacker could perform a path traversal on the /modules/messaging/ endpoint in splunk enterprise on windows. this vulnerability should only affect splunk enterprise on windows. cve-2024-36991 dhiyaneshdk cve cve2024 lfi splunk vkev vuln cwe-22" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Splunk Enterprise - Local File Inclusion</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-36991.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-36991.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 5, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-36991" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-36991</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Login \\| Splunk&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">In Splunk Enterprise on Windows versions below 9.2.2, 9.1.5, and 9.0.10, an attacker could perform a path traversal on the /modules/messaging/ endpoint in Splunk Enterprise on Windows. This vulnerability should only affect Splunk Enterprise on Windows.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can perform path traversal to access sensitive filesystem locations on Splunk Enterprise for Windows.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update Splunk Enterprise to version 9.2.2, 9.1.5, or 9.0.10 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">lfi</span><span class="nt-tag">splunk</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://x.com/sheikhrishad0/status/1809210005125746880/photo/1" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://x.com/chybeta/status/1809249794122215557/photo/1" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-36991" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="splunk enterprise login panel - detect info identify web-based control panels splunk enterprise login panel was detected. praetorian-thendrickson discovery panel splunk cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Splunk Enterprise Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/splunk-enterprise-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">splunk-enterprise-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> praetorian-thendrickson</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)login - splunk&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Splunk Enterprise login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">splunk</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.splunk.com/en_us/software/splunk-enterprise.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="splunk mcp server ide login - detect info identify web-based control panels splunk mcp server ide login interface was discovered. th3l0newolf discovery ide login mcp panel splunk cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Splunk MCP Server IDE Login - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/splunk-mcp-server-ide-login.yaml" target="_blank" rel="noopener" class="nt-source-link">splunk-mcp-server-ide-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Th3l0newolf</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 2, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;^Splunk MCP Server&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Splunk MCP Server IDE login interface was discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">ide</span><span class="nt-tag">login</span><span class="nt-tag">mcp</span><span class="nt-tag">panel</span><span class="nt-tag">splunk</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="splunk soar login panel - detect info identify web-based control panels splunk soar login panel was detected. dhiyaneshdk panel splunk discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Splunk SOAR Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/splunk-login.yaml" target="_blank" rel="noopener" class="nt-source-link">splunk-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Splunk SOAR&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Splunk SOAR login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">splunk</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="spotweb login panel - detect info identify web-based control panels  theamanrawat detect discovery panel spotweb spotweb_project" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">SpotWeb Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/spotweb-login-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">spotweb-login-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> theamanrawat</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 5, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)spotweb - overview&#34;})</code></div>
  <div class="nt-tags"><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">spotweb</span><span class="nt-tag">spotweb_project</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="spotweb &lt;= 1.5.1 - cross site scripting (reflected) medium identify critical remote vulnerabilities there is a cross site scripting (xss) vulnerability in spotpage_login.php of spotweb 1.5.1 and below, which allows remote attackers to inject arbitrary web script or html via the data[performredirect] parameter. cve-2021-43725 theamanrawat cve cve2021 spotweb spotweb_project unauth vuln xss cwe-79" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Spotweb &lt;= 1.5.1 - Cross Site Scripting (Reflected)</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2021/CVE-2021-43725.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2021-43725.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> theamanrawat</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 5, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-79</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2021-43725" target="_blank" rel="noopener" class="nt-cve-link">CVE-2021-43725</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)spotweb - overview&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">There is a Cross Site Scripting (XSS) vulnerability in SpotPage_login.php of Spotweb 1.5.1 and below, which allows remote attackers to inject arbitrary web script or HTML via the data[performredirect] parameter.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute malicious scripts in the victim&#39;s browser, potentially leading to session hijacking, data theft, or other attacks.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Fixed in version 1.5.2</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2021</span><span class="nt-tag">spotweb</span><span class="nt-tag">spotweb_project</span><span class="nt-tag">unauth</span><span class="nt-tag">vuln</span><span class="nt-tag">xss</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/spotweb/spotweb/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/spotweb/spotweb/issues/718" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2021-43725" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/spotweb/spotweb/commit/2bfa001689aae96009688a193c64478647ba45a1" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="spring cloud config server - local file inclusion high identify critical remote vulnerabilities spring cloud config server versions 2.2.x prior to 2.2.3, versions 2.1.x prior to 2.1.9, and older unsupported versions allow applications to serve arbitrary configuration files through the spring-cloud-config-server module. a malicious user or attacker can send a request using a specially crafted url that can lead to a local file inclusion attack. cve-2020-5410 mavericknerd config cve cve2020 kev lfi springcloud traversal vkev vmware vuln cwe-22,cwe-23" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Spring Cloud Config Server - Local File Inclusion</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2020/CVE-2020-5410.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2020-5410.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> mavericknerd</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22,CWE-23.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22,CWE-23</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2020-5410" target="_blank" rel="noopener" class="nt-cve-link">CVE-2020-5410</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.images.mmh3&#34;] == &#34;116323821&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Spring Cloud Config Server versions 2.2.x prior to 2.2.3, versions 2.1.x prior to 2.1.9, and older unsupported versions allow applications to serve arbitrary configuration files through the spring-cloud-config-server module. A malicious user or attacker can send a request using a specially crafted URL that can lead to a local file inclusion attack.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can exploit this vulnerability to read arbitrary files from the server, potentially leading to unauthorized access or sensitive information disclosure.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to a patched version of Spring Cloud Config Server or apply the recommended security patches.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">config</span><span class="nt-tag">cve</span><span class="nt-tag">cve2020</span><span class="nt-tag">kev</span><span class="nt-tag">lfi</span><span class="nt-tag">springcloud</span><span class="nt-tag">traversal</span><span class="nt-tag">vkev</span><span class="nt-tag">vmware</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://tanzu.vmware.com/security/cve-2020-5410" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2020-5410" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/Live-Hack-CVE/CVE-2020-5410" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/tdtc7/qps" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/alphaSeclab/sec-daily-2020" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="sqwebmail login panel - detect info identify web-based control panels sqwebmail login panel was detected. ritikchaddha webmail sqwebmail panel discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">SqWebMail Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/sqwebmail-login-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">sqwebmail-login-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)SqWebMail&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">SqWebMail login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">webmail</span><span class="nt-tag">sqwebmail</span><span class="nt-tag">panel</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="squid end-of-life - detect info identify web-based control panels detected squid proxy versions that have reached end-of-life (eol) and no longer receive security updates. shivam kamboj tech squid eol" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Squid End-of-Life - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/technologies/eol/squid-eol.yaml" target="_blank" rel="noopener" class="nt-source-link">squid-eol.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Shivam Kamboj</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 5, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;product&#34;] contains &#34;Squid Cache:Squid&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detected Squid proxy versions that have reached End-of-Life (EOL) and no longer receive security updates.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">tech</span><span class="nt-tag">squid</span><span class="nt-tag">eol</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://endoflife.date/squid" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.squid-cache.org/Versions/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="squid proxy - http authentication credentials disclosure critical identify critical remote vulnerabilities squid versions prior to 7.2 fail to redact http authentication credentials in error page responses. the authorization header value is embedded in plain text inside the mailto: diagnostic block when squid generates an error page (e.g. err_dns_fail). cve-2025-62168 xtr0nix cve cve2025 info-disclosure proxy squid cwe-209" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Squid Proxy - HTTP Authentication Credentials Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-62168.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-62168.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> xtr0nix</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 14, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/209.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-209</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-62168" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-62168</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.head.server&#34;] matches `(?i)squid/`</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Squid versions prior to 7.2 fail to redact HTTP authentication credentials in error page responses. The Authorization header value is embedded in plain text inside the mailto: diagnostic block when Squid generates an error page (e.g. ERR_DNS_FAIL).</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can extract tokens and credentials used by trusted clients or backend applications proxied through Squid.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the version 7.2+ or disable debug information in administrator mailto links generated by Squid by configuring squid.conf with email_err_data off.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">info-disclosure</span><span class="nt-tag">proxy</span><span class="nt-tag">squid</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62168" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/squid-cache/squid/security/advisories/GHSA-c8cc-phh7-xmxr" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="squidex headless cms panel - detect info identify web-based control panels squidex is an open source headless cms and content management hub. johnk3r panel squidex login discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Squidex Headless CMS Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/squidex-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">squidex-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> johnk3r</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 13, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1099097618&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Squidex is an open source headless CMS and content management hub.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">squidex</span><span class="nt-tag">login</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/Squidex/squidex" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="squirrelmail 1.2.11 - local file inclusion high identify critical remote vulnerabilities squirrelmail 1.2.11 is vulnerable to local file inclusion. dhiyaneshdk edb lfi squirrelmail vuln cwe-22,cwe-73" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">SquirrelMail 1.2.11 - Local File Inclusion</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/vulnerabilities/squirrelmail/squirrelmail-lfi.yaml" target="_blank" rel="noopener" class="nt-source-link">squirrelmail-lfi.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22,CWE-73.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22,CWE-73</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1511806001&#34; || any([service[&#34;http.body&#34;], service[&#34;last.http.body&#34;]], {# matches &#34;(?i)squirrelmail&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">SquirrelMail 1.2.11 is vulnerable to local file inclusion.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">edb</span><span class="nt-tag">lfi</span><span class="nt-tag">squirrelmail</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.exploit-db.com/exploits/22793" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="squirrelmail 1.2.6/1.2.7 - cross-site scripting high identify critical remote vulnerabilities the virtual keyboard plugin for squirrelmail 1.2.6/1.2.7 is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input. cve-2002-1131 dhiyaneshdk,s4e-io cve cve2002 edb squirrelmail vkev vuln xss cwe-80" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">SquirrelMail 1.2.6/1.2.7 - Cross-Site Scripting</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2002/CVE-2002-1131.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2002-1131.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDk,s4e-io</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/80.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-80</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2002-1131" target="_blank" rel="noopener" class="nt-cve-link">CVE-2002-1131</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1511806001&#34; || any([service[&#34;http.body&#34;], service[&#34;last.http.body&#34;]], {# matches &#34;(?i)squirrelmail&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The Virtual Keyboard plugin for SquirrelMail 1.2.6/1.2.7 is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute arbitrary script code in the context of the victim&#39;s browser, potentially leading to session hijacking, data theft, or other malicious activities.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to a patched version of SquirrelMail or apply the necessary security patches to mitigate the XSS vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2002</span><span class="nt-tag">edb</span><span class="nt-tag">squirrelmail</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">xss</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="http://www.redhat.com/support/errata/RHSA-2002-204.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="http://www.debian.org/security/2002/dsa-191" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="http://sourceforge.net/project/shownotes.php?group_id=311&amp;release_id=110774" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://www.exploit-db.com/exploits/21811" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="squirrelmail login panel - detect info identify web-based control panels squirrelmail login panel was detected. dhiyaneshdk,ritikchaddha discovery edb panel squirrelmail cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">SquirrelMail Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/squirrelmail-login.yaml" target="_blank" rel="noopener" class="nt-source-link">squirrelmail-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDk,ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1511806001&#34; || any([service[&#34;http.body&#34;], service[&#34;last.http.body&#34;]], {# matches &#34;(?i)squirrelmail&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">SquirrelMail login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">edb</span><span class="nt-tag">panel</span><span class="nt-tag">squirrelmail</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.exploit-db.com/ghdb/7407" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="squirrelmail &lt;=1.4.6 - local file inclusion high identify critical remote vulnerabilities squirrelmail 1.4.6 and earlier versions are susceptible to a php local file inclusion vulnerability in functions/plugin.php if register_globals is enabled and magic_quotes_gpc is disabled. this allows remote attackers to execute arbitrary php code via a url in the plugins array parameter. cve-2006-2842 dhiyaneshdk cve cve2006 edb lfi squirrelmail vuln cwe-22" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Squirrelmail &lt;=1.4.6 - Local File Inclusion</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2006/CVE-2006-2842.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2006-2842.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2006-2842" target="_blank" rel="noopener" class="nt-cve-link">CVE-2006-2842</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1511806001&#34; || any([service[&#34;http.body&#34;], service[&#34;last.http.body&#34;]], {# matches &#34;(?i)squirrelmail&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">SquirrelMail 1.4.6 and earlier versions are susceptible to a PHP local file inclusion vulnerability in functions/plugin.php if register_globals is enabled and magic_quotes_gpc is disabled. This allows remote attackers to execute arbitrary PHP code via a URL in the plugins array parameter.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can exploit this vulnerability to read sensitive files on the server, potentially leading to unauthorized access or information disclosure.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade Squirrelmail to a version higher than 1.4.6 or apply the necessary patches to fix the LFI vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2006</span><span class="nt-tag">edb</span><span class="nt-tag">lfi</span><span class="nt-tag">squirrelmail</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.exploit-db.com/exploits/27948" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="http://squirrelmail.cvs.sourceforge.net/squirrelmail/squirrelmail/functions/global.php?r1=1.27.2.16&amp;r2=1.27.2.17&amp;view=patch&amp;pathrev=SM-1_4-STABLE" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="http://www.squirrelmail.org/security/issue/2006-06-01" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2006-2842" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="ftp://patches.sgi.com/support/free/security/advisories/20060703-01-U.asc" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="stackposts social marketing tool v1.0 - sql injection high identify critical remote vulnerabilities sql injection is a type of sql injection attack in which an attacker can exploit a vulnerability in a web application&#39;s input fields to manipulate the application&#39;s sql queries. r3y3r53 sqli stackposts time-based-sqli unauth vuln cwe-89" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Stackposts Social Marketing Tool v1.0 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/vulnerabilities/other/stackposts-sqli.yaml" target="_blank" rel="noopener" class="nt-source-link">stackposts-sqli.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> r3Y3r53</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 17, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)stackposts&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">SQL Injection is a type of SQL injection attack in which an attacker can exploit a vulnerability in a web application&#39;s input fields to manipulate the application&#39;s SQL queries.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">sqli</span><span class="nt-tag">stackposts</span><span class="nt-tag">time-based-sqli</span><span class="nt-tag">unauth</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.exploit-db.com/exploits/51473" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://vulners.com/zdt/1337DAY-ID-38725" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://codecanyon.net/item/stackposts-social-marketing-tool/21747459" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="star micronics network utility panel - detect info identify web-based control panels star micronics network utility panel was detected. ritikchaddha panel utility discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Star Micronics Network Utility Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/star-network-utility.yaml" target="_blank" rel="noopener" class="nt-source-link">star-network-utility.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Network Utility&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Star Micronics Network Utility panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">utility</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="stash &lt; 0.26.0 - sql injection critical identify critical remote vulnerabilities stash up to v0.25.1 was discovered to contain a sql injection vulnerability via the sort parameter. cve-2024-32231 iamnoooob,rootxharsh,pdresearch cve cve2024 sqli stash vuln" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Stash &lt; 0.26.0 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-32231.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-32231.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> iamnoooob,rootxharsh,pdresearch</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 23, 2024</span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-32231" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-32231</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)&lt;title&gt;Stash&lt;/title&gt;&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Stash up to v0.25.1 was discovered to contain a SQL injection vulnerability via the sort parameter.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can execute arbitrary SQL queries via the sort parameter, potentially extracting sensitive database information.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update Stash to version 0.26.0 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">sqli</span><span class="nt-tag">stash</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/stashapp" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/stashapp/stash" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/stashapp/stash/pull/4865" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/advisories/GHSA-75jf-52jg-qqh4" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-32231" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="steve login panel - detect info identify web-based control panels steve login panel was detected. clem9669 discovery panel steve cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">SteVe Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/steve-login-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">steve-login-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> clem9669</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)SteVe - Steckdosenverwaltung&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">SteVe login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">steve</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/steve-community/steve" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="steve login panel - detect info identify default logins in web-based control panels steve login panel was detected. clem9669 default-login panel steve vuln cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">SteVe Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/steve/steve-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">steve-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> clem9669</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;SteVe - Steckdosenverwaltung&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">SteVe login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">panel</span><span class="nt-tag">steve</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/steve-community/steve" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/steve-community/steve/blob/e42ddcf1acf6c4ad2287bb466b2d3550663ce978/src/main/resources/config/test/main.properties" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="stirling pdf panel - detect info identify web-based control panels stirling pdf panel was discovered. s4e-io panel login stirling-pdf detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Stirling PDF Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/stirling-pdf-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">stirling-pdf-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> s4e-io</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 8, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)StirlingPDF&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Stirling PDF panel was discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">login</span><span class="nt-tag">stirling-pdf</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/Stirling-Tools/Stirling-PDF" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="stock ticker &lt;= 3.23.2 - cross-site scripting medium identify critical remote vulnerabilities the stock ticker plugin for wordpress is vulnerable to reflected cross-site scripting in the ajax_stockticker_load function in versions up to, and including, 3.23.3 due to insufficient input sanitization and output escaping. this makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. cve-2023-40208 theamanrawat cve cve2023 stock-ticker urosevic vuln wordpress wp wp-plugin wpscan xss cwe-79" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Stock Ticker &lt;= 3.23.2 - Cross-Site Scripting</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-40208.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-40208.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> theamanrawat</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 17, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-79</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-40208" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-40208</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/stock-ticker/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The Stock Ticker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in the ajax_stockticker_load function in versions up to, and including, 3.23.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can inject malicious JavaScript through the class parameter in the ajax_stockticker_load function to execute attacks when users interact with malicious links.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Fixed in version 3.23.3</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">stock-ticker</span><span class="nt-tag">urosevic</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">wpscan</span><span class="nt-tag">xss</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/stock-ticker/stock-ticker-3233-reflected-cross-site-scripting" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://patchstack.com/database/vulnerability/stock-ticker/wordpress-stock-ticker-plugin-3-23-3-unauth-reflected-cross-site-scripting-xss-vulnerability" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://wordpress.org/plugins/stock-ticker/" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-40208" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://patchstack.com/database/vulnerability/stock-ticker/wordpress-stock-ticker-plugin-3-23-3-unauth-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="stop user enumeration wordpress plugin - authentication bypass medium identify critical remote vulnerabilities stop user enumeration wordpress plugin &lt; 1.7.3 contains an authentication bypass caused by url-encoding the rest api path /wp-json/wp/v2/users/, letting attackers bypass user enumeration restrictions, exploit requires crafted url encoding. cve-2025-4302 kazgangap cve cve2025 stop-user-enumeration vuln wordpress wp wp-plugin wpscan" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Stop User Enumeration WordPress plugin - Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-4302.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-4302.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Kazgangap</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 7, 2025</span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-4302" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-4302</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/stop-user-enumeration/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Stop User Enumeration WordPress plugin &lt; 1.7.3 contains an authentication bypass caused by URL-encoding the REST API path /wp-json/wp/v2/users/, letting attackers bypass user enumeration restrictions, exploit requires crafted URL encoding.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can bypass user enumeration protection through URL-encoding manipulation, potentially facilitating brute force attacks against user accounts.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade Stop User Enumeration WordPress plugin to version 1.7.3 or later that properly handles URL-encoded REST API paths.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">stop-user-enumeration</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">wpscan</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wpscan.com/vulnerability/19f67d6e-4ffe-4126-ac42-fb23c5017a3e/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/Kazgangap/cve-poc-garage/blob/main/2025/CVE-2025-4302.md" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-4302" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="storybook panel - detect info identify web-based control panels storybook panel was detected. kh4sh3i panel storybook workshop discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Storybook Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/storybook-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">storybook-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> kh4sh3i</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)storybook&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Storybook panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">storybook</span><span class="nt-tag">workshop</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://storybook.js.org/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/storybookjs/storybook" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="strapi login panel - detect info identify web-based control panels strapi login panel was detected. idealphase,righettod panel strapi login discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Strapi Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/strapi-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">strapi-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> idealphase,righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)strapi&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Strapi login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">strapi</span><span class="nt-tag">login</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/strapi/strapi" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://strapi.io/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="strider cd panel - detect info identify web-based control panels strider cd panel was detected. adam crosser panel cicd oss stridercd strider discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Strider CD Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/stridercd-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">stridercd-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Adam Crosser</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;115295460&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Strider CD panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">cicd</span><span class="nt-tag">oss</span><span class="nt-tag">stridercd</span><span class="nt-tag">strider</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/Strider-CD/strider" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://strider-cd.github.io" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="structurizr - default login high identify default logins in web-based control panels structurizr contains default credentials. dhiyaneshdk default-login structurizr vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Structurizr - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/structurizr/structurizr-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">structurizr-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 20, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1199592666&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Structurizr contains default credentials.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">structurizr</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://docs.structurizr.com/onpremises/quickstart" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="structurizr panel - detect info identify web-based control panels structurizr login panel was detected. dhiyaneshdk detect discovery panel structurizr cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Structurizr Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/structurizr-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">structurizr-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 20, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1199592666&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Structurizr login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">structurizr</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="subscribe to category &lt;= 2.7.4 - sql injection critical identify critical remote vulnerabilities the subscribe to category contains a sql_injection caused by improper neutralization of special elements used in an sql command, letting attackers execute arbitrary sql commands, exploit requires user interaction. cve-2023-32590 shivam kamboj cve cve2023 sqli subscribe-to-category unauth wordpress wp wp-plugin cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Subscribe to Category &lt;= 2.7.4 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-32590.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-32590.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Shivam Kamboj</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 15, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-32590" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-32590</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/subscribe-to-category/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The Subscribe to Category contains a sql_injection caused by improper neutralization of special elements used in an SQL command, letting attackers execute arbitrary SQL commands, exploit requires user interaction.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can execute arbitrary SQL commands, potentially leading to data leakage, modification, or deletion.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest version beyond 2.7.4 or apply security patches that neutralize special elements in SQL queries.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">sqli</span><span class="nt-tag">subscribe-to-category</span><span class="nt-tag">unauth</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/subscribe-to-category/subscribe-to-category-274-unauthenticated-sql-injection" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-32590" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="sugarcrm login panel - detect info identify web-based control panels sugarcrm login panel was detected. johnk3r discovery panel sugarcrm cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">SugarCRM Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/sugarcrm-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">sugarcrm-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> johnk3r</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)sugarcrm&#34;}) || service[&#34;http.body&#34;] matches &#34;(?i)sugarcrm inc\\. all rights reserved&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">SugarCRM login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">sugarcrm</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="suitecrm - sql injection critical identify critical remote vulnerabilities suitecrm is an open-source customer relationship management (crm) software application. prior to versions 7.14.4 and 8.6.1, a vulnerability in events response entry point allows for a sql injection attack. versions 7.14.4 and 8.6.1 contain a fix for this issue. cve-2024-36412 s4e-io cve cve2024 sqli suitecrm time-based-sqli vuln cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">SuiteCRM - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-36412.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-36412.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> s4e-io</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 11, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-36412" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-36412</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)SuiteCRM&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6.1, a vulnerability in events response entry point allows for a SQL injection attack. Versions 7.14.4 and 8.6.1 contain a fix for this issue.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can execute time-based SQL injection to extract sensitive CRM data.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update SuiteCRM to version 7.14.4 or 8.6.1 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">sqli</span><span class="nt-tag">suitecrm</span><span class="nt-tag">time-based-sqli</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://0x5001.com/web-security/cve-2024-36412-proof-of-concept" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-36412" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="suitecrm unauthenticated graphql introspection medium identify critical remote vulnerabilities graphql introspection is enabled without authentication, exposing the scheme defining all object types, arguments, and functions. cve-2023-47643 isacaya cve cve2023 graphql introspection salesagility suitecrm vkev vuln cwe-200" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">SuiteCRM Unauthenticated Graphql Introspection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-47643.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-47643.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> isacaya</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 28, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-47643" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-47643</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)suitecrm&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Graphql Introspection is enabled without authentication, exposing the scheme defining all object types, arguments, and functions.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can obtain the GraphQL schema and understand the entire attack surface of the API, including sensitive fields such as UserHash.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to version 8.4.2.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">graphql</span><span class="nt-tag">introspection</span><span class="nt-tag">salesagility</span><span class="nt-tag">suitecrm</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/salesagility/SuiteCRM-Core/security/advisories/GHSA-fxww-jqfv-9rrr" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-47643" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.apollographql.com/blog/graphql/security/why-you-should-disable-graphql-introspection-in-production/" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="sunbird dcim - detect info identify web-based control panels sunbird dcim login panel was detected. bhutch sunbird panel login discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Sunbird DCIM - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/sunbird-dcim-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">sunbird-dcim-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> bhutch</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 7, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;781922099&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Sunbird DCIM login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">sunbird</span><span class="nt-tag">panel</span><span class="nt-tag">login</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="supabase studio panel - detect info identify web-based control panels supabase studio login panel was detected. the admin dashboard shipped with supabase, the popular open-source firebase alternative (postgres + auth + realtime + storage + edge functions). chrisjr404 detect discovery login panel studio supabase" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Supabase Studio Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/supabase-studio-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">supabase-studio-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ChrisJr404</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 4, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Supabase Studio&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Supabase Studio login panel was detected. The admin dashboard shipped with Supabase, the popular open-source Firebase alternative (Postgres + auth + realtime + storage + edge functions).</div></div></div>
  <div class="nt-tags"><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">login</span><span class="nt-tag">panel</span><span class="nt-tag">studio</span><span class="nt-tag">supabase</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/supabase/supabase" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://supabase.com/docs/guides/self-hosting" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="superagi panel - detect info identify web-based control panels superagi panel was detected. superagi was an open-source autonomous ai agent platform that enables building, managing, and running ai agents. exposed instances may allow unauthorized access to agent configurations and execution environments. rxerium agent ai detect discovery panel superagi" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">SuperAGI Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/superagi-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">superagi-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 14, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-2056571568&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">SuperAGI panel was detected. SuperAGI was an open-source autonomous AI agent platform that enables building, managing, and running AI agents. Exposed instances may allow unauthorized access to agent configurations and execution environments.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">agent</span><span class="nt-tag">ai</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">superagi</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/TransformerOptimus/SuperAGI" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://superagi.com/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="superadmin login panel - detect info identify web-based control panels superadmin login panel was detected. hardik-solanki panel superadmin discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">SuperAdmin Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/superadmin-ui-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">superadmin-ui-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Hardik-Solanki</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Superadmin UI - 4myhealth&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">SuperAdmin login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">superadmin</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="superwebmailer 9.00.0.01710 - cross-site scripting medium identify critical remote vulnerabilities an issue was discovered in superwebmailer 9.00.0.01710 allowing xss via crafted incorrect passwords. cve-2023-38192 ritikchaddha cve cve2023 superwebmailer vkev vuln xss cwe-79" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">SuperWebMailer 9.00.0.01710 - Cross-Site Scripting</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-38192.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-38192.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 20, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-79</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-38192" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-38192</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)SuperWebMailer&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An issue was discovered in SuperWebMailer 9.00.0.01710 allowing XSS via crafted incorrect passwords.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation could lead to unauthorized access or data theft.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Implement input validation and output encoding to prevent XSS attacks.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">superwebmailer</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">xss</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://herolab.usd.de/security-advisories/usd-2023-0011/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://herolab.usd.de/security-advisories/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-38192" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="superwebmailer 7.21.0.01526 - remote code execution critical identify critical remote vulnerabilities superwebmailer 7.21.0.01526 is susceptible to a remote code execution vulnerability in the language parameter of mailingupgrade.php. an unauthenticated remote attacker can exploit this behavior to execute arbitrary php code via code injection. cve-2020-11546 official_blackhat13 cve cve2020 rce superwebmailer vkev vuln cwe-94" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">SuperWebmailer 7.21.0.01526 - Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2020/CVE-2020-11546.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2020-11546.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Official_BlackHat13</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/94.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-94</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2020-11546" target="_blank" rel="noopener" class="nt-cve-link">CVE-2020-11546</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)superwebmailer&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">SuperWebMailer 7.21.0.01526 is susceptible to a remote code execution vulnerability in the Language parameter of mailingupgrade.php. An unauthenticated remote attacker can exploit this behavior to execute arbitrary PHP code via Code Injection.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to the latest version of SuperWebmailer to mitigate this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2020</span><span class="nt-tag">rce</span><span class="nt-tag">superwebmailer</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/Official-BlackHat13/CVE-2020-11546/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://blog.to.com/advisory-superwebmailer-cve-2020-11546/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2020-11546" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/ARPSyndicate/kenzer-templates" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/HimmelAward/Goby_POC" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="supermicro bmc login panel - detect info identify web-based control panels supermicro bmc login panel was detected. idealphase bmc discovery panel supermicro cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Supermicro BMC Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/supermicro-bmc-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">supermicro-bmc-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> idealphase</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Supermicro BMC Login&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Supermicro BMC login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">bmc</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">supermicro</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.supermicro.com/en" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.supermicro.com/en/solutions/management-software/bmc-resources" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.supermicro.com/white_paper/IPMI_white_paper.pdf" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="supermicro ipmi - default admin login high identify default logins in web-based control panels supermicro ipmi default admin login credentials were successful. for3stco1d default-login supermicro vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Supermicro Ipmi - Default Admin Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/supermicro/supermicro-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">supermicro-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> For3stCo1d</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.bodies&#34;]), {# matches &#34;/cgi/login.cgi&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Supermicro Ipmi default admin login credentials were successful.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">supermicro</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.gearprimer.com/wiki/supermicro-ipmi-default-username-pasword/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="supershell - default login high identify default logins in web-based control panels supershell is a web management platform that integrates the reverse_ssh service. sleepingbag945 default-login supershell vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Supershell - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/others/supershell-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">supershell-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> SleepingBag945</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 18, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)supershell&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Supershell is a WEB management platform that integrates the reverse_ssh service.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">supershell</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/tdragon6/Supershell" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.ctfiot.com/129689.html" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="supertokens login panel - detect info identify web-based control panels a supertokens login panel was detected. rxerium panel login supertokens discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Supertokens Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/supertokens-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">supertokens-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 14, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)&lt;title&gt;SuperTokens &#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A Supertokens login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">login</span><span class="nt-tag">supertokens</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://supertokens.com" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="supportcandy &lt; 2.2.7 - reflected cross-site scripting medium identify critical remote vulnerabilities the supportcandy wordpress plugin before 2.2.7 does not sanitise and escape the query string before outputting it back in pages with the [wpsc_create_ticket] shortcode embed, leading to a reflected cross-site scripting issue cve-2021-24878 popcorn94 cve cve2021 supportcandy vkev vuln wordpress wp-plugin wpscan xss cwe-79" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">SupportCandy &lt; 2.2.7 - Reflected Cross-Site Scripting</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2021/CVE-2021-24878.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2021-24878.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> popcorn94</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 10, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-79</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2021-24878" target="_blank" rel="noopener" class="nt-cve-link">CVE-2021-24878</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/supportcandy/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The SupportCandy WordPress plugin before 2.2.7 does not sanitise and escape the query string before outputting it back in pages with the [wpsc_create_ticket] shortcode embed, leading to a Reflected Cross-Site Scripting issue</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can inject malicious JavaScript via reflected XSS in pages with wpsc_create_ticket shortcode, potentially stealing user session cookies or manipulating support ticket data.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Fixed in 2.2.7</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2021</span><span class="nt-tag">supportcandy</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">wpscan</span><span class="nt-tag">xss</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2021-24878" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/andrewcy86/supportcandy(plugin)" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://wpscan.com/vulnerability/d2f1fd60-5e5e-4e38-9559-ba2d14ae37bf/" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="suprema biostar 2 panel - detect info identify web-based control panels  ritikchaddha panel login biostar detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Suprema BioStar 2 Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/suprema-biostar-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">suprema-biostar-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 12, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Biostar&#34;})</code></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">login</span><span class="nt-tag">biostar</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="swarmui panel - detect info identify web-based control panels swarmui (formerly stableswarmui) is a modular stable diffusion web interface built on asp.net core.
it provides a feature-rich ui for ai image generation rxerium ai detect discovery image-generation panel stablediffusion swarmui" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">SwarmUI Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/swarmui-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">swarmui-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 27, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;SwarmUI&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">SwarmUI (formerly StableSwarmUI) is a modular Stable Diffusion web interface built on ASP.NET Core.
It provides a feature-rich UI for AI image generation</div></div></div>
  <div class="nt-tags"><span class="nt-tag">ai</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">image-generation</span><span class="nt-tag">panel</span><span class="nt-tag">stablediffusion</span><span class="nt-tag">swarmui</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/mcmonkeyprojects/SwarmUI" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="swift performance lite &lt; 2.3.7.2 - local php file inclusion high identify critical remote vulnerabilities a vulnerability in swift performance lite before version 2.3.7.2 allows unauthenticated attackers to perform local php file inclusion via the &#39;ajaxify&#39; parameter. this can lead to arbitrary code execution on the server. cve-2024-10516 ritikchaddha cve cve2024 lfi swift-performance vuln wordpress wp wp-plugin cwe-98" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Swift Performance Lite &lt; 2.3.7.2 - Local PHP File Inclusion</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-10516.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-10516.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 7, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/98.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-98</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-10516" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-10516</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/swift-performance-lite&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A vulnerability in Swift Performance Lite before version 2.3.7.2 allows unauthenticated attackers to perform local PHP file inclusion via the &#39;ajaxify&#39; parameter. This can lead to arbitrary code execution on the server.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can perform local PHP file inclusion via the ajaxify parameter to execute arbitrary code, potentially compromising the entire WordPress site.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update Swift Performance Lite plugin to version 2.3.7.2 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">lfi</span><span class="nt-tag">swift-performance</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/RandomRobbieBF/CVE-2024-10516" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-10516" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="syfadis xperience login panel - detect info identify web-based control panels syfadis xperience login panel was detected. righettod panel syfadis login detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Syfadis Xperience Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/syfadis-xperience-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">syfadis-xperience-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 1, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Syfadis Xperience&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Syfadis Xperience login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">syfadis</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://syfadis.fr/xperience" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="symantec data loss prevention login panel - detect info identify web-based control panels symantec data loss prevention login panel was detected. princechaddha discovery login panel symantec cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Symantec Data Loss Prevention Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/symantec/symantec-dlp-login.yaml" target="_blank" rel="noopener" class="nt-source-link">symantec-dlp-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> princechaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)symantec data loss prevention&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Symantec Data Loss Prevention login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">login</span><span class="nt-tag">panel</span><span class="nt-tag">symantec</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="symantec encryption server login panel - detect info identify web-based control panels symantec encryption server login panel was detected. johnk3r panel symantec login discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Symantec Encryption Server Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/symantec/symantec-ewep-login.yaml" target="_blank" rel="noopener" class="nt-source-link">symantec-ewep-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> johnk3r</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Symantec Encryption Server&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Symantec Encryption Server login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">symantec</span><span class="nt-tag">login</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="symantec endpoint protection manager login panel - detect info identify web-based control panels symantec endpoint protection manager login panel was detected. princechaddha discovery login panel symantec cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Symantec Endpoint Protection Manager Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/symantec/symantec-epm-login.yaml" target="_blank" rel="noopener" class="nt-source-link">symantec-epm-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> princechaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)symantec endpoint protection manager&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Symantec Endpoint Protection Manager login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">login</span><span class="nt-tag">panel</span><span class="nt-tag">symantec</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="symantec pgp global directory panel - detect info identify web-based control panels symantec pgp global directory panel was detected. princechaddha symantec panel discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Symantec PGP Global Directory Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/symantec/symantec-pgp-global-directory.yaml" target="_blank" rel="noopener" class="nt-source-link">symantec-pgp-global-directory.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> princechaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)PGP Global Directory&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Symantec PGP Global Directory panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">symantec</span><span class="nt-tag">panel</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="symfony lock file - exposure low identify critical remote vulnerabilities symfony.lock was found accessible, exposing a full list of installed composer packages, library versions, and metadata for a symfony-based php application. disclosure of this file can provide insight into the application&#39;s attack surface, potentially revealing vulnerable or outdated dependencies and aiding an attacker in choosing their exploit strategy. ritikchaddha symfony exposure composer php config" data-nt-sev="low">
  <div class="nt-card-header">
    <div class="nt-title">Symfony Lock File - Exposure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposures/configs/symfony-lock-exposure.yaml" target="_blank" rel="noopener" class="nt-source-link">symfony-lock-exposure.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 21, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)symfony\\.lock&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">symfony.lock was found accessible, exposing a full list of installed Composer packages, library versions, and metadata for a Symfony-based PHP application. Disclosure of this file can provide insight into the application&#39;s attack surface, potentially revealing vulnerable or outdated dependencies and aiding an attacker in choosing their exploit strategy.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can enumerate all installed Composer packages and versions, increasing the risk of targeted attacks (e.g., against known CVEs in dependencies) or application fingerprinting.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Restrict direct access to internal and sensitive files such as symfony.lock via proper web server configuration (e.g., .htaccess, nginx directives) and consider excluding such files from the web root in deployment.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">symfony</span><span class="nt-tag">exposure</span><span class="nt-tag">composer</span><span class="nt-tag">php</span><span class="nt-tag">config</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://cheatsheetseries.owasp.org/cheatsheets/Information_Leakage.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://symfony.com/doc/current/deployment.html" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="symfony profiler - remote access via injected arguments high identify critical remote vulnerabilities symfony/runtime is a module for the symphony php framework which enables decoupling php applications from global state. when the `register_argv_argc` php directive is set to `on` , and users call any url with a special crafted query string, they are able to change the environment or debug mode used by the kernel when handling the request. as of versions 5.4.46, 6.4.14, and 7.1.7 the `symfonyruntime` now ignores the `argv` values for non-sapi php runtimes. cve-2024-50340 dhiyaneshdk cve cve2024 phpinfo symfony vuln cwe-74" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Symfony Profiler - Remote Access via Injected Arguments</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-50340.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-50340.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 12, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/74.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-74</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-50340" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-50340</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)&lt;div id=\\\\&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">symfony/runtime is a module for the Symphony PHP framework which enables decoupling PHP applications from global state. When the `register_argv_argc` php directive is set to `on` , and users call any URL with a special crafted query string, they are able to change the environment or debug mode used by the kernel when handling the request. As of versions 5.4.46, 6.4.14, and 7.1.7 the `SymfonyRuntime` now ignores the `argv` values for non-SAPI PHP runtimes.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can exploit vulnerabilities to compromise the system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest patched version addressing CVE-2024-50340.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">phpinfo</span><span class="nt-tag">symfony</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/symfony/symfony/commit/a77b308c3f179ed7c8a8bc295f82b2d6ee3493fa" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/symfony/symfony/security/advisories/GHSA-x8vp-gf4q-mw5j" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://blog.nollium.com/cve-2024-50340-remote-access-to-symfony-profiler-via-injected-arguments-d2f14b4f6ad7" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/nollium/CVE-2024-50340-eos-exploit" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-50340" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="symmetricom syncserver panel - detect info identify web-based control panels  dhiyaneshdk detect discovery login microchip panel symmetricom syncserver" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Symmetricom SyncServer Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/syncserver-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">syncserver-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 22, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)symmetricom syncserver&#34;</code></div>
  <div class="nt-tags"><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">login</span><span class="nt-tag">microchip</span><span class="nt-tag">panel</span><span class="nt-tag">symmetricom</span><span class="nt-tag">syncserver</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="symmetricom syncserver unauthenticated - remote command execution critical identify critical remote vulnerabilities microchip technology (microsemi) syncserver s650 was discovered to contain a command injection vulnerability. cve-2022-40022 dhiyaneshdk,mielverkerken cve cve2022 microchip packetstorm rce syncserver unauth vkev vuln cwe-77" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Symmetricom SyncServer Unauthenticated - Remote Command Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-40022.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-40022.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK,mielverkerken</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 22, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/77.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-77</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-40022" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-40022</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Symmetricom SyncServer&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Microchip Technology (Microsemi) SyncServer S650 was discovered to contain a command injection vulnerability.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute arbitrary commands on the affected device.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches or firmware updates provided by the vendor to mitigate this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">microchip</span><span class="nt-tag">packetstorm</span><span class="nt-tag">rce</span><span class="nt-tag">syncserver</span><span class="nt-tag">unauth</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="http://packetstormsecurity.com/files/172907/Symmetricom-SyncServer-Unauthenticated-Remote-Command-Execution.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-40022" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.microsemi.com/campaigns/network-time-servers/S650p/%3Fgd%3D1&amp;id=5&amp;gclid=Cj0KCQjwjbyYBhCdARIsAArC6LL-202ej5YfDB5lMIMSZ2735qjo5yaj2i-PrvLv2Cnh_kIJtFJ0oF8aAlMpEALw_wcB" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://www.microsemi.com/campaigns/network-time-servers/syncserver-s600/?url=" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://www.microsemi.com/document-portal/doc_download/135737-datasheet-syncserver-s650" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="synacor zimbra collaboration &lt;8.7.11p10 - xml external entity injection critical identify critical remote vulnerabilities synacor zimbra collaboration suite 8.7.x before 8.7.11p10 has an xml external entity injection (xxe) vulnerability via the mailboxd component. cve-2019-9670 ree4pwn cve cve2019 edb kev packetstorm synacor vkev vuln xxe zimbra cwe-611" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Synacor Zimbra Collaboration &lt;8.7.11p10 - XML External Entity Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2019/CVE-2019-9670.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2019-9670.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ree4pwn</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/611.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-611</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2019-9670" target="_blank" rel="noopener" class="nt-cve-link">CVE-2019-9670</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)zimbra collaboration suite&#34;}) || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)zimbra web client sign in&#34;}) || service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1624375939&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML external entity injection (XXE) vulnerability via the mailboxd component.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to read arbitrary files on the server, leading to unauthorized access to sensitive information.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to the latest version of Synacor Zimbra Collaboration (8.7.11p10 or higher) to mitigate this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2019</span><span class="nt-tag">edb</span><span class="nt-tag">kev</span><span class="nt-tag">packetstorm</span><span class="nt-tag">synacor</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">xxe</span><span class="nt-tag">zimbra</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.exploit-db.com/exploits/46693/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://bugzilla.zimbra.com/show_bug.cgi?id=109129" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="http://www.rapid7.com/db/modules/exploit/linux/http/zimbra_xxe_rce" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="http://packetstormsecurity.com/files/152487/Zimbra-Collaboration-Autodiscover-Servlet-XXE-ProxyServlet-SSRF.html" target="_blank" rel="noopener" class="nt-ref-link">[5]</a> <a href="https://isc.sans.edu/forums/diary/CVE20199670+Zimbra+Collaboration+Suite+XXE+vulnerability/27570/" target="_blank" rel="noopener" class="nt-ref-link">[6]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2019-9670" target="_blank" rel="noopener" class="nt-ref-link">[7]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="synapse mobility login panel - detect info identify web-based control panels synapse mobility login panel was detected. idealphase panel synapse discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Synapse Mobility Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/synapse-mobility-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">synapse-mobility-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> idealphase</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Synapse Mobility Login&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Synapse Mobility login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">synapse</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://synapse.fujifilm.eu/synapse-mobility.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="syncthru web service panel - detect info identify web-based control panels syncthru web service panel was detected. dhiyaneshdk discovery edb panel printer samsung syncthru cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">SyncThru Web Service Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/syncthru-web-service.yaml" target="_blank" rel="noopener" class="nt-source-link">syncthru-web-service.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)syncthru web service&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">SyncThru Web Service panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">edb</span><span class="nt-tag">panel</span><span class="nt-tag">printer</span><span class="nt-tag">samsung</span><span class="nt-tag">syncthru</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.exploit-db.com/ghdb/7843" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="synology dsm system info - detect info identify critical remote vulnerabilities detected the disclosure of synology diskstation manager (dsm) system information via the syno.api.info endpoint, identifying all available apis, versions, and installed packages returned without authentication. dhiyaneshdk synology dsm misconfig diskstation-manager detect" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Synology DSM System Info - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/misconfiguration/synology-dsm-system-info.yaml" target="_blank" rel="noopener" class="nt-source-link">synology-dsm-system-info.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 17, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">asset[&#34;hw_vendor&#34;] == &#34;Synology&#34; &amp;&amp; asset[&#34;type&#34;] == &#34;NAS&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detected the disclosure of Synology DiskStation Manager (DSM) system information via the SYNO.API.Info endpoint, identifying all available APIs, versions, and installed packages returned without authentication.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">synology</span><span class="nt-tag">dsm</span><span class="nt-tag">misconfig</span><span class="nt-tag">diskstation-manager</span><span class="nt-tag">detect</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.synology.com/en-us/dsm" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="synopsys coverity panel info identify web-based control panels coverity® is a fast, accurate, and highly scalable static analysis (sast) solution that helps development and security teams address security and quality defects early in the software development life cycle (sdlc), track and manage risks across the application portfolio, and ensure compliance with security and coding standards. idealphase panel coverity synopsys discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Synopsys Coverity Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/synopsys-coverity-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">synopsys-coverity-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> idealphase</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Coverity&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Coverity® is a fast, accurate, and highly scalable static analysis (SAST) solution that helps development and security teams address security and quality defects early in the software development life cycle (SDLC), track and manage risks across the application portfolio, and ensure compliance with security and coding standards.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">coverity</span><span class="nt-tag">synopsys</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.synopsys.com/software-integrity/security-testing/static-analysis-sast.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="synway smg gateway 9-2radius.php - remote command execution critical identify critical remote vulnerabilities synway smg gateway management software contains a remote command execution vulnerability in 9-2radius.php, where the radius_address parameter is passed to a system() call without sanitization. this allows unauthenticated attackers to execute arbitrary commands on the server. chenkh gateway rce synway unauth" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Synway SMG Gateway 9-2radius.php - Remote Command Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/vulnerabilities/synway/synwaysmg-radius-rce.yaml" target="_blank" rel="noopener" class="nt-source-link">synwaysmg-radius-rce.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Chenkh</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 8, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)text ml10 mr20&#34; &amp;&amp; any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)(Gateway Management|网关管理软件)&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Synway SMG Gateway Management Software contains a remote command execution vulnerability in 9-2radius.php, where the radius_address parameter is passed to a system() call without sanitization. This allows unauthenticated attackers to execute arbitrary commands on the server.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">gateway</span><span class="nt-tag">rce</span><span class="nt-tag">synway</span><span class="nt-tag">unauth</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://mp.weixin.qq.com/s/PyepoFSuQ63E3RnpQa9nsA" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="sysaid login panel - detect info identify web-based control panels detects the presence of a sysaid help desk software login panel by identifying characteristic login pages, favicon hash, and system-specific content. pdteam,darses panel sysaid helpdesk detect discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">SysAid Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/sysaid-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">sysaid-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pdteam,darses</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1540720428&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detects the presence of a SysAid Help Desk Software login panel by identifying characteristic login pages, favicon hash, and system-specific content.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">sysaid</span><span class="nt-tag">helpdesk</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="t-up openframe info identify web-based control panels  dhiyaneshdk exposure login tup openframe panel discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">T-Up OpenFrame</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/tup-openframe.yaml" target="_blank" rel="noopener" class="nt-source-link">tup-openframe.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 20, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;824580113&#34;</code></div>
  <div class="nt-tags"><span class="nt-tag">exposure</span><span class="nt-tag">login</span><span class="nt-tag">tup</span><span class="nt-tag">openframe</span><span class="nt-tag">panel</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.facebook.com/photo/?fbid=642772827893240&amp;set=a.467014098802448" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="tibco jasperreports library - directory traversal medium identify critical remote vulnerabilities the default server implementation of tibco software inc.&#39;s tibco jasperreports library, tibco jasperreports library community edition, tibco jasperreports library for activematrix bpm, tibco jasperreports server, tibco jasperreports server community edition, tibco jasperreports server for activematrix bpm, tibco jaspersoft for aws with multi-tenancy, and tibco jaspersoft reporting and analytics for aws contains a directory-traversal vulnerability that may theoretically allow web server users to access contents of the host system. cve-2018-18809 dhiyaneshdk cve cve2018 jasperreport jasperserver kev lfi packetstorm seclists tibco vkev vuln cwe-22" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">TIBCO JasperReports Library - Directory Traversal</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2018/CVE-2018-18809.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2018-18809.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 4, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2018-18809" target="_blank" rel="noopener" class="nt-cve-link">CVE-2018-18809</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)jasperserver-pro&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The default server implementation of TIBCO Software Inc.&#39;s TIBCO JasperReports Library, TIBCO JasperReports Library Community Edition, TIBCO JasperReports Library for ActiveMatrix BPM, TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, and TIBCO Jaspersoft Reporting and Analytics for AWS contains a directory-traversal vulnerability that may theoretically allow web server users to access contents of the host system.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can access sensitive files, potentially leading to unauthorized disclosure of sensitive information.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches or upgrade to a patched version of TIBCO JasperReports Library.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2018</span><span class="nt-tag">jasperreport</span><span class="nt-tag">jasperserver</span><span class="nt-tag">kev</span><span class="nt-tag">lfi</span><span class="nt-tag">packetstorm</span><span class="nt-tag">seclists</span><span class="nt-tag">tibco</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://packetstormsecurity.com/files/154406/Tibco-JasperSoft-Path-Traversal.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://security.elarlang.eu/cve-2018-18809-path-traversal-in-tibco-jaspersoft.html" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2018-18809" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="http://packetstormsecurity.com/files/154406/Tibco-JasperSoft-Path-Traversal.html" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="http://seclists.org/fulldisclosure/2019/Sep/17" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="tibco jaspersoft login panel - detect info identify web-based control panels tibco jaspersoft login panel was detected. koti2,daffainfo discovery jaspersoft panel tibco cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">TIBCO Jaspersoft Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/jaspersoft-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">jaspersoft-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> koti2,daffainfo</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)jaspersoft&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">TIBCO Jaspersoft login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">jaspersoft</span><span class="nt-tag">panel</span><span class="nt-tag">tibco</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="tibco managed file transfer - panel info identify web-based control panels tibco managed file transfer login panel was discovered. th3l0newolf tibco mft login web panel discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">TIBCO Managed File Transfer - Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/tibco-mft-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">tibco-mft-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Th3l0newolf</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 2, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)TIBCO Managed&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">TIBCO Managed File Transfer Login Panel was discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">tibco</span><span class="nt-tag">mft</span><span class="nt-tag">login</span><span class="nt-tag">web</span><span class="nt-tag">panel</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.tibco.com/products/managed-file-transfer" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="titool printmonitor - blind sql injection critical identify critical remote vulnerabilities the username parameter of the titool printmonitor solution during the login request is vulnerable to and/or time-based blind sqli. cve-2018-7282 theamanrawat cve cve2018 printmonitor sqli time-based-sqli titool unauth vkev vuln cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">TITool PrintMonitor - Blind SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2018/CVE-2018-7282.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2018-7282.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> theamanrawat</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 17, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2018-7282" target="_blank" rel="noopener" class="nt-cve-link">CVE-2018-7282</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)printmonitor&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The username parameter of the TITool PrintMonitor solution during the login request is vulnerable to and/or time-based blind SQLi.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can execute time-based blind SQL injection to extract database contents, potentially compromising user credentials and sensitive printing data.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to PM18.2.1.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2018</span><span class="nt-tag">printmonitor</span><span class="nt-tag">sqli</span><span class="nt-tag">time-based-sqli</span><span class="nt-tag">titool</span><span class="nt-tag">unauth</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://fenceposterror.github.io/cve-2018-7282.txt" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2018-7282" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="http://print.com" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="http://ti-tool.com" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="totolink a3002ru 1.0.8 - information disclosure medium identify critical remote vulnerabilities totolink a3002ru firmware version 1.0.8 contains a vulnerability in which an unauthenticated attacker can obtain the plaintext admin password by making a get request for `password.htm`. this allows remote attackers to gain administrative access without credentials. cve-2018-13317 ritikchaddha cve cve2018 exposure password totolink vkev cwe-79" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">TOTOLINK A3002RU 1.0.8 - Information Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2018/CVE-2018-13317.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2018-13317.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 20, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-79</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2018-13317" target="_blank" rel="noopener" class="nt-cve-link">CVE-2018-13317</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)totolink&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">TOTOLINK A3002RU firmware version 1.0.8 contains a vulnerability in which an unauthenticated attacker can obtain the plaintext admin password by making a GET request for `password.htm`. This allows remote attackers to gain administrative access without credentials.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can obtain the plaintext administrator password without any authentication, leading to complete device compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest firmware version that addresses this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2018</span><span class="nt-tag">exposure</span><span class="nt-tag">password</span><span class="nt-tag">totolink</span><span class="nt-tag">vkev</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://blog.securityevaluators.com/new-vulnerabilities-in-totolink-a3002ru-d6f42a081154" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2018-13317" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="totolink a3700r - command injection critical identify critical remote vulnerabilities an issue in totolink a3700r v.9.1.2u.6165_20211012 allows a remote attacker to execute arbitrary code via the filename parameter of the uploadfirmwarefile function. cve-2023-46574 dhiyaneshdk cve cve2023 iot rce router totolink vkev vuln cwe-77" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">TOTOLINK A3700R - Command Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-46574.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-46574.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 25, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/77.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-77</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-46574" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-46574</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)totolink&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An issue in TOTOLINK A3700R v.9.1.2u.6165_20211012 allows a remote attacker to execute arbitrary code via the FileName parameter of the UploadFirmwareFile function.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can execute arbitrary commands on the router, potentially gaining full device control and compromising network security.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update TOTOLINK A3700R firmware to a version newer than 9.1.2u.6165_20211012.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">iot</span><span class="nt-tag">rce</span><span class="nt-tag">router</span><span class="nt-tag">totolink</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-46574" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/OraclePi/repo/blob/main/totolink%20A3700R/1/A3700R%20%20V9.1.2u.6165_20211012%20vuln.md" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/Marco-zcl/POC" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/d4n-sec/d4n-sec.github.io" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/wy876/POC" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="totolink cp450 v4.1.0cu.747_b20191224 - hard-coded password vulnerability critical identify critical remote vulnerabilities a critical vulnerability has been discovered in totolink cp450 version 4.1.0cu.747_b20191224. this vulnerability affects an unknown part of the file /web_cste/cgi-bin/product.ini of the telnet service component. the issue stems from the use of a hard-coded password, which can be exploited remotely without any user interaction. cve-2024-7332 s4e-io cve cve2024 totolink vuln cwe-259" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">TOTOLINK CP450 v4.1.0cu.747_B20191224 - Hard-Coded Password Vulnerability</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-7332.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-7332.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> s4e-io</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 1, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/259.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-259</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-7332" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-7332</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)totolink&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A critical vulnerability has been discovered in TOTOLINK CP450 version 4.1.0cu.747_B20191224. This vulnerability affects an unknown part of the file /web_cste/cgi-bin/product.ini of the Telnet Service component. The issue stems from the use of a hard-coded password, which can be exploited remotely without any user interaction.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can retrieve hard-coded credentials from the accessible product.ini file, enabling complete device compromise through Telnet service access with administrative privileges.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Contact TOTOLINK for security updates addressing the hard-coded password vulnerability in CP450 firmware version 4.1.0cu.747_B20191224, or implement network segmentation to restrict access.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">totolink</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/abcdefg-png/IoT-vulnerable/blob/main/TOTOLINK/CP450/product.md" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-7332" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://cvefeed.io/vuln/detail/CVE-2024-7332" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://www.tenable.com/cve/CVE-2024-7332" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="totolink cx-a3002ru - remote code execution medium identify critical remote vulnerabilities an issue in totolink-cx-a3002ru v1.0.4-b20171106.1512 and totolink-cx-n150rt v2.1.6-b20171121.1002 and totolink-cx-n300rt v2.1.6-b20170724.1420 and totolink-cx-n300rt v2.1.8-b20171113.1408 and totolink-cx-n300rt v2.1.8-b20191010.1107 and totolink-cx-n302re v2.0.2-b20170511.1523 allows a remote attacker to execute arbitrary code via the /boafrm/formsyscmd component. cve-2024-51228 dhiyaneshdk cve cve2024 sqli time-based-sqli totolink vkev vuln cwe-78" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">TOTOLINK CX-A3002RU - Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-51228.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-51228.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 5, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/78.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-78</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-51228" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-51228</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)TOTOLINK&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An issue in TOTOLINK-CX-A3002RU V1.0.4-B20171106.1512 and TOTOLINK-CX-N150RT V2.1.6-B20171121.1002 and TOTOLINK-CX-N300RT V2.1.6-B20170724.1420 and TOTOLINK-CX-N300RT V2.1.8-B20171113.1408 and TOTOLINK-CX-N300RT V2.1.8-B20191010.1107 and TOTOLINK-CX-N302RE V2.0.2-B20170511.1523 allows a remote attacker to execute arbitrary code via the /boafrm/formSysCmd component.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can exploit this vulnerability to compromise system security and integrity.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches and updates to address this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">sqli</span><span class="nt-tag">time-based-sqli</span><span class="nt-tag">totolink</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/yckuo-sdc/totolink-boa-api-vulnerabilities" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://totolink.tw/support_view/A3002RU" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://totolink.tw/support_view/N150RT" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://www.totolink.tw/products_view/N300RT" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="totolink ex1200t 4.1.2cu.5215 - authentication bypass critical identify critical remote vulnerabilities totolink ex1200t 4.1.2cu.5215 is susceptible to authentication bypass. an attacker can bypass login by sending a specific request through formloginauth.htm, thus potentially being able to obtain sensitive information, modify data, and/or execute unauthorized operations. cve-2021-42887 gy741 auth-bypass cve cve2021 router totolink vuln cwe-287" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">TOTOLINK EX1200T 4.1.2cu.5215 - Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2021/CVE-2021-42887.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2021-42887.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> gy741</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/287.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-287</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2021-42887" target="_blank" rel="noopener" class="nt-cve-link">CVE-2021-42887</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)totolink&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">TOTOLINK EX1200T 4.1.2cu.5215 is susceptible to authentication bypass. An attacker can bypass login by sending a specific request through formLoginAuth.htm, thus potentially being able to obtain sensitive information, modify data, and/or execute unauthorized operations.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can exploit this vulnerability to gain unauthorized access to the device, potentially leading to further compromise of the network.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest firmware update provided by TOTOLINK to fix the authentication bypass vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2021</span><span class="nt-tag">router</span><span class="nt-tag">totolink</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/p1Kk/vuln/blob/main/totolink_ex1200t_login_bypass.md" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/cve-2021-42887" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/ARPSyndicate/kenzer-templates" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="totolink ex1800t totolink ex1800t - command injection high identify critical remote vulnerabilities totolink ex1800t v9.1.0cu.2112_b20220316 has a vulnerability in the apcliencryptype parameter that allows unauthorized execution of arbitrary commands, allowing an attacker to obtain device administrator privileges. cve-2024-34257 pussycat0x cve cve2024 rce unauth vkev vuln cwe-285" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">TOTOLINK EX1800T TOTOLINK EX1800T - Command Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-34257.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-34257.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 4, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/285.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-285</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-34257" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-34257</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)totolink&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">TOTOLINK EX1800T V9.1.0cu.2112_B20220316 has a vulnerability in the apcliEncrypType parameter that allows unauthorized execution of arbitrary commands, allowing an attacker to obtain device administrator privileges.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can execute arbitrary commands via the apcliEncrypType parameter, gaining device administrator privileges.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update TOTOLINK EX1800T firmware to a version that patches the command injection vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">rce</span><span class="nt-tag">unauth</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/ZackSecurity/VulnerReport/blob/cve/totolink/EX1800T/1.md" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://immense-mirror-b42.notion.site/TOTOLINK-EX1800T-has-an-unauthorized-arbitrary-command-execution-vulnerability-2f3e308f5e1d45a2b8a64f198cacc350" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/20142995/nuclei-templates" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="totolink n150rt - password exposure high identify critical remote vulnerabilities detects password exposure vulnerability in totolink n150rt router where sensitive credentials are exposed in the password.htm page. ritikchaddha credentials exposure router totolink vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">TOTOLINK N150RT - Password Exposure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/vulnerabilities/totolink-n150rt-password-exposure.yaml" target="_blank" rel="noopener" class="nt-source-link">totolink-n150rt-password-exposure.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 19, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)totolink&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detects password exposure vulnerability in TOTOLINK N150RT router where sensitive credentials are exposed in the password.htm page.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">credentials</span><span class="nt-tag">exposure</span><span class="nt-tag">router</span><span class="nt-tag">totolink</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/fizz-is-on-the-way/Iot_vuls/blob/main/N150RT/Information_disclosure_password/imgs/2.png" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="totolink/realtek routers - captcha bypass critical identify critical remote vulnerabilities on certain totolink realtek sdk based routers, the captcha text can be retrieved via a post request to the boafrm/formlogin uri with the json payload {&#34;topicurl&#34;:&#34;setting/getsanvas&#34;}. this allows an unauthenticated attacker to bypass captcha verification, gaining unauthorized access to restricted functions. once valid credentials are known or brute-forced, an attacker can fully control the device using http requests and basic authentication. affected router models include a3002ru through 2.0.0, a702r through 2.1.3, n301rt through 2.1.6, n302r through 3.4.0, n300rt through 3.4.0, n200re through 4.0.0, n150rt through 3.4.0, n100re through 3.4.0, and other realtek sdk-derived devices. cve-2019-19825 ritikchaddha bypass captcha cve cve2019 realtek totolink vkev cwe-287" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">TOTOLINK/Realtek Routers - CAPTCHA Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2019/CVE-2019-19825.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2019-19825.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 20, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/287.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-287</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2019-19825" target="_blank" rel="noopener" class="nt-cve-link">CVE-2019-19825</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)TOTOLINK&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">On certain TOTOLINK Realtek SDK based routers, the CAPTCHA text can be retrieved via a POST request to the boafrm/formLogin URI with the JSON payload {&#34;topicurl&#34;:&#34;setting/getSanvas&#34;}. This allows an unauthenticated attacker to bypass CAPTCHA verification, gaining unauthorized access to restricted functions. Once valid credentials are known or brute-forced, an attacker can fully control the device using HTTP requests and Basic Authentication. Affected router models include A3002RU through 2.0.0, A702R through 2.1.3, N301RT through 2.1.6, N302R through 3.4.0, N300RT through 3.4.0, N200RE through 4.0.0, N150RT through 3.4.0, N100RE through 3.4.0, and other Realtek SDK-derived devices.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can bypass CAPTCHA verification to brute-force credentials and gain unauthorized administrative access, leading to complete device control and potential network compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to firmware versions beyond those listed as vulnerable, or replace affected devices with patched alternatives.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">bypass</span><span class="nt-tag">captcha</span><span class="nt-tag">cve</span><span class="nt-tag">cve2019</span><span class="nt-tag">realtek</span><span class="nt-tag">totolink</span><span class="nt-tag">vkev</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="http://packetstormsecurity.com/files/156083/Realtek-SDK-Information-Disclosure-Code-Execution.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2019-19825" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="totolink/realtek routers - information disclosure high identify critical remote vulnerabilities a certain router administration interface using realtek apmib (e.g., on totolink models) allows unauthenticated remote attackers to disclose the entire router configuration, including sensitive credentials, via accessing the &#34;config.dat&#34; file. affected devices include totolink a3002ru through 2.0.0, a702r through 2.1.3, n301rt through 2.1.6, n302r through 3.4.0, n300rt through 3.4.0, n200re through 4.0.0, n150rt through 3.4.0, n100re through 3.4.0, and other realtek sdk-based devices. cve-2019-19822 ritikchaddha boa config cve cve2019 information-disclosure realtek totolink cwe-306" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">TOTOLINK/Realtek Routers - Information Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2019/CVE-2019-19822.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2019-19822.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 20, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/306.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-306</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2019-19822" target="_blank" rel="noopener" class="nt-cve-link">CVE-2019-19822</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)totolink&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A certain router administration interface using Realtek APMIB (e.g., on TOTOLINK models) allows unauthenticated remote attackers to disclose the entire router configuration, including sensitive credentials, via accessing the &#34;config.dat&#34; file. Affected devices include TOTOLINK A3002RU through 2.0.0, A702R through 2.1.3, N301RT through 2.1.6, N302R through 3.4.0, N300RT through 3.4.0, N200RE through 4.0.0, N150RT through 3.4.0, N100RE through 3.4.0, and other Realtek SDK-based devices.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can retrieve the entire router configuration including Wi-Fi passwords, admin credentials, and network settings, enabling complete network takeover.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to firmware versions beyond those listed as vulnerable, or replace affected devices with patched alternatives.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">boa</span><span class="nt-tag">config</span><span class="nt-tag">cve</span><span class="nt-tag">cve2019</span><span class="nt-tag">information-disclosure</span><span class="nt-tag">realtek</span><span class="nt-tag">totolink</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="http://packetstormsecurity.com/files/156083/Realtek-SDK-Information-Disclosure-Code-Execution.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2019-19822" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="totolink/realtek routers - information disclosure high identify critical remote vulnerabilities a certain router administration interface using realtek apmib (e.g., on totolink models) allows unauthenticated remote attackers to disclose the entire router configuration, including sensitive credentials, via accessing the &#34;config.dat&#34; file. affected devices include totolink a3002ru through 2.0.0, a702r through 2.1.3, n301rt through 2.1.6, n302r through 3.4.0, n300rt through 3.4.0, n200re through 4.0.0, n150rt through 3.4.0, n100re through 3.4.0, and other realtek sdk-based devices. cve-2019-19823 ritikchaddha boa config cve cve2019 exposure realtek totolink cwe-306" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">TOTOLINK/Realtek Routers - Information Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2019/CVE-2019-19823.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2019-19823.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 20, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/306.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-306</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2019-19823" target="_blank" rel="noopener" class="nt-cve-link">CVE-2019-19823</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)totolink&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A certain router administration interface using Realtek APMIB (e.g., on TOTOLINK models) allows unauthenticated remote attackers to disclose the entire router configuration, including sensitive credentials, via accessing the &#34;config.dat&#34; file. Affected devices include TOTOLINK A3002RU through 2.0.0, A702R through 2.1.3, N301RT through 2.1.6, N302R through 3.4.0, N300RT through 3.4.0, N200RE through 4.0.0, N150RT through 3.4.0, N100RE through 3.4.0, and other Realtek SDK-based devices.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can retrieve the entire router configuration including Wi-Fi passwords, admin credentials, and network settings, enabling complete network takeover.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to firmware versions beyond those listed as vulnerable, or replace affected devices with patched alternatives.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">boa</span><span class="nt-tag">config</span><span class="nt-tag">cve</span><span class="nt-tag">cve2019</span><span class="nt-tag">exposure</span><span class="nt-tag">realtek</span><span class="nt-tag">totolink</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="http://packetstormsecurity.com/files/156083/Realtek-SDK-Information-Disclosure-Code-Execution.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2019-19822" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="totolink router - remote command execution critical identify critical remote vulnerabilities totolink routers are vulnerable to unauthenticated remote command execution via the /boaform/formwsc endpoint. an attacker can inject os commands through the localpin parameter. ritikchaddha totolink rce router boaform vuln cwe-78" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">TOTOLink Router - Remote Command Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/vulnerabilities/totolink-boaform-rce.yaml" target="_blank" rel="noopener" class="nt-source-link">totolink-boaform-rce.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 19, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/78.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-78</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)TOTOLINK&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">TOTOLink routers are vulnerable to unauthenticated remote command execution via the /boaform/formWsc endpoint. An attacker can inject OS commands through the localPin parameter.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">totolink</span><span class="nt-tag">rce</span><span class="nt-tag">router</span><span class="nt-tag">boaform</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/fizz-is-on-the-way/Iot_vuls/blob/main/N150RT/RCE_formWsc/README.md" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="tp-link - local file inclusion high identify critical remote vulnerabilities tp-link is susceptible to local file inclusion in these products: archer c5 (1.2) with firmware before 150317, archer c7 (2.0) with firmware before 150304, and c8 (1.0) with firmware before 150316, archer c9 (1.0), tl-wdr3500 (1.0), tl-wdr3600 (1.0), and tl-wdr4300 (1.0) with firmware before 150302, tl-wr740n (5.0) and tl-wr741nd (5.0) with firmware before 150312, and tl-wr841n (9.0), tl-wr841n (10.0), tl-wr841nd (9.0), and tl-wr841nd (10.0) with firmware before 150310.  because of insufficient input validation, arbitrary local files can be disclosed. files that include passwords and other sensitive information can be accessed. cve-2015-3035 0x_akoko cve cve2015 kev lfi router seclists tp-link tplink vkev vuln cwe-22" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">TP-LINK - Local File Inclusion</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2015/CVE-2015-3035.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2015-3035.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_Akoko</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2015-3035" target="_blank" rel="noopener" class="nt-cve-link">CVE-2015-3035</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)tp-link&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">TP-LINK is susceptible to local file inclusion in these products: Archer C5 (1.2) with firmware before 150317, Archer C7 (2.0) with firmware before 150304, and C8 (1.0) with firmware before 150316, Archer C9 (1.0), TL-WDR3500 (1.0), TL-WDR3600 (1.0), and TL-WDR4300 (1.0) with firmware before 150302, TL-WR740N (5.0) and TL-WR741ND (5.0) with firmware before 150312, and TL-WR841N (9.0), TL-WR841N (10.0), TL-WR841ND (9.0), and TL-WR841ND (10.0) with firmware before 150310.  Because of insufficient input validation, arbitrary local files can be disclosed. Files that include passwords and other sensitive information can be accessed.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can read sensitive files on the TP-LINK router, potentially leading to unauthorized access or disclosure of sensitive information.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest firmware update provided by TP-LINK to fix the local file inclusion vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2015</span><span class="nt-tag">kev</span><span class="nt-tag">lfi</span><span class="nt-tag">router</span><span class="nt-tag">seclists</span><span class="nt-tag">tp-link</span><span class="nt-tag">tplink</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://seclists.org/fulldisclosure/2015/Apr/26" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.sec-consult.com/fxdata/seccons/prod/temedia/advisories_txt/20150410-0_TP-Link_Unauthenticated_local_file_disclosure_vulnerability_v10.txt" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="http://www.tp-link.com/en/download/TL-WDR3600_V1.html#Firmware" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2015-3035" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="http://www.tp-link.com/en/download/Archer-C5_V1.20.html#Firmware" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="tp-link wr840n v6 up to 0.9.1 4.16 - improper authentication critical identify critical remote vulnerabilities a vulnerability in the tp-link wr840n v6 router with firmware version 0.9.1 4.16 and earlier permits unauthorized individuals to bypass the authentication of some interfaces under the /cgi directory.when adding referer- http-//tplinkwifi.net to the the request, it will be recognized as passing the authentication. cve-2024-57050 dhiyaneshdk auth-bypass cve cve2024 tp-link vuln cwe-287" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">TP-LINK WR840N v6 up to 0.9.1 4.16 - Improper Authentication</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-57050.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-57050.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 11, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/287.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-287</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-57050" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-57050</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)WR840N&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A vulnerability in the TP-Link WR840N v6 router with firmware version 0.9.1 4.16 and earlier permits unauthorized individuals to bypass the authentication of some interfaces under the /cgi directory.When adding Referer- http-//tplinkwifi.net to the the request, it will be recognized as passing the authentication.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can bypass authentication by adding a specific Referer header, gaining unauthorized access to router administrative interfaces.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update TP-Link WR840N v6 router to firmware version later than 0.9.1 4.16 that addresses the authentication bypass vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">tp-link</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/Shuanunio/CVE_Requests/blob/main/TP-Link/WR840N%20v6/ACL%20bypass%20Vulnerability%20in%20TP-Link%20TL-WR840N.md" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-57050" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="tp-link archer ax21 (ax1800) - unauthenticated command injection critical identify critical remote vulnerabilities tp-link archer ax21 (ax1800) routers are vulnerable to unauthenticated os command injection via the country parameter in the locale endpoint. this allows remote attackers to execute arbitrary commands as root. cve-2023-1389 ritikchaddha archer ax21 cve cve2023 kev rce router tp-link vkev vuln cwe-78" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">TP-Link Archer AX21 (AX1800) - Unauthenticated Command Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-1389.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-1389.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 22, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/78.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-78</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-1389" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-1389</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)TP-Link Router&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">TP-Link Archer AX21 (AX1800) routers are vulnerable to unauthenticated OS command injection via the country parameter in the locale endpoint. This allows remote attackers to execute arbitrary commands as root.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can exploit OS command injection through the country parameter in the locale endpoint to execute arbitrary commands as root and completely compromise TP-Link Archer AX21 routers.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest firmware version provided by TP-Link.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">archer</span><span class="nt-tag">ax21</span><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">kev</span><span class="nt-tag">rce</span><span class="nt-tag">router</span><span class="nt-tag">tp-link</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.tenable.com/security/research/tra-2023-11" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-1389" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/tenable/poc-cve-2023-1389" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="tp-link archer c20 - authentication bypass critical identify critical remote vulnerabilities a vulnerability in the tp-link archer c20 router with firmware version v6.6_230412 and earlier permits unauthorized individuals to bypass authentication on interfaces under the /cgi directory. when adding a referer header with value &#34;http://tplinkwifi.net&#34; to requests, the router will recognize the request as passing authentication, allowing access to protected administration interfaces. cve-2024-57049 ritikchaddha archer-c20 auth-bypass cve cve2024 tp-link vkev vuln cwe-287" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">TP-Link Archer C20 - Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-57049.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-57049.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 20, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/287.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-287</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-57049" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-57049</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Archer C20&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A vulnerability in the TP-Link Archer C20 router with firmware version V6.6_230412 and earlier permits unauthorized individuals to bypass authentication on interfaces under the /cgi directory. When adding a Referer header with value &#34;http://tplinkwifi.net&#34; to requests, the router will recognize the request as passing authentication, allowing access to protected administration interfaces.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can bypass authentication by adding a specific Referer header, gaining unauthorized access to protected administration interfaces and router configuration.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update TP-Link Archer C20 router to firmware version later than V6.6_230412 that addresses the authentication bypass vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">archer-c20</span><span class="nt-tag">auth-bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">tp-link</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/Shuanunio/CVE_Requests/blob/main/TP-Link/archer%20c20/ACL%20bypass%20Vulnerability%20in%20TP-Link%20archer%20c20.md" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-57049" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/advisories/GHSA-qr32-fcm4-m5h9" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="tp-link wireless n router wr940n - default-login high identify default logins in web-based control panels  ritikchaddha default-login misconfig tplink vuln wr940n" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">TP-Link Wireless N Router WR940N - Default-Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/tplink/tplink-wR940n-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">tplink-wR940n-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 23, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;/userRpm/&#34;</code></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">misconfig</span><span class="nt-tag">tplink</span><span class="nt-tag">vuln</span><span class="nt-tag">wR940n</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="trendnet tew-827dru login panel - detect info identify web-based control panels trendnet tew-827dru login panel was detected. princechaddha discovery panel router trendnet cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">TRENDnet TEW-827DRU Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/trendnet/trendnet-tew827dru-login.yaml" target="_blank" rel="noopener" class="nt-source-link">trendnet-tew827dru-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> princechaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)tew-827dru&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">TRENDnet TEW-827DRU login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">router</span><span class="nt-tag">trendnet</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="trufusion enterprise &lt;= 7.10.4.0 - admin contact portal high identify critical remote vulnerabilities trufusion enterprise versions 7.10.4.0 and earlier contained a vulnerability that allowed unauthenticated access to the internal admin contact page, resulting in the disclosure of pii (including partner and contact names). cve-2025-27225 dhiyaneshdk,rcesecurity auth-bypass cve cve2025 trufusion vuln cwe-288" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">TRUfusion Enterprise &lt;= 7.10.4.0 - Admin Contact Portal</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-27225.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-27225.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK,rcesecurity</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 2, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/288.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-288</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-27225" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-27225</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)TRUfusion&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">TRUfusion Enterprise versions 7.10.4.0 and earlier contained a vulnerability that allowed unauthenticated access to the Internal Admin Contact Page, resulting in the disclosure of PII (including partner and contact names).</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can access the Internal Admin Contact Page, exposing personally identifiable information including partner and contact names without any authorization.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade TRUfusion Enterprise to a secure version by updating to one of the following releases: 7.10.3.1, 7.10.1.1, 7.10.1.0, 7.10.3.0, 7.9.6.1, 7.9.6.0, 7.9.5.0, 7.9.4.0, 7.9.3.1, 7.9.3.0, 7.9.2.1, 7.10.2.0, or 7.10.0.1.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">trufusion</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/MrTuxracer/advisories/blob/master/CVEs/CVE-2025-27225.txt" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.rcesecurity.com/2025/09/when-audits-fail-four-critical-pre-auth-vulnerabilities-in-trufusion-enterprise/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://docs.rocketsoftware.com/bundle/trufusion_rn_71031/page/kwg1743156415157.html" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="trufusion enterprise &lt;= 7.10.4.0 - authentication bypass critical identify critical remote vulnerabilities hard-coded cryptographic key allowing to forge session cookies that can be used to entirely bypass authentication cve-2025-27223 dhiyaneshdk,rcesecurity auth-bypass cve cve2025 trufusion vkev vuln cwe-1004" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">TRUfusion Enterprise &lt;= 7.10.4.0 - Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-27223.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-27223.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK,rcesecurity</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 2, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/1004.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-1004</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-27223" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-27223</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)TRUfusion&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Hard-Coded Cryptographic key allowing to forge session cookies that can be used to entirely bypass authentication</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can forge session cookies using hard-coded cryptographic keys to completely bypass authentication, gaining unauthorized access to the system with arbitrary user privileges.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade TRUfusion Enterprise to a secure version by updating to one of the following releases: 7.10.3.1, 7.10.1.1, 7.10.1.0, 7.10.3.0, 7.9.6.1, 7.9.6.0, 7.9.5.0, 7.9.4.0, 7.9.3.1, 7.9.3.0, 7.9.2.1, 7.10.2.0, or 7.10.0.1.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">trufusion</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/MrTuxracer/advisories/blob/master/CVEs/CVE-2025-27223.txt" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.rcesecurity.com/2025/09/when-audits-fail-four-critical-pre-auth-vulnerabilities-in-trufusion-enterprise/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://docs.rocketsoftware.com/bundle/trufusion_rn_71031/page/kwg1743156415157.html" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="trufusion enterprise &lt;= 7.10.4.0 - path traversal critical identify critical remote vulnerabilities pre-auth path traversal allowing to leak local server files disclosing sensitive clear-text passwords. cve-2025-27222 dhiyaneshdk,rcesecurity cve cve2025 lfi trufusion vkev vuln cwe-35" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">TRUfusion Enterprise &lt;= 7.10.4.0 - Path Traversal</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-27222.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-27222.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK,rcesecurity</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 2, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/35.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-35</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-27222" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-27222</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)TRUfusion&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Pre-Auth Path Traversal Allowing to Leak Local server files disclosing sensitive clear-text passwords.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can exploit path traversal to read arbitrary files from the server, potentially exposing sensitive clear-text passwords, configuration files, and other confidential data.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade TRUfusion Enterprise to a secure version by updating to one of the following releases: 7.10.3.1, 7.10.1.1, 7.10.1.0, 7.10.3.0, 7.9.6.1, 7.9.6.0, 7.9.5.0, 7.9.4.0, 7.9.3.1, 7.9.3.0, 7.9.2.1, 7.10.2.0, or 7.10.0.1.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">lfi</span><span class="nt-tag">trufusion</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/MrTuxracer/advisories/blob/master/CVEs/CVE-2025-27222.txt" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.rcesecurity.com/2025/09/when-audits-fail-four-critical-pre-auth-vulnerabilities-in-trufusion-enterprise/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://docs.rocketsoftware.com/bundle/trufusion_rn_71031/page/kwg1743156415157.html" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="tvt nvms 1000 - local file inclusion high identify critical remote vulnerabilities tvt nvms-1000 devices allow get /.. local file inclusion attacks. cve-2019-20085 daffainfo cve cve2019 edb iot kev lfi packetstorm tvt vkev vuln cwe-22" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">TVT NVMS 1000 - Local File Inclusion</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2019/CVE-2019-20085.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2019-20085.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> daffainfo</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2019-20085" target="_blank" rel="noopener" class="nt-cve-link">CVE-2019-20085</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)^NVMS-1000&#34; })</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">TVT NVMS-1000 devices allow GET /.. local file inclusion attacks.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can exploit this vulnerability to gain unauthorized access to sensitive information stored on the system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches or updates provided by the vendor to fix the local file inclusion vulnerability in TVT NVMS 1000 software.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2019</span><span class="nt-tag">edb</span><span class="nt-tag">iot</span><span class="nt-tag">kev</span><span class="nt-tag">lfi</span><span class="nt-tag">packetstorm</span><span class="nt-tag">tvt</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.exploit-db.com/exploits/48311" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.exploit-db.com/exploits/47774" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="http://packetstormsecurity.com/files/157196/TVT-NVMS-1000-Directory-Traversal.html" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2019-20085" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/ARPSyndicate/kenzer-templates" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="typo3 ceselector extension - insecure deserialization critical identify critical remote vulnerabilities typo3 extension contains a php object injection caused by passing attacker-controlled cookie to unserialize() without validation, letting remote unauthenticated attackers achieve remote code execution, exploit requires persistent mode: static configuration. cve-2026-46725 dhiyaneshdk ceselector cve cve2026 deserialization rce typo3 vuln cwe-502" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">TYPO3 ceselector Extension - Insecure Deserialization</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2026/CVE-2026-46725.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2026-46725.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 27, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/502.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-502</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2026-46725" target="_blank" rel="noopener" class="nt-cve-link">CVE-2026-46725</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches `(?i)content\s*=\s*&#34;TYPO3 CMS&#34;`</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">TYPO3 extension contains a PHP Object Injection caused by passing attacker-controlled cookie to unserialize() without validation, letting remote unauthenticated attackers achieve remote code execution, exploit requires Persistent Mode: Static configuration.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Remote unauthenticated attackers can execute arbitrary code on the TYPO3 server, leading to full system compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest version of TYPO3 with the vulnerability fixed or apply patches that validate and sanitize unserialize input.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">ceselector</span><span class="nt-tag">cve</span><span class="nt-tag">cve2026</span><span class="nt-tag">deserialization</span><span class="nt-tag">rce</span><span class="nt-tag">typo3</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://typo3.org/security/advisory/typo3-ext-sa-2026-001" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://packagist.org/packages/mmc/ceselector" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="tabby panel - detect info identify web-based control panels tabby panel was discovered. s4e-io panel login tabby detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Tabby Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/tabby-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">tabby-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> s4e-io</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 14, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Tabby&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Tabby panel was discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">login</span><span class="nt-tag">tabby</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/TabbyML/tabby" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="tableau services manager login panel - detect info identify web-based control panels tableau services manager login panel was detected. dhiyaneshdk discovery panel tableau tableausoftware cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Tableau Services Manager Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/tableau-service-manager.yaml" target="_blank" rel="noopener" class="nt-source-link">tableau-service-manager.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)login - tableau services manager&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Tableau Services Manager login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">tableau</span><span class="nt-tag">tableausoftware</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://help.tableau.com/current/server/en-us/sign_in_tsm.htm" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="tactical rmm login panel - detect info identify web-based control panels tactical rmm login panel was detected. johnk3r panel tacticalrmm login detect discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Tactical RMM Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/tactical-rmm-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">tactical-rmm-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> johnk3r</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 20, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Tactical RMM - Login&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Tactical RMM login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">tacticalrmm</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="tailon panel - detect unknown identify web-based control panels  ritikchaddha panel tailon detect discovery" data-nt-sev="unknown">
  <div class="nt-card-header">
    <div class="nt-title">Tailon Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-unknown fd-badge-sm">Unknown</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/tailon-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">tailon-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 3, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)tailon&#34;})</code></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">tailon</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/gvalkov/tailon" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="tamronos iptv/vod - remote command execution critical identify critical remote vulnerabilities tamronos iptv/vod contains a remote command execution in the &#39;host&#39; parameter of the /api/ping endpoint. pikpikcu rce tamronos vuln cwe-78" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">TamronOS IPTV/VOD - Remote Command Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/vulnerabilities/other/tamronos-rce.yaml" target="_blank" rel="noopener" class="nt-source-link">tamronos-rce.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pikpikcu</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/78.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-78</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)TamronOS IPTV系统&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">TamronOS IPTV/VOD contains a remote command execution in the &#39;host&#39; parameter of the /api/ping endpoint.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">rce</span><span class="nt-tag">tamronos</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://twitter.com/sec715/status/1405336456923471874" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="taskingai panel - detect info identify web-based control panels taskingai is an open-source platform for building and deploying llm-based agents
and ai applications with a unified api rxerium agents ai detect discovery llm panel taskingai" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">TaskingAI Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/taskingai-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">taskingai-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 27, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;TaskingAI \\| Console&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">TaskingAI is an open-source platform for building and deploying LLM-based agents
and AI applications with a unified API</div></div></div>
  <div class="nt-tags"><span class="nt-tag">agents</span><span class="nt-tag">ai</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">llm</span><span class="nt-tag">panel</span><span class="nt-tag">taskingai</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/TaskingAI/TaskingAI" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.tasking.ai" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="tattile camera &lt; 1.181.5 - default login high identify critical remote vulnerabilities tattile smart+, vega, and basic device families firmware &lt;= 1.181.5 contain a broken authentication caused by default credentials not forced to be changed, letting attackers with management interface access gain administrative privileges. cve-2026-26341 0x_akoko camera cve cve2026 default-login iot tattile cwe-1392" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Tattile Camera &lt; 1.181.5 - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2026/CVE-2026-26341.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2026-26341.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_Akoko</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 11, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/1392.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-1392</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2026-26341" target="_blank" rel="noopener" class="nt-cve-link">CVE-2026-26341</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;2030104257&#34; || service[&#34;http.body&#34;] matches &#34;(?i)Tattile camera manager&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Tattile Smart+, Vega, and Basic device families firmware &lt;= 1.181.5 contain a broken authentication caused by default credentials not forced to be changed, letting attackers with management interface access gain administrative privileges.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can gain administrative access to device configuration and data, leading to unauthorized control and data exposure.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update firmware to a version later than 1.181.5 or the latest available version.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">camera</span><span class="nt-tag">cve</span><span class="nt-tag">cve2026</span><span class="nt-tag">default-login</span><span class="nt-tag">iot</span><span class="nt-tag">tattile</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.cve.org/CVERecord?id=CVE-2026-26341" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="tautulli panel - detect info identify web-based control panels a python based monitoring and tracking tool for plex media server. rxerium detect discovery panel tautulli" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Tautulli Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/tautulli-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">tautulli-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 27, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)tautulli&#34;}) || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)tautulli - home&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A Python based monitoring and tracking tool for Plex Media Server.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">tautulli</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://tautulli.com/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/Tautulli/Tautulli" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="tautulli panel - unauthenticated access medium identify web-based control panels  ritikchaddha discovery exposure misconfig panel tautulli unauth" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Tautulli Panel - Unauthenticated Access</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/unauth/tautulli-unauth.yaml" target="_blank" rel="noopener" class="nt-source-link">tautulli-unauth.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 9, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)tautulli - home&#34;}) || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)tautulli&#34;})</code></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">exposure</span><span class="nt-tag">misconfig</span><span class="nt-tag">panel</span><span class="nt-tag">tautulli</span><span class="nt-tag">unauth</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="teamcity &lt; 2023.11.4 - authentication bypass critical identify critical remote vulnerabilities in jetbrains teamcity before 2023.11.4 authentication bypass allowing to perform admin actions was possible cve-2024-27198 dhiyaneshdk auth-bypass cve cve2024 jetbrains kev teamcity vkev vuln cwe-288" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">TeamCity &lt; 2023.11.4 - Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-27198.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-27198.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 5, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/288.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-288</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-27198" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-27198</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)teamcity&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can bypass authentication to perform administrative actions on TeamCity servers, potentially compromising build pipelines and source code.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update JetBrains TeamCity to version 2023.11.4 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">jetbrains</span><span class="nt-tag">kev</span><span class="nt-tag">teamcity</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.rapid7.com/blog/post/2024/03/04/etr-cve-2024-27198-and-cve-2024-27199-jetbrains-teamcity-multiple-authentication-bypass-vulnerabilities-fixed/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-27198" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.darkreading.com/cyberattacks-data-breaches/jetbrains-teamcity-mass-exploitation-underway-rogue-accounts-thrive" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/rampantspark/CVE-2024-27198" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/fireinrain/github-trending" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="teamcity login panel - detect info identify web-based control panels teamcity login panel was detected. princechaddha detect discovery jetbrains panel teamcity cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">TeamCity Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/teamcity-login-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">teamcity-login-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> princechaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)teamcity&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">TeamCity login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">jetbrains</span><span class="nt-tag">panel</span><span class="nt-tag">teamcity</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="teamforge panel - detection info identify web-based control panels teamforge login panel was discovered. lstatro panel teamforge login discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">TeamForge Panel - Detection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/teamforge-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">teamforge-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> lstatro</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 7, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)TeamForge :&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">TeamForge Login Panel was discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">teamforge</span><span class="nt-tag">login</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://digital.ai/products/teamforge/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="teampass 2.1.27.36 - improper authentication high identify critical remote vulnerabilities teampass 2.1.27.36 is susceptible to improper authentication. an attacker can retrieve files from the teampass web root, which may include backups or ldap debug files, and therefore possibly obtain sensitive information, modify data, and/or execute unauthorized operations. cve-2020-12478 arafatansari cve cve2020 exposure teampass unauth vuln cwe-306" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">TeamPass 2.1.27.36 - Improper Authentication</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2020/CVE-2020-12478.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2020-12478.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> arafatansari</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/306.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-306</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2020-12478" target="_blank" rel="noopener" class="nt-cve-link">CVE-2020-12478</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)teampass&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">TeamPass 2.1.27.36 is susceptible to improper authentication. An attacker can retrieve files from the TeamPass web root, which may include backups or LDAP debug files, and therefore possibly obtain sensitive information, modify data, and/or execute unauthorized operations.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can bypass authentication and gain unauthorized access to sensitive information.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to a patched version of TeamPass or apply the recommended security patches.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2020</span><span class="nt-tag">exposure</span><span class="nt-tag">teampass</span><span class="nt-tag">unauth</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/nilsteampassnet/TeamPass/issues/2764" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2020-12478" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/ARPSyndicate/cvemon" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/ARPSyndicate/kenzer-templates" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/StarCrossPortal/scalpel" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="teampass panel - detect info identify web-based control panels teampass panel was detected. arafatansari panel teampass discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">TeamPass Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/teampass-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">teampass-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> arafatansari</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)teampass&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">TeamPass panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">teampass</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="tekton dashboard panel - detect info identify web-based control panels tekton dashboard panel was detected. dhiyaneshdk panel tekton exposure discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Tekton Dashboard Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/tekton-dashboard.yaml" target="_blank" rel="noopener" class="nt-source-link">tekton-dashboard.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Tekton&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Tekton Dashboard panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">tekton</span><span class="nt-tag">exposure</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="telecontrol server basic panel - detect info identify web-based control panels telecontrol server basic panel was discovered. kazgangap panel login siemens detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Telecontrol Server Basic Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/telecontrol-server-basic-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">telecontrol-server-basic-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Kazgangap</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 15, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Logon - Telecontrol Server Basic&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Telecontrol Server Basic panel was discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">login</span><span class="nt-tag">siemens</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://sieportal.siemens.com/en-ca/products-services/10087338?tree=CatalogTree" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="teleport - authentication bypass critical identify critical remote vulnerabilities teleport versions prior to 17.5.2 are vulnerable to a remote authentication bypass vulnerability. this issue allows attackers to gain unauthorized access to affected systems. cve-2025-49825 pdteam auth-bypass cve cve2025 passive teleport vuln" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Teleport - Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-49825.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-49825.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pdteam</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 24, 2025</span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-49825" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-49825</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-1275955539&#34; || service[&#34;favicon.ico.image.mmh3&#34;] == &#34;544208100&#34; || service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1854879765&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Teleport versions prior to 17.5.2 are vulnerable to a remote authentication bypass vulnerability. This issue allows attackers to gain unauthorized access to affected systems.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can bypass authentication mechanisms to gain unauthorized access to Teleport systems, potentially compromising protected infrastructure and sensitive resources.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade Teleport to version 17.5.2, 16.5.12, 15.5.3, 14.4.1, 13.4.27, or 12.4.35 depending on your version branch.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">passive</span><span class="nt-tag">teleport</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/gravitational/teleport/security/advisories/GHSA-8cqv-pj7f-pwpc" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="teleport login panel - detect info identify web-based control panels detects teleport web login interface exposed at /web/login and version information from /webapi/ping pdteam,mahmoud0x00 panel teleport login oss discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Teleport Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/teleport-login-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">teleport-login-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pdteam,mahmoud0x00</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 17, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;544208100&#34; || service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1854879765&#34; || service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-1275955539&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detects Teleport web login interface exposed at /web/login and version information from /webapi/ping</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">teleport</span><span class="nt-tag">login</span><span class="nt-tag">oss</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/gravitational/teleport" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="telerik report server login panel - detect info identify web-based control panels telerik report server login panel was detected. ritikchaddha discovery panel telerik cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Telerik Report Server Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/telerik-server-login.yaml" target="_blank" rel="noopener" class="nt-source-link">telerik-server-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Telerik Report Server&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Telerik Report Server login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">telerik</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="telesquare tlr-2005ksh - remote command execution critical identify critical remote vulnerabilities telesquare tlr-2005ksh is a sk telecom lte router from south korea&#39;s telesquare company.telesquare tlr-2005ksh versions 1.0.0 and 1.1.4 have an unauthorized remote command execution vulnerability. an attacker can exploit this vulnerability to execute system commands without authorization through the cmd parameter and obtain server permissions. cve-2024-29269 ritikchaddha cve cve2024 rce telesquare tlr vkev vuln" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Telesquare TLR-2005KSH - Remote Command Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-29269.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-29269.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 4, 2024</span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-29269" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-29269</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Login to TLR-2005KSH&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Telesquare Tlr-2005Ksh is a Sk Telecom Lte router from South Korea&#39;s Telesquare company.Telesquare TLR-2005Ksh versions 1.0.0 and 1.1.4 have an unauthorized remote command execution vulnerability. An attacker can exploit this vulnerability to execute system commands without authorization through the Cmd parameter and obtain server permissions.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can execute arbitrary commands on the router, leading to complete device compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update Telesquare TLR-2005KSH firmware to a version that patches the RCE vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">rce</span><span class="nt-tag">telesquare</span><span class="nt-tag">tlr</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/wutalent/CVE-2024-29269/blob/main/index.md" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://gist.github.com/win3zz/c26047ae4b182c3619509d537b808d2b" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/Ostorlab/KEV" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/YongYe-Security/CVE-2024-29269" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/nomi-sec/PoC-in-GitHub" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="telesquare tlr-2005ksh login panel - detect info identify web-based control panels telesquare tlr-2005ksh login panel was detected. princechaddha discovery panel router telesquare cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Telesquare TLR-2005KSH Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/telesquare/tlr-2005ksh-login.yaml" target="_blank" rel="noopener" class="nt-source-link">tlr-2005ksh-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> princechaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)tlr-2005ksh&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Telesquare TLR-2005KSH login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">router</span><span class="nt-tag">telesquare</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="tembosocial admin panel - detect info identify web-based control panels tembosocial admin panel was detected. dhiyaneshdk panel tembosocial discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">TemboSocial Admin Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/tembosocial-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">tembosocial-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)TemboSocial Administration&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">TemboSocial Admin panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">tembosocial</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="temenos transact login panel - detect info identify web-based control panels temenos transact login panel was detected. korteke discovery exposure panel temenos cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Temenos Transact Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/temenos-t24-login.yaml" target="_blank" rel="noopener" class="nt-source-link">temenos-t24-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> korteke</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)t24 sign in&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Temenos Transact login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">exposure</span><span class="nt-tag">panel</span><span class="nt-tag">temenos</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.temenos.com/products/transact/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="tenable nessus panel - detect info identify web-based control panels tenable nessus panel was detected. joanbono,tess discovery nessus panel tenable cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Tenable Nessus Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/nessus-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">nessus-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> joanbono,tess</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)nessus&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Tenable Nessus panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">nessus</span><span class="nt-tag">panel</span><span class="nt-tag">tenable</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="tenda 11n - authentication bypass critical identify critical remote vulnerabilities tenda 11n with firmware version v5.07.33_cn contains an authentication bypass vulnerability. an attacker can possibly obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site. cve-2022-42233 for3stco1d auth-bypass cve cve2022 iot router tenda vuln cwe-287" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Tenda 11N - Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-42233.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-42233.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> For3stCo1d</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/287.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-287</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-42233" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-42233</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)tenda 11n&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Tenda 11N with firmware version V5.07.33_cn contains an authentication bypass vulnerability. An attacker can possibly obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can bypass authentication by setting an admin cookie to gain full administrative access to Tenda 11N routers, enabling complete device configuration changes and network compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest firmware update provided by Tenda to fix the authentication bypass vulnerability (CVE-2022-42233).</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">iot</span><span class="nt-tag">router</span><span class="nt-tag">tenda</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/D0ngsec/vulns/blob/main/Tenda/Tenda_11N_Authentication_Bypass.md" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-42233" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/ARPSyndicate/cvemon" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/ARPSyndicate/kenzer-templates" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/Henry4E36/POCS" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="tenda 11n wireless router - admin panel info identify web-based control panels the administrative panel for a tenda technology 11n wireless router was found. idealphase discovery panel tenda cwe-668" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Tenda 11n Wireless Router - Admin Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/tenda-11n-wireless-router-login.yaml" target="_blank" rel="noopener" class="nt-source-link">tenda-11n-wireless-router-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> idealphase</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/668.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-668</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Tenda 11N Wireless Router Login Screen&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The administrative panel for a Tenda Technology 11n Wireless Router was found.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">tenda</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.tendacn.com/products/11n-routers.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="tenda web master login panel - detect info identify web-based control panels tenda web master login panel was detected. dhiyaneshdk panel tenda router discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Tenda Web Master Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/tenda-web-master.yaml" target="_blank" rel="noopener" class="nt-source-link">tenda-web-master.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Tenda Web Master&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Tenda Web Master login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">tenda</span><span class="nt-tag">router</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="tenemos t24 login panel - detect info identify web-based control panels tenemos t24 products was detected. righettod panel tenemos login discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Tenemos T24 Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/tenemos-t24-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">tenemos-t24-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 6, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)T24 Sign in&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Tenemos T24 products was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">tenemos</span><span class="nt-tag">login</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.temenos.com/products/core-banking" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="tensorboard panel - detect info identify web-based control panels tensorboard is tensorflow&#39;s visualization toolkit for machine learning experimentation rxerium ai detect discovery ml panel tensorboard tensorflow" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">TensorBoard Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/tensorboard-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">tensorboard-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 27, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;TensorBoard&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">TensorBoard is TensorFlow&#39;s visualization toolkit for machine learning experimentation</div></div></div>
  <div class="nt-tags"><span class="nt-tag">ai</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">ml</span><span class="nt-tag">panel</span><span class="nt-tag">tensorboard</span><span class="nt-tag">tensorflow</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/tensorflow/tensorboard" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.tensorflow.org/tensorboard" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="teradek cube administrative console - panel info identify web-based control panels  dhiyaneshdk panel login teradek discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Teradek Cube Administrative Console - Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/teradek-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">teradek-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 20, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Teradek Cube Administrative Console&#34;})</code></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">login</span><span class="nt-tag">teradek</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.facebook.com/photo/?fbid=612496907587499&amp;set=a.467014098802448" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="terramaster tos &lt; 4.2.30 server information disclosure high identify critical remote vulnerabilities terramaster nas devices running tos prior to version 4.2.30 are vulnerable to information disclosure. cve-2022-24990 dwisiswant0 cve cve2022 exposure kev packetstorm terra-master terramaster vkev vuln cwe-306" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">TerraMaster TOS &lt; 4.2.30 Server Information Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-24990.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-24990.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dwisiswant0</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/306.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-306</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-24990" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-24990</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)terramaster&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">TerraMaster NAS devices running TOS prior to version 4.2.30 are vulnerable to information disclosure.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can exploit this vulnerability to gain sensitive information about the server, potentially leading to further attacks.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade the TerraMaster TOS server to version 4.2.30 or later to mitigate the vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">exposure</span><span class="nt-tag">kev</span><span class="nt-tag">packetstorm</span><span class="nt-tag">terra-master</span><span class="nt-tag">terramaster</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://octagon.net/blog/2022/03/07/cve-2022-24990-terrmaster-tos-unauthenticated-remote-command-execution-via-php-object-instantiation/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.broadcom.com/support/security-center/attacksignatures/detail?asid=33732" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://forum.terra-master.com/en/viewforum.php?f=28" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="http://packetstormsecurity.com/files/172904/TerraMaster-TOS-4.2.29-Remote-Code-Execution.html" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/ArrestX/--POC" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="terraform enterprise panel - detect info identify web-based control panels terraform enterprise panel was detected. adam crosser,idealphase discovery hashicorp panel terraform cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Terraform Enterprise Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/terraform-enterprise-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">terraform-enterprise-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Adam Crosser,idealphase</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)terraform enterprise&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Terraform Enterprise panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">hashicorp</span><span class="nt-tag">panel</span><span class="nt-tag">terraform</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.terraform.io/enterprise/releases" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="the events calendar &lt; 6.4.0.1 - cross-site scripting medium identify critical remote vulnerabilities the events calendar wordpress plugin &lt; 6.4.0.1 contains a stored xss caused by improper sanitization of user-submitted content when rendering views via ajax, letting attackers execute scripts in the context of the affected site. exploitation requires user interaction. cve-2024-4180 0x_akoko cve cve2024 the-events-calendar wordpress wp wp-plugin wpscan xss cwe-79" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">The Events Calendar &lt; 6.4.0.1 - Cross-site Scripting</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-4180.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-4180.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_Akoko</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 31, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-79</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-4180" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-4180</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)wp-content/plugins/the-events-calendar/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The Events Calendar WordPress plugin &lt; 6.4.0.1 contains a stored XSS caused by improper sanitization of user-submitted content when rendering views via AJAX, letting attackers execute scripts in the context of the affected site. Exploitation requires user interaction.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can execute arbitrary scripts in the context of the affected site, leading to potential session hijacking or defacement.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to version 6.4.0.1 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">the-events-calendar</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">wpscan</span><span class="nt-tag">xss</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wpscan.com/vulnerability/b2a92316-e404-4a5e-8426-f88df6e87550/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://wordpress.org/plugins/the-events-calendar/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-4180" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="the events calendar &lt;= 6.15.2 - information disclosure medium identify critical remote vulnerabilities the events calendar wordpress plugin &lt;= 6.15.2 contains an information disclosure vulnerability caused by rest endpoint exposure, letting unauthenticated attackers extract data about password-protected vendors or venues, exploit requires no authentication. cve-2025-9808 zer0p0int cve cve2025 wordpress wp-plugin wpscan the-events-calendar unauth vuln cwe-200" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">The Events Calendar &lt;= 6.15.2 - Information Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-9808.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-9808.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> zer0p0int</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 9, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-9808" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-9808</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/the-events-calendar/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The Events Calendar WordPress plugin &lt;= 6.15.2 contains an information disclosure vulnerability caused by REST endpoint exposure, letting unauthenticated attackers extract data about password-protected vendors or venues, exploit requires no authentication.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can access sensitive information about password-protected vendors or venues.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest version beyond 6.15.2</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">wpscan</span><span class="nt-tag">the-events-calendar</span><span class="nt-tag">unauth</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.wiz.io/vulnerability-database/cve/cve-2025-9808" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://wpscan.com/plugin/the-events-calendar/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/the-events-calendar" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://wordpress.org/plugins/the-events-calendar/" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-9808" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="the plus addons for elementor page builder &lt; 4.1.7 - authentication bypass critical identify critical remote vulnerabilities the plus addons for elementor plugin (before version 4.1.7) allowed attackers to bypass authentication, gain admin access, and create accounts with elevated roles, even when registration was disabled and the login widget was inactive. cve-2021-24175 pussycat0x cve cve2021 elementor passive plus-addons vkev vuln wordpress wp-theme wpscan cwe-287" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">The Plus Addons for Elementor Page Builder &lt; 4.1.7 - Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2021/CVE-2021-24175.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2021-24175.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 24, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/287.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-287</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2021-24175" target="_blank" rel="noopener" class="nt-cve-link">CVE-2021-24175</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/the-plus-addons-for-elementor-page-builder/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The Plus Addons for Elementor plugin (before version 4.1.7) allowed attackers to bypass authentication, gain admin access, and create accounts with elevated roles, even when registration was disabled and the Login widget was inactive.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can bypass authentication, gain administrator access, and create elevated privilege accounts even when registration is disabled, leading to complete WordPress site takeover.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Fixed in 4.1.7</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2021</span><span class="nt-tag">elementor</span><span class="nt-tag">passive</span><span class="nt-tag">plus-addons</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp-theme</span><span class="nt-tag">wpscan</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wpscan.com/vulnerability/c311feef-7041-4c21-9525-132b9bd32f89/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.wordfence.com/blog/2021/03/critical-0-day-in-the-plus-addons-for-elementor-allows-site-takeover/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="themegrill demo importer &lt; 1.6.2 - database reset critical identify critical remote vulnerabilities themegrill demo importer before 1.6.2 does not require authentication for wiping the database due to a reset_wizard_actions hook. in versions 1.3.4 and above and versions 1.6.1 and below, there is a vulnerability that allows any unauthenticated user to wipe the entire database to its default state after which they are automatically logged in as an administrator. cve-2020-36333 iamnoooob,pdresearch cve cve2020 themegrill vkev vuln wordpress wp wp-plugin cwe-285" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">ThemeGrill Demo Importer &lt; 1.6.2 - Database Reset</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2020/CVE-2020-36333.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2020-36333.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> iamnoooob,pdresearch</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 21, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/285.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-285</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2020-36333" target="_blank" rel="noopener" class="nt-cve-link">CVE-2020-36333</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/plugins/themegrill-demo-importer&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">ThemeGrill Demo Importer before 1.6.2 does not require authentication for wiping the database due to a reset_wizard_actions hook. In versions 1.3.4 and above and versions 1.6.1 and below, there is a vulnerability that allows any unauthenticated user to wipe the entire database to its default state after which they are automatically logged in as an administrator.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can wipe the entire WordPress database to its default state and gain automatic administrator access, resulting in complete site takeover and data loss.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to ThemeGrill Demo Importer version 1.6.2 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2020</span><span class="nt-tag">themegrill</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.openwall.com/lists/oss-security/2020/02/19/1" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2020-36333" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="themes coder ecommerce &lt;= 1.3.4 - sql injection high identify critical remote vulnerabilities the themes coder ecommerce wordpress plugin through 1.3.4 does not properly sanitise and escape a parameter before using it in a sql statement via an ajax action available to unauthenticated users, leading to a sql injection. cve-2024-13726 s4e-io cve cve2024 sqli tc-ecommerce timebased-sqli vuln wordpress wp wp-plugin wpscan cwe-89" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Themes Coder Ecommerce &lt;= 1.3.4 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-13726.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-13726.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> s4e-io</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 17, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-13726" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-13726</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)wp-content/plugins/tc-ecommerce/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The Themes Coder Ecommerce WordPress plugin through 1.3.4 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can execute time-based SQL injection to extract sensitive database information or manipulate data.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update Themes Coder Ecommerce plugin to a version newer than 1.3.4.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">sqli</span><span class="nt-tag">tc-ecommerce</span><span class="nt-tag">timebased-sqli</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">wpscan</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wpscan.com/vulnerability/ec226d22-0c09-4e7c-86ec-b64819089b60/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-13726" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="thinvnc - authentication bypass critical identify critical remote vulnerabilities thinvnc version 1.0b1 allows an unauthenticated user to bypass the authentication process via a specific command, potentially leading to unauthorized access and code execution. cve-2022-25226 ritikchaddha auth-bypass cve cve2022 thinvnc vuln" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">ThinVNC - Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-25226.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-25226.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 11, 2025</span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-25226" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-25226</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-1414548363&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">ThinVNC version 1.0b1 allows an unauthenticated user to bypass the authentication process via a specific command, potentially leading to unauthorized access and code execution.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can bypass authentication and gain unauthorized access to the ThinVNC server.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the vendor-supplied patch or update to the latest version to mitigate the CVE-2022-25226 vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">thinvnc</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="thinfinity iframe injection critical identify critical remote vulnerabilities a vulnerability exists in thinfinity virtualui in a function located in /lab.html reachable which by default  could allow iframe injection via the &#34;vpath&#34; parameter. cve-2021-45092 danielmofer cve cve2021 cybelesoft iframe injection packetstorm tenable thinfinity vkev vuln cwe-74" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Thinfinity Iframe Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2021/CVE-2021-45092.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2021-45092.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> danielmofer</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/74.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-74</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2021-45092" target="_blank" rel="noopener" class="nt-cve-link">CVE-2021-45092</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)thinfinity virtualui&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A vulnerability exists in Thinfinity VirtualUI in a function located in /lab.html reachable which by default  could allow IFRAME injection via the &#34;vpath&#34; parameter.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability can lead to unauthorized access, data leakage, and potential remote code execution.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches or updates provided by the vendor to fix the vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2021</span><span class="nt-tag">cybelesoft</span><span class="nt-tag">iframe</span><span class="nt-tag">injection</span><span class="nt-tag">packetstorm</span><span class="nt-tag">tenable</span><span class="nt-tag">thinfinity</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/cybelesoft/virtualui/issues/2" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2021-44848" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.tenable.com/cve/CVE-2021-45092" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="http://packetstormsecurity.com/files/166068/Thinfinity-VirtualUI-2.5.41.0-IFRAME-Injection.html" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/danielmofer/nuclei_templates" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="thinfinity virtualui panel - detect info identify web-based control panels thinfinity virtualui panel was detected. princechaddha cybelesoft discovery panel thinfinity virtualui cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Thinfinity VirtualUI Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/thinfinity-virtualui-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">thinfinity-virtualui-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> princechaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)thinfinity virtualui&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Thinfinity VirtualUI panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cybelesoft</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">thinfinity</span><span class="nt-tag">virtualui</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="thinfinity virtualui user enumeration medium identify critical remote vulnerabilities thinfinity virtualui (before v3.0), /changepassword returns different responses for requests depending on whether the username exists. it may enumerate os users (administrator, guest, etc.) cve-2021-44848 danielmofer cve cve2021 cybelesoft exposure packetstorm tenable thinfinity virtualui vuln cwe-203" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Thinfinity VirtualUI User Enumeration</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2021/CVE-2021-44848.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2021-44848.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> danielmofer</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/203.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-203</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2021-44848" target="_blank" rel="noopener" class="nt-cve-link">CVE-2021-44848</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)thinfinity virtualui&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Thinfinity VirtualUI (before v3.0), /changePassword returns different responses for requests depending on whether the username exists. It may enumerate OS users (Administrator, Guest, etc.)</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can use the gathered usernames for further attacks, such as brute-forcing passwords or launching targeted phishing campaigns.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the vendor-supplied patch or upgrade to the latest version of Thinfinity VirtualUI to mitigate the user enumeration vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2021</span><span class="nt-tag">cybelesoft</span><span class="nt-tag">exposure</span><span class="nt-tag">packetstorm</span><span class="nt-tag">tenable</span><span class="nt-tag">thinfinity</span><span class="nt-tag">virtualui</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/cybelesoft/virtualui/issues/1" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2021-44848" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.tenable.com/cve/CVE-2021-44848" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="http://packetstormsecurity.com/files/165327/Cibele-Thinfinity-VirtualUI-2.5.41.0-User-Enumeration.html" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/ARPSyndicate/cvemon" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="thingsboard panel - detect info identify web-based control panels thingsboard was detected — a open-source iot platform for device management, data collection, processing and visualization. righettod panel thingsboard detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">ThingsBoard Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/thingsboard-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">thingsboard-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 8, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)ThingsBoard&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">ThingsBoard was detected — a Open-source IoT Platform for device management, data collection, processing and visualization.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">thingsboard</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/thingsboard/thingsboard" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://thingsboard.io/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="thinkphp 5.0.24 - information disclosure high identify critical remote vulnerabilities thinkphp 5.0.24 is susceptible to information disclosure. this version was configured without the pathinfo parameter. this can allow an attacker to access all system environment parameters from index.php, thereby possibly obtaining sensitive information, modifying data, and/or executing unauthorized operations. cve-2022-25481 caon cve cve2022 exposure oss thinkphp vuln cwe-668" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">ThinkPHP 5.0.24 - Information Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-25481.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-25481.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> caon</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/668.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-668</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-25481" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-25481</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)thinkphp&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">ThinkPHP 5.0.24 is susceptible to information disclosure. This version was configured without the PATHINFO parameter. This can allow an attacker to access all system environment parameters from index.php, thereby possibly obtaining sensitive information, modifying data, and/or executing unauthorized operations.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can exploit this vulnerability to gain sensitive information.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to a patched version of ThinkPHP or apply the necessary security patches.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">exposure</span><span class="nt-tag">oss</span><span class="nt-tag">thinkphp</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/Lyther/VulnDiscover/blob/master/Web/ThinkPHP_InfoLeak.md" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-25481" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/20142995/sectool" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/ARPSyndicate/cvemon" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/ARPSyndicate/kenzer-templates" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="thinkphp &lt; 3.2.4 - remote code execution high identify critical remote vulnerabilities thinkphp before 3.2.4, as used in open source bms v1.1.1 and other products, allows remote command execution via the s parameter in index.php through the invokefunction functionality. cve-2019-9082 0xanis cve cve2019 kev none_cms open_source_bms rce thinkphp vkev cwe-94" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">ThinkPHP &lt; 3.2.4 - Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2019/CVE-2019-9082.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2019-9082.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0xanis</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 14, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/94.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-94</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2019-9082" target="_blank" rel="noopener" class="nt-cve-link">CVE-2019-9082</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;product&#34;] contains &#34;ThinkPHP:ThinkPHP&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">ThinkPHP before 3.2.4, as used in Open Source BMS v1.1.1 and other products, allows Remote Command Execution via the s parameter in index.php through the invokefunction functionality.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can execute arbitrary system commands true the server without authentication, potentially leading to full system compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to ThinkPHP 3.2.4 or later, or apply vendor patches.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2019</span><span class="nt-tag">kev</span><span class="nt-tag">none_cms</span><span class="nt-tag">open_source_bms</span><span class="nt-tag">rce</span><span class="nt-tag">thinkphp</span><span class="nt-tag">vkev</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/xyl-tools/open_source_bms/issues/33" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="http://packetstormsecurity.com/files/157218/ThinkPHP-5.0.23-Remote-Code-Execution.html" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.exploit-db.com/exploits/46488/" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/unix/webapp/thinkphp_rce.rb" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2019-9082" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="thinkphp lang - local file inclusion critical identify critical remote vulnerabilities thinkphp framework before 6.0.14 allows local file inclusion via the lang parameter when the language pack feature is enabled (lang_switch_on=true). an unauthenticated and remote attacker can exploit this to execute arbitrary operating system commands, as demonstrated by including pearcmd.php. cve-2022-47945 kagamigawa cve cve2022 lfi thinkphp vkev vuln cwe-22" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Thinkphp Lang - Local File Inclusion</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-47945.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-47945.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> kagamigawa</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-47945" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-47945</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Thinkphp&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">ThinkPHP Framework before 6.0.14 allows local file inclusion via the lang parameter when the language pack feature is enabled (lang_switch_on=true). An unauthenticated and remote attacker can exploit this to execute arbitrary operating system commands, as demonstrated by including pearcmd.php.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">This vulnerability can lead to unauthorized access, data leakage, and remote code execution.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches and updates provided by the Thinkphp framework.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">lfi</span><span class="nt-tag">thinkphp</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://tttang.com/archive/1865/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-47945" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/top-think/framework/compare/v6.0.13...v6.0.14" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/top-think/framework/commit/c4acb8b4001b98a0078eda25840d33e295a7f099" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/ARPSyndicate/kenzer-templates" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="thruk login panel - detect info identify web-based control panels thruk monitoring panel was detected. ffffffff0x,righettod discovery login panel thruk cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Thruk Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/thruk-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">thruk-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ffffffff0x,righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 16, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)thruk&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Thruk Monitoring panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">login</span><span class="nt-tag">panel</span><span class="nt-tag">thruk</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://thruk.org/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="tigase xmpp server - exposure info identify web-based control panels  dhiyaneshdk tigase xmpp server panel exposure discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Tigase XMPP Server - Exposure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/tigase-xmpp-server.yaml" target="_blank" rel="noopener" class="nt-source-link">tigase-xmpp-server.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 20, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Tigase XMPP Server&#34;})</code></div>
  <div class="nt-tags"><span class="nt-tag">tigase</span><span class="nt-tag">xmpp</span><span class="nt-tag">server</span><span class="nt-tag">panel</span><span class="nt-tag">exposure</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.facebook.com/photo/?fbid=617926933711163&amp;set=a.467014098802448" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="tiki wiki cms groupware - authentication bypass critical identify critical remote vulnerabilities tiki-login.php in tiki before 21.2 sets the admin password to a blank value after 50 invalid login attempts. cve-2020-15906 jeonsunghyun[nukunga],gy741,oifloraio,nechyo,harksu auth-bypass cve cve2020 packetstorm tiki vuln wiki cwe-307" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Tiki Wiki CMS GroupWare - Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2020/CVE-2020-15906.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2020-15906.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> JeonSungHyun[nukunga],gy741,oIfloraIo,nechyo,harksu</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 20, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/307.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-307</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2020-15906" target="_blank" rel="noopener" class="nt-cve-link">CVE-2020-15906</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Tiki Wiki CMS&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">tiki-login.php in Tiki before 21.2 sets the admin password to a blank value after 50 invalid login attempts.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can trigger 50 failed login attempts to reset the admin password to blank, gaining complete administrative access to the Tiki Wiki CMS and all its content.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to Tiki Wiki CMS version 21.2 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2020</span><span class="nt-tag">packetstorm</span><span class="nt-tag">tiki</span><span class="nt-tag">vuln</span><span class="nt-tag">wiki</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://packetstormsecurity.com/files/159663/Tiki-Wiki-CMS-Groupware-21.1-Authentication-Bypass.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15906" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/Z0fhack/Goby_POC" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/bakery312/Vulhub-Reproduce" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/20142995/Goby" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="tiki wiki cms groupware 5.2 - local file inclusion critical identify critical remote vulnerabilities tiki wiki cms groupware 5.2 is susceptible to a local file inclusion vulnerability. cve-2010-4239 0x_akoko cve cve2010 lfi tiki tikiwiki vuln cwe-20" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Tiki Wiki CMS Groupware 5.2 - Local File Inclusion</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2010/CVE-2010-4239.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2010-4239.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_akoko</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/20.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-20</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2010-4239" target="_blank" rel="noopener" class="nt-cve-link">CVE-2010-4239</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)tiki wiki&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Tiki Wiki CMS Groupware 5.2 is susceptible to a local file inclusion vulnerability.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">The LFI vulnerability can lead to unauthorized access to sensitive files, potentially exposing sensitive information or allowing for further exploitation.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade Tiki Wiki CMS Groupware to a version that is not affected by the CVE-2010-4239 vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2010</span><span class="nt-tag">lfi</span><span class="nt-tag">tiki</span><span class="nt-tag">tikiwiki</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://dl.packetstormsecurity.net/1009-exploits/tikiwiki52-lfi.txt" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.openwall.com/lists/oss-security/2010/11/22/9" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://security-tracker.debian.org/tracker/CVE-2010-4239" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2010-4239" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://access.redhat.com/security/cve/cve-2010-4239" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="tiki wiki cms groupware login panel - detect info identify web-based control panels tiki wiki cms groupware login panel was detected. chron0x panel tikiwiki tiki discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Tiki Wiki CMS Groupware Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/tikiwiki-cms.yaml" target="_blank" rel="noopener" class="nt-source-link">tikiwiki-cms.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> chron0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)tiki wiki&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Tiki Wiki CMS Groupware login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">tikiwiki</span><span class="nt-tag">tiki</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="tileserver api - cross site scripting medium identify critical remote vulnerabilities tileserver-gl up to v4.4.10 was discovered to contain a cross-site scripting (xss) vulnerability via the component /data/v3/?key. cve-2024-35627 dhiyaneshdk cve cve2024 tileserver vuln xss cwe-79" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">TileServer API - Cross Site Scripting</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-35627.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-35627.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 7, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-79</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-35627" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-35627</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-1258058404&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">tileserver-gl up to v4.4.10 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /data/v3/?key.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can inject malicious scripts via the key parameter, potentially compromising user sessions or stealing sensitive information.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update tileserver-gl to a version later than v4.4.10 that patches the XSS vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">tileserver</span><span class="nt-tag">vuln</span><span class="nt-tag">xss</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://gist.github.com/SaleSlave/e23d49e7f8eb937784d15c2c2fc34fca" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="time clock &lt;= 1.2.2 &amp; time clock pro &lt;= 1.1.4 - remote code execution high identify critical remote vulnerabilities the time clock plugin and time clock pro plugin for wordpress are vulnerable to remote code execution in versions up to, and including, 1.2.2 (for time clock) and 1.1.4 (for time clock pro) via the &#39;etimeclockwp_load_function_callback&#39; function. this allows unauthenticated attackers to execute code on the server. the invoked function&#39;s parameters cannot be specified. cve-2024-9593 s4e-io cve cve2024 rce time-clock time-clock-pro vkev vuln wordpress wp wp-plugin cwe-94" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Time Clock &lt;= 1.2.2 &amp; Time Clock Pro &lt;= 1.1.4 - Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-9593.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-9593.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> s4e-io</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 23, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/94.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-94</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-9593" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-9593</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/time-clock/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The Time Clock plugin and Time Clock Pro plugin for WordPress are vulnerable to Remote Code Execution in versions up to, and including, 1.2.2 (for Time Clock) and 1.1.4 (for Time Clock Pro) via the &#39;etimeclockwp_load_function_callback&#39; function. This allows unauthenticated attackers to execute code on the server. The invoked function&#39;s parameters cannot be specified.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can execute limited PHP functions on the server through the etimeclockwp_load_function_callback function, potentially exposing sensitive system information through phpinfo and other callable functions.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update Time Clock plugin to a version later than 1.2.2 or Time Clock Pro plugin to a version later than 1.1.4 to address the remote code execution vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">rce</span><span class="nt-tag">time-clock</span><span class="nt-tag">time-clock-pro</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/detail/time-clock-122-unauthenticated-limited-remote-code-execution" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-9593" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/RandomRobbieBF/CVE-2024-9593" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="timekeeper - default login high identify default logins in web-based control panels timekeeper contains default credentials. an attacker can obtain access to user accounts and access sensitive information, modify data, and/or execute unauthorized operations. theamanrawat default-login timekeeper vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">TimeKeeper - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/timekeeper/timekeeper-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">timekeeper-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> theamanrawat</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 17, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;2134367771&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">TimeKeeper contains default credentials. An attacker can obtain access to user accounts and access sensitive information, modify data, and/or execute unauthorized operations.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">timekeeper</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://fsmlabs.com" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="tiny file manager - default login high identify default logins in web-based control panels tiny file manager contains a default login vulnerability. an attacker can obtain access to user accounts and access sensitive information, modify data, and/or execute unauthorized operations. shelled default-login filemanager tiny vuln cwe-522" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Tiny File Manager - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/tiny-file-manager-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">tiny-file-manager-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> shelled</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/522.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-522</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;Tiny File Manager&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Tiny File Manager contains a default login vulnerability. An attacker can obtain access to user accounts and access sensitive information, modify data, and/or execute unauthorized operations.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">filemanager</span><span class="nt-tag">tiny</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/prasathmani/tinyfilemanager" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://tinyfilemanager.github.io/docs/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="tiny file manager panel - detect info identify web-based control panels tiny file manager panel was detected. dhiyaneshdk,huta0 panel filemanager login detect discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Tiny File Manager Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/tiny-file-manager.yaml" target="_blank" rel="noopener" class="nt-source-link">tiny-file-manager.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK,HuTa0</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Tiny File Manager&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Tiny File Manager panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">filemanager</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="tiny rss panel - detect info identify web-based control panels tiny tiny rss is a free rss feed reader userdehghani panel tiny-rss login detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Tiny RSS Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/tiny-rss-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">tiny-rss-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> userdehghani</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 14, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-418614327&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Tiny Tiny RSS is a free RSS feed reader</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">tiny-rss</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://tt-rss.org/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="titan ftp server 6.03 and 6.0.5.549 - heap overflow via long commands critical identify critical remote vulnerabilities titan ftp server versions 6.03 and 6.05 (builds) contain multiple heap-based buffer overflow vulnerabilities. remote attackers can cause denial of service (daemon crash) or potentially execute arbitrary code by sending excessively long user, pass, or other ftp commands that trigger heap overflows. cve-2008-0702 pussycat0x cve cve2008 ftp network passive tcp titan-ftp vuln cwe-119" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Titan FTP Server 6.03 and 6.0.5.549 - Heap Overflow via Long Commands</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/network/cves/2008/CVE-2008-0702.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2008-0702.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 2, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/119.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-119</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2008-0702" target="_blank" rel="noopener" class="nt-cve-link">CVE-2008-0702</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;protocol&#34;] contains &#34;ftp&#34; and service[&#34;service.transport&#34;] contains &#34;tcp&#34; and service[&#34;banner&#34;] matches `(?i)Titan\s+FTP\s+Server`</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Titan FTP Server versions 6.03 and 6.05 (builds) contain multiple heap-based buffer overflow vulnerabilities. Remote attackers can cause denial of service (daemon crash) or potentially execute arbitrary code by sending excessively long USER, PASS, or other FTP commands that trigger heap overflows.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can send excessively long USER, PASS, or other FTP commands to trigger heap overflows, causing denial of service by crashing the daemon or potentially executing arbitrary code on the server.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update Titan FTP Server to a version newer than 6.05 build 549 that properly validates command length and prevents heap overflow vulnerabilities in FTP command handlers.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2008</span><span class="nt-tag">ftp</span><span class="nt-tag">network</span><span class="nt-tag">passive</span><span class="nt-tag">tcp</span><span class="nt-tag">titan-ftp</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="http://securityreason.com/securityalert/3639" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="http://www.vupen.com/english/advisories/2008/0393" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.exploit-db.com/exploits/5036" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="titan ftp server 6.05 dele command - heap overflow critical identify critical remote vulnerabilities titan ftp server version 6.05 build 550 contains a heap overflow vulnerability when processing long dele commands. remote attackers can cause denial of service (daemon crash) or potentially execute arbitrary code by sending excessively long arguments to the dele command. cve-2008-5281 pussycat0x cve cve2008 ftp network passive tcp titan-ftp vuln cwe-119" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Titan FTP Server 6.05 DELE Command - Heap Overflow</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/network/cves/2008/CVE-2008-5281.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2008-5281.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 2, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/119.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-119</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2008-5281" target="_blank" rel="noopener" class="nt-cve-link">CVE-2008-5281</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;protocol&#34;] contains &#34;ftp&#34; and service[&#34;service.transport&#34;] contains &#34;tcp&#34; and service[&#34;banner&#34;] matches `(?i)Titan\s+FTP\s+Server`</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Titan FTP Server version 6.05 build 550 contains a heap overflow vulnerability when processing long DELE commands. Remote attackers can cause denial of service (daemon crash) or potentially execute arbitrary code by sending excessively long arguments to the DELE command.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can send long DELE commands to trigger heap overflow, causing denial of service by crashing the FTP daemon or potentially executing arbitrary code on the server.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update Titan FTP Server to a version newer than 6.05 build 550 that properly validates command length and prevents heap overflow vulnerabilities in the DELE command handler.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2008</span><span class="nt-tag">ftp</span><span class="nt-tag">network</span><span class="nt-tag">passive</span><span class="nt-tag">tcp</span><span class="nt-tag">titan-ftp</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="tixeo login panel - detect info identify web-based control panels tixeo login panel was detected. righettod panel tixeo login detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Tixeo Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/tixeo-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">tixeo-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 21, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)tixeo&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Tixeo login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">tixeo</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.tixeo.com/en/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="tomcat exposed - detect info identify web-based control panels an apache tomcat instance was detected. podalirius,righettod apache detect discovery panel tomcat" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Tomcat Exposed - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/tomcat/tomcat-exposed.yaml" target="_blank" rel="noopener" class="nt-source-link">tomcat-exposed.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Podalirius,righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 19, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)apache tomcat&#34;}) || service[&#34;http.body&#34;] matches &#34;(?i)apache tomcat&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An Apache Tomcat instance was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">apache</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">tomcat</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="tongda oa 11.7 - authentication bypass high identify critical remote vulnerabilities tongda oa is a collaborative office automation software independently developed by beijing tongda xinke technology co., ltd v11.7 has the interface query online user function, when the user is online, it will return phpsession so that it can log in to the background system. huta0 tongda auth-bypass fuzz vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Tongda OA 11.7 - Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/vulnerabilities/tongda/tongda-auth-bypass.yaml" target="_blank" rel="noopener" class="nt-source-link">tongda-auth-bypass.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> HuTa0</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 20, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)通达OA&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Tongda OA is a collaborative office automation software independently developed by Beijing Tongda Xinke Technology Co., LTD v11.7 has the interface query online user function, when the user is online, it will return PHPSESSION so that it can log in to the background system.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">tongda</span><span class="nt-tag">auth-bypass</span><span class="nt-tag">fuzz</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://s1xhcl.github.io/2021/03/13/%E9%80%9A%E8%BE%BEOA-v11-7-%E5%9C%A8%E7%BA%BF%E7%94%A8%E6%88%B7%E7%99%BB%E5%BD%95%E6%BC%8F%E6%B4%9E/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="tooljet - default login high identify default logins in web-based control panels tooljet contains a default login vulnerability. an attacker can obtain access to user accounts and access sensitive information, modify data, and/or execute unauthorized operations. random-robbie default-login tooljet vuln cwe-522" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">ToolJet - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/tooljet/tooljet-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">tooljet-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> random-robbie</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/522.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-522</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)tooljet&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">ToolJet contains a default login vulnerability. An attacker can obtain access to user accounts and access sensitive information, modify data, and/or execute unauthorized operations.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">tooljet</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://docs.tooljet.com/docs/contributing-guide/setup/docker/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="tooljet login panel - detect info identify web-based control panels tooljet login panel was detected. dhiyaneshdk discovery panel tooljet cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">ToolJet Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/tooljet-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">tooljet-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)ToolJet - Dashboard&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">ToolJet login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">tooljet</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="tools4ever self-service reset password manager - panel info identify web-based control panels detects tools4ever self-service reset password manager login panel. darses detect discovery panel tools4ever" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Tools4Ever Self-Service Reset Password Manager - Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/tools4ever-ssrpm-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">tools4ever-ssrpm-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> darses</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 20, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-948009664&#34; || service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-916902413&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detects Tools4Ever Self-Service Reset Password Manager login panel.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">tools4ever</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.tools4ever.com/ssrpm/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="topsec topapplb - authentication bypass high identify critical remote vulnerabilities topsec topapplb is vulnerable to authetication bypass .enter any account on the login page, the password is `;id`. sleepingbag945 topsec topapplb auth-bypass vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Topsec TopAppLB - Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/vulnerabilities/topsec/topsec-topapplb-auth-bypass.yaml" target="_blank" rel="noopener" class="nt-source-link">topsec-topapplb-auth-bypass.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> SleepingBag945</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 15, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)TopApp-LB 负载均衡系统&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Topsec TopAppLB is vulnerable to authetication bypass .Enter any account on the login page, the password is `;id`.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">topsec</span><span class="nt-tag">topapplb</span><span class="nt-tag">auth-bypass</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/cqr-cryeye-forks/goby-pocs/blob/main/Topsec-TopAppLB-Any-account-Login.json" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="toshiba topaccess - default-login high identify default logins in web-based control panels  ritikchaddha default-login misconfig topaccess vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Toshiba TopAccess - Default-Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/topaccess/topaccess-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">topaccess-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 24, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)topaccess&#34;})</code></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">misconfig</span><span class="nt-tag">topaccess</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://business.toshiba.com/downloads/KB/f1Ulds/11646/KH-1020_TAG_EN_0002.pdf" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="toshiba topaccess panel - detect info identify web-based control panels  ritikchaddha topaccess panel login detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Toshiba TopAccess Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/toshiba/topaccess-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">topaccess-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 23, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)topaccess&#34;})</code></div>
  <div class="nt-tags"><span class="nt-tag">topaccess</span><span class="nt-tag">panel</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://business.toshiba.com/downloads/KB/f1Ulds/11646/KH-1020_TAG_EN_0002.pdf" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="total donations plugin for wordpress &lt; 2.0.6 - arbitrary options update critical identify critical remote vulnerabilities incorrect access control in migla_ajax_functions.php in the calmar webmedia total donations plugin through 2.0.5 for wordpress allows unauthenticated attackers to update arbitrary wordpress option values, leading to site takeover. these attackers can send requests to wp-admin/admin-ajax.php to call the miglaa_update_me action to change arbitrary options on affected sites. this can be used to enable new user registration and set the default role for new users to administrator. cve-2019-6703 dhiyaneshdk cve cve2019 passive total-donations vkev vuln wordpress wp wp-plugin wpscan" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Total Donations Plugin for WordPress &lt; 2.0.6 - Arbitrary Options Update</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2019/CVE-2019-6703.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2019-6703.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 7, 2025</span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2019-6703" target="_blank" rel="noopener" class="nt-cve-link">CVE-2019-6703</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/total-donations/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Incorrect access control in migla_ajax_functions.php in the Calmar Webmedia Total Donations plugin through 2.0.5 for WordPress allows unauthenticated attackers to update arbitrary WordPress option values, leading to site takeover. These attackers can send requests to wp-admin/admin-ajax.php to call the miglaA_update_me action to change arbitrary options on affected sites. This can be used to enable new user registration and set the default role for new users to Administrator.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can modify site options, enabling new user registration as Administrator, leading to site takeover.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest version of the plugin where this issue is fixed.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2019</span><span class="nt-tag">passive</span><span class="nt-tag">total-donations</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">wpscan</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wpscan.com/vulnerability/6e6342b0-82ca-4f5f-8b59-92ec3bdf1d02/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2019-6703" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="totemomail login panel - detect info identify web-based control panels totemomail login panel was detected. johnk3r,daffainfo totemomail panel totemo discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Totemomail Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/totemomail-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">totemomail-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> johnk3r,daffainfo</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)totemomail&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Totemomail login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">totemomail</span><span class="nt-tag">panel</span><span class="nt-tag">totemo</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.totemo.com/en/products/email-encryption" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="traccar panel - detect info identify web-based control panels traccar panel was discovered. s4e-io detect discovery login panel traccar" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Traccar Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/traccar-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">traccar-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> s4e-io</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 12, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Traccar&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Traccar panel was discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">login</span><span class="nt-tag">panel</span><span class="nt-tag">traccar</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="traccar(windows) 6.1- 6.8.1 - local file inclusion high identify critical remote vulnerabilities traccar 5.8-6.0 (non-default installs with web.override set) and 6.1-6.8.1 (default installs) contain a local file inclusion vulnerability caused by enabled web override configuration, letting unauthenticated attackers leak arbitrary files including passwords, exploit requires local access. cve-2025-61666 securitytaters cve cve2025 lfi traccar vkev vuln cwe-22" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Traccar(Windows) 6.1- 6.8.1 - Local File Inclusion</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-61666.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-61666.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> securitytaters</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 7, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-61666" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-61666</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Traccar&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Traccar 5.8-6.0 (non-default installs with web.override set) and 6.1-6.8.1 (default installs) contain a local file inclusion vulnerability caused by enabled web override configuration, letting unauthenticated attackers leak arbitrary files including passwords, exploit requires local access.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated local attackers can read arbitrary files, potentially exposing sensitive information like passwords and configuration data.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to version 6.9.0 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">lfi</span><span class="nt-tag">traccar</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/traccar/traccar/security/advisories/GHSA-hprc-rph8-fj87" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://projectblack.io/blog/jetty-addpath-lfi/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="traefik dashboard panel - detect info identify web-based control panels traefik dashboard panel was detected. schniggie,streetofhackerr007 panel traefik discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Traefik Dashboard Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/traefik-dashboard.yaml" target="_blank" rel="noopener" class="nt-source-link">traefik-dashboard.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> schniggie,StreetOfHackerR007</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)traefik&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Traefik Dashboard panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">traefik</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="traggo server - local file inclusion high identify critical remote vulnerabilities traggo/server version 0.3.0 is vulnerable to directory traversal. cve-2023-34843 dhiyaneshdk cve cve2023 lfi server traggo vuln cwe-22" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Traggo Server - Local File Inclusion</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-34843.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-34843.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 28, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-34843" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-34843</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)traggo&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">traggo/server version 0.3.0 is vulnerable to directory traversal.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability can lead to unauthorized access to sensitive files, remote code execution, and potential compromise of the server.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to the latest version to mitigate this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">lfi</span><span class="nt-tag">server</span><span class="nt-tag">traggo</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/rootd4ddy/CVE-2023-34843" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/0x783kb/Security-operation-book" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/Imahian/CVE-2023-34843" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/hheeyywweellccoommee/CVE-2023-34843-illrj" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/nomi-sec/PoC-in-GitHub" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="trassir webview default login - detect high identify default logins in web-based control panels trassir webview contains a default login vulnerability. an attacker can obtain access to user accounts and access sensitive information, modify data, and/or execute unauthorized operations. gtrrnr,metascan default-login trassir vuln webview cwe-522" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Trassir WebView Default Login - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/trassir/trassir-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">trassir-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> gtrrnr,metascan</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/522.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-522</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;Trassir Webview&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Trassir WebView contains a default login vulnerability. An attacker can obtain access to user accounts and access sensitive information, modify data, and/or execute unauthorized operations.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">trassir</span><span class="nt-tag">vuln</span><span class="nt-tag">webview</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://confluence.trassir.com/display/TKB/How+to+reset+the+administrator+password+on+the+TRASSIR+NVR" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="trend micro apex one login panel - detect info identify web-based control panels trend micro apex one login panel was detected. johnk3r,s4e-io detect discovery login panel trendmicro cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Trend Micro Apex One Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/trendmicro-apexone-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">trendmicro-apexone-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> johnk3r,s4e-io</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 23, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)officescan&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Trend Micro Apex One login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">login</span><span class="nt-tag">panel</span><span class="nt-tag">trendmicro</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="trilium &lt;0.52.4 - cross-site scripting medium identify critical remote vulnerabilities trilium prior to 0.52.4, 0.53.1-beta contains a cross-site scripting vulnerability which can allow an attacker to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. cve-2022-2290 dbrwsky cve cve2022 huntr trilium trilium_project vkev vuln xss cwe-79" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Trilium &lt;0.52.4 - Cross-Site Scripting</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-2290.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-2290.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dbrwsky</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-79</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-2290" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-2290</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Trilium Notes&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Trilium prior to 0.52.4, 0.53.1-beta contains a cross-site scripting vulnerability which can allow an attacker to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute malicious scripts in the context of the victim&#39;s browser, leading to potential data theft, session hijacking, or defacement of the affected Trilium instance.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade Trilium to version 0.52.4 or later, which includes proper input sanitization to mitigate the XSS vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">huntr</span><span class="nt-tag">trilium</span><span class="nt-tag">trilium_project</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">xss</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://huntr.dev/bounties/367c5c8d-ad6f-46be-8503-06648ecf09cf/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/zadam/trilium" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/zadam/trilium/commit/3faae63b849a1fabc31b823bb7af3a84d32256a7" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-2290" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/ARPSyndicate/cvemon" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="trinity audio &lt;= 5.21.0 - information exposure medium identify critical remote vulnerabilities the trinity audio text to speech ai audio player to convert content into audio plugin for wordpress is vulnerable to sensitive information exposure in all versions up to, and including, 5.21.0 via the ~/admin/inc/phpinfo.php file that gets created on install. this makes it possible for unauthenticated attackers to extract sensitive data including configuration data. cve-2025-9196 kazgangap cve cve2025 exposure trinity-audio vuln wordpress wp-plugin cwe-200" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Trinity Audio &lt;= 5.21.0 - Information Exposure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-9196.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-9196.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Kazgangap</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 14, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-9196" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-9196</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/trinity-audio&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The Trinity Audio Text to Speech AI audio player to convert content into audio plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.21.0 via the ~/admin/inc/phpinfo.php file that gets created on install. This makes it possible for unauthenticated attackers to extract sensitive data including configuration data.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can extract sensitive configuration data, potentially aiding further attacks.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest version beyond 5.21.0.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">exposure</span><span class="nt-tag">trinity-audio</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp-plugin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/trinity-audio/trinity-audio-5210-unauthenticated-information-exposure" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-9196" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="triofox - improper access control critical identify critical remote vulnerabilities the gladinet triofox solution before 12.91.1126.65588 and centrestack before 12.10.595.65696 allow unauthenticated access to the /management/admindatabase.aspx endpoint, exposing sensitive database management functionality to anyone with network access. an unauthenticated attacker can remotely access, view, and potentially interact with the database management interface, risking data disclosure or system compromise. cve-2025-12480 johnk3r,gti cve cve2025 exposure kev triofox unauth vkev cwe-306" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Triofox - Improper Access Control</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-12480.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-12480.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> johnk3r,gti</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 11, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/306.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-306</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-12480" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-12480</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-177043778&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The Gladinet Triofox solution before 12.91.1126.65588 and CentreStack before 12.10.595.65696 allow unauthenticated access to the /management/admindatabase.aspx endpoint, exposing sensitive database management functionality to anyone with network access. An unauthenticated attacker can remotely access, view, and potentially interact with the database management interface, risking data disclosure or system compromise.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers may gain access to sensitive administrative functions of the Triofox database, resulting in unauthorized data access, modification, or potential system compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to Triofox 12.91.1126.65588 or CentreStack 12.10.595.65696 and later to resolve this vulnerability and restrict unauthenticated access to the administrative database panel.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">exposure</span><span class="nt-tag">kev</span><span class="nt-tag">triofox</span><span class="nt-tag">unauth</span><span class="nt-tag">vkev</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://cloud.google.com/blog/topics/threat-intelligence/triofox-vulnerability-cve-2025-12480" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://attackerkb.com/topics/5C4wRy6hY7/cve-2025-12480/rapid7-analysis" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-12480" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="truenas panel - detect info identify web-based control panels truenas scale is a free and open-source nas solution rxerium discovery ixsystems login panel truenas" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">TrueNAS Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/truenas-scale-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">truenas-scale-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 27, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)truenas&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">TrueNAS scale is a free and open-source NAS solution</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">ixsystems</span><span class="nt-tag">login</span><span class="nt-tag">panel</span><span class="nt-tag">truenas</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.truenas.com" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="tufin securetrack login panel - detect info identify web-based control panels tufin securetrack login panel was detected. idealphase discovery panel tufin cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Tufin SecureTrack Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/tufin-securetrack-login.yaml" target="_blank" rel="noopener" class="nt-source-link">tufin-securetrack-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> idealphase</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)securetrack - tufin technologies&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Tufin SecureTrack login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">tufin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.tufin.com/tufin-orchestration-suite/securetrack" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="turbomeeting - boolean-based sql injection critical identify critical remote vulnerabilities a boolean-based sql injection vulnerability in the &#34;rhub turbomeeting&#34; web application. this vulnerability could allow an attacker to execute arbitrary sql commands on the database server, potentially allowing them to access sensitive data or compromise the server. cve-2024-38289 rootxharsh,iamnoooob,pdresearch cve cve2024 sqli turbomeeting vkev vuln cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">TurboMeeting - Boolean-based SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-38289.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-38289.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rootxharsh,iamnoooob,pdresearch</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 25, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-38289" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-38289</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)TurboMeeting&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A Boolean-based SQL injection vulnerability in the &#34;RHUB TurboMeeting&#34; web application. This vulnerability could allow an attacker to execute arbitrary SQL commands on the database server, potentially allowing them to access sensitive data or compromise the server.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can execute arbitrary SQL commands to extract sensitive data including user credentials, meeting information, and potentially compromise the entire TurboMeeting database.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to the latest patched version of RHUB TurboMeeting or apply vendor-provided security updates.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">sqli</span><span class="nt-tag">turbomeeting</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/google/security-research/security/advisories/GHSA-vx5j-8pgx-v42v" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="turnkey lamp panel - detect info identify web-based control panels turnkey lamp control panel was detected. ritikchaddha panel login turnkey lamp detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">TurnKey LAMP Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/turnkey-lamp-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">turnkey-lamp-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 16, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)TurnKey LAMP&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">TurnKey LAMP Control Panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">login</span><span class="nt-tag">turnkey</span><span class="nt-tag">lamp</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.turnkeylinux.org/lamp" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="turnkey openvpn panel - detect info identify web-based control panels turnkey openvpn panel was detected. ritikchaddha panel openvpn turnkey webshell vpn discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">TurnKey OpenVPN Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/turnkey-openvpn.yaml" target="_blank" rel="noopener" class="nt-source-link">turnkey-openvpn.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)TurnKey OpenVPN&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">TurnKey OpenVPN panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">openvpn</span><span class="nt-tag">turnkey</span><span class="nt-tag">webshell</span><span class="nt-tag">vpn</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="tutor lms &lt;= 2.1.10 - sql injection high identify critical remote vulnerabilities tutor lms – elearning and online course solution plugin for wordpress [all versions up to 2.6.1] contains a time-based sql injection caused by insufficient escaping on the question_id parameter in sql queries, letting authenticated attackers with subscriber or higher access extract sensitive information, exploit requires attacker to be authenticated with subscriber or higher privileges. cve-2024-1751 shivam kamboj cve cve2024 sqli tutor unauth wordpress wp wp-plugin cwe-89" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Tutor LMS &lt;= 2.1.10 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-1751.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-1751.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Shivam Kamboj</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 5, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-1751" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-1751</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/plugins/tutor/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Tutor LMS – eLearning and online course solution plugin for WordPress [all versions up to 2.6.1] contains a time-based SQL Injection caused by insufficient escaping on the question_id parameter in SQL queries, letting authenticated attackers with subscriber or higher access extract sensitive information, exploit requires attacker to be authenticated with subscriber or higher privileges.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Authenticated attackers can extract sensitive database information through SQL injection, potentially leading to data breach or further exploitation.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to version 2.6.2 or later to fix the vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">sqli</span><span class="nt-tag">tutor</span><span class="nt-tag">unauth</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/tutor/tutor-lms-2110-unauthenticated-sql-injection" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://plugins.trac.wordpress.org/changeset?old=2919134%40tutor&amp;new=2919134%40tutor" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-1751" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="tutor lms &lt;= 2.7.6 - sql injection high identify critical remote vulnerabilities the tutor lms plugin for wordpress is vulnerable to sql injection via the ‘rating_filter’ parameter in all versions up to, and including, 2.7.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing sql query. this makes it possible for unauthenticated attackers to append additional sql queries into already existing queries that can be used to extract sensitive information from the database. cve-2024-10400 iamnoooob,rootxharsh,pdresearch cve cve2024 lms sqli tutor-lms vkev vuln cwe-89" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Tutor LMS &lt;= 2.7.6 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-10400.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-10400.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> iamnoooob,rootxharsh,pdresearch</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 18, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-10400" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-10400</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/tutor/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The Tutor LMS plugin for WordPress is vulnerable to SQL Injection via the ‘rating_filter’ parameter in all versions up to, and including, 2.7.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can execute arbitrary SQL queries via the rating_filter parameter, potentially extracting sensitive database information including user credentials and course data.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update Tutor LMS plugin to version 2.7.7 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">lms</span><span class="nt-tag">sqli</span><span class="nt-tag">tutor-lms</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/tutor/tutor-lms-276-unauthenticated-sql-injection-via-rating-filter" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-10400" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="typebot panel - detect info identify web-based control panels typebot is an open-source chatbot builder that allows you to create advanced
chatbots visually. rxerium ai chatbot detect discovery panel typebot" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Typebot Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/typebot-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">typebot-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 27, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;Typebot&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Typebot is an open-source chatbot builder that allows you to create advanced
chatbots visually.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">ai</span><span class="nt-tag">chatbot</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">typebot</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/baptisteArno/typebot.io" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://typebot.io" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="typo3 directory listing low identify critical remote vulnerabilities detects directory listing enabled on the typo3 temp directory. the typo3temp folder contains cached files, compiled assets, and temporary data that may reveal sensitive information about the application structure and configuration. theamanrawat typo3 directory-listing exposure" data-nt-sev="low">
  <div class="nt-card-header">
    <div class="nt-title">Typo3 Directory Listing</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/misconfiguration/typo3-directory-listing.yaml" target="_blank" rel="noopener" class="nt-source-link">typo3-directory-listing.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> theamanrawat</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 21, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;product&#34;] contains &#34;TYPO3:TYPO3&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detects directory listing enabled on the TYPO3 temp directory. The typo3temp folder contains cached files, compiled assets, and temporary data that may reveal sensitive information about the application structure and configuration.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">typo3</span><span class="nt-tag">directory-listing</span><span class="nt-tag">exposure</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://docs.typo3.org/m/typo3/reference-coreapi/main/en-us/ExtensionArchitecture/FileStructure/Index.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="ufida nc - arbitrary file read high identify critical remote vulnerabilities ufida nc is vulnerable to an arbitrary file read vulnerability in the nc.uap.lfw.file.action.docservlet component. an unauthenticated remote attacker can exploit this flaw to read sensitive files on the server by sending crafted requests. vva lfi ufida yonyou cwe-22" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">UFIDA NC - Arbitrary File Read</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/vulnerabilities/yonyou/yonyou-nc-lfi.yaml" target="_blank" rel="noopener" class="nt-source-link">yonyou-nc-lfi.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> vva</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 22, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)用友\&#34; \&#34;NC&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">UFIDA NC is vulnerable to an arbitrary file read vulnerability in the nc.uap.lfw.file.action.DocServlet component. An unauthenticated remote attacker can exploit this flaw to read sensitive files on the server by sending crafted requests.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation allows attackers to access sensitive files and information stored on the server.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">lfi</span><span class="nt-tag">ufida</span><span class="nt-tag">yonyou</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/szjr123/Target-practice/blob/05ed667090d8040a09235826f7698ff5347a93cf/%E7%94%A8%E5%8F%8BOA/NC%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96_DocServlet/yongyou_read.py" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="ufida u8 crm cfillbacksetting.php - sql injection high identify critical remote vulnerabilities ufida u8-crm system /config/fillbacksetting.php contains an sql injection vulnerability, which allows attackers to manipulate the database through maliciously constructed sql statements, resulting in data leaks, tampering or destruction, and seriously threatening system security. s4e-io sqli u8-crm vuln yonyou cwe-89" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">UFIDA U8 CRM cfillbacksetting.php - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/vulnerabilities/yonyou/yonyou-u8-crm-sqli.yaml" target="_blank" rel="noopener" class="nt-source-link">yonyou-u8-crm-sqli.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> s4e-io</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 8, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)用友U8CRM&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">UFIDA U8-CRM system /config/fillbacksetting.php contains an SQL injection vulnerability, which allows attackers to manipulate the database through maliciously constructed SQL statements, resulting in data leaks, tampering or destruction, and seriously threatening system security.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">sqli</span><span class="nt-tag">u8-crm</span><span class="nt-tag">vuln</span><span class="nt-tag">yonyou</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/wy876/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BU8-CRM%E7%B3%BB%E7%BB%9Ffillbacksetting.php%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="ufida u8 crm fillbacksetting.php - sql injection high identify critical remote vulnerabilities ufida u8-crm system /config/fillbacksetting.php contains an sql injection vulnerability, which allows attackers to manipulate the database through maliciously constructed sql statements, resulting in data leaks, tampering or destruction, and seriously threatening system security. s4e-io sqli u8-crm vuln yonyou cwe-89" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">UFIDA U8 CRM fillbacksetting.php - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/vulnerabilities/yonyou/yonyou-u8-crm-tb-sqli.yaml" target="_blank" rel="noopener" class="nt-source-link">yonyou-u8-crm-tb-sqli.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> s4e-io</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 8, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)用友U8CRM&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">UFIDA U8-CRM system /config/fillbacksetting.php contains an SQL injection vulnerability, which allows attackers to manipulate the database through maliciously constructed SQL statements, resulting in data leaks, tampering or destruction, and seriously threatening system security.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">sqli</span><span class="nt-tag">u8-crm</span><span class="nt-tag">vuln</span><span class="nt-tag">yonyou</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/wy876/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BU8-CRM%E7%B3%BB%E7%BB%9Ffillbacksetting.php%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="uisp fiber panel - detect info identify web-based control panels uisp fiber login interface was discovered. th3l0newolf discovery fiber login panel uisp cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">UISP Fiber Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/uisp-fiber-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">uisp-fiber-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Th3l0newolf</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 27, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches `^UISP\s*Fiber\s*-\s*Login`})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">UISP Fiber login interface was discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">fiber</span><span class="nt-tag">login</span><span class="nt-tag">panel</span><span class="nt-tag">uisp</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="una cms &lt;= 14.0.0-rc4 - php object injection critical identify critical remote vulnerabilities the vulnerability is located in the /template/scripts/bxbasemenusetacllevel.php script. specifically, within the bxbasemenusetacllevel::getcode() method. when calling this method, user input passed through the &#34;profile_id&#34; post parameter is not properly sanitized before being used in a call to the unserialize() php function. this can be exploited by remote, unauthenticated attackers to inject arbitrary php objects into the application scope, allowing them to perform a variety of attacks, such as writing and executing arbitrary php code. cve-2025-32101 iamnoooob,rootxharsh,pdresearch cve cve2025 una-cms php rce vuln" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">UNA CMS &lt;= 14.0.0-RC4 - PHP Object Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-32101.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-32101.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> iamnoooob,rootxharsh,pdresearch</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 9, 2025</span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-32101" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-32101</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Powered by UNA&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The vulnerability is located in the /template/scripts/BxBaseMenuSetAclLevel.php script. Specifically, within the BxBaseMenuSetAclLevel::getCode() method. When calling this method, user input passed through the &#34;profile_id&#34; POST parameter is not properly sanitized before being used in a call to the unserialize() PHP function. This can be exploited by remote, unauthenticated attackers to inject arbitrary PHP objects into the application scope, allowing them to perform a variety of attacks, such as writing and executing arbitrary PHP code.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can inject arbitrary PHP objects through the profile_id parameter, allowing remote code execution and complete server compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to UNA CMS version 14.0.0 or later that properly validates and sanitizes serialized input.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">una-cms</span><span class="nt-tag">php</span><span class="nt-tag">rce</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.exploit-db.com/exploits/52139" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://karmainsecurity.com/KIS-2025-01" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="ups adapter cs141 snmp module default login medium identify default logins in web-based control panels ups adapter cs141 snmp module default login credentials were discovered. socketz default-login hiawatha iot vuln cwe-798" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">UPS Adapter CS141 SNMP Module Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/abb/cs141-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">cs141-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> socketz</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/798.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-798</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;CS141&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">UPS Adapter CS141 SNMP Module default login credentials were discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">hiawatha</span><span class="nt-tag">iot</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.generex.de/media/pages/packages/documents/manuals/f65348d5b6-1628841637/manual_CS141_en.pdf" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="ubigeo de peru &lt; 3.6.4 - sql injection critical identify critical remote vulnerabilities the plugin does not properly sanitise and escape some parameters before using them in sql statements via various ajax actions, some of which are available to unauthenticated users, leading to sql injections. cve-2022-0814 r3y3r53 cve cve2022 sqli ubigeo-peru ubigeo_de_peru_para_woocommerce_project unauth vuln wordpress wp-plugin wpscan cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Ubigeo de Peru &lt; 3.6.4 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-0814.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-0814.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> r3Y3r53</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 17, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-0814" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-0814</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/ubigeo-peru/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The plugin does not properly sanitise and escape some parameters before using them in SQL statements via various AJAX actions, some of which are available to unauthenticated users, leading to SQL Injections.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can exploit SQL injection via AJAX actions to extract usernames and password hashes from the WordPress database.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Fixed in version 3.6.4</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">sqli</span><span class="nt-tag">ubigeo-peru</span><span class="nt-tag">ubigeo_de_peru_para_woocommerce_project</span><span class="nt-tag">unauth</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">wpscan</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wpscan.com/vulnerability/fd84dc08-0079-4fcf-81c3-a61d652e3269" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0814" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://wordpress.org/plugins/ubigeo-peru/" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/cyllective/CVEs" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="uipath orchestrator login panel - detect info identify web-based control panels uipath orchestrator login panel was detected. righettod panel uipath login detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">UiPath Orchestrator Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/uipath-orchestrator-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">uipath-orchestrator-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 21, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)UiPath Orchestrator&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">UiPath Orchestrator login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">uipath</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.uipath.com/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="umami panel - detect info identify web-based control panels simple, fast, privacy-focused, open-source analytics solution. userdehghani panel umami login detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Umami Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/umami-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">umami-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> userdehghani</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 7, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-130447705&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">simple, fast, privacy-focused, open-source analytics solution.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">umami</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://umami.is/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://umami.is/docs" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="umbraco cms - directory listing exposure medium identify critical remote vulnerabilities detected directory listing enabled on sensitive umbraco cms directories, potentially exposing configuration files, logs, backups, and other sensitive data. dhiyaneshdk umbraco misconfig exposure cms vuln cwe-548" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Umbraco CMS - Directory Listing Exposure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/misconfiguration/umbraco-directory-listing.yaml" target="_blank" rel="noopener" class="nt-source-link">umbraco-directory-listing.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 19, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/548.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-548</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Umbraco&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detected directory listing enabled on sensitive Umbraco CMS directories, potentially exposing configuration files, logs, backups, and other sensitive data.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">umbraco</span><span class="nt-tag">misconfig</span><span class="nt-tag">exposure</span><span class="nt-tag">cms</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://docs.umbraco.com/umbraco-cms/reference/security/security-hardening" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="umbraco login panel - detect info identify web-based control panels umbraco login panel was detected. ola456,stvnhrlnd detect discovery panel umbraco cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Umbraco Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/umbraco-login.yaml" target="_blank" rel="noopener" class="nt-source-link">umbraco-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ola456,stvnhrlnd</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)umbraco&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Umbraco login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">umbraco</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://our.umbraco.com/documentation/Fundamentals/Backoffice/Login/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="umbraco mini profiler - exposure low identify critical remote vulnerabilities detected the exposure of the miniprofiler debugging interface in umbraco cms. when exposed, it can reveal sensitive information including sql queries, execution times, stack traces, and internal application details. theamanrawat umbraco miniprofiler exposure debug misconfig" data-nt-sev="low">
  <div class="nt-card-header">
    <div class="nt-title">Umbraco Mini Profiler - Exposure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/misconfiguration/umbraco-miniprofiler-exposure.yaml" target="_blank" rel="noopener" class="nt-source-link">umbraco-miniprofiler-exposure.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> theamanrawat</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 20, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Umbraco&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detected the exposure of the MiniProfiler debugging interface in Umbraco CMS. When exposed, it can reveal sensitive information including SQL queries, execution times, stack traces, and internal application details.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">umbraco</span><span class="nt-tag">miniprofiler</span><span class="nt-tag">exposure</span><span class="nt-tag">debug</span><span class="nt-tag">misconfig</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://miniprofiler.com/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://umbraco.com/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="unraid &lt;=6.80 - remote code execution critical identify critical remote vulnerabilities unraid &lt;=6.80 allows remote unauthenticated attackers to execute arbitrary code. cve-2020-5847 madrobot cve cve2020 kev rce unraid vkev vuln cwe-668,cwe-94" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">UnRaid &lt;=6.80 - Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2020/CVE-2020-5847.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2020-5847.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> madrobot</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/668,CWE-94.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-668,CWE-94</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2020-5847" target="_blank" rel="noopener" class="nt-cve-link">CVE-2020-5847</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.head.setCookie&#34;] matches `^unraid_` || service[&#34;last.http.head.setCookie&#34;] matches `^unraid_`</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">UnRaid &lt;=6.80 allows remote unauthenticated attackers to execute arbitrary code.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can execute arbitrary code on UnRaid servers, leading to complete system compromise and access to all stored data.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade UnRaid to a version higher than 6.80 to mitigate the vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2020</span><span class="nt-tag">kev</span><span class="nt-tag">rce</span><span class="nt-tag">unraid</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://sysdream.com/news/lab/2020-02-06-cve-2020-5847-cve-2020-5849-unraid-6-8-0-unauthenticated-remote-code-execution-as-root/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-5847" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://sysdream.com/news/lab/" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://forums.unraid.net/forum/7-announcements/" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/Ostorlab/KEV" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="unauthenticated remote code execution – bricks &lt;= 1.9.6 critical identify critical remote vulnerabilities bricks builder is a popular wordpress development theme with approximately 25,000 active installations. it provides an intuitive drag-and-drop interface for designing and building wordpress websites. bricks &lt;= 1.9.6 is vulnerable to unauthenticated remote code execution (rce) which means that anybody can run arbitrary commands and take over the site/server. this can lead to various malicious activities cve-2024-25600 christbowel bricks cve cve2024 rce vkev vuln wordpress wp wp-plugin wpscan cwe-94" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Unauthenticated Remote Code Execution – Bricks &lt;= 1.9.6</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-25600.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-25600.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> christbowel</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 21, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/94.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-94</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-25600" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-25600</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/themes/bricks/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Bricks Builder is a popular WordPress development theme with approximately 25,000 active installations. It provides an intuitive drag-and-drop interface for designing and building WordPress websites. Bricks &lt;= 1.9.6 is vulnerable to unauthenticated remote code execution (RCE) which means that anybody can run arbitrary commands and take over the site/server. This can lead to various malicious activities</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can execute arbitrary code through the Bricks Builder theme, leading to complete site takeover and potential server compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update Bricks Builder theme to version 1.9.7 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">bricks</span><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">rce</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">wpscan</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-25600" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://wpscan.com/vulnerability/afea4f8c-4d45-4cc0-8eb7-6fa6748158bd/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://snicco.io/vulnerability-disclosure/bricks/unauthenticated-rce-in-bricks-1-9-6" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/Chocapikk/CVE-2024-25600" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://op-c.net/blog/cve-2024-25600-wordpresss-bricks-builder-rce-flaw-under-active-exploitation" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="unifi - nfc credentials high identify critical remote vulnerabilities an unauthenticated get to /api/v1/user_assets/touch_pass/keys returns json containing live credential material (pem private key, apple nfc/express key values, terminal type, ttl, google_pass_auth_key block, version identifiers) over a publicly reachable port — allowing theft and immediate misuse of mobile/nfc access credentials. dhiyaneshdk unifi unauth vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">UniFi - NFC Credentials</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/vulnerabilities/unifi/unifi-nfc-credentials.yaml" target="_blank" rel="noopener" class="nt-source-link">unifi-nfc-credentials.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 5, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)UniFi Dream Machine SE&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An unauthenticated GET to /api/v1/user_assets/touch_pass/keys returns JSON containing live credential material (PEM private key, Apple NFC/express key values, terminal type, TTL, google_pass_auth_key block, version identifiers) over a publicly reachable port — allowing theft and immediate misuse of mobile/NFC access credentials.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">unifi</span><span class="nt-tag">unauth</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.catchify.sa/post/cve-2025-52665-rce-in-unifi-os-25-000" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="unifi network login panel - detect info identify web-based control panels unifi network login panel was detected. techbrunchfr discovery panel ubnt unifi cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">UniFi Network Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/unifi-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">unifi-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> TechbrunchFR</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)UniFi Network&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">UniFi Network login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">ubnt</span><span class="nt-tag">unifi</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="unifi os - panel info identify web-based control panels unifi os panel was discovered dhiyaneshdk panel router discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">UniFi OS - Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/unifi-os-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">unifi-os-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 6, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)UniFi OS&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">UniFi OS Panel was discovered</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">router</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://gbhackers.com/critical-unifi-os-flaw/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="unibox panel - detect info identify web-based control panels unibox administrator panel was detected. theamanrawat panel unibox login discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Unibox Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/unibox-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">unibox-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> theamanrawat</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 17, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;176427349&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Unibox Administrator panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">unibox</span><span class="nt-tag">login</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="unitronics plc - login panel info identify web-based control panels unitronics plc web interface panel has been detected. rxerium discovery ics panel plc unitronics" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Unitronics PLC - Login Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/unitronics-plc-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">unitronics-plc-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 27, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;^Unitronics&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Unitronics PLC web interface panel has been detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">ics</span><span class="nt-tag">panel</span><span class="nt-tag">plc</span><span class="nt-tag">unitronics</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.unitronicsplc.com/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="unity plastic scm login panel - detect info identify web-based control panels unity plastic scm login panel was detected. dhiyaneshdk panel plastic discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Unity Plastic SCM Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/plastic-scm-login.yaml" target="_blank" rel="noopener" class="nt-source-link">plastic-scm-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Plastic SCM&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Unity Plastic SCM login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">plastic</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="universal media server v13.2.1 - cross site scripting medium identify critical remote vulnerabilities universal media server v13.2.1 cms v2.0 was discovered to contain a reflected cross-site scripting (xss) vulnerability. r3y3r53 xss universal media unauth packetstorm vuln" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Universal Media Server v13.2.1 - Cross Site Scripting</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/vulnerabilities/other/universal-media-xss.yaml" target="_blank" rel="noopener" class="nt-source-link">universal-media-xss.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> r3Y3r53</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 7, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-902890504&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Universal Media Server v13.2.1 CMS v2.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Fixed in version 13.2.2</div></div></div>
  <div class="nt-tags"><span class="nt-tag">xss</span><span class="nt-tag">universal</span><span class="nt-tag">media</span><span class="nt-tag">unauth</span><span class="nt-tag">packetstorm</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://packetstormsecurity.com/files/171754/Universal-Media-Server-13.2.1-Cross-Site-Scripting.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="unleash panel - detect info identify web-based control panels open-source feature management solution built for developers. userdehghani panel unleash login detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Unleash Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/unleash-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">unleash-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> userdehghani</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 12, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-608690655&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Open-source feature management solution built for developers.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">unleash</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.getunleash.io/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="unraid authentication bypass vulnerability high identify critical remote vulnerabilities unraid 6.8.0 allows authentication bypass. cve-2020-5849 n3integration cve cve2020 kev vuln authbypass cwe-697" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Unraid Authentication Bypass Vulnerability</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2020/CVE-2020-5849.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2020-5849.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> n3integration</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 17, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/697.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-697</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2020-5849" target="_blank" rel="noopener" class="nt-cve-link">CVE-2020-5849</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;product&#34;] contains &#34;Unraid:Unraid&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Unraid 6.8.0 allows authentication bypass.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply updates per vendor instructions.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2020</span><span class="nt-tag">kev</span><span class="nt-tag">vuln</span><span class="nt-tag">authbypass</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-5849" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.cve.org/CVERecord?id=CVE-2020-5849" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="untangle administrator login panel - detect info identify web-based control panels untangle administrator is a centralized web-based management console that allows administrators to efficiently configure, monitor, and control various network security and filtering features provided by the untangle ng firewall, ensuring robust network protection and policy enforcement. irshad ahamed admin discovery login panel untangle cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Untangle Administrator Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/untangle-admin-login.yaml" target="_blank" rel="noopener" class="nt-source-link">untangle-admin-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> irshad ahamed</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 3, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)untangle administrator login&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Untangle Administrator is a centralized web-based management console that allows administrators to efficiently configure, monitor, and control various network security and filtering features provided by the Untangle NG Firewall, ensuring robust network protection and policy enforcement.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">admin</span><span class="nt-tag">discovery</span><span class="nt-tag">login</span><span class="nt-tag">panel</span><span class="nt-tag">untangle</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://edge.arista.com/ng-firewall/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="uptime kuma - panel info identify web-based control panels realtime website and application monitoring tool irshad ahamed uptime kuma panel login detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Uptime Kuma - Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/uptime-kuma-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">uptime-kuma-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> irshad ahamed</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 1, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Uptime Kuma&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Realtime website and application monitoring tool</div></div></div>
  <div class="nt-tags"><span class="nt-tag">uptime</span><span class="nt-tag">kuma</span><span class="nt-tag">panel</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/louislam/uptime-kuma" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/louislam/uptime-kuma/wiki" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="urbackup panel - detect info identify web-based control panels  dhiyaneshdk urbackup panel login detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">UrBackup Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/urbackup-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">urbackup-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 17, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)UrBackup - Keeps your data safe&#34;</code></div>
  <div class="nt-tags"><span class="nt-tag">urbackup</span><span class="nt-tag">panel</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="user control panel - detect info identify web-based control panels user control panel was detected. dhiyaneshdk panel ucp discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">User Control Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/user-control-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">user-control-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)User Control Panel&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">User Control Panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">ucp</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="user management/registration &amp; login v3.0 - sql injection high identify critical remote vulnerabilities user registration &amp; login and user management system v3.0 admin panel has sql vulnerability. even though the person who discovered the vulnerability tested it in version 3.0, version 3.2 also contains the same vulnerability. it can be exploited by entering &#34;admin&#39; -- -&#34; as the username parameter in the admin panel. f0xy auth-bypass sqli user-management vuln cwe-89" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">User Management/Registration &amp; Login v3.0 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/vulnerabilities/other/user-management-system-sqli.yaml" target="_blank" rel="noopener" class="nt-source-link">user-management-system-sqli.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> f0xy</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 15, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Registration and Login System&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">User Registration &amp; Login and User Management System v3.0 admin panel has SQL vulnerability. Even though the person who discovered the vulnerability tested it in version 3.0, version 3.2 also contains the same vulnerability. It can be exploited by entering &#34;admin&#39; -- -&#34; as the username parameter in the admin panel.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">sqli</span><span class="nt-tag">user-management</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.exploit-db.com/exploits/51695" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://phpgurukul.com/user-registration-login-and-user-management-system-with-admin-panel/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="user meta wp plugin &lt; 3.1 - sensitive information exposure medium identify critical remote vulnerabilities the user meta is vulnerable to sensitive information exposure in all versions up to, and including, 3.0 via the /views/debug.php file. this makes it possible for unauthenticated attackers, with to extract sensitive configuration data. cve-2024-33575 s4e-io user meta cve cve2024 info-leak user-meta vkev vuln wordpress wp-plugin wpscan cwe-200" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">User Meta WP Plugin &lt; 3.1 - Sensitive Information Exposure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-33575.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-33575.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> s4e-io</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 6, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-33575" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-33575</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/user-meta/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The User Meta is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.0 via the /views/debug.php file. This makes it possible for unauthenticated attackers, with to extract sensitive configuration data.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can extract sensitive configuration data from the User Meta plugin.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update User Meta plugin to version 3.1 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">User Meta</span><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">info-leak</span><span class="nt-tag">user-meta</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">wpscan</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-33575" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://wpscan.com/vulnerability/3b75549c-3fc5-4e6f-84ae-264d8276bfb3/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://patchstack.com/database/vulnerability/user-meta/wordpress-user-meta-plugin-3-0-sensitive-data-exposure-vulnerability?_s_id=cve" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="user submitted posts &lt;= 20251121 - unauthenticated open redirect medium identify critical remote vulnerabilities the user submitted posts plugin for wordpress is vulnerable to open redirect in all versions up to and including 20251121. this is due to insufficient validation on the redirect-override post parameter. unauthenticated attackers can redirect users to potentially malicious sites by tricking them into submitting a form. shivam kamboj cve cve2025 wordpress wp-plugin user-submitted-posts open-redirect wp" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">User Submitted Posts &lt;= 20251121 - Unauthenticated Open Redirect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-68509.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-68509.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Shivam Kamboj</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 5, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)usp-nonce&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The User Submitted Posts plugin for WordPress is vulnerable to Open Redirect in all versions up to and including 20251121. This is due to insufficient validation on the redirect-override POST parameter. Unauthenticated attackers can redirect users to potentially malicious sites by tricking them into submitting a form.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can redirect users to malicious sites, facilitating phishing attacks and credential theft.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest version.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">user-submitted-posts</span><span class="nt-tag">open-redirect</span><span class="nt-tag">wp</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/user-submitted-posts/user-submitted-posts-20251121-unauthenticated-open-redirect" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://plugins.trac.wordpress.org/changeset?old_path=/user-submitted-posts/tags/20251121&amp;new_path=/user-submitted-posts/tags/20251210" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="userpro &lt;= 5.1.1 - authentication bypass critical identify critical remote vulnerabilities the userpro plugin for wordpress through 5.1.1 allows authentication bypass via the userpro_fbconnect ajax action. cve-2023-2437 intelligent-ears auth-bypass cve cve2023 userpro vkev wordpress wp wp-plugin cwe-287" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">UserPro &lt;= 5.1.1 - Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-2437.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-2437.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> intelligent-ears</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 1, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/287.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-287</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-2437" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-2437</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/userpro/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The UserPro plugin for WordPress through 5.1.1 allows authentication bypass via the userpro_fbconnect AJAX action.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can bypass authentication by exploiting the Facebook connect AJAX action with arbitrary user IDs, potentially gaining full administrative access to the WordPress site and all user accounts.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update UserPro plugin to a version newer than 5.1.1 that properly validates authentication in the userpro_fbconnect AJAX action.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">userpro</span><span class="nt-tag">vkev</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/RxRCoder/CVE-2023-2437" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.wordfence.com/blog/2023/11/several-critical-vulnerabilities-including-privilege-escalation-authentication-bypass-and-more-patched-in-userpro-wordpress-plugin/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-2437" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://codecanyon.net/item/userpro-user-profiles-with-social-login/5958681" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="usermin 2.100 - username enumeration medium identify critical remote vulnerabilities usermin version 2.100 and below is susceptible to username enumeration via the password change functionality. an attacker can determine valid usernames by analyzing the response messages from the password change endpoint. cve-2024-44762 ritikchaddha cve cve2024 exposure usermin usernames vuln webmin cwe-209" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Usermin 2.100 - Username Enumeration</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-44762.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-44762.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 21, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/209.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-209</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-44762" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-44762</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Usermin&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Usermin version 2.100 and below is susceptible to username enumeration via the password change functionality. An attacker can determine valid usernames by analyzing the response messages from the password change endpoint.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can enumerate valid usernames by analyzing password change responses, aiding in further attacks.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to the latest version of Usermin that addresses this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">exposure</span><span class="nt-tag">usermin</span><span class="nt-tag">usernames</span><span class="nt-tag">vuln</span><span class="nt-tag">webmin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.exploit-db.com/exploits/52254" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.webmin.com/usermin.html" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://senscybersecurity.nl/cve-2024-44762-explained/" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-44762" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="usermin panel - detect info identify web-based control panels usermin panel was discovered. s4e-io panel login usermin detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Usermin Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/usermin-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">usermin-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> s4e-io</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 17, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# contains &#34;Login to Usermin&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Usermin panel was discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">login</span><span class="nt-tag">usermin</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="v2924 admin login panel - detect info identify web-based control panels v2924 admin login panel was detected. dhiyaneshdk panel v2924 discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">V2924 Admin Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/v2924-admin-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">v2924-admin-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)V2924&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">V2924 admin login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">v2924</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.facebook.com/ExWareLabs/photos/a.361854183878462/5538760399521122" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="vicidial - sql injection critical identify critical remote vulnerabilities an unauthenticated attacker can leverage a time-based sql injection vulnerability in vicidial to enumerate database records. by default, vicidial stores plaintext credentials within the database. cve-2024-8503 s4e-io cve cve2024 sqli time-based-sqli vicidial vkev vuln cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">VICIdial - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-8503.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-8503.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> s4e-io</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 16, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-8503" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-8503</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1375401192&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An unauthenticated attacker can leverage a time-based SQL injection vulnerability in VICIdial to enumerate database records. By default, VICIdial stores plaintext credentials within the database.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can exploit SQL injection to enumerate database records and extract plaintext credentials stored by VICIdial, leading to complete system compromise and unauthorized access to the call center platform.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply security patches for VICIdial to address the SQL injection vulnerability in VERM_AJAX_functions.php and implement proper credential encryption.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">sqli</span><span class="nt-tag">time-based-sqli</span><span class="nt-tag">vicidial</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://en.0day.today/exploit/39746" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/Chocapikk/CVE-2024-8504" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-8503" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="vmware - local file inclusion critical identify critical remote vulnerabilities vmware workspace one access, identity manager, and realize automation are vulnerable to local file inclusion because they contain an authentication bypass vulnerability affecting local domain users. a malicious actor with network access to the ui may be able to obtain administrative access without the need to authenticate. cve-2022-31656 dhiyaneshdk cve cve2022 lfi vkev vmware vuln cwe-287" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">VMware - Local File Inclusion</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-31656.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-31656.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/287.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-287</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-31656" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-31656</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-1250474341&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">VMware Workspace ONE Access, Identity Manager, and Realize Automation are vulnerable to local file inclusion because they contain an authentication bypass vulnerability affecting local domain users. A malicious actor with network access to the UI may be able to obtain administrative access without the need to authenticate.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">The impact of this vulnerability is that an attacker can read sensitive files on the server, which may contain credentials, configuration files, or other sensitive information.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">To remediate this vulnerability, ensure that all user-supplied input is properly validated and sanitized before being used in file inclusion operations.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">lfi</span><span class="nt-tag">vkev</span><span class="nt-tag">vmware</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://petrusviet.medium.com/dancing-on-the-architecture-of-vmware-workspace-one-access-eng-ad592ae1b6dd" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.vmware.com/security/advisories/VMSA-2022-0021.html" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31656" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/ARPSyndicate/cvemon" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/ARPSyndicate/kenzer-templates" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="vmware aria operations login - detect info identify web-based control panels detects vmware aria operations panel. rxerium panel aria login detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">VMware Aria Operations Login - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/vmware-aria-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">vmware-aria-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 10, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)VMware Aria Operations&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detects VMware Aria Operations Panel.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">aria</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="vmware carbon black edr panel - detect info identify web-based control panels vmware carbon black edr panel was detected. dhiyaneshdk panel vmware discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">VMware Carbon Black EDR Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/vmware-carbon-black-edr.yaml" target="_blank" rel="noopener" class="nt-source-link">vmware-carbon-black-edr.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)VMware Carbon Black EDR&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">VMware Carbon Black EDR panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">vmware</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="vmware cloud director availability login panel - detect info identify web-based control panels vmware cloud director availability login panel was detected. dhiyaneshdk discovery panel vmware cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">VMware Cloud Director Availability Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/vmware-cloud-availability.yaml" target="_blank" rel="noopener" class="nt-source-link">vmware-cloud-availability.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)VMware Cloud Director Availability&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">VMware Cloud Director Availability login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">vmware</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="vmware cloud director login panel - detect info identify web-based control panels vmware cloud director login panel was detected. dhiyaneshdk discovery panel vmware cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">VMware Cloud Director Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/vmware-cloud-director.yaml" target="_blank" rel="noopener" class="nt-source-link">vmware-cloud-director.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)welcome to vmware cloud director&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">VMware Cloud Director login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">vmware</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="vmware ftp server login panel - detect info identify web-based control panels vmware ftp server login panel was detected. dhiyaneshdk panel vmware ftp discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">VMware FTP Server Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/vmware-ftp-server.yaml" target="_blank" rel="noopener" class="nt-source-link">vmware-ftp-server.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)VMWARE FTP SERVER&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">VMware FTP Server login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">vmware</span><span class="nt-tag">ftp</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="vmware hcx login panel - detect info identify web-based control panels vmware hcx login panel was detected. dhiyaneshdk discovery panel vmware cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">VMware HCX Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/vmware-hcx-login.yaml" target="_blank" rel="noopener" class="nt-source-link">vmware-hcx-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)VMware HCX&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">VMware HCX login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">vmware</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="vmware nsx login panel - detect info identify web-based control panels vmware nsx login panel was detected. dhiyaneshdk discovery panel vmware cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">VMware NSX Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/vmware-nsx-login.yaml" target="_blank" rel="noopener" class="nt-source-link">vmware-nsx-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)vmw_nsx_logo-black-triangle-500w\\.png&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">VMware NSX login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">vmware</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="vmware nsx sd-wan edge - command injection critical identify critical remote vulnerabilities vmware nsx sd-wan edge (formerly velocloud edge) before 3.1.2 contains an unauthenticated command injection in the local web ui diagnostic tools (ping/traceroute). this template detects it reliably by injecting &#39;id&#39;, &#39;whoami&#39;, and a random marker. cve-2018-6961 d3nverng,thewindghost cve cve2018 kev nsx rce sd-wan velocloud vkev vmware cwe-78" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">VMware NSX SD-WAN Edge - Command Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2018/CVE-2018-6961.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2018-6961.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> D3nverNg,thewindghost</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 30, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/78.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-78</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2018-6961" target="_blank" rel="noopener" class="nt-cve-link">CVE-2018-6961</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)VeloCloud&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">VMware NSX SD-WAN Edge (formerly VeloCloud Edge) before 3.1.2 contains an unauthenticated command injection in the local web UI diagnostic tools (Ping/Traceroute). This template detects it reliably by injecting &#39;id&#39;, &#39;whoami&#39;, and a random marker.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation allows unauthenticated remote code execution as root.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to VMware SD-WAN Edge version 3.1.2 or later (diagnostic web UI component removed).</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2018</span><span class="nt-tag">kev</span><span class="nt-tag">nsx</span><span class="nt-tag">rce</span><span class="nt-tag">sd-wan</span><span class="nt-tag">velocloud</span><span class="nt-tag">vkev</span><span class="nt-tag">vmware</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.vmware.com/security/advisories/VMSA-2018-0011.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.exploit-db.com/exploits/44959" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2018-6961" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="vmware workspace one access - server-side template injection critical identify critical remote vulnerabilities vmware workspace one access is susceptible to a remote code execution vulnerability due to a server-side template injection flaw. an unauthenticated attacker with network access could exploit this vulnerability by sending a specially crafted request to a vulnerable vmware workspace one or identity manager. cve-2022-22954 sherlocksecurity cve cve2022 kev packetstorm ssti tenable vkev vmware vuln workspaceone cwe-94" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">VMware Workspace ONE Access - Server-Side Template Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-22954.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-22954.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> sherlocksecurity</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/94.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-94</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-22954" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-22954</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-1250474341&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">VMware Workspace ONE Access is susceptible to a remote code execution vulnerability due to a server-side template injection flaw. An unauthenticated attacker with network access could exploit this vulnerability by sending a specially crafted request to a vulnerable VMware Workspace ONE or Identity Manager.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could lead to remote code execution, compromising the confidentiality, integrity, and availability of the affected system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches provided by VMware to mitigate this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">kev</span><span class="nt-tag">packetstorm</span><span class="nt-tag">ssti</span><span class="nt-tag">tenable</span><span class="nt-tag">vkev</span><span class="nt-tag">vmware</span><span class="nt-tag">vuln</span><span class="nt-tag">workspaceone</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.tenable.com/blog/vmware-patches-multiple-vulnerabilities-in-workspace-one-vmsa-2022-0011" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.vmware.com/security/advisories/VMSA-2022-0011.html" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="http://packetstormsecurity.com/files/166935/VMware-Workspace-ONE-Access-Template-Injection-Command-Execution.html" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-22954" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="vmware workspace one uem airwatch login panel - detect info identify web-based control panels vmware workspace one uem airwatch login panel was detected. gevakun,hanlaomo discovery panel vmware workspaceone cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">VMware Workspace ONE UEM Airwatch Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/workspace-one-uem.yaml" target="_blank" rel="noopener" class="nt-source-link">workspace-one-uem.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> gevakun,hanlaomo</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)airwatch&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">VMware Workspace ONE UEM Airwatch login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">vmware</span><span class="nt-tag">workspaceone</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://twitter.com/Jhaddix/status/1295861505963909120" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="vmware workspace one uem airwatch self-service portal - detect info identify web-based control panels vmware workspace one uem airwatch self-service portal (ssp) login panel was detected. koratsec panel workspaceone vmware airwatch ssp login detect discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">VMware Workspace ONE UEM Airwatch Self-Service Portal - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/workspace-one-uem-ssp.yaml" target="_blank" rel="noopener" class="nt-source-link">workspace-one-uem-ssp.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> KoratSec</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 6, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;321909464&#34; || service[&#34;http.body&#34;] matches &#34;(?i)Self-Service Portal&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">VMware Workspace ONE UEM Airwatch Self-Service Portal (SSP) login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">workspaceone</span><span class="nt-tag">vmware</span><span class="nt-tag">airwatch</span><span class="nt-tag">ssp</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://docs.vmware.com/en/VMware-Workspace-ONE-UEM/2209/UEM_ConsoleBasics/GUID-AWT-SELFSERVICEPORTALOVERVIEW.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="vmware vcenter converter panel - detect info identify web-based control panels vmware vcenter converter panel was detected. dhiyaneshdk discovery panel vcenter vmware cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">VMware vCenter Converter Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/vmware-vcenter-converter-standalone.yaml" target="_blank" rel="noopener" class="nt-source-link">vmware-vcenter-converter-standalone.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)vmware vcenter converter standalone&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">VMware vCenter Converter panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">vcenter</span><span class="nt-tag">vmware</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="vmware vcenter server - out-of-bounds write critical identify critical remote vulnerabilities vcenter server contains an out-of-bounds write caused by a vulnerability in the dcerpc protocol implementation. a malicious actor with network access can trigger remote code execution on vcenter server. cve-2023-34048 ritikchaddha cve cve2023 kev passive rce vcenter vkev vmware cwe-787" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">VMware vCenter Server - Out-of-Bounds Write</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-34048.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-34048.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 17, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/787.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-787</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-34048" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-34048</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)VMware VCenter&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">vCenter Server contains an out-of-bounds write caused by a vulnerability in the DCERPC protocol implementation. A malicious actor with network access can trigger remote code execution on vCenter Server.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers with network access can exploit the out-of-bounds write vulnerability in the DCERPC protocol to execute arbitrary code on vCenter Server, potentially compromising the entire VMware virtualization infrastructure.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply VMware security patches from VMSA-2023-0023 for vCenter Server versions 4.0-5.5 and 7.0-8.0 that fix the DCERPC protocol vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">kev</span><span class="nt-tag">passive</span><span class="nt-tag">rce</span><span class="nt-tag">vcenter</span><span class="nt-tag">vkev</span><span class="nt-tag">vmware</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.vicarius.io/vsociety/posts/understanding-cve-2023-34048-a-zero-day-out-of-bound-write-in-vcenter-server" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.vmware.com/security/advisories/VMSA-2023-0023.html" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-34048" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="vmware vcloud director panel - detect info identify web-based control panels vmware vcloud director panel was detected. dhiyaneshdk discovery panel vcloud vmware cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">VMware vCloud Director Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/vmware-vcloud-director.yaml" target="_blank" rel="noopener" class="nt-source-link">vmware-vcloud-director.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)vmware vcloud director&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">VMware vCloud Director panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">vcloud</span><span class="nt-tag">vmware</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="vmware vrealize log insight - improper access control to rce critical identify critical remote vulnerabilities the vrealize log insight contains a broken access control vulnerability. an unauthenticated malicious actor can remotely inject code into sensitive files of an impacted appliance which can result in remote code execution. cve-2022-31704 ritikchaddha cve cve2022 lfi passive rce vkev vmware vrealize vuln cwe-22" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">VMware vRealize Log Insight - Improper Access Control to RCE</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-31704.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-31704.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 15, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-31704" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-31704</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)vrealize log insight&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The vRealize Log Insight contains a broken access control vulnerability. An unauthenticated malicious actor can remotely inject code into sensitive files of an impacted appliance which can result in remote code execution.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation allows a remote, unauthenticated attacker to inject and execute malicious code on the target appliance, potentially resulting in complete compromise of the affected system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update VMware vRealize Log Insight to version 8.10.2 or later, as detailed in the official vendor advisory.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">lfi</span><span class="nt-tag">passive</span><span class="nt-tag">rce</span><span class="nt-tag">vkev</span><span class="nt-tag">vmware</span><span class="nt-tag">vrealize</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="http://packetstormsecurity.com/files/174606/VMware-vRealize-Log-Insight-Unauthenticated-Remote-Code-Execution.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.vmware.com/security/advisories/VMSA-2023-0001.html" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31704" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="vmware vrealize log insight - path traversal critical identify critical remote vulnerabilities he vrealize log insight contains a directory traversal vulnerability. an unauthenticated, malicious actor can inject files into the operating system of an impacted appliance which can result in remote code execution. cve-2022-31706 ritikchaddha cve cve2022 lfi passive rce vkev vmware vrealize vuln cwe-22" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">VMware vRealize Log Insight - Path Traversal</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-31706.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-31706.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 15, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-31706" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-31706</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)vrealize log insight&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">he vRealize Log Insight contains a Directory Traversal Vulnerability. An unauthenticated, malicious actor can inject files into the operating system of an impacted appliance which can result in remote code execution.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">A remote, unauthenticated attacker can inject malicious files leading to remote code execution on the target appliance, resulting in complete compromise of the affected system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update VMware vRealize Log Insight to version 8.10.2 or later as per the official vendor advisory.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">lfi</span><span class="nt-tag">passive</span><span class="nt-tag">rce</span><span class="nt-tag">vkev</span><span class="nt-tag">vmware</span><span class="nt-tag">vrealize</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="http://packetstormsecurity.com/files/174606/VMware-vRealize-Log-Insight-Unauthenticated-Remote-Code-Execution.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.vmware.com/security/advisories/VMSA-2023-0001.html" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/cve-2022-31706" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="vmware vrealize log insight &lt; v8.10.2 - information disclosure medium identify critical remote vulnerabilities vmware vrealize log insight contains an information disclosure vulnerability. a malicious actor can remotely collect sensitive session and application information without authentication. cve-2022-31711 dhiyaneshdk cve cve2022 exposure passive vkev vmware vuln" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">VMware vRealize Log Insight &lt; v8.10.2 - Information Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-31711.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-31711.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 13, 2025</span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-31711" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-31711</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)vrealize log insight&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">VMware vRealize Log Insight contains an Information Disclosure Vulnerability. A malicious actor can remotely collect sensitive session and application information without authentication.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can access sensitive session and application data, leading to potential information leakage and security breaches.&#34;</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches and updates provided by VMware to mitigate this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">exposure</span><span class="nt-tag">passive</span><span class="nt-tag">vkev</span><span class="nt-tag">vmware</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="http://packetstormsecurity.com/files/174606/VMware-vRealize-Log-Insight-Unauthenticated-Remote-Code-Execution.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/horizon3ai/vRealizeLogInsightRCE" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="vsftpd 2.3.4 - backdoor command execution critical identify critical remote vulnerabilities vsftpd v2.3.4 had a serious backdoor vulnerability allowing attackers to execute arbitrary commands on the server with root-level access. the backdoor was triggered by a specific string of characters in a user login request, which allowed attackers to execute any command they wanted. cve-2011-2523 pussycat0x backdoor cve cve2011 ftp network packetstorm tcp vsftpd vsftpd_project vuln cwe-78" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">VSFTPD 2.3.4 - Backdoor Command Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/network/cves/2011/CVE-2011-2523.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2011-2523.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 3, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/78.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-78</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2011-2523" target="_blank" rel="noopener" class="nt-cve-link">CVE-2011-2523</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;protocol&#34;] contains &#34;ftp&#34; and service[&#34;service.transport&#34;] contains &#34;tcp&#34; and service[&#34;banner&#34;] matches `(?i)vsFTPd`</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">VSFTPD v2.3.4 had a serious backdoor vulnerability allowing attackers to execute arbitrary commands on the server with root-level access. The backdoor was triggered by a specific string of characters in a user login request, which allowed attackers to execute any command they wanted.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability allows remote attackers to execute arbitrary commands with the privileges of the FTP server.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest version of VSFTPD, which does not contain the backdoor.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">backdoor</span><span class="nt-tag">cve</span><span class="nt-tag">cve2011</span><span class="nt-tag">ftp</span><span class="nt-tag">network</span><span class="nt-tag">packetstorm</span><span class="nt-tag">tcp</span><span class="nt-tag">vsftpd</span><span class="nt-tag">vsftpd_project</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.rapid7.com/db/modules/exploit/unix/ftp/vsftpd_234_backdoor/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.exploit-db.com/exploits/49757" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="http://packetstormsecurity.com/files/162145/vsftpd-2.3.4-Backdoor-Command-Execution.html" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://access.redhat.com/security/cve/cve-2011-2523" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://security-tracker.debian.org/tracker/CVE-2011-2523" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="vtscada - internet client panel info identify web-based control panels vtscada (by trihedral engineering) is a scada platform used in water/
wastewater, oil and gas, and utilities. the internet client feature exposes
a browser-based view of process data, and is commonly deployed by municipal
water systems across north america. rxerium discovery ics oil-gas panel scada trihedral utilities vtscada water" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">VTScada - Internet Client Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/vtscada-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">vtscada-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 27, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;VTScada Internet Client from Trihedral&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">VTScada (by Trihedral Engineering) is a SCADA platform used in water/
wastewater, oil and gas, and utilities. The Internet Client feature exposes
a browser-based view of process data, and is commonly deployed by municipal
water systems across North America.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">ics</span><span class="nt-tag">oil-gas</span><span class="nt-tag">panel</span><span class="nt-tag">scada</span><span class="nt-tag">trihedral</span><span class="nt-tag">utilities</span><span class="nt-tag">vtscada</span><span class="nt-tag">water</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.trihedral.com/vtscada/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="vanna - sql injection critical identify critical remote vulnerabilities vanna v0.3.4 is vulnerable to sql injection in its duckdb integration exposed to its flask web apis. attackers can inject malicious sql training data and generate corresponding queries to write arbitrary files on the victim&#39;s file system, such as backdoor.php with contents `&lt;?php system($_get[0]); ?&gt;`. this can lead to command execution or the creation of backdoors. cve-2024-5827 olfloralo,nukunga,harksu,nechyo,gy741 cve cve2024 sqli vanna vkev vuln cwe-434" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Vanna - SQL injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-5827.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-5827.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> olfloralo,nukunga,harksu,nechyo,gy741</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 27, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/434.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-434</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-5827" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-5827</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)&#39;vanna\\.ai&#39;&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Vanna v0.3.4 is vulnerable to SQL injection in its DuckDB integration exposed to its Flask Web APIs. Attackers can inject malicious SQL training data and generate corresponding queries to write arbitrary files on the victim&#39;s file system, such as backdoor.php with contents `&lt;?php system($_GET[0]); ?&gt;`. This can lead to command execution or the creation of backdoors.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can exploit SQL injection to inject malicious training data and write arbitrary files on the victim&#39;s filesystem, including PHP backdoors, leading to remote code execution.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update Vanna to version 0.3.5 or later to address the SQL injection vulnerability in the DuckDB integration.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">sqli</span><span class="nt-tag">vanna</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://huntr.com/bounties/a3f913d6-c717-4528-b974-26d8d9e839ca" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-5827" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://huntr.com/bounties/e4e64a51-618b-41d0-8f56-1d2146d8825e" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/fkie-cad/nvd-json-data-feeds" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="vanna ai panel - detect info identify web-based control panels vanna ai is a chat interface for text-to-sql generation using natural language. this template detects the presence of a vanna ai chat panel. rxerium ai chat detect discovery panel sql vanna" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Vanna AI Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/vanna-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">vanna-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 27, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;Vanna Agents Chat&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Vanna AI is a chat interface for text-to-SQL generation using natural language. This template detects the presence of a Vanna AI chat panel.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">ai</span><span class="nt-tag">chat</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">sql</span><span class="nt-tag">vanna</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/vanna-ai/vanna" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://vanna.ai" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="vault login panel - detect info identify web-based control panels vault login panel was detected. dhiyaneshdk,righettod detect discovery hashicorp panel vault cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Vault Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/vault-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">vault-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK,righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-919788577&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Vault login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">hashicorp</span><span class="nt-tag">panel</span><span class="nt-tag">vault</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://developer.hashicorp.com/vault" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://developer.hashicorp.com/vault/api-docs" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://developer.hashicorp.com/vault/api-docs#help" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="vaultwarden login panel - detect info identify web-based control panels vaultwarden products was detected. righettod panel vaultwarden login discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Vaultwarden Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/vaultwarden-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">vaultwarden-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 14, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)vaultwarden&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Vaultwarden products was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">vaultwarden</span><span class="nt-tag">login</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/dani-garcia/vaultwarden" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="vectoradmin panel - detect info identify web-based control panels vectoradmin panel was discovered. s4e-io panel login vectoradmin detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">VectorAdmin Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/vectoradmin-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">vectoradmin-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> s4e-io</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 21, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)VectorAdmin - Vector database management made easy\\.&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">VectorAdmin panel was discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">login</span><span class="nt-tag">vectoradmin</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://vectoradmin.com" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/Mintplex-Labs/vector-admin" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://elest.io/open-source/vectoradmin/resources" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="veeam backup &amp; replication - unauthenticated critical identify critical remote vulnerabilities a deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code execution (rce). cve-2024-40711 rootxharsh,iamnoooob,dhiyaneshdk backup cve cve2024 kev passive unauth veeam vkev vuln cwe-502" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Veeam Backup &amp; Replication - Unauthenticated</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-40711.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-40711.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rootxharsh,iamnoooob,DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 6, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/502.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-502</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-40711" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-40711</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Veeam Backup&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code execution (RCE).</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can exploit deserialization vulnerabilities to achieve remote code execution on Veeam Backup &amp; Replication servers.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update Veeam Backup &amp; Replication to a patched version addressing CVE-2024-40711.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">backup</span><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">kev</span><span class="nt-tag">passive</span><span class="nt-tag">unauth</span><span class="nt-tag">veeam</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://x.com/codewhitesec/status/1831720125747069389?s=46" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.veeam.com/kb4649" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-40711" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="veeam backup enterprise manager login - detect info identify web-based control panels veeam backup enterprise manager login charles d detect discovery enterprise-manager login panel veeam cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Veeam Backup Enterprise Manager Login - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/veeam-backup-manager-login.yaml" target="_blank" rel="noopener" class="nt-source-link">veeam-backup-manager-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Charles D</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 11, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)veeam backup enterprise manager&#34;}) || service[&#34;favicon.ico.image.mmh3&#34;] == &#34;169658321&#34; || service[&#34;http.body&#34;] matches &#34;(?i)Veeam&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Veeam Backup Enterprise Manager Login</div></div></div>
  <div class="nt-tags"><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">enterprise-manager</span><span class="nt-tag">login</span><span class="nt-tag">panel</span><span class="nt-tag">veeam</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="veeam backup for google cloud platform panel - detect info identify web-based control panels veeam backup for google cloud platform panel was detected. dhiyaneshdk cloud discovery google panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Veeam Backup for Google Cloud Platform Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/veeam-backup-gcp.yaml" target="_blank" rel="noopener" class="nt-source-link">veeam-backup-gcp.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Veeam Backup for GCP&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Veeam Backup for Google Cloud Platform panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cloud</span><span class="nt-tag">discovery</span><span class="nt-tag">google</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="veeam backup for microsoft azure panel - detect info identify web-based control panels veeam backup for microsoft azure panel was detected. dhiyaneshdk azure panel backup veeam microsoft discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Veeam Backup for Microsoft Azure Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/veeam-backup-azure-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">veeam-backup-azure-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Veeam Backup for Microsoft Azure&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Veeam Backup for Microsoft Azure panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">azure</span><span class="nt-tag">panel</span><span class="nt-tag">backup</span><span class="nt-tag">veeam</span><span class="nt-tag">microsoft</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="veeam login panel - detect info identify web-based control panels veeam login panel was detected. dhiyaneshdk discovery panel veeam cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Veeam Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/veeam-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">veeam-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-633512412&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Veeam login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">veeam</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="vendure core - sql injection critical identify critical remote vulnerabilities vendure, an open-source headless commerce platform built on node.js/typescript, contains a critical sql injection vulnerability in its shop api. the languagecode query parameter is interpolated directly into a raw sql case expression in productservice.findonebyslug without parameterization or input validation, allowing unauthenticated attackers to execute arbitrary sql commands. this can lead to full database disclosure and denial of service. cve-2026-40887 theamanrawat cve cve2026 sqli unauthenticated vendure cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Vendure Core - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2026/CVE-2026-40887.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2026-40887.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> theamanrawat</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 17, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2026-40887" target="_blank" rel="noopener" class="nt-cve-link">CVE-2026-40887</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.head.accessControlExposeHeaders&#34;] matches `(?i)vendure-auth-token` || service[&#34;last.http.head.accessControlExposeHeaders&#34;] matches `(?i)vendure-auth-token`</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Vendure, an open-source headless commerce platform built on Node.js/TypeScript, contains a critical SQL injection vulnerability in its Shop API. The languageCode query parameter is interpolated directly into a raw SQL CASE expression in ProductService.findOneBySlug without parameterization or input validation, allowing unauthenticated attackers to execute arbitrary SQL commands. This can lead to full database disclosure and denial of service.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade @vendure/core to version 3.6.2, 3.5.7, or 2.3.4 or later, which add input validation and parameterized queries for the languageCode parameter.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2026</span><span class="nt-tag">sqli</span><span class="nt-tag">unauthenticated</span><span class="nt-tag">vendure</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/advisories/GHSA-9pp3-53p2-ww9v" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/vendurehq/vendure/security/advisories/GHSA-9pp3-53p2-ww9v" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/vendurehq/vendure/commit/3ff0bc1" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40887" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="veracore login - detect info identify web-based control panels a veracore login panel was detected. rxerium panel veracore login detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Veracore Login - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/veracore-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">veracore-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 10, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)veraCoreScreenHeight&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A veracore login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">veracore</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.advantive.com/brands/veracore/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="veritas netbackup opscenter analytics login - detect info identify web-based control panels a veritas netbackup opscenter analytics page was detected. rxerium panel veritas netbackup opscenter login detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Veritas NetBackup OpsCenter Analytics Login - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/veritas-netbackup-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">veritas-netbackup-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 8, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Veritas NetBackup OpsCenter Analytics&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A Veritas NetBackup OpsCenter Analytics page was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">veritas</span><span class="nt-tag">netbackup</span><span class="nt-tag">opscenter</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.veritas.com/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="veriz0wn osint - detect info identify web-based control panels  pussycat0x veriz0wn panel discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Veriz0wn OSINT - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/veriz0wn-osint.yaml" target="_blank" rel="noopener" class="nt-source-link">veriz0wn-osint.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Veriz0wn&#34;})</code></div>
  <div class="nt-tags"><span class="nt-tag">veriz0wn</span><span class="nt-tag">panel</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="verizon router panel - detect info identify web-based control panels verizon router panel was detected. theamanrawat discovery panel router verizon cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Verizon Router Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/verizon-router-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">verizon-router-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> theamanrawat</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Verizon Router&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Verizon router panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">router</span><span class="nt-tag">verizon</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="versa concerto api path based - authentication bypass critical identify critical remote vulnerabilities authentication bypass in the versa concerto api, caused by url decoding inconsistencies. it allowed unauthorized access to certain api endpoints by manipulating the url path.this issue enabled attackers to bypass authentication controls and access restricted resources. cve-2025-34027 iamnoooob,rootxharsh,parthmalhotra,pdresearch auth-bypass concerto cve cve2025 versa vkev vuln cwe-367" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Versa Concerto API Path Based - Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-34027.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-34027.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> iamnoooob,rootxharsh,parthmalhotra,pdresearch</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 22, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/367.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-367</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-34027" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-34027</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-534530225&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Authentication bypass in the Versa Concerto API, caused by URL decoding inconsistencies. It allowed unauthorized access to certain API endpoints by manipulating the URL path.This issue enabled attackers to bypass authentication controls and access restricted resources.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can bypass authentication through URL path manipulation to access restricted API endpoints and retrieve sensitive role information without credentials.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to the latest Versa Concerto version that properly handles URL decoding and path validation in authentication checks.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">concerto</span><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">versa</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://projectdiscovery.io/blog/versa-concerto-authentication-bypass-rce/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://versa-networks.com/documents/datasheets/versa-concerto.pdf" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.cve.org/CVERecord?id=CVE-2025-34027" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://security-portal.versa-networks.com/emailbulletins/6830fa3f28defa375486ff2f" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="versa concerto actuator endpoint - authentication bypass critical identify critical remote vulnerabilities an authentication bypass vulnerability affected the spring boot actuator endpoints in versa concerto due to improper handling of the x-real-ip header.attackers could access restricted endpoints by omitting this header.the issue allowed unauthorized access to sensitive functionality, highlighting the need for proper header validation. cve-2025-34026 iamnoooob,rootxharsh,parthmalhotra,pdresearch actuator auth-bypass concerto cve cve2025 kev springboot versa vkev vuln cwe-288" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Versa Concerto Actuator Endpoint - Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-34026.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-34026.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> iamnoooob,rootxharsh,parthmalhotra,pdresearch</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 22, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/288.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-288</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-34026" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-34026</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-534530225&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An authentication bypass vulnerability affected the Spring Boot Actuator endpoints in Versa Concerto due to improper handling of the X-Real-Ip header.Attackers could access restricted endpoints by omitting this header.The issue allowed unauthorized access to sensitive functionality, highlighting the need for proper header validation.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can bypass authentication by omitting the X-Real-Ip header to access restricted Spring Boot Actuator endpoints, potentially exposing sensitive system information and functionality.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to the latest Versa Concerto version that properly validates authentication for all Actuator endpoints regardless of header presence.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">actuator</span><span class="nt-tag">auth-bypass</span><span class="nt-tag">concerto</span><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">kev</span><span class="nt-tag">springboot</span><span class="nt-tag">versa</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://projectdiscovery.io/blog/versa-concerto-authentication-bypass-rce/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://security-portal.versa-networks.com/emailbulletins/6830f94328defa375486ff2e" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.cve.org/CVERecord?id=CVE-2025-34026" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="versa director login panel - detect info identify web-based control panels versa director login panel was detected. c-sh0,darses director discovery panel versa cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Versa Director Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/versa/versa-director-login.yaml" target="_blank" rel="noopener" class="nt-source-link">versa-director-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> c-sh0,darses</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Versa Director&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Versa Director login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">director</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">versa</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://versa-networks.com/products/components/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="versa flexvnf - default login high identify default logins in web-based control panels versa flexvnf contains a default login vulnerability. an attacker can obtain access to user accounts and access sensitive information, modify data, and/or execute unauthorized operations. c-sh0 default-login flexvnf versa vuln cwe-522" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Versa FlexVNF - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/versa/versa-flexvnf-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">versa-flexvnf-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> c-sh0</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/522.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-522</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;Flex VNF Web-UI&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Versa FlexVNF contains a default login vulnerability. An attacker can obtain access to user accounts and access sensitive information, modify data, and/or execute unauthorized operations.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">flexvnf</span><span class="nt-tag">versa</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://versa-networks.com/products/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="versa flexvnf panel - detect info identify web-based control panels versa flexvnf panel was detected. c-sh0 panel versa flexvnf discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Versa FlexVNF Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/versa/versa-flexvnf-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">versa-flexvnf-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> c-sh0</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Flex VNF Web-UI&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Versa FlexVNF panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">versa</span><span class="nt-tag">flexvnf</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://versa-networks.com/products/components/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="vertaai modeldb - path traversal high identify critical remote vulnerabilities the endpoint &#34;/api/v1/artifact/getartifact?artifact_path=&#34; is vulnerable to path traversal. the main cause of this vulnerability is due to the lack of validation and sanitization of the artifact_path parameter. cve-2023-6023 m0ck3d,cookiehanhoan cve cve2023 lfi modeldb vertaai vkev vuln cwe-22,cwe-29" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">VertaAI ModelDB - Path Traversal</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-6023.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-6023.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> m0ck3d,cookiehanhoan</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 23, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22,CWE-29.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22,CWE-29</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-6023" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-6023</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-2097033750&#34; || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)verta ai&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The endpoint &#34;/api/v1/artifact/getArtifact?artifact_path=&#34; is vulnerable to path traversal. The main cause of this vulnerability is due to the lack of validation and sanitization of the artifact_path parameter.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can potentially exploit this vulnerability to perform a relative path traversal attack, which can lead to unauthorized access to sensitive local files on the server. As an impact it is known to affect confidentiality.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Restrict access to the web application</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">lfi</span><span class="nt-tag">modeldb</span><span class="nt-tag">vertaai</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://huntr.com/bounties/644ab868-db6d-4685-ab35-1a897632d2ca/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-6023" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="vertex tax installer panel - detect info identify web-based control panels vertex tax installer panel was detected. ritikchaddha panel vertex discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Vertex Tax Installer Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/vertex-tax-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">vertex-tax-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Vertex Tax Installer&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Vertex Tax Installer panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">vertex</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="victoriametrics panel - detect info identify web-based control panels a victoriametrics panel was discovered. shivam kamboj victoriametrics login panel discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">VictoriaMetrics Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/victoriametrics-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">victoriametrics-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Shivam Kamboj</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 5, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)VictoriaMetrics&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A VictoriaMetrics panel was discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">victoriametrics</span><span class="nt-tag">login</span><span class="nt-tag">panel</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://victoriametrics.com/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://docs.victoriametrics.com/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="vidyo admin login panel - detect info identify web-based control panels vidyo admin login panel was detected. johnk3r discovery panel vidyo cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Vidyo Admin Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/vidyo-login.yaml" target="_blank" rel="noopener" class="nt-source-link">vidyo-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> johnk3r</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-1970367401&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Vidyo admin login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">vidyo</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="viessmann vitogate 300 - hardcoded password critical identify critical remote vulnerabilities a critical vulnerability in viessmann vitogate 300 up to 2.1.3.0 allows attackers to authenticate using hardcoded credentials in the web management interface. cve-2023-5222 ritikchaddha cve cve2023 default-login viessmann vitogate vkev vuln cwe-259" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Viessmann Vitogate 300 - Hardcoded Password</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-5222.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-5222.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 30, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/259.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-259</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-5222" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-5222</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Vitogate 300&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A critical vulnerability in Viessmann Vitogate 300 up to 2.1.3.0 allows attackers to authenticate using hardcoded credentials in the Web Management Interface.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker could potentially gain unauthorized access to the device.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update the device firmware to remove the hardcoded password or change it to a strong, unique password.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">default-login</span><span class="nt-tag">viessmann</span><span class="nt-tag">vitogate</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://vuldb.com/?ctiid.240364" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://vuldb.com/?id.240364" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-5222" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="viessmann vitogate 300 - remote code execution critical identify critical remote vulnerabilities in vitogate 300 2.1.3.0, /cgi-bin/vitogate.cgi allows an unauthenticated attacker to bypass authentication and execute arbitrary commands via shell metacharacters in the ipaddr params json data for the put method. cve-2023-45852 iamnoooob,rootxharsh,pdresearch cve cve2023 rce viessmann vitogate vkev vuln cwe-77" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Viessmann Vitogate 300 - Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-45852.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-45852.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> iamnoooob,rootxharsh,pdresearch</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 26, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/77.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-77</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-45852" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-45852</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)vitogate 300&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">In Vitogate 300 2.1.3.0, /cgi-bin/vitogate.cgi allows an unauthenticated attacker to bypass authentication and execute arbitrary commands via shell metacharacters in the ipaddr params JSON data for the put method.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can execute arbitrary commands with elevated privileges through shell metacharacters in the ipaddr parameter, potentially compromising the heating control gateway and accessing building management systems.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update Viessmann Vitogate 300 firmware to a version newer than 2.1.3.0 that properly sanitizes the ipaddr parameter and prevents command injection through the JSON API.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">rce</span><span class="nt-tag">viessmann</span><span class="nt-tag">vitogate</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://connectivity.viessmann.com/gb/mp-fp/vitogate/vitogate-300-bn-mb.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/Push3AX/vul/blob/main/viessmann/Vitogate300_RCE.md" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-45852" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/tanjiti/sec_profile" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/komodoooo/Some-things" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="vikunja login panel - detect info identify web-based control panels vikunja login panel was detected. vikunja is a self-hosted to-do and project management application. matheusalbarello discovery login panel vikunja" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Vikunja Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/vikunja-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">vikunja-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> matheusalbarello</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 4, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;^Vikunja$&#34;}) || service[&#34;http.head.server&#34;] matches &#34;^Vikunja&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Vikunja login panel was detected. Vikunja is a self-hosted to-do and project management application.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">login</span><span class="nt-tag">panel</span><span class="nt-tag">vikunja</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://vikunja.io" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/go-vikunja/vikunja" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="vinchin backup &amp; recovery panel - detect info identify web-based control panels vinchin backup &amp; recovery login panel was detected. pussycat0x discovery login panel vinchin cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Vinchin Backup &amp; Recovery Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/vinchin-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">vinchin-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 26, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)VinChin&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Vinchin Backup &amp; Recovery login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">login</span><span class="nt-tag">panel</span><span class="nt-tag">vinchin</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="virtua software cobranca &lt;12r - blind sql injection high identify critical remote vulnerabilities virtua cobranca before 12r allows blind sql injection on the login page. cve-2021-37589 princechaddha cve cve2021 sqli virtua virtuasoftware vuln cwe-89" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Virtua Software Cobranca &lt;12R - Blind SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2021/CVE-2021-37589.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2021-37589.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> princechaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2021-37589" target="_blank" rel="noopener" class="nt-cve-link">CVE-2021-37589</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;876876147&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Virtua Cobranca before 12R allows blind SQL injection on the login page.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could lead to unauthorized access, data leakage, and potential compromise of the underlying system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest patch or update provided by the vendor to fix the SQL Injection vulnerability in Virtua Software Cobranca &lt;12R.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2021</span><span class="nt-tag">sqli</span><span class="nt-tag">virtua</span><span class="nt-tag">virtuasoftware</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/luca-regne/my-cves/tree/main/CVE-2021-37589" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.virtuasoftware.com.br/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.virtuasoftware.com.br/conteudo.php?content=downloads&amp;lang=pt-br" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2021-37589" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/luca-regne/public-exploits" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="virtua software panel - detect info identify web-based control panels virtua software panel was detected. princechaddha discovery panel virtua virtuasoftware cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Virtua Software Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/virtua-software-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">virtua-software-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> princechaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;876876147&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Virtua Software panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">virtua</span><span class="nt-tag">virtuasoftware</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="vite - arbitrary file read medium identify critical remote vulnerabilities vite, a provider of frontend development tooling, has a vulnerability in versions prior to 6.2.3, 6.1.2, 6.0.12, 5.4.15, and 4.5.10. `@fs` denies access to files outside of vite serving allow list. adding `?raw??` or `?import&amp;raw??` to the url bypasses this limitation and returns the file content if it exists. this bypass exists because trailing separators such as `?` are removed in several places, but are not accounted for in query string regexes. the contents of arbitrary files can be returned to the browser. only apps explicitly exposing the vite dev server to the network (using `--host` or `server.host` config option) are affected. versions 6.2.3, 6.1.2, 6.0.12, 5.4.15, and 4.5.10 fix the issue. cve-2025-30208 v2htw,s4e-io cve-2025-30208 arbitrary-file-read cve cve2025 vite vkev vuln cwe-200,cwe-284" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Vite - Arbitrary File Read</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-30208.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-30208.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> v2htw,s4e-io</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 26, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200,CWE-284.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200,CWE-284</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-30208" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-30208</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/@vite/client&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Vite, a provider of frontend development tooling, has a vulnerability in versions prior to 6.2.3, 6.1.2, 6.0.12, 5.4.15, and 4.5.10. `@fs` denies access to files outside of Vite serving allow list. Adding `?raw??` or `?import&amp;raw??` to the URL bypasses this limitation and returns the file content if it exists. This bypass exists because trailing separators such as `?` are removed in several places, but are not accounted for in query string regexes. The contents of arbitrary files can be returned to the browser. Only apps explicitly exposing the Vite dev server to the network (using `--host` or `server.host` config option) are affected. Versions 6.2.3, 6.1.2, 6.0.12, 5.4.15, and 4.5.10 fix the issue.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can bypass file access restrictions by adding special query parameters to URLs, potentially reading arbitrary files when the Vite dev server is exposed to the network.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to Vite version 6.2.3, 6.1.2, 6.0.12, 5.4.15, or 4.5.10 that properly validates query parameters.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">CVE-2025-30208</span><span class="nt-tag">arbitrary-file-read</span><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">vite</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/vitejs/vite/security/advisories/GHSA-x574-m823-4x7w" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-30208" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="vite - information disclosure medium identify critical remote vulnerabilities vite is a frontend tooling framework for javascript.in versions from 2.9.18 to before 3.0.0, 3.2.9 to before 4.0.0, 4.5.3 to before 5.0.0, 5.2.6 to before 5.4.21, 6.0.0 to before 6.4.1, 7.0.0 to before 7.0.8, and 7.1.0 to before 7.1.11, files denied by server.fs.deny were sent if the url ended with \ when the dev server is running on windows. only apps explicitly exposing the vite dev server to the network and running the dev server on windows were affected. this issue has been patched in versions 5.4.21, 6.4.1, 7.0.8, and 7.1.11. cve-2025-62522 dhiyaneshdk cve cve2025 env vite disclosure cwe-22" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Vite - Information Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-62522.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-62522.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 6, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-62522" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-62522</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/@vite/client&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Vite is a frontend tooling framework for JavaScript.In versions from 2.9.18 to before 3.0.0, 3.2.9 to before 4.0.0, 4.5.3 to before 5.0.0, 5.2.6 to before 5.4.21, 6.0.0 to before 6.4.1, 7.0.0 to before 7.0.8, and 7.1.0 to before 7.1.11, files denied by server.fs.deny were sent if the URL ended with \ when the dev server is running on Windows. Only apps explicitly exposing the Vite dev server to the network and running the dev server on Windows were affected. This issue has been patched in versions 5.4.21, 6.4.1, 7.0.8, and 7.1.11.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Remote attackers can access files denied by server.fs.deny, leading to sensitive information disclosure.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to versions 5.4.21, 6.4.1, 7.0.8, or 7.1.11 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">env</span><span class="nt-tag">vite</span><span class="nt-tag">disclosure</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/vitejs/vite/security/advisories/GHSA-93m4-6634-74q7" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="vite dev server - path traversal low identify critical remote vulnerabilities vite is a frontend tooling framework for javascript. prior to versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20, files starting with the same name with the public directory were served bypassing the `server.fs` settings. only apps that explicitly expose the vite dev server to the network (using --host or `server.host` config option), use the public directory feature (enabled by default), and have a symlink in the public directory are affected. versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20 fix the issue. cve-2025-58751 wn147 cve cve2025 lfi vite vuln cwe-22" data-nt-sev="low">
  <div class="nt-card-header">
    <div class="nt-title">Vite Dev Server - Path Traversal</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-58751.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-58751.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> wn147</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 8, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-58751" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-58751</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/@vite/client&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Vite is a frontend tooling framework for JavaScript. Prior to versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20, files starting with the same name with the public directory were served bypassing the `server.fs` settings. Only apps that explicitly expose the Vite dev server to the network (using --host or `server.host` config option), use the public directory feature (enabled by default), and have a symlink in the public directory are affected. Versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20 fix the issue.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can access unauthorized files bypassing filesystem restrictions, potentially exposing sensitive data.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to versions 7.1.5, 7.0.7, 6.3.6, or 5.4.20 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">lfi</span><span class="nt-tag">vite</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/vitejs/vite/security/advisories/GHSA-g4jq-h2w9-997c" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58751" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="vite dev server - path traversal in optimized deps .map handling medium identify critical remote vulnerabilities vite development server versions prior to 8.0.5, 7.3.2, and 6.4.2 are vulnerable to path traversal through the optimized dependencies sourcemap handler. the dev server&#39;s handling of .map requests for optimized dependencies resolves file paths via normalizepath(path.resolve(root, url.slice(1))) and calls readfile without restricting ../ segments in the url. this allows an attacker to bypass server.fs.strict and retrieve auto-generated sourcemaps for files located outside the project root, leaking absolute filesystem paths. only dev servers explicitly exposed to the network using --host or server.host are affected. cve-2026-39365 theamanrawat cve cve2026 lfi path-traversal unauthenticated vite vkev vuln cwe-22" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Vite Dev Server - Path Traversal in Optimized Deps .map Handling</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2026/CVE-2026-39365.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2026-39365.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> theamanrawat</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 8, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2026-39365" target="_blank" rel="noopener" class="nt-cve-link">CVE-2026-39365</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches `src=&#34;/@vite/client&#34;` &amp;&amp; service[&#34;service.port&#34;] == &#34;5173&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Vite development server versions prior to 8.0.5, 7.3.2, and 6.4.2 are vulnerable to path traversal through the optimized dependencies sourcemap handler. The dev server&#39;s handling of .map requests for optimized dependencies resolves file paths via normalizePath(path.resolve(root, url.slice(1))) and calls readFile without restricting ../ segments in the URL. This allows an attacker to bypass server.fs.strict and retrieve auto-generated sourcemaps for files located outside the project root, leaking absolute filesystem paths. Only dev servers explicitly exposed to the network using --host or server.host are affected.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can trigger auto-generated sourcemap responses for files outside the project directory, leaking absolute filesystem paths and potentially reading .map files containing sensitive source code or configuration data.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade Vite to version 8.0.5, 7.3.2, 6.4.2 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2026</span><span class="nt-tag">lfi</span><span class="nt-tag">path-traversal</span><span class="nt-tag">unauthenticated</span><span class="nt-tag">vite</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/advisories/GHSA-4w7w-66w2-5vf9" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/vitejs/vite/security/advisories/GHSA-4w7w-66w2-5vf9" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39365" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="vite development server - path traversal medium identify critical remote vulnerabilities path traversal vulnerability in vite development server&#39;s @fs endpoint allows attackers to access files outside the intended directory. when exposed to the network, attackers can exploit this via crafted urls to access sensitive system files. cve-2025-31125 martian,ritikchaddha,v2htw cve cve2025 kev lfi vite vkev vuln cwe-200" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Vite Development Server - Path Traversal</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-31125.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-31125.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> martian,ritikchaddha,v2htw</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 1, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-31125" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-31125</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Vite App&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Path traversal vulnerability in Vite development server&#39;s @fs endpoint allows attackers to access files outside the intended directory. When exposed to the network, attackers can exploit this via crafted URLs to access sensitive system files.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can exploit path traversal in the @fs endpoint to access files outside the intended directory when the Vite dev server is exposed to the network, potentially reading sensitive system files.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to the patched version or avoid exposing the Vite development server to the network (do not use --host flag or configure server.host); if upgrading is not immediately possible, implement access restrictions to the Vite development server</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">kev</span><span class="nt-tag">lfi</span><span class="nt-tag">vite</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/vitejs/vite/issues/8498" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/vitejs/vite/pull/8804" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/vitejs/vite/pull/8979" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-31125" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="vite server.fs.deny bypass - local file inclusion medium identify critical remote vulnerabilities vite is a frontend tooling framework for javascript. the contents of arbitrary files can be returned to the browser. by adding ?.svg with ?.wasm?init or with sec-fetch-dest- script header, the server.fs.deny restriction was able to bypass. this bypass is only possible if the file is smaller than build.assetsinlinelimit (default- 4kb) and when using vite 6.0+. only apps explicitly exposing the vite dev server to the network (using --host or server.host config option) are affected. cve-2025-31486 wn147 cve cve2025 lfi vite cwe-200" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Vite server.fs.deny Bypass - Local File Inclusion</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-31486.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-31486.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> wn147</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 22, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-31486" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-31486</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Vite App&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Vite is a frontend tooling framework for javascript. The contents of arbitrary files can be returned to the browser. By adding ?.svg with ?.wasm?init or with sec-fetch-dest- script header, the server.fs.deny restriction was able to bypass. This bypass is only possible if the file is smaller than build.assetsInlineLimit (default- 4kB) and when using Vite 6.0+. Only apps explicitly exposing the Vite dev server to the network (using --host or server.host config option) are affected.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can bypass server.fs.deny restrictions to read arbitrary files smaller than 4kB when the Vite dev server is exposed to the network, potentially exposing sensitive configuration data.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update Vite to version 4.5.12, 5.4.17, 6.0.14, 6.1.4, 6.2.5 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">lfi</span><span class="nt-tag">vite</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/advisories/GHSA-xcj6-pq6g-qj4x" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/vitejs/vite/blob/037f801075ec35bb6e52145d659f71a23813c48f/packages/vite/src/node/plugins/asset.ts#L285-L290" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/vitejs/vite/commit/62d7e81ee189d65899bb65f3263ddbd85247b647" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/vitejs/vite/security/advisories/GHSA-xcj6-pq6g-qj4x" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-31486" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="voipmonitor login panel - detect info identify web-based control panels voipmonitor login panel was detected. yanyun discovery login panel voipmonitor cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">VoIPmonitor Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/voipmonitor-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">voipmonitor-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Yanyun</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)voipmonitor&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">VoIPmonitor login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">login</span><span class="nt-tag">panel</span><span class="nt-tag">voipmonitor</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="vodafone vox ui login panel - detect info identify web-based control panels vodafone vox ui login panel was detected. hardik-solanki panel vodafone discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Vodafone Vox UI Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/vodafone-voxui-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">vodafone-voxui-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Hardik-Solanki</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Vodafone Vox UI&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Vodafone Vox UI login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">vodafone</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="void aural rec monitor 9.0.0.1 - sql injection high identify critical remote vulnerabilities void aural rec monitor 9.0.0.1 contains a sql injection vulnerability in svc-login.php. an attacker can send a crafted http request to perform a blind time-based sql injection via the param1 parameter and thus possibly obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site. cve-2021-25899 edoardottt aurall cve cve2021 sqli time-based-sqli vkev void vuln cwe-89" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Void Aural Rec Monitor 9.0.0.1 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2021/CVE-2021-25899.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2021-25899.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> edoardottt</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2021-25899" target="_blank" rel="noopener" class="nt-cve-link">CVE-2021-25899</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)aurall&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Void Aural Rec Monitor 9.0.0.1 contains a SQL injection vulnerability in svc-login.php. An attacker can send a crafted HTTP request to perform a blind time-based SQL injection via the param1 parameter and thus possibly obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized access, data leakage, or data manipulation.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest patch or update provided by the vendor to fix the SQL Injection vulnerability in Void Aural Rec Monitor 9.0.0.1.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">aurall</span><span class="nt-tag">cve</span><span class="nt-tag">cve2021</span><span class="nt-tag">sqli</span><span class="nt-tag">time-based-sqli</span><span class="nt-tag">vkev</span><span class="nt-tag">void</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/all-your-databases-belong-to-me-a-blind-sqli-case-study/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.trustwave.com/en-us/resources/security-resources/security-advisories/?fid=28765" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2021-25899" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/ARPSyndicate/kenzer-templates" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="voilà panel - detect info identify web-based control panels voilà is an open-source tool that turns jupyter notebooks into standalone web applications.
it is commonly used to share ai/ml dashboards and interactive data science tools. rxerium ai detect discovery jupyter notebook panel voila" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Voilà Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/voila-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">voila-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 27, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)voila-notebooks&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Voilà is an open-source tool that turns Jupyter Notebooks into standalone web applications.
It is commonly used to share AI/ML dashboards and interactive data science tools.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">ai</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">jupyter</span><span class="nt-tag">notebook</span><span class="nt-tag">panel</span><span class="nt-tag">voila</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/voila-dashboards/voila" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://voila.readthedocs.io" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="voipmonitor - pre-auth sql injection critical identify critical remote vulnerabilities a sql injection vulnerability in voipmonitor gui before v24.96 allows attackers to escalate privileges to the administrator level. cve-2022-24260 gy741 cve cve2022 sqli unauth vkev voipmonitor vuln cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">VoipMonitor - Pre-Auth SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-24260.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-24260.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> gy741</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-24260" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-24260</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)voipmonitor&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A SQL injection vulnerability in Voipmonitor GUI before v24.96 allows attackers to escalate privileges to the Administrator level.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized accessand data leakage.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches or updates provided by the vendor to fix the SQL injection vulnerability in the VoipMonitor application.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">sqli</span><span class="nt-tag">unauth</span><span class="nt-tag">vkev</span><span class="nt-tag">voipmonitor</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://kerbit.io/research/read/blog/3" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-24260" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.voipmonitor.org/changelog-gui?major=5" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/ARPSyndicate/cvemon" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/ARPSyndicate/kenzer-templates" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="voipmonitor &lt;24.61 - remote code execution critical identify critical remote vulnerabilities voipmonitor prior to 24.61 is susceptible to remote code execution vulnerabilities because of its use of user supplied data via its web interface, allowing  remote unauthenticated users to trigger a remote php code execution vulnerability. cve-2021-30461 shifacyclewala,hackergautam cve cve2021 rce vkev voipmonitor vuln cwe-94" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">VoipMonitor &lt;24.61 - Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2021/CVE-2021-30461.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2021-30461.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> shifacyclewala,hackergautam</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/94.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-94</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2021-30461" target="_blank" rel="noopener" class="nt-cve-link">CVE-2021-30461</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)voipmonitor&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">VoipMonitor prior to 24.61 is susceptible to remote code execution vulnerabilities because of its use of user supplied data via its web interface, allowing  remote unauthenticated users to trigger a remote PHP code execution vulnerability.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade VoipMonitor to version 24.61 or later to mitigate this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2021</span><span class="nt-tag">rce</span><span class="nt-tag">vkev</span><span class="nt-tag">voipmonitor</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://ssd-disclosure.com/ssd-advisory-voipmonitor-unauth-rce/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2021-30461" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://ssd-disclosure.com/ssd-advisory--voipmonitor-unauth-rce" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/ARPSyndicate/cvemon" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/openx-org/BLEN" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="vtiger crm - default login high identify default logins in web-based control panels detected a vtiger crm instance that enabled default admin credentials. icarot default-login vtiger vtiger_crm vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Vtiger CRM - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/vtigercrm-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">vtigercrm-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> icarot</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 17, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Powered by vtiger CRM&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detected a Vtiger CRM instance that enabled default admin credentials.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">vtiger</span><span class="nt-tag">vtiger_crm</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/vtiger-crm/vtigercrm" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://code.vtiger.com/vtiger/vtigercrm" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="vtiger crm v7.2.0 - directory listing medium identify critical remote vulnerabilities vtiger crm v7.2.0 contains a directory traversal vulnerability caused by improper access controls in /libraries and /layout directories, letting attackers display hidden files and list directories, exploit requires no authentication. cve-2020-19363 0x_akoko cve cve2020 exposure listing vkev vtiger cwe-200" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Vtiger CRM v7.2.0 - Directory Listing</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2020/CVE-2020-19363.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2020-19363.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_Akoko</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 12, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2020-19363" target="_blank" rel="noopener" class="nt-cve-link">CVE-2020-19363</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)vtiger CRM&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Vtiger CRM v7.2.0 contains a directory traversal vulnerability caused by improper access controls in /libraries and /layout directories, letting attackers display hidden files and list directories, exploit requires no authentication.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can access sensitive files and directory structures, potentially leading to information disclosure or further exploitation.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest version of Vtiger CRM or apply security patches that enforce proper access controls.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2020</span><span class="nt-tag">exposure</span><span class="nt-tag">listing</span><span class="nt-tag">vkev</span><span class="nt-tag">vtiger</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/EmreOvunc/Vtiger-CRM-Vulnerabilities" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2020-19363" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="vue pacs - panel info identify web-based control panels vue pacs was detected. righettod discovery login pacs panel philips vue" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Vue PACS - Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/vue-pacs-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">vue-pacs-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 14, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)vue pacs&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Vue PACS was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">login</span><span class="nt-tag">pacs</span><span class="nt-tag">panel</span><span class="nt-tag">philips</span><span class="nt-tag">vue</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.usa.philips.com/healthcare/solutions/diagnostic-informatics/enterprise-imaging-pacs" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="vue vben admin - default credentials critical identify critical remote vulnerabilities vue vben admin 2.10.1 contains a broken authentication caused by hardcoded credentials in the backend, letting attackers log in without proper authorization, exploit requires access to the login interface. cve-2025-25570 0x_akoko credentials cve cve2025 default-login vben vue cwe-798" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Vue Vben Admin - Default Credentials</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-25570.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-25570.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_Akoko</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 13, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/798.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-798</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-25570" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-25570</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)vben&#34; || service[&#34;http.body&#34;] matches &#34;(?i)vue-vben-admin&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Vue Vben Admin 2.10.1 contains a broken authentication caused by hardcoded credentials in the backend, letting attackers log in without proper authorization, exploit requires access to the login interface.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can gain unauthorized access to the backend, potentially leading to data theft or system control</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Remove hardcoded credentials and implement proper authentication mechanisms, update to the latest version if available.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">credentials</span><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">default-login</span><span class="nt-tag">vben</span><span class="nt-tag">vue</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/vbenjs/vue-vben-admin" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://doc.vvbin.cn/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wago - remote command execution critical identify critical remote vulnerabilities in multiple products of wago, a vulnerability allows an unauthenticated, remote attacker to create new users and change the device configuration which can result in unintended behavior, denial of service, and full system compromise. cve-2023-1698 xianke cve cve2023 rce vkev vuln wago cwe-78" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">WAGO - Remote Command Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-1698.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-1698.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> xianke</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 30, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/78.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-78</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-1698" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-1698</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wbm/\&#34; html:\&#34;wago&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">In multiple products of WAGO, a vulnerability allows an unauthenticated, remote attacker to create new users and change the device configuration which can result in unintended behavior, Denial of Service, and full system compromise.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability can lead to unauthorized access, data leakage, and potential compromise of the target system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches and updates provided by the vendor to mitigate this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">rce</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">wago</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://onekey.com/blog/security-advisory-wago-unauthenticated-remote-command-execution/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-1698" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://cert.vde.com/en/advisories/VDE-2023-007/" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/codeb0ss/CVE-2023-1698-PoC" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/deIndra/CVE-2023-1698" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wago web based management - default login high identify default logins in web-based control panels identified wago web-based management interfaces that were accessible using default credentials (admin:wago).these interfaces are used to configure and monitor wago programmable logic controllers (plcs) and automation systems. use of factory-default credentials exposed critical ot infrastructure to unauthorized access. biero-el-corridor default-login vuln wago" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">WAGO Web based Management - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/wago/wago-webbased-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">wago-webbased-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> biero-el-corridor</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 2, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)WAGO Ethernet Web-based Management&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Identified WAGO Web-Based Management interfaces that were accessible using default credentials (admin:wago).These interfaces are used to configure and monitor WAGO programmable logic controllers (PLCs) and automation systems. Use of factory-default credentials exposed critical OT infrastructure to unauthorized access.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">vuln</span><span class="nt-tag">wago</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="wapples web application firewall &lt;=6.0 - hardcoded credentials critical identify critical remote vulnerabilities wapples web application firewall through 6.0 contains a hardcoded credentials vulnerability. it contains a hardcoded system account accessible via db/wp.no1, as configured in the /opt/penta/wapples/script/wcc_auto_scaling.py file. an attacker can use this account to access system configuration and confidential information, such as ssl keys, via an https request to the /webapi/ uri on port 443 or 5001. cve-2022-35413 for3stco1d cve cve2022 default-login firewall pentasecurity vkev vuln wapples cwe-798" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">WAPPLES Web Application Firewall &lt;=6.0 - Hardcoded Credentials</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-35413.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-35413.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> For3stCo1d</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/798.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-798</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-35413" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-35413</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Intelligent WAPPLES&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">WAPPLES Web Application Firewall through 6.0 contains a hardcoded credentials vulnerability. It contains a hardcoded system account accessible via db/wp.no1, as configured in the /opt/penta/wapples/script/wcc_auto_scaling.py file. An attacker can use this account to access system configuration and confidential information, such as SSL keys, via an HTTPS request to the /webapi/ URI on port 443 or 5001.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can exploit this vulnerability to gain unauthorized access to the WAPPLES Web Application Firewall.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to a version of WAPPLES Web Application Firewall that does not contain hardcoded credentials or apply the vendor-provided patch to fix the vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">default-login</span><span class="nt-tag">firewall</span><span class="nt-tag">pentasecurity</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">wapples</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://medium.com/@_sadshade/wapples-web-application-firewall-multiple-vulnerabilities-35bdee52c8fb" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-35413" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://azuremarketplace.microsoft.com/en/marketplace/apps/penta-security-systems-inc.wapples_sa_v6?tab=Overview" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-35413" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://www.pentasecurity.com/product/wapples/" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wavlink - access control high identify critical remote vulnerabilities wavlink wn530hg4, wn531g3, wn533a8, and wn551k are susceptible to improper access control via /cgi-bin/exportallsettings.sh, where a crafted post request returns the current configuration of the device, including the administrator password. no authentication is required. the attacker must perform a decryption step, but all decryption information is readily available. cve-2020-10973 arafatansari cve cve2020 exposure vuln wavlink cwe-306" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">WAVLINK - Access Control</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2020/CVE-2020-10973.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2020-10973.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> arafatansari</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/306.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-306</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2020-10973" target="_blank" rel="noopener" class="nt-cve-link">CVE-2020-10973</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)wavlink&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Wavlink WN530HG4, WN531G3, WN533A8, and WN551K are susceptible to improper access control via /cgi-bin/ExportAllSettings.sh, where a crafted POST request returns the current configuration of the device, including the administrator password. No authentication is required. The attacker must perform a decryption step, but all decryption information is readily available.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability can lead to unauthorized access to sensitive information or control of the affected device.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest firmware update provided by the vendor to fix the access control issue.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2020</span><span class="nt-tag">exposure</span><span class="nt-tag">vuln</span><span class="nt-tag">wavlink</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/sudo-jtcsec/CVE/blob/master/CVE-2020-10973" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/sudo-jtcsec/Nyra" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2020-10973" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/Roni-Carta/nyra" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/sudo-jtcsec/CVE/blob/master/CVE-2020-10973-affected_devices" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wavlink ac1200 - information disclosure high identify critical remote vulnerabilities a vulnerability is in the &#39;live_mfg.html&#39; page of the wavlink ac1200, version wavlink-a42w-1.27.6-20180418, which can allow a remote attacker to access this page without any authentication. when processed, it exposes some key information of the manager of router. cve-2021-44260 ritikchaddha ac1200 cve cve2021 exposure vuln wavlink" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">WAVLINK AC1200 - Information Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2021/CVE-2021-44260.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2021-44260.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 6, 2024</span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2021-44260" target="_blank" rel="noopener" class="nt-cve-link">CVE-2021-44260</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)AC1200&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A vulnerability is in the &#39;live_mfg.html&#39; page of the WAVLINK AC1200, version WAVLINK-A42W-1.27.6-20180418, which can allow a remote attacker to access this page without any authentication. When processed, it exposes some key information of the manager of router.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation could lead to sensitive information disclosure.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches and updates from the vendor to address this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">ac1200</span><span class="nt-tag">cve</span><span class="nt-tag">cve2021</span><span class="nt-tag">exposure</span><span class="nt-tag">vuln</span><span class="nt-tag">wavlink</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/zer0yu/CVE_Request/blob/master/WAVLINK/WAVLINK_AC1200_unauthorized_access_vulnerability_first.md" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2021-44260" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wavlink quantum d4g (wl-wn531g3) - information disclosure high identify critical remote vulnerabilities wavlink quantum d4g (wl-wn531g3) running firmware versions m31g3.v5030.201204 and m31g3.v5030.200325 has an access control issue which allows unauthenticated attackers to download configuration data and log files. cve-2022-44356 ritikchaddha cve cve2022 exposure vuln wavlink wn531g3" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">WAVLINK Quantum D4G (WL-WN531G3) - Information Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-44356.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-44356.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 6, 2024</span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-44356" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-44356</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)WN531G3&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">WAVLINK Quantum D4G (WL-WN531G3) running firmware versions M31G3.V5030.201204 and M31G3.V5030.200325 has an access control issue which allows unauthenticated attackers to download configuration data and log files.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation could lead to sensitive information disclosure.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest firmware updates from Wavlink or implement network segmentation to restrict access to the device administration interface.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">exposure</span><span class="nt-tag">vuln</span><span class="nt-tag">wavlink</span><span class="nt-tag">wn531g3</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/strik3r0x1/Vulns/blob/main/Wavlink%20WL-WN531G3.md" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-44356" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wavlink wn530h4 m30h4.v5030.190403 - information disclosure high identify critical remote vulnerabilities wavlink wn530h4 m30h4.v5030.190403 contains an information disclosure vulnerability in the /cgi-bin/exportallsettings.sh endpoint. this can allow an attacker to leak router settings, including cleartext login details, dns settings, and other sensitive information without authentication. cve-2020-12127 arafatansari cve cve2020 exposure vuln wavlink cwe-306" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">WAVLINK WN530H4 M30H4.V5030.190403 - Information Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2020/CVE-2020-12127.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2020-12127.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> arafatansari</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/306.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-306</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2020-12127" target="_blank" rel="noopener" class="nt-cve-link">CVE-2020-12127</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)wavlink&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">WAVLINK WN530H4 M30H4.V5030.190403 contains an information disclosure vulnerability in the /cgi-bin/ExportAllSettings.sh endpoint. This can allow an attacker to leak router settings, including cleartext login details, DNS settings, and other sensitive information without authentication.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can exploit this vulnerability to gain access to sensitive information, such as router configuration settings and user credentials.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest firmware update provided by the vendor to fix the information disclosure vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2020</span><span class="nt-tag">exposure</span><span class="nt-tag">vuln</span><span class="nt-tag">wavlink</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://cerne.xyz/bugs/CVE-2020-12127" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.wavlink.com/en_us/product/WL-WN530H4.html" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2020-12127" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/ARPSyndicate/cvemon" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/ARPSyndicate/kenzer-templates" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wavlink wn530h4 live_api.cgi - command injection critical identify critical remote vulnerabilities a remote command-line injection vulnerability in the /cgi-bin/live_api.cgi endpoint of the wavlink wn530h4 m30h4.v5030.190403 allows an attacker to execute arbitrary linux commands as root without authentication. cve-2020-12124 dhiyaneshdk cve cve2020 rce vkev vuln wavlink cwe-78" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">WAVLINK WN530H4 live_api.cgi - Command Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2020/CVE-2020-12124.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2020-12124.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 28, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/78.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-78</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2020-12124" target="_blank" rel="noopener" class="nt-cve-link">CVE-2020-12124</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)wavlink&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A remote command-line injection vulnerability in the /cgi-bin/live_api.cgi endpoint of the WAVLINK WN530H4 M30H4.V5030.190403 allows an attacker to execute arbitrary Linux commands as root without authentication.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can execute arbitrary Linux commands as root on the WAVLINK WN530H4 device, potentially leading to complete system compromise, data theft, or using the device as a pivot point for further attacks.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply vendor security patches if available or replace the device with a secure alternative. Restrict access to the management interface.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2020</span><span class="nt-tag">rce</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">wavlink</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/db44k/CVE-2020-12124" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://cerne.xyz/bugs/CVE-2020-12124" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.wavlink.com/en_us/product/WL-WN530H4.html" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/Scorpion-Security-Labs/CVE-2020-12124" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wavlink wn530hg4 - improper access control critical identify critical remote vulnerabilities wavlink wn530hg4 m30hg4.v5030.191116 is susceptible to improper access control. it contains a hardcoded encryption/decryption key for its configuration files at /etc_ro/lighttpd/www/cgi-bin/exportallsettings.sh. an attacker can possibly obtain sensitive information, modify data, and/or execute unauthorized operations. cve-2022-34045 arafatansari cve cve2022 exposure vuln wavlink cwe-798" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">WAVLINK WN530HG4 - Improper Access Control</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-34045.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-34045.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> arafatansari</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/798.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-798</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-34045" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-34045</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)wn530hg4&#34; || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)wi-fi app login&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">WAVLINK WN530HG4 M30HG4.V5030.191116 is susceptible to improper access control. It contains a hardcoded encryption/decryption key for its configuration files at /etc_ro/lighttpd/www/cgi-bin/ExportAllSettings.sh. An attacker can possibly obtain sensitive information, modify data, and/or execute unauthorized operations.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can exploit this vulnerability to gain unauthorized access to the router&#39;s settings and potentially compromise the network.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest firmware update provided by the vendor to fix the access control issue.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">exposure</span><span class="nt-tag">vuln</span><span class="nt-tag">wavlink</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://drive.google.com/file/d/1s5uZGC_iSzfCJt9BJ8h-P24vmsrmttrf/view?usp=sharing" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-34045" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/ARPSyndicate/kenzer-templates" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/ARPSyndicate/cvemon" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wavlink wn530hg4 - improper access control high identify critical remote vulnerabilities wavlink wn530hg4 m30hg4.v5030.191116 is susceptible to improper access control. an attacker can obtain usernames and passwords via view-source:http://ip_address/set_safety.shtml?r=52300 and searching for [var syspasswd] and thereby possibly obtain sensitive information, modify data, and/or execute unauthorized operations. cve-2022-34047 for3stco1d cve cve2022 exposure packetstorm router vuln wavlink cwe-668" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">WAVLINK WN530HG4 - Improper Access Control</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-34047.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-34047.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> For3stCo1d</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/668.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-668</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-34047" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-34047</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)wi-fi app login&#34;}) || service[&#34;http.body&#34;] matches &#34;(?i)wn530hg4&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">WAVLINK WN530HG4 M30HG4.V5030.191116 is susceptible to improper access control. An attacker can obtain usernames and passwords via view-source:http://IP_ADDRESS/set_safety.shtml?r=52300 and searching for [var syspasswd] and thereby possibly obtain sensitive information, modify data, and/or execute unauthorized operations.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can exploit this vulnerability to gain unauthorized access to the router&#39;s settings and potentially compromise the network.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest firmware update provided by the vendor to fix the access control issue.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">exposure</span><span class="nt-tag">packetstorm</span><span class="nt-tag">router</span><span class="nt-tag">vuln</span><span class="nt-tag">wavlink</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://drive.google.com/file/d/1sTQdUc12aZvJRFeb5wp8AfPdUEkkU9Sy/view?usp=sharing" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-34047" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="http://packetstormsecurity.com/files/167891/Wavlink-WN530HG4-Password-Disclosure.html" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-34047" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/ARPSyndicate/cvemon" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wavlink wn530hg4 - improper access control medium identify critical remote vulnerabilities wavlink wn530hg4 m30hg4.v5030.191116 is susceptible to improper access control. an attacker can download log files and configuration data via exportlogs.sh and possibly obtain sensitive information, modify data, and/or execute unauthorized operations. cve-2022-34049 for3stco1d cve cve2022 exposure router vuln wavlink cwe-552" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">WAVLINK WN530HG4 - Improper Access Control</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-34049.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-34049.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> For3stCo1d</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/552.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-552</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-34049" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-34049</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)wi-fi app login&#34;}) || service[&#34;http.body&#34;] matches &#34;(?i)wn530hg4&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Wavlink WN530HG4 M30HG4.V5030.191116 is susceptible to improper access control. An attacker can download log files and configuration data via Exportlogs.sh and possibly obtain sensitive information, modify data, and/or execute unauthorized operations.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can exploit this vulnerability to gain unauthorized access to the router&#39;s settings, potentially leading to further compromise of the network or device.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest firmware update provided by the vendor to fix the access control issue.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">exposure</span><span class="nt-tag">router</span><span class="nt-tag">vuln</span><span class="nt-tag">wavlink</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://drive.google.com/file/d/1-eNgq6IS609bq2vB93c_N8jnZrJ2dgNF/view" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-34049" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://drive.google.com/file/d/1ZeSwqu04OghLQXeG7emU-w-Amgadafqx/view?usp=sharing" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://drive.google.com/file/d/1-eNgq6IS609bq2vB93c_N8jnZrJ2dgNF/view?usp=sharing" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-34049" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wavlink wn533a8 - improper access control high identify critical remote vulnerabilities wavlink wn533a8 m33a8.v5030.190716 is susceptible to improper access control. an attacker can obtain usernames and passwords via view-source:http://ip_address/sysinit.shtml?r=52300 and searching for [logincheck(user);] and thereby possibly obtain sensitive information, modify data, and/or execute unauthorized operations. cve-2022-34046 for3stco1d cve cve2022 exposure packetstorm router vuln wavlink cwe-863" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">WAVLINK WN533A8 - Improper Access Control</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-34046.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-34046.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> For3stCo1d</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/863.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-863</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-34046" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-34046</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)wi-fi app login&#34;}) || service[&#34;http.body&#34;] matches &#34;(?i)wavlink&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">WAVLINK WN533A8 M33A8.V5030.190716 is susceptible to improper access control. An attacker can obtain usernames and passwords via view-source:http://IP_ADDRESS/sysinit.shtml?r=52300 and searching for [logincheck(user);] and thereby possibly obtain sensitive information, modify data, and/or execute unauthorized operations.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can exploit this vulnerability to gain unauthorized access to the router&#39;s settings and potentially compromise the entire network.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest firmware update provided by the vendor to fix the access control issue.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">exposure</span><span class="nt-tag">packetstorm</span><span class="nt-tag">router</span><span class="nt-tag">vuln</span><span class="nt-tag">wavlink</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://drive.google.com/file/d/18ECQEqZ296LDzZ0wErgqnNfen1jCn0mG/view?usp=sharing" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-34046" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="http://packetstormsecurity.com/files/167890/Wavlink-WN533A8-Password-Disclosure.html" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-34046" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/ARPSyndicate/cvemon" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wavlink wn535 g3 - improper access control high identify critical remote vulnerabilities wavlink wn535 g3 m35g3r.v5030.180927 is susceptible to improper access control. a vulnerability in /cgi-bin/exportallsettings.sh allows an attacker to execute arbitrary code via a crafted post request and thereby possibly obtain sensitive information, modify data, and/or execute unauthorized operations. cve-2022-34576 arafatansari cve cve2022 exposure vuln wavlink" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">WAVLINK WN535 G3 - Improper Access Control</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-34576.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-34576.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> arafatansari</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-34576" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-34576</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)wavlink&#34; || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)wi-fi app login&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">WAVLINK WN535 G3 M35G3R.V5030.180927 is susceptible to improper access control. A vulnerability in /cgi-bin/ExportAllSettings.sh allows an attacker to execute arbitrary code via a crafted POST request and thereby possibly obtain sensitive information, modify data, and/or execute unauthorized operations.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can exploit this vulnerability to gain unauthorized access to the router&#39;s settings and potentially compromise the network.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest firmware update provided by the vendor to fix the access control issue.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">exposure</span><span class="nt-tag">vuln</span><span class="nt-tag">wavlink</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/pghuanghui/CVE_Request/blob/main/WAVLINK%20WN535%20G3_Sensitive%20information%20leakage.md" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-34576" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/ARPSyndicate/cvemon" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/ARPSyndicate/kenzer-templates" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/tr3ss/gofetch" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wavlink wn535 g3 - information disclosure high identify critical remote vulnerabilities wavlink wn535 g3 m35g3r.v5030.180927 is susceptible to information disclosure in live_check.shtml. an attacker can obtain sensitive router information via execution of the exec cmd function and thereby possibly obtain additional sensitive information, modify data, and/or execute unauthorized operations. cve-2022-31845 arafatansari cve cve2022 exposure vuln wavlink cwe-668" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">WAVLINK WN535 G3 - Information Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-31845.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-31845.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> arafatansari</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/668.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-668</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-31845" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-31845</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)wavlink&#34; || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)wi-fi app login&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">WAVLINK WN535 G3 M35G3R.V5030.180927 is susceptible to information disclosure in live_check.shtml. An attacker can obtain sensitive router information via execution of the exec cmd function and thereby possibly obtain additional sensitive information, modify data, and/or execute unauthorized operations.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can exploit this vulnerability to gain unauthorized access to sensitive information, such as login credentials or network configuration.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest firmware update provided by the vendor to fix the information disclosure vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">exposure</span><span class="nt-tag">vuln</span><span class="nt-tag">wavlink</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/pghuanghui/CVE_Request/blob/main/WAVLINK%20WN535%20G3__check_live.md" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30489" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31845" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wavlink wn535 g3 - information disclosure high identify critical remote vulnerabilities wavlink wn535 g3 m35g3r.v5030.180927 is susceptible to information disclosure in the live_mfg.shtml page. an attacker can obtain sensitive router information via the exec cmd function and possibly obtain additional sensitive information, modify data, and/or execute unauthorized operations. cve-2022-31846 arafatansari cve cve2022 exposure vuln wavlink cwe-668" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">WAVLINK WN535 G3 - Information Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-31846.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-31846.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> arafatansari</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/668.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-668</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-31846" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-31846</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)wavlink&#34; || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)wi-fi app login&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">WAVLINK WN535 G3 M35G3R.V5030.180927 is susceptible to information disclosure in the live_mfg.shtml page. An attacker can obtain sensitive router information via the exec cmd function and possibly obtain additional sensitive information, modify data, and/or execute unauthorized operations.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can exploit this vulnerability to gain unauthorized access to sensitive information, such as router configuration settings and user credentials.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest firmware update provided by the vendor to fix the information disclosure vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">exposure</span><span class="nt-tag">vuln</span><span class="nt-tag">wavlink</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/pghuanghui/CVE_Request/blob/main/WAVLINK%20WN535%20G3__live_mfg.md" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30489" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31846" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/ARPSyndicate/cvemon" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/ARPSyndicate/kenzer-templates" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wavlink wn579 x3 m79x3.v5030.180719 - information disclosure high identify critical remote vulnerabilities wavlink wn579 x3 m79x3.v5030.180719 is susceptible to information disclosure in /cgi-bin/exportallsettings.sh. an attacker can obtain sensitive router information via a crafted post request and thereby possibly obtain additional sensitive information, modify data, and/or execute unauthorized operations. cve-2022-31847 arafatansari cve cve2022 exposure vkev vuln wavlink cwe-425" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">WAVLINK WN579 X3 M79X3.V5030.180719 - Information Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-31847.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-31847.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> arafatansari</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/425.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-425</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-31847" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-31847</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)wavlink&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">WAVLINK WN579 X3 M79X3.V5030.180719 is susceptible to information disclosure in /cgi-bin/ExportAllSettings.sh. An attacker can obtain sensitive router information via a crafted POST request and thereby possibly obtain additional sensitive information, modify data, and/or execute unauthorized operations.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can exploit this vulnerability to gain access to sensitive information, such as router configuration settings and user credentials.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest firmware update provided by the vendor to fix the information disclosure vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">exposure</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">wavlink</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/pghuanghui/CVE_Request/blob/main/WAVLINK%20WN579%20X3__Sensitive%20information%20leakage.md" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31847" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/ARPSyndicate/cvemon" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/ARPSyndicate/kenzer-templates" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wcfm membership &lt;= 2.10.0 - broken access control high identify critical remote vulnerabilities the wcfm membership plugin for wordpress is vulnerable to unauthorized modification and access of data in versions up to, and including, 2.10.0 due to missing capability checks true the ajax actions: wcfm-memberships, wcfm-memberships-manage, and wcfm-memberships-settings. cve-2022-4940 0xanis cve cve2022 vkev wcfm woocommerce wordpress wp-plugin wp-scan cwe-862" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">WCFM Membership &lt;= 2.10.0 - Broken Access Control</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-4940.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-4940.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0xanis</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 24, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/862.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-862</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-4940" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-4940</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)wcfmmp_become_vendor_link&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The WCFM Membership plugin for WordPress is vulnerable to unauthorized modification and access of data in versions up to, and including, 2.10.0 due to missing capability checks true the AJAX actions: wcfm-memberships, wcfm-memberships-manage, and wcfm-memberships-settings.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can modify membership details, approve or deny memberships, and change renewal info, potentially leading to data tampering and unauthorized access.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to WCFM Membership version 2.10.1 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">vkev</span><span class="nt-tag">wcfm</span><span class="nt-tag">woocommerce</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">wp-scan</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wc-multivendor-membership/wcfm-membership-2100-missing-authorization" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;old=2633191%40wc-multivendor-membership&amp;new=2633191%40wc-multivendor-membership&amp;sfp_email=&amp;sfph_mail=" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://wpscan.com/vulnerability/41bdf07c-d707-436b-8cfc-5ef852f0b7f5/" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wcfm woocommerce multivendor marketplace &lt; 3.4.12 - sql injection critical identify critical remote vulnerabilities the wcfm_ajax_controller ajax action of the wcfm marketplace wordpress plugin before 3.4.12, available to unauthenticated and authenticated user, does not properly sanitise multiple parameters before using them in sql statements, leading to sql injections. cve-2021-24849 ritikchaddha cve cve2021 sqli time-based-sqli vuln wc-multivendor-marketplace wclovers wordpress wp wp-plugin wpscan cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">WCFM WooCommerce Multivendor Marketplace &lt; 3.4.12 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2021/CVE-2021-24849.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2021-24849.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 13, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2021-24849" target="_blank" rel="noopener" class="nt-cve-link">CVE-2021-24849</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/wc-multivendor-marketplace&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The wcfm_ajax_controller AJAX action of the WCFM Marketplace WordPress plugin before 3.4.12, available to unauthenticated and authenticated user, does not properly sanitise multiple parameters before using them in SQL statements, leading to SQL injections.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can execute SQL injection through multiple unsanitized parameters, potentially gaining access to all WooCommerce marketplace data including customer and vendor information.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Fixed in 3.4.12</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2021</span><span class="nt-tag">sqli</span><span class="nt-tag">time-based-sqli</span><span class="nt-tag">vuln</span><span class="nt-tag">wc-multivendor-marketplace</span><span class="nt-tag">wclovers</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">wpscan</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wpscan.com/vulnerability/763c08a0-4b2b-4487-b91c-be6cc2b9322e/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2021-24849" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://wordpress.org/plugins/wc-multivendor-marketplace/" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wd my cloud panel - detect info identify web-based control panels  dhiyaneshdk detect discovery login mycloud panel wd western_digital" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">WD My Cloud Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/wd-mycloud-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">wd-mycloud-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 26, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-1074357885&#34;</code></div>
  <div class="nt-tags"><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">login</span><span class="nt-tag">mycloud</span><span class="nt-tag">panel</span><span class="nt-tag">wd</span><span class="nt-tag">western_digital</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.zerodayinitiative.com/blog/2023/4/19/cve-2022-29844-a-classic-buffer-overflow-on-the-western-digital-my-cloud-pro-series-pr4100" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="wp directory kit &lt; 1.5.0 - unauthenticated email exposure medium identify critical remote vulnerabilities wp directory kit plugin for wordpress &lt;= 1.4.9 contains a sensitive information exposure caused by improper access control in wdk_public_action ajax handler, letting unauthenticated attackers extract email addresses of users with directory kit-specific roles. cve-2025-13920 0x_akoko cve cve2025 exposure unauth vkev wordpress wp-plugin wpdirectorykit cwe-862" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">WP Directory Kit &lt; 1.5.0 - Unauthenticated Email Exposure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-13920.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-13920.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_Akoko</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 17, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/862.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-862</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-13920" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-13920</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/wpdirectorykit/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">WP Directory Kit plugin for WordPress &lt;= 1.4.9 contains a sensitive information exposure caused by improper access control in wdk_public_action AJAX handler, letting unauthenticated attackers extract email addresses of users with Directory Kit-specific roles.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can extract email addresses of users with specific roles, leading to privacy breaches.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest version beyond 1.4.9.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">exposure</span><span class="nt-tag">unauth</span><span class="nt-tag">vkev</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">wpdirectorykit</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/8905dcc7-d3c8-4ae8-818c-df3e6ed2ad9c" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-13920" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://wordpress.org/plugins/wpdirectorykit/" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wp directory kit &lt;= 1.4.3 - unauthenticated sql injection high identify critical remote vulnerabilities the wp directory kit plugin for wordpress is vulnerable to sql injection via the &#39;columns_search&#39; parameter of the select_2_ajax() function in all versions up to, and including, 1.4.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing sql query. this makes it possible for unauthenticated attackers to append additional sql queries into already existing queries that can be used to extract sensitive information from the database. cve-2025-13138 shivam kamboj cve cve2025 wordpress wp-plugin sqli wpdirectorykit unauth wp time-based cwe-89" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">WP Directory Kit &lt;= 1.4.3 - Unauthenticated SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-13138.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-13138.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Shivam Kamboj</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 5, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-13138" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-13138</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)plugins/wpdirectorykit/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The WP Directory Kit plugin for WordPress is vulnerable to SQL Injection via the &#39;columns_search&#39; parameter of the select_2_ajax() function in all versions up to, and including, 1.4.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An unauthenticated attacker can extract sensitive information from the WordPress database including user credentials, posts, and other data.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update WP Directory Kit plugin to version 1.4.4 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">sqli</span><span class="nt-tag">wpdirectorykit</span><span class="nt-tag">unauth</span><span class="nt-tag">wp</span><span class="nt-tag">time-based</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wpdirectorykit/wp-directory-kit-143-unauthenticated-sql-injection-via-select-2-ajax-function" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://plugins.trac.wordpress.org/browser/wpdirectorykit/tags/1.4.3/application/controllers/Wdk_frontendajax.php#L546" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wp directory kit &lt;= 1.4.4 - authentication bypass critical identify critical remote vulnerabilities the wp directory kit plugin for wordpress version 1.4.4 and below contains an authentication bypass vulnerability in its auto-login functionality. the vulnerability allows unauthenticated attackers to gain administrative access by exploiting a cryptographically weak token generation mechanism that uses only the first 10 characters of md5(user_id). for user_id=1 (typically admin), the token is always predictable. cve-2025-13390 maxthepm auth-bypass cve cve2025 vkev wordpress wp wp-plugin wpdirectorykit cwe-287" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">WP Directory Kit &lt;= 1.4.4 - Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-13390.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-13390.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> maxthepm</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 23, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/287.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-287</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-13390" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-13390</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/wpdirectorykit&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The WP Directory Kit plugin for WordPress version 1.4.4 and below contains an authentication bypass vulnerability in its auto-login functionality. The vulnerability allows unauthenticated attackers to gain administrative access by exploiting a cryptographically weak token generation mechanism that uses only the first 10 characters of MD5(user_id). For user_id=1 (typically admin), the token is always predictable.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can gain administrative access, leading to full site takeover.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest version beyond 1.4.4.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">vkev</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">wpdirectorykit</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://plugins.trac.wordpress.org/browser/wpdirectorykit/trunk/actions.php#L116" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://ryankozak.com/posts/cve-2025-13390/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/d0n601/CVE-2025-13390" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-13390" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wp fastest cache 1.2.2 - sql injection high identify critical remote vulnerabilities the wp fastest cache wordpress plugin before 1.2.2 does not properly sanitise and escape a parameter before using it in a sql statement, leading to a sql injection exploitable by unauthenticated users. cve-2023-6063 dhiyaneshdk cve cve2023 sqli time-based-sqli vuln wordpress wp-fastest-cache wp-plugin wpfastestcache wpscan cwe-89" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">WP Fastest Cache 1.2.2 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-6063.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-6063.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 14, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-6063" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-6063</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/wp-fastest-cache/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The WP Fastest Cache WordPress plugin before 1.2.2 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can execute SQL injection to extract the complete WordPress database including user credentials and site data.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Fixed in 1.2.2</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">sqli</span><span class="nt-tag">time-based-sqli</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp-fastest-cache</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">wpfastestcache</span><span class="nt-tag">wpscan</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wpscan.com/blog/unauthenticated-sql-injection-vulnerability-addressed-in-wp-fastest-cache-1-2-2/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://wordpress.org/plugins/wp-fastest-cache/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/motikan2010/CVE-2023-6063-PoC" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-6063" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://wpscan.com/vulnerability/30a74105-8ade-4198-abe2-1c6f2967443e/" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wp google maps &lt; 9.0.48 - cross-site scripting high identify critical remote vulnerabilities wp google maps wordpress plugin &lt; 9.0.48 contains a stored xss vulnerability caused by unsanitized user input in ajax actions, letting unauthenticated attackers execute scripts via stored payloads. cve-2025-11307 0x_akoko cache-poisoning cve cve2025 vkev wordpress wp wp-plugin xss cwe-79" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">WP Google Maps &lt; 9.0.48 - Cross-Site Scripting</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-11307.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-11307.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_Akoko</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 26, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-79</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-11307" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-11307</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)wp-google-maps&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">WP Google Maps WordPress plugin &lt; 9.0.48 contains a stored XSS vulnerability caused by unsanitized user input in AJAX actions, letting unauthenticated attackers execute scripts via stored payloads.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can execute arbitrary scripts in users&#39; browsers, leading to session hijacking or defacement.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to version 9.0.48 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cache-poisoning</span><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">vkev</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">xss</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wpscan.com/vulnerability/f5b21a05-7a51-4530-9e07-4700f00eeca3/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-11307" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wp hotel booking &lt; 1.10.4 - php object injection critical identify critical remote vulnerabilities the wp-hotel-booking plugin through 1.10.2 for wordpress allows remote attackers to execute arbitrary code because of an unserialize operation on the thimpress_hotel_booking_1 cookie in load in includes/class-wphb-sessions.php. cve-2020-29047 dhiyaneshdk cve cve2020 rce thimpress vkev vuln wordpress wp wp-hotel-booking wp-plugin cwe-502" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">WP Hotel Booking &lt; 1.10.4 - PHP Object Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2020/CVE-2020-29047.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2020-29047.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 27, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/502.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-502</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2020-29047" target="_blank" rel="noopener" class="nt-cve-link">CVE-2020-29047</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/wp-hotel-booking/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The wp-hotel-booking plugin through 1.10.2 for WordPress allows remote attackers to execute arbitrary code because of an unserialize operation on the thimpress_hotel_booking_1 cookie in load in includes/class-wphb-sessions.php.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can exploit PHP object injection to execute arbitrary code, leading to complete server compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to WP Hotel Booking version 1.10.3 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2020</span><span class="nt-tag">rce</span><span class="nt-tag">thimpress</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-hotel-booking</span><span class="nt-tag">wp-plugin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wordpress.org/plugins/wp-hotel-booking/#developers" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/20142995/nuclei-templates" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2020-29047" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wp hotel booking &lt;= 2.0.7 - sql injection critical identify critical remote vulnerabilities wp hotel booking wordpress plugin before 2.0.8 contains a sql injection caused by lack of authorization, csrf checks, and input escaping in a function hooked to admin_init, letting unauthenticated users perform sql injections, exploit requires no authentication. cve-2023-5652 shivam kamboj,s4e-io cve cve2023 sqli unauth wordpress wp wp-hotel-booking wp-plugin cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">WP Hotel Booking &lt;= 2.0.7 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-5652.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-5652.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Shivam Kamboj,s4e-io</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 26, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-5652" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-5652</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/wp-hotel-booking/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">WP Hotel Booking WordPress plugin before 2.0.8 contains a SQL injection caused by lack of authorization, CSRF checks, and input escaping in a function hooked to admin_init, letting unauthenticated users perform SQL injections, exploit requires no authentication.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can execute arbitrary SQL commands, potentially leading to data theft, modification, or deletion.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to version 2.0.8 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">sqli</span><span class="nt-tag">unauth</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-hotel-booking</span><span class="nt-tag">wp-plugin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-hotel-booking/wp-hotel-booking-207-unauthenticated-sql-injection" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-5652" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wp hotel booking &lt;= 2.1.0 - sql injection critical identify critical remote vulnerabilities the wp hotel booking plugin for wordpress is vulnerable to sql injection via the &#39;room_type&#39; parameter of the /wphb/v1/rooms/search-rooms rest api endpoint in all versions up to, and including, 2.1.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing sql query. this makes it possible for unauthenticated attackers to append additional sql queries into already existing queries that can be used to extract sensitive information from the database. cve-2024-3605 shivam kamboj cve cve2024 sqli unauth vkev wordpress wp wp-hotel-booking wp-plugin cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">WP Hotel Booking &lt;= 2.1.0 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-3605.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-3605.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Shivam Kamboj</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 6, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-3605" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-3605</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/wp-hotel-booking/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The WP Hotel Booking plugin for WordPress is vulnerable to SQL Injection via the &#39;room_type&#39; parameter of the /wphb/v1/rooms/search-rooms REST API endpoint in all versions up to, and including, 2.1.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can execute arbitrary SQL queries, potentially leading to data leakage or database compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest version of WP Hotel Booking plugin that addresses this vulnerability, or apply security patches provided by the vendor.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">sqli</span><span class="nt-tag">unauth</span><span class="nt-tag">vkev</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-hotel-booking</span><span class="nt-tag">wp-plugin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-3605" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wp popup builder popup forms and marketing lead generation &lt;= 1.3.5 - arbitrary shortcode execution high identify critical remote vulnerabilities the the wp popup builder popup forms and marketing lead generation plugin for wordpress is vulnerable to arbitrary shortcode execution via the wp_ajax_nopriv_shortcode_api_add ajax action in all versions up to, and including, 1.3.5. this is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. this makes it possible for unauthenticated attackers to execute arbitrary shortcodes. cve-2024-9061 s4e-io cve cve2024 shortcode vuln wordpress wp wp-plugin wp-popup-builder cwe-94" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">WP Popup Builder Popup Forms and Marketing Lead Generation &lt;= 1.3.5 - Arbitrary Shortcode Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-9061.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-9061.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> s4e-io</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 23, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/94.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-94</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-9061" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-9061</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/wp-popup-builder/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The The WP Popup Builder Popup Forms and Marketing Lead Generation plugin for WordPress is vulnerable to arbitrary shortcode execution via the wp_ajax_nopriv_shortcode_Api_Add AJAX action in all versions up to, and including, 1.3.5. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can execute arbitrary shortcodes through the AJAX action, potentially leading to information disclosure, privilege escalation, or remote code execution depending on available shortcodes in the WordPress installation.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update WP Popup Builder plugin to a version later than 1.3.5 that properly validates values before executing do_shortcode in the wp_ajax_nopriv_shortcode_Api_Add AJAX action.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">shortcode</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">wp-popup-builder</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-9061" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0cac1dc0-87dc-43eb-9db1-638a91200b43?source=cve" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/RandomRobbieBF/CVE-2024-9061" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wp query console &lt;= 1.0 - remote code execution critical identify critical remote vulnerabilities improper control of generation of code (&#39;code injection&#39;) vulnerability in lubus wp query console allows code injection.this issue affects wp query console- from n/a through 1.0. cve-2024-50498 s4e-io cve cve2024 rce vkev vuln wordpress wp wp-plugin wp-query-console cwe-94" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">WP Query Console &lt;= 1.0 - Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-50498.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-50498.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> s4e-io</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 28, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/94.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-94</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-50498" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-50498</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)wp-content/plugins/wp-query-console/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Improper Control of Generation of Code (&#39;Code Injection&#39;) vulnerability in LUBUS WP Query Console allows Code Injection.This issue affects WP Query Console- from n/a through 1.0.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can exploit vulnerabilities to compromise the system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest patched version addressing CVE-2024-50498.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">rce</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">wp-query-console</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/RandomRobbieBF/CVE-2024-50498" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-query-console/wp-query-console-10-unauthenticated-remote-code-execution" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://patchstack.com/database/vulnerability/wp-query-console/wordpress-wp-query-console-plugin-1-0-remote-code-execution-rce-vulnerability?_s_id=cve" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-50498" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wp responsive images &lt;= 1.0 - arbitrary file read high identify critical remote vulnerabilities wp responsive images plugin for wordpress &lt;= 1.0 contains a path traversal caused by improper sanitization of the &#39;src&#39; parameter, letting unauthenticated attackers read arbitrary files on the server. cve-2026-1557 shivam kamboj cve cve2026 lfi vkev wordpress wp wp-plugin wp-responsive-images" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">WP Responsive Images &lt;= 1.0 - Arbitrary File Read</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2026/CVE-2026-1557.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2026-1557.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Shivam Kamboj</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 12, 2026</span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2026-1557" target="_blank" rel="noopener" class="nt-cve-link">CVE-2026-1557</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/wp-responsive-images/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">WP Responsive Images plugin for WordPress &lt;= 1.0 contains a path traversal caused by improper sanitization of the &#39;src&#39; parameter, letting unauthenticated attackers read arbitrary files on the server.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">nauthenticated attackers can read arbitrary files, potentially exposing sensitive information.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest version of WP Responsive Images plugin.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2026</span><span class="nt-tag">lfi</span><span class="nt-tag">vkev</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">wp-responsive-images</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-responsive-images/wp-responsive-images-10-unauthenticated-path-traversal-to-arbitrary-file-read-via-src" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1557" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wp travel engine &lt;= 5.7.9 - sql injection critical identify critical remote vulnerabilities wp travel engine 5.7.9 and earlier contains a sql injection caused by improper neutralization of special elements used in an sql command, letting attackers execute arbitrary sql queries, exploit requires user interaction. cve-2024-30502 shivam kamboj cve cve2024 sqli unauth wordpress wp wp-plugin wp-travel-engine cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">WP Travel Engine &lt;= 5.7.9 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-30502.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-30502.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Shivam Kamboj</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 7, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-30502" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-30502</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/wp-travel-engine/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">WP Travel Engine 5.7.9 and earlier contains a SQL injection caused by improper neutralization of special elements used in an SQL command, letting attackers execute arbitrary SQL queries, exploit requires user interaction.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can execute arbitrary SQL queries, potentially leading to data theft, modification, or deletion.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest version of WP Travel Engine.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">sqli</span><span class="nt-tag">unauth</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">wp-travel-engine</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-travel-engine/wp-travel-engine-579-unauthenticated-sql-injection" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://patchstack.com/database/wordpress/plugin/wp-travel-engine/vulnerability/wordpress-wp-travel-engine-plugin-5-7-9-unauth-blind-sql-injection-vulnerability" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://plugins.trac.wordpress.org/changeset?old_path=/wp-travel-engine/tags/5.7.9&amp;new_path=/wp-travel-engine/tags/5.8.0&amp;sfp_email=&amp;sfph_mail=" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-30502" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wp umbrella update backup restore &amp; monitoring &lt;= 2.17.0 - local file inclusion critical identify critical remote vulnerabilities the wp umbrella: update backup restore &amp; monitoring plugin for wordpress is vulnerable to local file inclusion in all versions up to, and including, 2.17.0 via the &#39;filename&#39; parameter of the &#39;umbrella-restore&#39; action. this makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any php code in those files. this can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included. cve-2024-12209 s4e-io cve cve2024 lfi vkev vuln wordpress wp wp-health wp-plugin cwe-98" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">WP Umbrella Update Backup Restore &amp; Monitoring &lt;= 2.17.0 - Local File Inclusion</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-12209.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-12209.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> s4e-io</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 9, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/98.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-98</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-12209" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-12209</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/wp-health&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The WP Umbrella: Update Backup Restore &amp; Monitoring plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.17.0 via the &#39;filename&#39; parameter of the &#39;umbrella-restore&#39; action. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can exploit local file inclusion through the filename parameter in the umbrella-restore action to read arbitrary server files including /etc/passwd, execute PHP code, and gain complete server compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Validate and sanitize user inputs to prevent directory traversal. Use a whitelist approach for file paths and restrict file access to intended directories only.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">lfi</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-health</span><span class="nt-tag">wp-plugin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/RandomRobbieBF/CVE-2024-12209" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://plugins.trac.wordpress.org/browser/wp-health/tags/v2.16.4/src/Actions/RestoreRouter.php#L45" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;old=3202883%40wp-health&amp;new=3202883%40wp-health&amp;sfp_email=&amp;sfph_mail=" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c74ce3e8-cab9-4cc6-a1ad-1e51f7268474?source=cve" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wp user &lt;= 7.0 - unauthenticated sqli critical identify critical remote vulnerabilities the wp user wordpress plugin through 7.0 does not properly sanitize and escape a parameter before using it in a sql statement, leading to a sql injection exploitable by unauthenticated users. cve-2022-4049 theamanrawat cve cve2022 sqli time-based-sqli unauth vuln wordpress wp wp-plugin wp-user wp_user_project wpscan cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">WP User &lt;= 7.0 - Unauthenticated SQLi</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-4049.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-4049.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> theamanrawat</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 17, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-4049" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-4049</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/wp-user/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The WP User WordPress plugin through 7.0 does not properly sanitize and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can execute time-based blind SQL injection through the id parameter in wpuser_group_action AJAX endpoint, potentially extracting sensitive database information including user credentials, personal data, and WordPress configuration.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update WP User plugin to a version later than 7.0 that properly sanitizes and parameterizes the id parameter in admin-ajax.php.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">sqli</span><span class="nt-tag">time-based-sqli</span><span class="nt-tag">unauth</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">wp-user</span><span class="nt-tag">wp_user_project</span><span class="nt-tag">wpscan</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wpscan.com/vulnerability/9b0781e2-ad62-4308-bafc-d45b9a2472be" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://wordpress.org/plugins/wp-user/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-4049" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/cyllective/CVEs" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wp visitor statistics (real time traffic) &lt; 6.9 - sql injection critical identify critical remote vulnerabilities the plugin does not escape user input which is concatenated to an sql query, allowing unauthenticated visitors to conduct sql injection attacks. cve-2023-0600 r3y3r53,j4vaovo cve cve2023 plugins-market sqli time-based-sqli unauth vkev vuln wordpress wp wp-plugin wp-stats-manager wpscan cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">WP Visitor Statistics (Real Time Traffic) &lt; 6.9 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-0600.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-0600.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> r3Y3r53,j4vaovo</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 17, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-0600" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-0600</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)wp-stats-manager&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The plugin does not escape user input which is concatenated to an SQL query, allowing unauthenticated visitors to conduct SQL Injection attacks.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can execute time-based SQL injection through the visitorId parameter to extract the complete WordPress database including user credentials and site statistics.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Fixed in version 6.9</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">plugins-market</span><span class="nt-tag">sqli</span><span class="nt-tag">time-based-sqli</span><span class="nt-tag">unauth</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">wp-stats-manager</span><span class="nt-tag">wpscan</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wpscan.com/vulnerability/8f46df4d-cb80-4d66-846f-85faf2ea0ec4" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-0600" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/truocphan/VulnBox" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wp-optimize wordpress plugin &lt; 3.2.13 - cross-site scripting medium identify critical remote vulnerabilities the wp-optimize wordpress plugin before 3.2.13 and srbtranslatin wordpress plugin before 2.4.1 are vulnerable to cross-site scripting due to a third-party library that improperly handles html character escaping. cve-2023-1119 ritikchaddha cve cve2023 vkev vuln wordpress wp wp-optimize wp-plugin xss cwe-79" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">WP-Optimize WordPress plugin &lt; 3.2.13 - Cross-Site Scripting</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-1119.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-1119.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 13, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-79</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-1119" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-1119</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/wp-optimize&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The WP-Optimize WordPress plugin before 3.2.13 and SrbTransLatin WordPress plugin before 2.4.1 are vulnerable to cross-site scripting due to a third-party library that improperly handles HTML character escaping.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can inject malicious JavaScript through search parameters due to improper HTML character escaping in a third-party library, enabling theft of WordPress user session cookies.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Users are recommended to upgrade WP-Optimize to version 3.2.13 and SrbTransLatin to version 2.4.1 to mitigate the vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-optimize</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">xss</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wpscan.com/vulnerability/1119" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-1119" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wp-recall – plugin &lt;= 16.26.10 - unauthenticated sql injection high identify critical remote vulnerabilities the wp-recall – registration, profile, commerce &amp; more plugin for wordpress is vulnerable to sql injection via the &#39;databeat&#39; parameter in all versions up to, and including, 16.26.10 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing sql query.  this makes it possible for unauthenticated attackers to append additional sql queries into already existing queries that can be used to extract sensitive information from the database. cve-2025-1323 iamnoooob,rootxharsh,pdresearch cve cve2025 sqli vuln wordpress wp wp-plugin wp-recall cwe-89" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">WP-Recall – Plugin &lt;= 16.26.10 - Unauthenticated SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-1323.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-1323.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> iamnoooob,rootxharsh,pdresearch</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 12, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-1323" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-1323</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/wp-recall/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The WP-Recall – Registration, Profile, Commerce &amp; More plugin for WordPress is vulnerable to SQL Injection via the &#39;databeat&#39; parameter in all versions up to, and including, 16.26.10 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can execute arbitrary SQL queries through time-based blind SQL injection in the databeat parameter, leading to extraction of sensitive database information including user credentials and personal data.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to version 16.26.12, or a newer patched version</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">sqli</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">wp-recall</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-recall/wp-recall-registration-profile-commerce-more-162610-unauthenticated-sql-injection" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ae5b4d81-c2f1-4d0d-b7b0-5556bf0451f5?source=cve" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wpengine wpgraphql 0.2.3 - unauthenticated comment posting medium identify critical remote vulnerabilities the createcomment mutation in the wpgraphql 0.2.3 plugin for wordpress allows unauthenticated users to post comments on any article, even when &#39;allow comment&#39; is disabled. cve-2019-9881 intelligent-ears cve cve2019 unauth vkev vuln wordpress wp wp-graphql wp-plugin wpengine cwe-306" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">WPEngine WPGraphQL 0.2.3 - Unauthenticated Comment Posting</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2019/CVE-2019-9881.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2019-9881.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> intelligent-ears</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 15, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/306.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-306</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2019-9881" target="_blank" rel="noopener" class="nt-cve-link">CVE-2019-9881</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)WordPress\&#34; \&#34;graphql&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The createComment mutation in the WPGraphQL 0.2.3 plugin for WordPress allows unauthenticated users to post comments on any article, even when &#39;allow comment&#39; is disabled.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can exploit this vulnerability to post unauthorized comments on WordPress posts, potentially leading to content manipulation and defacement.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update WPGraphQL to version 0.3.0 or later to fix this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2019</span><span class="nt-tag">unauth</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-graphql</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">wpengine</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2019-9881" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/wp-graphql/wp-graphql/releases/tag/v0.3.0" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.pentestpartners.com/security-blog/pwning-wordpress-graphql/" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://wpvulndb.com/vulnerabilities/9282" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wpengine wpgraphql 0.2.3 - unauthenticated user information disclosure critical identify critical remote vulnerabilities an issue was discovered in the wpgraphql 0.2.3 plugin for wordpress. by querying the &#39;users&#39; rootquery, it is possible, for an unauthenticated attacker, to retrieve all wordpress users details such as email address, role, and username. cve-2019-9880 intelligent-ears cve cve2019 info-leak unauth vkev vuln wordpress wp wp-graphql wp-plugin wpengine cwe-306" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">WPEngine WPGraphQL 0.2.3 - Unauthenticated User Information Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2019/CVE-2019-9880.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2019-9880.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> intelligent-ears</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 17, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/306.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-306</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2019-9880" target="_blank" rel="noopener" class="nt-cve-link">CVE-2019-9880</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/wp-graphql/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An issue was discovered in the WPGraphQL 0.2.3 plugin for WordPress. By querying the &#39;users&#39; RootQuery, it is possible, for an unauthenticated attacker, to retrieve all WordPress users details such as email address, role, and username.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can exploit this vulnerability to enumerate all WordPress users and extract sensitive information including email addresses, usernames, and user roles without authentication.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update WPGraphQL to version 0.3.0 or later to fix this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2019</span><span class="nt-tag">info-leak</span><span class="nt-tag">unauth</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-graphql</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">wpengine</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="http://packetstormsecurity.com/files/153025/WordPress-WPGraphQL-0.2.3-Authentication-Bypass-Information-Disclosure.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/pentestpartners/snippets/blob/master/wp-graphql0.2.3_exploit.py" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/wp-graphql/wp-graphql/releases/tag/v0.3.0" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://www.pentestpartners.com/security-blog/pwning-wordpress-graphql/" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wpmobile.app &lt;= 11.56 - open redirect high identify critical remote vulnerabilities the wpmobile.app plugin for wordpress is vulnerable to open redirect in all versions up to, and including, 11.56. this is due to insufficient validation on the redirect url supplied via the &#39;redirect&#39; parameter. this makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully trick them into performing an action. cve-2024-13888 s4e-io cve cve2024 redirect vuln wordpress wp wp-plugin wpappninja cwe-601" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">WPMobile.App &lt;= 11.56 - Open Redirect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-13888.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-13888.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> s4e-io</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 20, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/601.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-601</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-13888" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-13888</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/wpappninja&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The WPMobile.App plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 11.56. This is due to insufficient validation on the redirect URL supplied via the &#39;redirect&#39; parameter. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully trick them into performing an action.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can redirect users to malicious phishing sites or credential harvesting pages via the redirect parameter.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update WPMobile.App plugin to a version newer than 11.56.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">redirect</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">wpappninja</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wpappninja/wpmobileapp-1156-open-redirect-via-redirect-parameter" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-13888" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wps hide login &lt;= 1.5.2.2  - login page bypass high identify critical remote vulnerabilities wps-hide-login plugin before 1.5.3 for wordpress contains an action=confirmaction protection bypass, letting attackers bypass security checks, exploit requires sending crafted requests. cve-2019-15823 pussycat0x cve cve2019 wordpress wp-plugin wp disclosure wps-hide-login vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">WPS Hide Login &lt;= 1.5.2.2  - Login Page Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2019/CVE-2019-15823.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2019-15823.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 7, 2026</span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2019-15823" target="_blank" rel="noopener" class="nt-cve-link">CVE-2019-15823</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/wps-hide-login&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">WPS-Hide-Login plugin before 1.5.3 for WordPress contains an action=confirmaction protection bypass, letting attackers bypass security checks, exploit requires sending crafted requests.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can bypass login protection, potentially leading to unauthorized access.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to version 1.5.3 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2019</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">wp</span><span class="nt-tag">disclosure</span><span class="nt-tag">wps-hide-login</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://web.archive.org/web/20230601185557/https://secupress.me/blog/wps-hide-login-v1-5-2-2-multiples-vulnerabilities/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://web.archive.org/web/20230711062924/https://wpscan.com/vulnerability/9469/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wps hide login &lt;= 1.9.15.2 - login page disclosure medium identify critical remote vulnerabilities the wps hide login plugin for wordpress is vulnerable to login page disclosure in all versions up to, and including, 1.9.15.2. this is due to a bypass that is created when the &#39;action=postpass&#39; parameter is supplied. this makes it possible for attackers to easily discover any login page that may have been hidden by the plugin. cve-2024-2473 popcorn94,rodtvs cve cve2024 disclosure vkev vuln wordpress wp wp-plugin wps-hide-login cwe-200" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">WPS Hide Login &lt;= 1.9.15.2 - Login Page Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-2473.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-2473.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> popcorn94,rodtvs</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 15, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-2473" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-2473</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/wps-hide-login&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The WPS Hide Login plugin for WordPress is vulnerable to Login Page Disclosure in all versions up to, and including, 1.9.15.2. This is due to a bypass that is created when the &#39;action=postpass&#39; parameter is supplied. This makes it possible for attackers to easily discover any login page that may have been hidden by the plugin.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can discover hidden WordPress login pages by bypassing the WPS Hide Login plugin&#39;s protection mechanism.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update WPS Hide Login plugin to a version newer than 1.9.15.2.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">disclosure</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">wps-hide-login</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wps-hide-login/wps-hide-login-19152-login-page-disclosure" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-2473" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="ws-ftp ad hoc transfer panel - detect info identify web-based control panels ws_ftp ad hoc panel was detected. johnk3r ad-hoc detect discovery login panel progress wsftp" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">WS-FTP Ad Hoc Transfer Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/adhoc-transfer-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">adhoc-transfer-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> johnk3r</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 14, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)ad hoc transfer&#34;}) || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)ws_ftp server web transfer&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">WS_FTP Ad Hoc panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">ad-hoc</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">login</span><span class="nt-tag">panel</span><span class="nt-tag">progress</span><span class="nt-tag">wsftp</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="wso2 carbon management console &lt;=5.10 - cross-site scripting medium identify critical remote vulnerabilities wso2 management console through 5.10 is susceptible to reflected cross-site scripting which can be exploited by tampering a request parameter in management console. this can be performed in both authenticated and unauthenticated requests. cve-2020-17453 madrobot cve cve2020 vkev vuln wso2 xss cwe-79" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">WSO2 Carbon Management Console &lt;=5.10 - Cross-Site Scripting</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2020/CVE-2020-17453.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2020-17453.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> madrobot</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-79</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2020-17453" target="_blank" rel="noopener" class="nt-cve-link">CVE-2020-17453</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1398055326&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">WSO2 Management Console through 5.10 is susceptible to reflected cross-site scripting which can be exploited by tampering a request parameter in Management Console. This can be performed in both authenticated and unauthenticated requests.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute arbitrary JavaScript code in the context of the victim&#39;s browser, leading to potential data theft, session hijacking, or defacement of the affected application.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to a patched version of WSO2 Carbon Management Console (5.11 or above) or apply the provided security patch to mitigate this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2020</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">wso2</span><span class="nt-tag">xss</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://docs.wso2.com/display/Security/Security+Advisory+WSO2-2020-1132" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2020-17453" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://twitter.com/JacksonHHax/status/1374681422678519813" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2021/WSO2-2020-1132/" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/ARPSyndicate/cvemon" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wso2 management console - authentication bypass medium identify critical remote vulnerabilities an authentication bypass vulnerability exists in the management console of multiple wso2 products. a malicious actor with access to the console can manipulate the request uri to bypass authentication and access certain restricted resources, resulting in partial information disclosure. the known exposure from this issue is limited to memory statistics. while the vulnerability does not allow full account compromise, it still enables unauthorized access to internal system details. cve-2025-5605 dhiyaneshdk auth-bypass cve cve2025 vkev wso2 cwe-290" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">WSO2 Management Console - Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-5605.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-5605.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 30, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/290.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-290</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-5605" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-5605</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1398055326&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An authentication bypass vulnerability exists in the Management Console of multiple WSO2 products. A malicious actor with access to the console can manipulate the request URI to bypass authentication and access certain restricted resources, resulting in partial information disclosure. The known exposure from this issue is limited to memory statistics. While the vulnerability does not allow full account compromise, it still enables unauthorized access to internal system details.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can bypass authentication to access internal memory statistics, leading to partial information disclosure.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply security patches as per WSO2-2025-4115 advisory to enforce proper authentication on Management Console endpoints.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">vkev</span><span class="nt-tag">wso2</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://blog.lexfo.fr/wso2.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-5605" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2025/WSO2-2025-4115/" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wso2 management console default login high identify default logins in web-based control panels wso2 management console default admin credentials were discovered. cocxanh default-login vuln wso2 cwe-522" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">WSO2 Management Console Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/wso2/wso2-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">wso2-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> cocxanh</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/522.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-522</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;WSO2 Management Console&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">WSO2 Management Console default admin credentials were discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">vuln</span><span class="nt-tag">wso2</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://docs.wso2.com/display/UES100/Accessing+the+Management+Console" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://is.docs.wso2.com/en/5.12.0/learn/multi-attribute-login/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="wso2 management console login panel - detect info identify web-based control panels wso2 management console login panel was detected. dhiyaneshdk,johnk3r discovery edb panel wso2 cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">WSO2 Management Console Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/wso2-management-console.yaml" target="_blank" rel="noopener" class="nt-source-link">wso2-management-console.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDK,johnk3r</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1398055326&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">WSO2 Management Console login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">edb</span><span class="nt-tag">panel</span><span class="nt-tag">wso2</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.exploit-db.com/ghdb/5691" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="ws_ftp server - insecure deserialization critical identify critical remote vulnerabilities in ws_ftp server versions prior to 8.7.4 and 8.8.2, a pre-authenticated attacker could leverage a .net deserialization vulnerability in the ad hoc transfer module to execute remote commands on the underlying ws_ftp server operating system. cve-2023-40044 0x_akoko cve cve2023 kev passive vkev ws_ftp cwe-502" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">WS_FTP Server - Insecure Deserialization</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-40044.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-40044.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_Akoko</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 23, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/502.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-502</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-40044" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-40044</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Ad Hoc Transfer&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a pre-authenticated attacker could leverage a .NET deserialization vulnerability in the Ad Hoc Transfer module to execute remote commands on the underlying WS_FTP Server operating system.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can exploit .NET deserialization vulnerability in the Ad Hoc Transfer module to execute arbitrary commands on the WS_FTP Server, potentially compromising the entire file transfer infrastructure and accessing all transferred files.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update Progress WS_FTP Server to version 8.7.4 or 8.8.2 or later that properly validates deserialization input in the Ad Hoc Transfer module.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">kev</span><span class="nt-tag">passive</span><span class="nt-tag">vkev</span><span class="nt-tag">ws_ftp</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://attackerkb.com/topics/bn32f9sNax/cve-2023-40044" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://censys.com/cve-2023-40044/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.progress.com/ws_ftp" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://www.rapid7.com/blog/post/2023/09/29/etr-critical-vulnerabilities-in-ws_ftp-server/" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://www.theregister.com/2023/10/02/ws_ftp_update/" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="ws_ftp server web transfer - panel detect info identify web-based control panels ws_ftp server web transfer panel was detected. johnk3r discovery panel progress ws_ftp cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">WS_FTP Server Web Transfer - Panel Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/ws_ftp-server-web-transfer.yaml" target="_blank" rel="noopener" class="nt-source-link">ws_ftp-server-web-transfer.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> johnk3r</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 30, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)ws_ftp server web transfer&#34;}) || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)ad hoc transfer&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">WS_FTP Server Web Transfer panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">progress</span><span class="nt-tag">ws_ftp</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="wwbn avideo 11.6 - cross-site scripting medium identify critical remote vulnerabilities a reflected xss vulnerability exists in the functiongetopengraph videoname functionality of wwbn avideo 11.6 and dev master commit 3c6bb3ff, allowing arbitrary javascript execution. cve-2023-48728 ritikchaddha avideo cve cve2023 vkev vuln xss cwe-79" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">WWBN AVideo 11.6 - Cross-Site Scripting</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-48728.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-48728.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 13, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-79</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-48728" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-48728</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)AVideo&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A reflected XSS vulnerability exists in the functiongetOpenGraph videoName functionality of WWBN AVideo 11.6 and dev master commit 3c6bb3ff, allowing arbitrary Javascript execution.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation could lead to unauthorized access to sensitive information or account takeover.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Sanitize and validate user input to prevent XSS attacks.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">avideo</span><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">xss</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://talosintelligence.com/vulnerability_reports/TALOS-2023-1883" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-48728" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wagtail login - detect info identify web-based control panels the wagtail panel has been detected. kishore-hariram discovery panel torchbox wagtail cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Wagtail Login - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/wagtail-cms-detect.yaml" target="_blank" rel="noopener" class="nt-source-link">wagtail-cms-detect.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> kishore-hariram</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)wagtail - sign in&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The Wagtail panel has been detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">torchbox</span><span class="nt-tag">wagtail</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="wallix access manager panel - detect info identify web-based control panels wallix access manager panel was detected. righettod discovery panel wallix cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Wallix Access Manager Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/wallix-accessmanager-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">wallix-accessmanager-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Wallix Access Manager&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Wallix Access Manager panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">wallix</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.wallix.com/privileged-access-management/access-manager/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="wampserver panel - detect info identify web-based control panels wampserver panel was detected. dhiyaneshdk discovery panel wampserver cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">WampServer Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/wampserver-homepage.yaml" target="_blank" rel="noopener" class="nt-source-link">wampserver-homepage.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)WAMPSERVER Homepage&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">WampServer panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">wampserver</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="watchguard fireware ad helper component - credentials disclosure critical identify critical remote vulnerabilities watchguard fireware threat detection and response (tdr) service contains a credential-disclosure vulnerability in the ad helper component that allows unauthenticated attackers to gain active directory credentials for a windows domain in plaintext. cve-2020-10532 gy741 cve cve2020 disclosure edb vuln watchguard cwe-288" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">WatchGuard Fireware AD Helper Component - Credentials Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2020/CVE-2020-10532.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2020-10532.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> gy741</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 27, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/288.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-288</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2020-10532" target="_blank" rel="noopener" class="nt-cve-link">CVE-2020-10532</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;Fireware XTM User Authentication&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">WatchGuard Fireware Threat Detection and Response (TDR) service contains a credential-disclosure vulnerability in the AD Helper component that allows unauthenticated attackers to gain Active Directory credentials for a Windows domain in plaintext.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Remote attackers can retrieve cleartext passwords, leading to potential account compromise and further system exploitation.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to version 5.8.5.10317 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2020</span><span class="nt-tag">disclosure</span><span class="nt-tag">edb</span><span class="nt-tag">vuln</span><span class="nt-tag">watchguard</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2020-10532" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.exploit-db.com/exploits/48203" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.watchguard.com/wgrd-blog/tdr-ad-helper-credential-disclosure-vulnerability" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="watcher panel - detect info identify web-based control panels  dhiyaneshdk panel watcher login discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Watcher Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/watcher-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">watcher-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/vsaas/v2/static/&#34;</code></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">watcher</span><span class="nt-tag">login</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="watershed login panel - detect info identify web-based control panels watershed login panel was detected. tess panel watershed discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Watershed Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/watershed-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">watershed-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> tess</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Watershed LRS&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Watershed login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">watershed</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="wavlink - improper access control high identify critical remote vulnerabilities wavlink wl-wn530h4 m30h4.v5030.210121 is susceptible to improper access control in the component /cgi-bin/exportlogs.sh. an attacker can download configuration data and log files, obtain admin credentials, and potentially execute unauthorized operations. cve-2022-48165 for3stco1d cve cve2022 exposure router vuln wavlink cwe-284" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Wavlink - Improper Access Control</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-48165.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-48165.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> For3stCo1d</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/284.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-284</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-48165" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-48165</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-1350437236&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Wavlink WL-WN530H4 M30H4.V5030.210121 is susceptible to improper access control in the component /cgi-bin/ExportLogs.sh. An attacker can download configuration data and log files, obtain admin credentials, and potentially execute unauthorized operations.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">The vulnerability can lead to unauthorized access, data leakage, or unauthorized actions on the affected device.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest firmware update provided by the vendor to fix the access control issue.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">exposure</span><span class="nt-tag">router</span><span class="nt-tag">vuln</span><span class="nt-tag">wavlink</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://docs.google.com/document/d/1HD4GKumkZpa6FNHuf0QQSKFvoYhCfwXpbyWiJdx1VtE" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://twitter.com/For3stCo1d/status/1622576544190464000" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-48165" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/strik3r0x1/Vulns/blob/main/WAVLINK_WL-WN530H4.md" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-48165" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wavlink wl-wn530hg4 m30hg4.v5030.201217 - information disclosure high identify critical remote vulnerabilities an access control issue in wavlink wl-wn530hg4 m30hg4.v5030.201217 allows unauthenticated attackers to download configuration data and log files and obtain admin credentials. cve-2022-48166 ritikchaddha cve cve2022 exposure vuln wavlink wn530hg4" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Wavlink WL-WN530HG4 M30HG4.V5030.201217 - Information Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-48166.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-48166.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 6, 2024</span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-48166" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-48166</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)WN530HG4&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An access control issue in Wavlink WL-WN530HG4 M30HG4.V5030.201217 allows unauthenticated attackers to download configuration data and log files and obtain admin credentials.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation could lead to sensitive information disclosure.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest firmware updates from Wavlink or implement network segmentation to restrict access to the device administration interface.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">exposure</span><span class="nt-tag">vuln</span><span class="nt-tag">wavlink</span><span class="nt-tag">wn530hg4</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://docs.google.com/document/d/1zvbuu3Hkk3CAkojAivlUESvtHblHJNLJdpGOoNtk-Vo/edit?usp=sharing" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/strik3r0x1/Vulns/blob/main/WAVLINK%20WN530HG4.md" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-48166" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wavlink wl-wn533a8 m33a8.v5030.190716 - information disclosure high identify critical remote vulnerabilities an access control issue in the component /cgi-bin/exportlogs.sh of wavlink wl-wn533a8 m33a8.v5030.190716 allows unauthenticated attackers to download configuration data and log files and obtain admin credentials. cve-2022-48164 ritikchaddha cve cve2022 exposure vkev vuln wavlink wn533a8" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Wavlink WL-WN533A8 M33A8.V5030.190716 - Information Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-48164.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-48164.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 6, 2024</span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-48164" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-48164</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)WN533A8&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An access control issue in the component /cgi-bin/ExportLogs.sh of Wavlink WL-WN533A8 M33A8.V5030.190716 allows unauthenticated attackers to download configuration data and log files and obtain admin credentials.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation could lead to sensitive information disclosure.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest firmware updates from Wavlink or implement network segmentation to restrict access to the device administration interface.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">exposure</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">wavlink</span><span class="nt-tag">wn533a8</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://docs.google.com/document/d/1JgqpBYRxyU0WKDSqkvi4Yo0723k7mrIUeuH9i1eEs8U/edit?tab=t.0" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-48164" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wavlink wn535k2/wn535k3 - os command injection critical identify critical remote vulnerabilities wavlink wn535k2 and wn535k3 routers are susceptible to os command injection which affects unknown code in /cgi-bin/nightled.cgi via manipulation of the argument start_hour. an attacker can execute malware, obtain sensitive information, modify data, and/or gain full control over a compromised system without entering necessary credentials. cve-2022-2487 for3stco1d cve cve2022 iot oast rce router vkev vuln wavlink cwe-78" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Wavlink WN535K2/WN535K3 - OS Command Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-2487.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-2487.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> For3stCo1d</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/78.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-78</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-2487" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-2487</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)wi-fi app login&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Wavlink WN535K2 and WN535K3 routers are susceptible to OS command injection which affects unknown code in /cgi-bin/nightled.cgi via manipulation of the argument start_hour. An attacker can execute malware, obtain sensitive information, modify data, and/or gain full control over a compromised system without entering necessary credentials.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability can lead to unauthorized access, data leakage, and potential compromise of the entire network.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest firmware update provided by the vendor to mitigate this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">iot</span><span class="nt-tag">oast</span><span class="nt-tag">rce</span><span class="nt-tag">router</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">wavlink</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/1angx/webray.com.cn/blob/main/Wavlink/Wavlink%20nightled.cgi%20.md" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-2487" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://vuldb.com/?id.204538" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-2487" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wazuh - default login high identify default logins in web-based control panels wazuh contains default credentials. an attacker can obtain access to user accounts and access sensitive information, modify data, and/or execute unauthorized operations. theamanrawat,denandz,pulsesecurity.co.nz default-login vuln wazuh" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Wazuh - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/wazuh-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">wazuh-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> theamanrawat,denandz,PulseSecurity.co.nz</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 17, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;Wazuh&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Wazuh contains default credentials. An attacker can obtain access to user accounts and access sensitive information, modify data, and/or execute unauthorized operations.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">vuln</span><span class="nt-tag">wazuh</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://documentation.wazuh.com/current/user-manual/user-administration/password-management.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://wazuh.com" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://documentation.wazuh.com/current/deployment-options/docker/wazuh-container.html#single-node-deployment" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="wazuh login panel info identify web-based control panels wazuh - the open source security platform cyllective,daffainfo,idealphase discovery login panel wazuh" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Wazuh Login Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/wazuh-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">wazuh-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> cyllective,daffainfo,idealphase</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)wazuh&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Wazuh - The Open Source Security Platform</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">login</span><span class="nt-tag">panel</span><span class="nt-tag">wazuh</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/wazuh/wazuh" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="wechat agentinfo - information exposure high identify critical remote vulnerabilities there is an information leakage vulnerability in the agentinfo interface of tencent enterprise wechat. an attacker can obtain the enterprise wechat secret through the vulnerability. sleepingbag945 exposure tencent vuln wechat" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">WeChat agentinfo - Information Exposure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/vulnerabilities/wechat/wechat-info-leak.yaml" target="_blank" rel="noopener" class="nt-source-link">wechat-info-leak.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> SleepingBag945</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 18, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)wework_admin\\.normal_layout&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">There is an information leakage vulnerability in the agentinfo interface of Tencent Enterprise WeChat. An attacker can obtain the Enterprise WeChat Secret through the vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">exposure</span><span class="nt-tag">tencent</span><span class="nt-tag">vuln</span><span class="nt-tag">wechat</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/Threekiii/Awesome-POC/blob/f7869eb69bad66d177a88df4cebfe584691651ce/%E5%85%B6%E4%BB%96%E6%BC%8F%E6%B4%9E/%E8%85%BE%E8%AE%AF%20%E4%BC%81%E4%B8%9A%E5%BE%AE%E4%BF%A1%20agentinfo%20%E4%BF%A1%E6%81%AF%E6%B3%84%E6%BC%8F%E6%BC%8F%E6%B4%9E.md" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wegia - directory traversal critical identify critical remote vulnerabilities wegia is an open source web manager with a focus on the portuguese language and charitable institutions. prior to version 3.4.8, a path traversal vulnerability was discovered in the wegia application, html/socio/sistema/download_remessa.php endpoint. this vulnerability could allow an attacker to gain unauthorized access to local files in the server and sensitive information stored in config.php. config.php contains information that could allow direct access to the database. this issue has been patched in version 3.4.8. cve-2025-55169 praivesi cve cve2025 lfi vuln wegia cwe-287" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">WeGIA - Directory Traversal</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-55169.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-55169.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> praivesi</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 17, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/287.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-287</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-55169" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-55169</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)WeGIA&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. Prior to version 3.4.8, a path traversal vulnerability was discovered in the WeGIA application, html/socio/sistema/download_remessa.php endpoint. This vulnerability could allow an attacker to gain unauthorized access to local files in the server and sensitive information stored in config.php. config.php contains information that could allow direct access to the database. This issue has been patched in version 3.4.8.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can read arbitrary files including sensitive configuration files containing database credentials through path traversal in the download_remessa.php endpoint.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to WeGIA version 3.4.8 or later, which patches the path traversal vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">lfi</span><span class="nt-tag">vuln</span><span class="nt-tag">wegia</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-55169" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/LabRedesCefetRJ/WeGIA/security/advisories/GHSA-mm3p-7573-4x4j" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="web file manager login panel - detect info identify web-based control panels web file manager login panel was detected. dhiyaneshdk discovery filemanager panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Web File Manager Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/web-file-manager.yaml" target="_blank" rel="noopener" class="nt-source-link">web-file-manager.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Web File Manager&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Web File Manager login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">filemanager</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="web transfer client login panel - detect info identify web-based control panels progress web transfer client login panel was detected. righettod panel webtransferclient login detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Web Transfer Client Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/webtransfer-client-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">webtransfer-client-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 5, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Web Transfer Client&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Progress Web Transfer Client login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">webtransferclient</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.progress.com/ftp-server/web-transfer" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="web viewer for samsung dvr - detect info identify web-based control panels  justaacat detect discovery panel samsung web-viewer" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Web Viewer for Samsung DVR - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/web-viewer-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">web-viewer-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> JustaAcat</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)web viewer for samsung dvr&#34;})</code></div>
  <div class="nt-tags"><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">samsung</span><span class="nt-tag">web-viewer</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="webiq 2.15.9 - directory traversal high identify critical remote vulnerabilities the windows version of webiq 2.15.9 is affected by a directory traversal vulnerability that allows remote attackers to read any file on the system. cve-2024-8752 s4e-io cve cve2024 lfi vkev vuln webiq" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">WebIQ 2.15.9 - Directory Traversal</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-8752.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-8752.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> s4e-io</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 16, 2024</span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-8752" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-8752</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)WebIQ&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The Windows version of WebIQ 2.15.9 is affected by a directory traversal vulnerability that allows remote attackers to read any file on the system.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can exploit directory traversal to read arbitrary files from the Windows system, potentially exposing sensitive configuration files, credentials, database files, and system information.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update WebIQ to a version later than 2.15.9 to address the directory traversal vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">lfi</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">webiq</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.tenable.com/security/research/tra-2024-38" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-8752" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="webmethod integration server default login high identify default logins in web-based control panels  christianpoeschl,olewagner,usdag default-login vuln webmethod" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">WebMethod Integration Server Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/webmethod/webmethod-integration-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">webmethod-integration-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ChristianPoeschl,OleWagner,usdAG</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 20, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-234335289&#34;</code></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">vuln</span><span class="nt-tag">webmethod</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://documentation.softwareag.com/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="webpagetest login panel - detect info identify web-based control panels webpagetest login panel was detected. pdteam discovery panel webpagetest cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">WebPageTest Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/webpagetest-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">webpagetest-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pdteam</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)WebPageTest&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">WebPageTest login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">webpagetest</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="webshell4 login panel - detect info identify web-based control panels webshell4 login panel was detected. ritikchaddha webshell4 panel discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">WebShell4 Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/webshell4-login-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">webshell4-login-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)webshell4&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">WebShell4 login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">webshell4</span><span class="nt-tag">panel</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="webtitan cloud panel - detect info identify web-based control panels webtitan cloud is a cloud-based web filtering solution that monitors, controls, and protects users and businesses online. it blocks malware, phishing, viruses, ransomware, and malicious sites. ritikchaddha cloud detect discovery panel titanhq webtitan" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">WebTitan Cloud Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/webtitan-cloud-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">webtitan-cloud-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 25, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1090061843&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">WebTitan Cloud is a cloud-based web filtering solution that monitors, controls, and protects users and businesses online. It blocks malware, phishing, viruses, ransomware, and malicious sites.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cloud</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">titanhq</span><span class="nt-tag">webtitan</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="webcomco - panel info identify web-based control panels  dhiyaneshdk panel webcomco login discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">WebcomCo - Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/webcomco-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">webcomco-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 20, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)WebcomCo&#34;})</code></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">webcomco</span><span class="nt-tag">login</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.facebook.com/photo/?fbid=626548889515634&amp;set=a.467014098802448" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="weblate public project - exposure info identify critical remote vulnerabilities weblate instance is publicly accessible. public exposure of weblate may lead to unauthorized access to translation projects, potential data leaks, credential exposure, or manipulation of open source localization data. attackers can view available projects and access sensitive information if proper access controls are not implemented. ritikchaddha misconfig exposure weblate public" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Weblate Public Project - Exposure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/misconfiguration/weblate-public-project-exposure.yaml" target="_blank" rel="noopener" class="nt-source-link">weblate-public-project-exposure.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 19, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Weblate&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Weblate instance is publicly accessible. Public exposure of Weblate may lead to unauthorized access to translation projects, potential data leaks, credential exposure, or manipulation of open source localization data. Attackers can view available projects and access sensitive information if proper access controls are not implemented.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">misconfig</span><span class="nt-tag">exposure</span><span class="nt-tag">weblate</span><span class="nt-tag">public</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://docs.weblate.org/en/latest/admin/security.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/WeblateOrg/weblate" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="webmin - default login high identify default logins in web-based control panels webmin default login credentials were discovered. pussycat0x default-login vuln webmin cwe-798" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Webmin - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/webmin-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">webmin-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 9, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/798.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-798</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;Webmin&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Webmin default login credentials were discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">vuln</span><span class="nt-tag">webmin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://webmin.com/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://doxfer.webmin.com/Webmin/Installing_Webmin" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="webmin &lt; 1.290 / usermin &lt; 1.220 - arbitrary file disclosure medium identify critical remote vulnerabilities webmin before 1.290 and usermin before 1.220 contain a path traversal caused by calling the simplify_path function before decoding html, letting remote attackers read arbitrary files, exploit requires sending crafted &#39;..%01&#39; sequences. cve-2006-3392 s4e-io cve cve2006 lfi traversal unauth usermin vuln webmin cwe-22" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Webmin &lt; 1.290 / Usermin &lt; 1.220 - Arbitrary File Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2006/CVE-2006-3392.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2006-3392.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> s4e-io</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 3, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2006-3392" target="_blank" rel="noopener" class="nt-cve-link">CVE-2006-3392</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;product&#34;] contains &#34;Webmin:Usermin&#34; || service[&#34;product&#34;] contains &#34;Webmin:Webmin&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Webmin before 1.290 and Usermin before 1.220 contain a path traversal caused by calling the simplify_path function before decoding HTML, letting remote attackers read arbitrary files, exploit requires sending crafted &#39;..%01&#39; sequences.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can read arbitrary files on the server, potentially exposing sensitive information.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to Webmin 1.290 and Usermin 1.220 or later versions.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2006</span><span class="nt-tag">lfi</span><span class="nt-tag">traversal</span><span class="nt-tag">unauth</span><span class="nt-tag">usermin</span><span class="nt-tag">vuln</span><span class="nt-tag">webmin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.exploit-db.com/exploits/1997" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.exploit-db.com/exploits/2017" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="webmin &lt; 1.920 - authenticated remote code execution high identify critical remote vulnerabilities rpc.cgi in webmin through 1.920 allows authenticated remote code execution via a crafted object name because unserialise_variable makes an eval call. note: the webmin_servers_index documentation states &#34;rpc can be used to run any command or modify any file on a server, which is why access to it must not be granted to un-trusted webmin users.&#34; cve-2019-15642 pussycat0x cve cve2019 rce vkev vuln webmin cwe-94" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Webmin &lt; 1.920 - Authenticated Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2019/CVE-2019-15642.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2019-15642.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 9, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/94.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-94</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2019-15642" target="_blank" rel="noopener" class="nt-cve-link">CVE-2019-15642</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)webmin&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">rpc.cgi in Webmin through 1.920 allows authenticated Remote Code Execution via a crafted object name because unserialise_variable makes an eval call. NOTE: the Webmin_Servers_Index documentation states &#34;RPC can be used to run any command or modify any file on a server, which is why access to it must not be granted to un-trusted Webmin users.&#34;</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability allows an authenticated attacker to execute arbitrary code on the target system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade Webmin to version 1.920 or later to mitigate this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2019</span><span class="nt-tag">rce</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">webmin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2019-15642" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/jas502n/CVE-2019-15642" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://doxfer.webmin.com/Webmin/Webmin_Servers_Index" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/webmin/webmin/blob/ab5e00e41ea1ecc1e24b8f8693f3495a0abb1aed/rpc.cgi#L26-L37" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/webmin/webmin/commit/df8a43fb4bdc9c858874f72773bcba597ae9432c" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="webmin &lt;= 1.920 - unauthenticated remote command execution critical identify critical remote vulnerabilities webmin &lt;=1.920. is vulnerable to an unauthenticated remote command execution via the parameter &#39;old&#39; in password_change.cgi. cve-2019-15107 bp0lr cve cve2019 edb kev packetstorm rce vkev vuln webmin cwe-78" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Webmin &lt;= 1.920 - Unauthenticated Remote Command Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2019/CVE-2019-15107.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2019-15107.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> bp0lr</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/78.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-78</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2019-15107" target="_blank" rel="noopener" class="nt-cve-link">CVE-2019-15107</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)webmin&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Webmin &lt;=1.920. is vulnerable to an unauthenticated remote command execution via the parameter &#39;old&#39; in password_change.cgi.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability allows remote attackers to execute arbitrary commands with root privileges.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to Webmin version 1.930 or later to mitigate this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2019</span><span class="nt-tag">edb</span><span class="nt-tag">kev</span><span class="nt-tag">packetstorm</span><span class="nt-tag">rce</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">webmin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://pentest.com.tr/exploits/DEFCON-Webmin-1920-Unauthenticated-Remote-Command-Execution.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2019-15107" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.exploit-db.com/exploits/47230" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="http://www.pentest.com.tr/exploits/DEFCON-Webmin-1920-Unauthenticated-Remote-Command-Execution.html" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="http://packetstormsecurity.com/files/154485/Webmin-1.920-Remote-Code-Execution.html" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="webmin admin login panel - detect info identify web-based control panels webmin admin login panel was detected. pr3r00t panel webmin discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Webmin Admin Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/webmin-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">webmin-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> PR3R00T</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)webmin&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Webmin admin login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">webmin</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="webmodule login panel - detect info identify web-based control panels webmodule login panel was detected. pussycat0x,daffainfo edb panel webmodule-ee login discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Webmodule Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/webmodule-ee-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">webmodule-ee-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x,daffainfo</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Webmodule&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Webmodule login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">edb</span><span class="nt-tag">panel</span><span class="nt-tag">webmodule-ee</span><span class="nt-tag">login</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.exploit-db.com/ghdb/7001" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="webnus inc. modern events calendar - broken access control medium identify critical remote vulnerabilities webnus inc. modern events calendar &lt;= 7.29.0 contains a broken access control vulnerability caused by incorrectly configured access control security levels, letting attackers bypass authorization, exploit requires no special privileges. cve-2026-32583 theamanrawat cve cve2026 mec vuln wordpress wp wp-plugin cwe-862" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Webnus Inc. Modern Events Calendar - Broken Access Control</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2026/CVE-2026-32583.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2026-32583.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> theamanrawat</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 19, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/862.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-862</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2026-32583" target="_blank" rel="noopener" class="nt-cve-link">CVE-2026-32583</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/modern-events-calendar(?:-lite)?/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Webnus Inc. Modern Events Calendar &lt;= 7.29.0 contains a broken access control vulnerability caused by incorrectly configured access control security levels, letting attackers bypass authorization, exploit requires no special privileges.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can bypass authorization and access restricted functionality or data, potentially compromising system integrity.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest version beyond 7.29.0.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2026</span><span class="nt-tag">mec</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32583" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="webroot login panel - detect info identify web-based control panels webroot login panel was detected. dhiyaneshdk discovery panel webroot cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Webroot Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/webroot-login.yaml" target="_blank" rel="noopener" class="nt-source-link">webroot-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Webroot - Login&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Webroot login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">webroot</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="webuzo admin login panel - detect info identify web-based control panels webuzo admin login panel was detected. theamanrawat admin discovery panel softaculous webuzo cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Webuzo Admin Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/webuzo-admin-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">webuzo-admin-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> theamanrawat</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)webuzo - admin panel&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Webuzo admin login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">admin</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">softaculous</span><span class="nt-tag">webuzo</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="weiphp 5.0 - sql injection critical identify critical remote vulnerabilities weiphp 5.0 contains a sql injection vulnerability via the wp_where function. an attacker can possibly obtain sensitive information from a database, modify data, and execute unauthorized administrative operations in the context of the affected site. cve-2020-20300 pikpikcu cve cve2020 sql sqli vkev vuln weiphp cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">WeiPHP 5.0 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2020/CVE-2020-20300.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2020-20300.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pikpikcu</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2020-20300" target="_blank" rel="noopener" class="nt-cve-link">CVE-2020-20300</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)weiphp5\\.0&#34; || service[&#34;http.body&#34;] matches &#34;(?i)weiphp&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">WeiPHP 5.0 contains a SQL injection vulnerability via the wp_where function. An attacker can possibly obtain sensitive information from a database, modify data, and execute unauthorized administrative operations in the context of the affected site.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized access, data leakage, or data manipulation.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to a patched version of WeiPHP or apply the vendor-supplied patch to fix the SQL Injection vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2020</span><span class="nt-tag">sql</span><span class="nt-tag">sqli</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">weiphp</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/Y4er/Y4er.com/blob/15f49973707f9d526a059470a074cb6e38a0e1ba/content/post/weiphp-exp-sql.md" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2020-20300" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/Y4er/Y4er.com/blob/master/content/post/weiphp-exp-sql.md" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/ARPSyndicate/cvemon" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/ARPSyndicate/kenzer-templates" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="weiphp panel - detect info identify web-based control panels weiphp panel was detected. ritikchaddha panel weiphp discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Weiphp Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/weiphp-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">weiphp-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)weiphp&#34; || service[&#34;http.body&#34;] matches &#34;(?i)weiphp5\\.0&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Weiphp panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">weiphp</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="wekan sign up page - exposure medium identify critical remote vulnerabilities detected exposed wekan sign-up functionality, indicating that unauthenticated users could access the registration page and potentially create new accounts. dhiyaneshdk wekan sign-up register exposure" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Wekan Sign Up Page - Exposure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/misconfiguration/wekan-signup-page.yaml" target="_blank" rel="noopener" class="nt-source-link">wekan-signup-page.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 21, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Wekan&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detected exposed Wekan sign-up functionality, indicating that unauthenticated users could access the registration page and potentially create new accounts.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">wekan</span><span class="nt-tag">sign-up</span><span class="nt-tag">register</span><span class="nt-tag">exposure</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wekan.fi/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="westermo industrial router - login panel info identify web-based control panels westermo industrial router web interface panel has been detected. rxerium discovery ics panel router westermo" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Westermo Industrial Router - Login Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/westermo-router-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">westermo-router-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 27, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;^lynx - westermo&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Westermo industrial router web interface panel has been detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">ics</span><span class="nt-tag">panel</span><span class="nt-tag">router</span><span class="nt-tag">westermo</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.westermo.com/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="western digital mycloud nas - authentication bypass critical identify critical remote vulnerabilities it was discovered that the western digital my cloud device before 2.30.196 is affected by an authentication bypass vulnerability. an unauthenticated attacker can exploit this vulnerability to authenticate as an admin user without needing to provide a password, thereby gaining full control of the device. (whenever an admin logs into my cloud, a server-side session is created that is bound to the user&#39;s ip address. after the session is created, it is possible to call authenticated cgi modules by sending the cookie username=admin in the http request. the invoked cgi will check if a valid session is present and bound to the user&#39;s ip address.) it was found that it is possible for an unauthenticated attacker to create a valid session without a login. the network_mgr.cgi cgi module contains a command called \&#34;cgi_get_ipv6\&#34; that starts an admin session -- tied to the ip address of the user making the request -- if the additional parameter \&#34;flag\&#34; with the value \&#34;1\&#34; is provided. subsequent invocation of commands that would normally require admin privileges now succeed if an attacker sets the username=admin cookie. cve-2018-17153 dhiyaneshdk auth-bypass cve cve2018 packetstorm rce vuln wdcloud western_digital cwe-287" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Western Digital MyCloud NAS - Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2018/CVE-2018-17153.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2018-17153.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 29, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/287.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-287</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2018-17153" target="_blank" rel="noopener" class="nt-cve-link">CVE-2018-17153</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-1074357885&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">It was discovered that the Western Digital My Cloud device before 2.30.196 is affected by an authentication bypass vulnerability. An unauthenticated attacker can exploit this vulnerability to authenticate as an admin user without needing to provide a password, thereby gaining full control of the device. (Whenever an admin logs into My Cloud, a server-side session is created that is bound to the user&#39;s IP address. After the session is created, it is possible to call authenticated CGI modules by sending the cookie username=admin in the HTTP request. The invoked CGI will check if a valid session is present and bound to the user&#39;s IP address.) It was found that it is possible for an unauthenticated attacker to create a valid session without a login. The network_mgr.cgi CGI module contains a command called \&#34;cgi_get_ipv6\&#34; that starts an admin session -- tied to the IP address of the user making the request -- if the additional parameter \&#34;flag\&#34; with the value \&#34;1\&#34; is provided. Subsequent invocation of commands that would normally require admin privileges now succeed if an attacker sets the username=admin cookie.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can bypass authentication and gain unauthorized access to the device, potentially leading to data theft or unauthorized control of the NAS.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest firmware update provided by Western Digital to fix the authentication bypass vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2018</span><span class="nt-tag">packetstorm</span><span class="nt-tag">rce</span><span class="nt-tag">vuln</span><span class="nt-tag">wdcloud</span><span class="nt-tag">western_digital</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://web.archive.org/web/20170315123948/https://www.stevencampbell.info/2016/12/command-injection-in-western-digital-mycloud-nas/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://packetstormsecurity.com/files/173802/Western-Digital-MyCloud-Unauthenticated-Command-Injection.html" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://securify.nl/nl/advisory/SFY20180102/authentication-bypass-vulnerability-in-western-digital-my-cloud-allows-escalation-to-admin-privileges.html" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2016-10108" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="http://packetstormsecurity.com/files/173802/Western-Digital-MyCloud-Unauthenticated-Command-Injection.html" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="whatsup gold login panel - detect info identify web-based control panels whatsup gold login panel was detected. rxerium panel whatsup-gold detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Whatsup Gold Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/whatsup-gold-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">whatsup-gold-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 9, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)WhatsUp Gold&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Whatsup Gold login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">whatsup-gold</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.whatsupgold.com/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="white star software protop - directory traversal high identify critical remote vulnerabilities a directory traversal vulnerability was discovered in white star software protop version 4.4.2-2024-11-27, specifically in the /pt3upd/ endpoint. an unauthenticated attacker can remotely read arbitrary files on the underlying os using encoded traversal sequences. cve-2025-44177 s-cu-bot cve cve2025 lfi protop traversal vkev vuln whitestar cwe-22" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">White Star Software ProTop - Directory Traversal</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-44177.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-44177.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> s-cu-bot</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 30, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-44177" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-44177</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)&lt;title&gt;ProTop&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A directory traversal vulnerability was discovered in White Star Software Protop version 4.4.2-2024-11-27, specifically in the /pt3upd/ endpoint. An unauthenticated attacker can remotely read arbitrary files on the underlying OS using encoded traversal sequences.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can read arbitrary files from the operating system through encoded traversal sequences in the /pt3upd/ endpoint, potentially exposing sensitive configuration and credential files.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade White Star Software ProTop to a version after v4.4.2-2024-11-27.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">lfi</span><span class="nt-tag">protop</span><span class="nt-tag">traversal</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">whitestar</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-44177" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://client.protop.co.za/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://wss.com/" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://gist.github.com/stSLAYER/4a2ecfbab1215a0be0dde59c4ac0122d" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="whodb &lt; 0.45.0 - path traversal high identify critical remote vulnerabilities whodb contains a path traversal caused by lack of validation when opening database files, letting unauthenticated attackers access arbitrary sqlite3 databases on the host system, exploit requires attacker to manipulate database filename input. cve-2025-24786 basicbeny cve cve2025 lfi pathtraversal unauth whodb cwe-22" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">WhoDB &lt; 0.45.0 - Path Traversal</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-24786.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-24786.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> basicbeny</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 1, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-24786" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-24786</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)whodb&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">WhoDB contains a path traversal caused by lack of validation when opening database files, letting unauthenticated attackers access arbitrary Sqlite3 databases on the host system, exploit requires attacker to manipulate database filename input.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can access any Sqlite3 database on the system, potentially exposing sensitive data.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to version 0.45.0 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">lfi</span><span class="nt-tag">pathtraversal</span><span class="nt-tag">unauth</span><span class="nt-tag">whodb</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/clidey/whodb" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/clidey/whodb/security/advisories/GHSA-9r4c-jwx3-3j76" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24786" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wifisky default login high identify default logins in web-based control panels wifisky default admin credentials were discovered. pikpikcu default-login vuln wifisky cwe-522" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Wifisky Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/wifisky/wifisky-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">wifisky-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pikpikcu</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/522.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-522</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;WIFISKY-7层流控路由器&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Wifisky default admin credentials were discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">vuln</span><span class="nt-tag">wifisky</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://securityforeveryone.com/tools/wifisky-default-password-scanner" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="wildfly - default admin login high identify default logins in web-based control panels wildfly default admin login credentials were successful. s0obi default-login vuln wildfly" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Wildfly - Default Admin Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/wildfly/wildfly-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">wildfly-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> s0obi</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;Welcome to WildFly&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Wildfly default admin login credentials were successful.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">vuln</span><span class="nt-tag">wildfly</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://docs.wildfly.org/26.1/#administrator-guides" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="wildix collaboration panel - detect info identify web-based control panels wildix collaboration login panel was detected. rxerium panel login wildix detect discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Wildix Collaboration Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/wildix-collaboration-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">wildix-collaboration-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 11, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-1295577382&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Wildix Collaboration login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">login</span><span class="nt-tag">wildix</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.wildix.com/product/collaboration-ucc-platform/#" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="windmill panel - detect info identify web-based control panels windmill panel was detected. windmill (windmill.dev) is an open-source developer platform for workflows, scripts and internal apps, often self-hosted as a postgres-backed ui. exposed instances may reveal scripts, secrets and connected resources, and provide an authenticated path to script execution. chrisjr404 automation detect discovery login panel windmill workflow" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Windmill Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/windmill-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">windmill-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ChrisJr404</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 6, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Windmill&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Windmill panel was detected. Windmill (windmill.dev) is an open-source developer platform for workflows, scripts and internal apps, often self-hosted as a Postgres-backed UI. Exposed instances may reveal scripts, secrets and connected resources, and provide an authenticated path to script execution.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">automation</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">login</span><span class="nt-tag">panel</span><span class="nt-tag">windmill</span><span class="nt-tag">workflow</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/windmill-labs/windmill" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://windmill.dev/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="windmill/nextcloud flow &lt; 1.603.3 - unauthenticated path traversal critical identify critical remote vulnerabilities windmill &lt; 1.603.3 contains a path traversal caused by unsanitized filename parameter in get_log_file endpoint, letting unauthenticated attackers read arbitrary files on the server, exploit requires no authentication. cve-2026-29059 0x_akoko cve cve2026 lfi nextcloud unauth windmill cwe-22" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Windmill/Nextcloud Flow &lt; 1.603.3 - Unauthenticated Path Traversal</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2026/CVE-2026-29059.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2026-29059.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_Akoko</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 4, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2026-29059" target="_blank" rel="noopener" class="nt-cve-link">CVE-2026-29059</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches `id=&#34;Windmill&#34;` &amp;&amp; service[&#34;http.body&#34;] matches `svelte-global-loader`</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Windmill &lt; 1.603.3 contains a path traversal caused by unsanitized filename parameter in get_log_file endpoint, letting unauthenticated attackers read arbitrary files on the server, exploit requires no authentication.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can read arbitrary files on the server, potentially exposing sensitive information.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to version 1.603.3 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2026</span><span class="nt-tag">lfi</span><span class="nt-tag">nextcloud</span><span class="nt-tag">unauth</span><span class="nt-tag">windmill</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/Chocapikk/Windfall" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://chocapikk.com/posts/2026/windfall-nextcloud-flow-windmill-rce/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-29059" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="windows admin center panel - detection info identify web-based control panels detect windows admin center panel web interface. darses detect windows panel discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Windows Admin Center Panel - Detection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/windows-admin-center-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">windows-admin-center-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> darses</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 21, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-765377534&#34; || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Windows Admin Center&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detect Windows Admin Center Panel web interface.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">detect</span><span class="nt-tag">windows</span><span class="nt-tag">panel</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/microsoft/Windows-admin-center" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="wing ftp server &lt;= 7.4.3 - path disclosure via overlong uid cookie medium identify critical remote vulnerabilities wing ftp server versions prior to 7.4.4 are vulnerable to an authenticated information disclosure vulnerability (cve-2025-47813).
the vulnerability occurs due to improper validation of the &#39;uid&#39; session cookie in the /loginok.html endpoint. supplying an
overlong uid value causes the server to respond with an error that includes the full local filesystem path. this can aid in further
exploitation (e.g., cve-2025-47812) by revealing the application’s file system layout. cve-2025-47813 rcesecurity,pdteam cve cve2025 exposure kev unauth vkev vuln wingftp cwe-209" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Wing FTP Server &lt;= 7.4.3 - Path Disclosure via Overlong UID Cookie</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-47813.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-47813.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rcesecurity,pdteam</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 2, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/209.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-209</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-47813" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-47813</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;963565804&#34; || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Wing FTP Server&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Wing FTP Server versions prior to 7.4.4 are vulnerable to an authenticated information disclosure vulnerability (CVE-2025-47813).
The vulnerability occurs due to improper validation of the &#39;UID&#39; session cookie in the /loginok.html endpoint. Supplying an
overlong UID value causes the server to respond with an error that includes the full local filesystem path. This can aid in further
exploitation (e.g., CVE-2025-47812) by revealing the application’s file system layout.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Authenticated attackers can supply an overlong UID cookie value to trigger error responses that disclose the full local filesystem path, aiding in further exploitation attempts.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade Wing FTP Server to version 7.4.4 or later that properly validates UID cookie values.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">exposure</span><span class="nt-tag">kev</span><span class="nt-tag">unauth</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">wingftp</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.rcesecurity.com/2025/06/what-the-null-wing-ftp-server-rce-cve-2025-47812/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.wftpserver.com" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wing ftp server &lt;= 7.4.3 - remote code execution critical identify critical remote vulnerabilities wing ftp server versions prior to 7.4.4 are vulnerable to an unauthenticated remote code execution (rce) flaw (cve-2025-47812).
the vulnerability arises from improper null byte handling in the &#39;username&#39; parameter during login, which allows lua code injection
into session files. these injected session files are executed when accessing authenticated endpoints such as /dir.html, resulting
in arbitrary command execution with elevated privileges. this attack is possible only when anonymous login is enabled on the server. cve-2025-47812 rcesecurity,4m3rr0r cve cve2025 ftp kev rce unauth vkev vuln wingftp" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Wing FTP Server &lt;= 7.4.3 - Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-47812.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-47812.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rcesecurity,4m3rr0r</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 2, 2025</span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-47812" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-47812</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)wing ftp server&#34;}) || service[&#34;http.head.server&#34;] matches &#34;wing ftp server&#34; || service[&#34;http.body.mmh3&#34;] == &#34;2121146066&#34; || service[&#34;favicon.ico.image.mmh3&#34;] == &#34;963565804&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Wing FTP Server versions prior to 7.4.4 are vulnerable to an unauthenticated remote code execution (RCE) flaw (CVE-2025-47812).
The vulnerability arises from improper NULL byte handling in the &#39;username&#39; parameter during login, which allows Lua code injection
into session files. These injected session files are executed when accessing authenticated endpoints such as /dir.html, resulting
in arbitrary command execution with elevated privileges. This attack is possible only when anonymous login is enabled on the server.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can inject and execute Lua code through NULL byte handling in the username parameter when anonymous login is enabled, achieving remote code execution with elevated privileges.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade Wing FTP Server to version 7.4.4 or later that properly handles NULL bytes in authentication parameters.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">ftp</span><span class="nt-tag">kev</span><span class="nt-tag">rce</span><span class="nt-tag">unauth</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">wingftp</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.rcesecurity.com/2025/06/what-the-null-wing-ftp-server-rce-cve-2025-47812/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/4m3rr0r/CVE-2025-47812-poc" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wiren board webui panel - detect medium identify web-based control panels wiren board webui panel was detected. tess panel exposure wiren discovery cwe-200" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Wiren Board WebUI Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/wiren-board-webui.yaml" target="_blank" rel="noopener" class="nt-source-link">wiren-board-webui.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> tess</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Wiren Board Web UI&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Wiren Board WebUI panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">exposure</span><span class="nt-tag">wiren</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="woocommerce ultimate gift card ≤ 2.6.0 - arbitrary file upload critical identify critical remote vulnerabilities the woocommerce ultimate gift card plugin for wordpress is vulnerable to arbitrary file uploads due to insufficient file type validation in the &#39;mwb_wgm_preview_mail&#39; and &#39;mwb_wgm_woocommerce_add_cart_item_data&#39; functions in all versions up to, and including, 2.6.0. this makes it possible for unauthenticated attackers to upload arbitrary files on the affected site&#39;s server which may make remote code execution possible. cve-2024-8425 jsnv-dev cve cve2024 file-upload vkev vuln woocommerce woocommerce-ultimate-gift-card wordpress wp wp-plugin cwe-434" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">WooCommerce Ultimate Gift Card ≤ 2.6.0 - Arbitrary File Upload</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-8425.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-8425.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> jsnv-dev</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 5, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/434.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-434</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-8425" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-8425</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/woocommerce-ultimate-gift-card&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The WooCommerce Ultimate Gift Card plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the &#39;mwb_wgm_preview_mail&#39; and &#39;mwb_wgm_woocommerce_add_cart_item_data&#39; functions in all versions up to, and including, 2.6.0. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site&#39;s server which may make remote code execution possible.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can upload arbitrary files including PHP scripts to the server through insufficient file type validation, enabling remote code execution and complete server compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update WooCommerce Ultimate Gift Card plugin to a version later than 2.6.0 that addresses the arbitrary file upload vulnerability in the mwb_wgm_preview_mail and mwb_wgm_woocommerce_add_cart_item_data functions.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">file-upload</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">woocommerce</span><span class="nt-tag">woocommerce-ultimate-gift-card</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/KTN1990/CVE-2024-8425" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/woocommerce-ultimate-gift-card/woocommerce-ultimate-gift-card-260-unauthenticated-arbitrary-file-upload" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-8425" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="woodpecker ci panel - detect info identify web-based control panels woodpecker ci panel was detected. woodpecker is a community fork of drone ci, providing a simple yet powerful continuous integration platform. shivam kamboj panel woodpecker login discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Woodpecker CI Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/woodpecker-ci-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">woodpecker-ci-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Shivam Kamboj</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 27, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;product&#34;] contains &#34;Woodpecker CI:Woodpecker&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Woodpecker CI panel was detected. Woodpecker is a community fork of Drone CI, providing a simple yet powerful continuous integration platform.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">woodpecker</span><span class="nt-tag">login</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://woodpecker-ci.org/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/woodpecker-ci/woodpecker" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="woodwing studio server panel - detect info identify web-based control panels  pdteam,righettod woodwing panel discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Woodwing Studio Server Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/woodwing-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">woodwing-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pdteam,righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 13, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)WoodWing Studio Server&#34;})</code></div>
  <div class="nt-tags"><span class="nt-tag">woodwing</span><span class="nt-tag">panel</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://twitter.com/ynsmroztas/status/1680961398011047936" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress 12 step meeting list plugin &lt;= 3.14.33 - cross-site scripting medium identify critical remote vulnerabilities code for recovery 12 step meeting list versions up to 3.14.33 contain a reflected cross-site scripting caused by improper input neutralization during web page generation, letting attackers execute malicious scripts in users&#39; browsers, exploit requires attacker to craft a malicious url. cve-2024-35693 intelligent-ears 12-step-meeting-list cve cve2024 reflected vkev wordpress wp wp-plugin xss cwe-79" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">WordPress 12 Step Meeting List Plugin &lt;= 3.14.33 - Cross-Site Scripting</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-35693.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-35693.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> intelligent-ears</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 16, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-79</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-35693" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-35693</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/12-step-meeting-list/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Code for Recovery 12 Step Meeting List versions up to 3.14.33 contain a reflected cross-site scripting caused by improper input neutralization during web page generation, letting attackers execute malicious scripts in users&#39; browsers, exploit requires attacker to craft a malicious URL.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can execute malicious scripts in user browsers, potentially stealing cookies, session tokens, or performing actions on behalf of users.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Implement proper input sanitization and output encoding, and update to the latest version.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">12-step-meeting-list</span><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">reflected</span><span class="nt-tag">vkev</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">xss</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://patchstack.com/database/vulnerability/12-step-meeting-list/wordpress-12-step-meeting-list-plugin-3-14-33-cross-site-scripting-xss-vulnerability" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/code4recovery/12-step-meeting-list/issues/1415" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://wordpress.org/plugins/12-step-meeting-list" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-35693" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress &lt;= 5.2.4 - unauthenticated view private/draft posts medium identify critical remote vulnerabilities wordpress before 5.2.4 contains an information disclosure caused by mishandling of the static query property, letting unauthenticated users view certain content, exploit requires no authentication. cve-2019-17671 0x_akoko cve cve2019 disclosure unauth wordpress wp cwe-200" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">WordPress &lt;= 5.2.4 - Unauthenticated View Private/Draft Posts</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2019/CVE-2019-17671.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2019-17671.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_Akoko</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 4, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2019-17671" target="_blank" rel="noopener" class="nt-cve-link">CVE-2019-17671</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Wordpress&#34; &amp;&amp; service[&#34;http.body&#34;] matches `(?i)status-draft`</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">WordPress before 5.2.4 contains an information disclosure caused by mishandling of the static query property, letting unauthenticated users view certain content, exploit requires no authentication.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated users can view restricted content, leading to information disclosure.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to WordPress 5.2.4 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2019</span><span class="nt-tag">disclosure</span><span class="nt-tag">unauth</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://blog.wpscan.com/wordpress/security/release/2019/10/15/wordpress-523-security-and-maintenance-release.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://core.trac.wordpress.org/changeset/46474" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2019-17671" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://seclists.org/bugtraq/2020/Jan/8" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress ai chatbot (wpbot) &lt;= 4.8.9 - sql injection critical identify critical remote vulnerabilities chatbot plugin for wordpress up to 4.8.9 contains a sql_injection caused by insufficient escaping and lack of preparation on the $strid parameter, letting unauthenticated attackers extract sensitive data, exploit requires no authentication. cve-2023-5204 shivam kamboj chatbot cve cve2023 sqli time-based unauth wordpress wp wp-plugin wpbot cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">WordPress AI ChatBot (WPBot) &lt;= 4.8.9 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-5204.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-5204.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Shivam Kamboj</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 12, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-5204" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-5204</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/chatbot/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">ChatBot plugin for WordPress up to 4.8.9 contains a sql_injection caused by insufficient escaping and lack of preparation on the $strid parameter, letting unauthenticated attackers extract sensitive data, exploit requires no authentication.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can execute arbitrary SQL queries, leading to data disclosure and potential database compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest version of the plugin that addresses this vulnerability, or apply security patches provided by the vendor.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">chatbot</span><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">sqli</span><span class="nt-tag">time-based</span><span class="nt-tag">unauth</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">wpbot</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-5204" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/chatbot/chatbot-489-unauthenticated-sql-injection-via-qc-wpbo-search-response" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://plugins.trac.wordpress.org/browser/chatbot/trunk/qcld-wpwbot-search.php?rev=2957286#L177" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress ai engine plugin - token exposure critical identify critical remote vulnerabilities unauthenticated sensitive information exposure in ai engine wordpress plugin &lt;= 3.1.3 exposes bearer tokens via rest api endpoints when no-auth url is enabled. cve-2025-11749 4m3rr0r ai ai-engine cve cve2025 exposure token vkev wordpress wp-plugin" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">WordPress AI Engine Plugin - Token Exposure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-11749.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-11749.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 4m3rr0r</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 11, 2025</span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-11749" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-11749</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/ai-engine/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Unauthenticated sensitive information exposure in AI Engine WordPress plugin &lt;= 3.1.3 exposes bearer tokens via REST API endpoints when No-Auth URL is enabled.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can retrieve sensitive bearer tokens from AI Engine WordPress plugin through exposed REST API endpoints, potentially allowing privilege escalation and unauthorized access to AI service credentials.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to AI Engine version 3.1.4 or later that properly secures REST API endpoints and token handling.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">ai</span><span class="nt-tag">ai-engine</span><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">exposure</span><span class="nt-tag">token</span><span class="nt-tag">vkev</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp-plugin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.wordfence.com/blog/2025/11/100000-wordpress-sites-affected-by-privilege-escalation-vulnerability-in-ai-engine-wordpress-plugin/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://cve.mitre.org/cgi-bin/cvename/cgi?name=CVE-2025-11749" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress amp - full path disclosure low identify critical remote vulnerabilities the wordpress amp - accelerated mobile pages plugin was detected to be vulnerable to full path disclosure, allowing unauthenticated access to the full application path. pussycat0x wordpress wp wp-plugin accelerated-mobile-pages fpd" data-nt-sev="low">
  <div class="nt-card-header">
    <div class="nt-title">WordPress AMP - Full Path Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/misconfiguration/wordpress/wordpress-amp-fpd.yaml" target="_blank" rel="noopener" class="nt-source-link">wordpress-amp-fpd.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 23, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/accelerated-mobile-pages&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The WordPress AMP - Accelerated Mobile Pages plugin was detected to be vulnerable to Full Path Disclosure, allowing unauthenticated access to the full application path.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">accelerated-mobile-pages</span><span class="nt-tag">fpd</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wordpress.org/plugins/accelerated-mobile-pages/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress addtoany share buttons plugin - full path disclosure low identify critical remote vulnerabilities the addtoany share buttons plugin for wordpress was detected to be vulnerable to full path disclosure, allowing unauthenticated access to the full application path. pussycat0x wordpress wp wp-plugin fpd disclosure add-to-any" data-nt-sev="low">
  <div class="nt-card-header">
    <div class="nt-title">WordPress AddToAny Share Buttons Plugin - Full Path Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/misconfiguration/wordpress/wp-add-to-any-fpd.yaml" target="_blank" rel="noopener" class="nt-source-link">wp-add-to-any-fpd.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 23, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/add-to-any/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The AddToAny Share Buttons plugin for WordPress was detected to be vulnerable to Full Path Disclosure, allowing unauthenticated access to the full application path.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">fpd</span><span class="nt-tag">disclosure</span><span class="nt-tag">add-to-any</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wordpress.org/plugins/add-to-any/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress astra - full path disclosure low identify critical remote vulnerabilities wordpress astra theme files are publicly accessible without abspath protection, exposing sensitive server path information through php error messages when accessed directly. dhiyaneshdk debug wp wp-theme wordpress fpd vuln astra" data-nt-sev="low">
  <div class="nt-card-header">
    <div class="nt-title">WordPress Astra - Full Path Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/misconfiguration/wordpress/wp-astra-fpd.yaml" target="_blank" rel="noopener" class="nt-source-link">wp-astra-fpd.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 7, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/themes/astra/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">WordPress Astra Theme files are publicly accessible without ABSPATH protection, exposing sensitive server path information through PHP error messages when accessed directly.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">debug</span><span class="nt-tag">wp</span><span class="nt-tag">wp-theme</span><span class="nt-tag">wordpress</span><span class="nt-tag">fpd</span><span class="nt-tag">vuln</span><span class="nt-tag">astra</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wordpress.org/themes/astra/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress astra sites - full path disclosure low identify critical remote vulnerabilities wordpress starter templates plugin is vulnerable to full path disclosure via direct access to plugin files. ritikchaddha wp wordpress wp-plugin fpd astra-sites exposure" data-nt-sev="low">
  <div class="nt-card-header">
    <div class="nt-title">WordPress Astra Sites - Full Path Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/misconfiguration/wordpress/wp-astra-sites-fpd.yaml" target="_blank" rel="noopener" class="nt-source-link">wp-astra-sites-fpd.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 17, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/astra-sites/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">WordPress Starter Templates plugin is vulnerable to full path disclosure via direct access to plugin files.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">wp</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">fpd</span><span class="nt-tag">astra-sites</span><span class="nt-tag">exposure</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wordpress.org/plugins/astra-sites/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress backwpup &lt; 4.0.4 - backup file disclosure high identify critical remote vulnerabilities backwpup wordpress plugin &lt; 4.0.4 contains a directory listing vulnerability caused by lack of access restrictions in its temporary backup folder, letting unauthenticated attackers download site backups, exploit requires no authentication. cve-2023-7164 0x_akoko backwpup cve cve2023 disclosure exposure wordpress wp wp-plugin cwe-200" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">WordPress BackWPup &lt; 4.0.4 - Backup File Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-7164.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-7164.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_Akoko</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 10, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-7164" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-7164</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/backwpup/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">BackWPup WordPress plugin &lt; 4.0.4 contains a directory listing vulnerability caused by lack of access restrictions in its temporary backup folder, letting unauthenticated attackers download site backups, exploit requires no authentication.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can download site backups, potentially leading to data theft or further exploitation.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to version 4.0.4 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">backwpup</span><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">disclosure</span><span class="nt-tag">exposure</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wpscan.com/vulnerability/79b07f37-2c6b-4846-bb28-91a1e5bf112e/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://research.cleantalk.org/cve-2023-7164/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-7164" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress backup migration &lt;= 1.3.6 - path traversal high identify critical remote vulnerabilities wordpress backup migration plugin versions up to 1.3.6 contain a path traversal and file validation issue in handle_downloading function, letting unauthenticated attackers download backup files containing sensitive information. cve-2023-6266 riteshs4hu backup-migration backupbliss cve cve2023 vkev wordpress wp wp-plugin cwe-552" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">WordPress Backup Migration &lt;= 1.3.6 - Path Traversal</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-6266.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-6266.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> riteshs4hu</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 13, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/552.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-552</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-6266" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-6266</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)backup-migration&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">WordPress Backup Migration plugin versions up to 1.3.6 contain a path traversal and file validation issue in handle_downloading function, letting unauthenticated attackers download backup files containing sensitive information.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can download backup files with sensitive data, leading to data breaches and privacy violations.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest version of the plugin, version 1.3.7 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">backup-migration</span><span class="nt-tag">backupbliss</span><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">vkev</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d8c3c04e-c0f9-4f7e-b7e5-3e3e3e3e3e3e" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://patchstack.com/database/vulnerability/backup-backup/wordpress-backup-migration-plugin-1-3-7-unauthenticated-arbitrary-backup-download-vulnerability" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://plugins.trac.wordpress.org/browser/backup-backup/tags/1.3.5/includes/initializer.php#L1048" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://plugins.trac.wordpress.org/browser/backup-backup/tags/1.3.5/includes/initializer.php#L972" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress burst statistics 3.4.0-3.4.1.1 - authentication bypass critical identify critical remote vulnerabilities burst statistics – privacy-friendly wordpress analytics plugin 3.4.0 to 3.4.1.1 contains an authentication bypass caused by incorrect return-value handling in is_mainwp_authenticated() function, letting unauthenticated attackers impersonate administrators, exploit requires knowledge of an administrator username. cve-2026-8181 0x_akoko auth-bypass burst-statistics cve cve2026 unauth vkev wordpress wp wp-plugin cwe-287" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">WordPress Burst Statistics 3.4.0-3.4.1.1 - Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2026/CVE-2026-8181.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2026-8181.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_Akoko</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 27, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/287.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-287</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2026-8181" target="_blank" rel="noopener" class="nt-cve-link">CVE-2026-8181</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/burst-statistics/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Burst Statistics – Privacy-Friendly WordPress Analytics plugin 3.4.0 to 3.4.1.1 contains an authentication bypass caused by incorrect return-value handling in is_mainwp_authenticated() function, letting unauthenticated attackers impersonate administrators, exploit requires knowledge of an administrator username.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can impersonate administrators, leading to privilege escalation and full control over the application.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to a version later than 3.4.1.1 or the latest available version.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">burst-statistics</span><span class="nt-tag">cve</span><span class="nt-tag">cve2026</span><span class="nt-tag">unauth</span><span class="nt-tag">vkev</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/murrez/CVE-2026-8181" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8181" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress cmb2 - full path disclosure low identify critical remote vulnerabilities wordpress cmb2 plugin is vulnerable to full path disclosure via direct access to plugin files. ritikchaddha wp wordpress wp-plugin fpd cmb2 exposure" data-nt-sev="low">
  <div class="nt-card-header">
    <div class="nt-title">WordPress CMB2 - Full Path Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/misconfiguration/wordpress/wordpress-cmb2-fpd.yaml" target="_blank" rel="noopener" class="nt-source-link">wordpress-cmb2-fpd.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 17, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/cmb2/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">WordPress CMB2 plugin is vulnerable to full path disclosure via direct access to plugin files.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">wp</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">fpd</span><span class="nt-tag">cmb2</span><span class="nt-tag">exposure</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wordpress.org/plugins/cmb2/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress campress theme &lt;= 1.35 - unauthenticated local file inclusion critical identify critical remote vulnerabilities campress theme for wordpress up to 1.35 contains a local file inclusion caused by &#39;campress_woocommerce_get_ajax_products&#39; function, letting unauthenticated attackers include and execute arbitrary php files, exploit requires no authentication. cve-2024-10763 pussycat0x campress cve cve2024 lfi unauth wordpress wp-theme cwe-98" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">WordPress Campress Theme &lt;= 1.35 - Unauthenticated Local File Inclusion</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-10763.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-10763.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 12, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/98.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-98</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-10763" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-10763</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/themes/campress/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Campress theme for WordPress up to 1.35 contains a local file inclusion caused by &#39;campress_woocommerce_get_ajax_products&#39; function, letting unauthenticated attackers include and execute arbitrary PHP files, exploit requires no authentication.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can include and execute arbitrary PHP files, leading to remote code execution and potential full server compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest version beyond 1.35.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">campress</span><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">lfi</span><span class="nt-tag">unauth</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp-theme</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-themes/campress/campress-135-unauthenticated-local-file-inclusion" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress collapsing categories &lt;= 3.0.8 - sql injection high identify critical remote vulnerabilities collapsing categories plugin for wordpress &lt;= 3.0.8 contains a sql_injection caused by insufficient escaping of &#39;taxonomy&#39; parameter in /wp-json/collapsing-categories/v1/get rest api, letting unauthenticated attackers execute arbitrary sql queries, exploit requires sending crafted &#39;taxonomy&#39; parameter. cve-2024-12025 shivam kamboj collapsing-categories cve cve2024 sqli vkev wordpress wp wp-plugin cwe-89" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">WordPress Collapsing Categories &lt;= 3.0.8 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-12025.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-12025.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Shivam Kamboj</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 1, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-12025" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-12025</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/collapsing-categories/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Collapsing Categories plugin for WordPress &lt;= 3.0.8 contains a sql_injection caused by insufficient escaping of &#39;taxonomy&#39; parameter in /wp-json/collapsing-categories/v1/get REST API, letting unauthenticated attackers execute arbitrary SQL queries, exploit requires sending crafted &#39;taxonomy&#39; parameter.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can execute arbitrary SQL queries, potentially leading to data leakage or database compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest version of the plugin that addresses this vulnerability or apply security patches provided by the vendor.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">collapsing-categories</span><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">sqli</span><span class="nt-tag">vkev</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/collapsing-categories/collapsing-categories-308-unauthenticated-sql-injection" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-12025" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress coming soon page - full path disclosure low identify critical remote vulnerabilities wordpress coming soon page &amp; maintenance mode plugin files are publicly accessible without abspath protection, exposing sensitive server path information through php error messages when accessed directly. dhiyaneshdk debug wp wp-plugin wordpress fpd vuln responsive-coming-soon" data-nt-sev="low">
  <div class="nt-card-header">
    <div class="nt-title">WordPress Coming Soon Page - Full Path Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/misconfiguration/wordpress/wp-responsive-fpd.yaml" target="_blank" rel="noopener" class="nt-source-link">wp-responsive-fpd.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 7, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/responsive-coming-soon&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">WordPress Coming Soon Page &amp; Maintenance Mode plugin files are publicly accessible without ABSPATH protection, exposing sensitive server path information through PHP error messages when accessed directly.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">debug</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">wordpress</span><span class="nt-tag">fpd</span><span class="nt-tag">vuln</span><span class="nt-tag">responsive-coming-soon</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wordpress.org/plugins/responsive-coming-soon/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress core - post author email disclosure medium identify critical remote vulnerabilities wordpress core is vulnerable to sensitive information exposure in versions between 4.7.0 and 6.3.1 via the user rest endpoint. while the search results do not display user email addresses unless the requesting user has the &#39;list_users&#39; capability, the search is applied to the user_email column. cve-2023-5561 nqdung2002 cve cve2023 disclosure email exposure vuln wordpress wp wpscan cwe-200" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">WordPress Core - Post Author Email Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-5561.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-5561.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> nqdung2002</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 9, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-5561" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-5561</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)oembed&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">WordPress Core is vulnerable to Sensitive Information Exposure in versions between 4.7.0 and 6.3.1 via the User REST endpoint. While the search results do not display user email addresses unless the requesting user has the &#39;list_users&#39; capability, the search is applied to the user_email column.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">This can allow unauthenticated attackers to brute force or verify the email addresses of users with published posts or pages on the site.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches and updates from the vendor to address this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">disclosure</span><span class="nt-tag">email</span><span class="nt-tag">exposure</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wpscan</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-core/wordpress-core-470-631-sensitive-information-exposure-via-user-search-rest-endpoint?asset_slug=wordpress" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://wpscan.com/vulnerability/19380917-4c27-4095-abf1-eba6f913b441/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-5561" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress core &lt;=6.2 - directory traversal medium identify critical remote vulnerabilities wordpress core is vulnerable to directory traversal in versions up to, and including, 6.2, via the ‘wp_lang’ parameter. cve-2023-2745 nqdung2002 cve cve2023 disclosure lfi vkev vuln wordpress wp wpscan cwe-22" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">WordPress Core &lt;=6.2 - Directory Traversal</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-2745.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-2745.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> nqdung2002</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 9, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-2745" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-2745</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">WordPress Core is vulnerable to Directory Traversal in versions up to, and including, 6.2, via the ‘wp_lang’ parameter.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">This allows unauthenticated attackers to access and load arbitrary translation files. In cases where an attacker is able to upload a crafted translation file onto the site, such as via an upload form, this could be also used to perform a Cross-Site Scripting attack.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches and updates from the vendor to address this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">disclosure</span><span class="nt-tag">lfi</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wpscan</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-2745" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.cvedetails.com/cve/CVE-2023-2745/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress download manager - file password exposure medium identify critical remote vulnerabilities the wordpress download manager plugin contains a vulnerability that allows attackers to obtain passwords for password-protected downloads by sending a specially crafted request to the validate-password api endpoint. cve-2023-6421 ritikchaddha cve cve2023 download-manager exposure vuln wordpress wp wp-plugin cwe-200" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">WordPress Download Manager - File Password Exposure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-6421.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-6421.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 5, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-6421" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-6421</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)wp-content/plugins/download-manager/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The WordPress Download Manager plugin contains a vulnerability that allows attackers to obtain passwords for password-protected downloads by sending a specially crafted request to the validate-password API endpoint.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can obtain passwords for password-protected downloads by sending crafted requests to the validate-password API endpoint.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update the WordPress Download Manager plugin to the latest version.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">download-manager</span><span class="nt-tag">exposure</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wpscan.com/vulnerability/244c7c00-fc8d-4a73-bbe0-7865c621d410/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress download manager &lt; 3.3.07 - unauthenticated data exposure medium identify critical remote vulnerabilities the wordpress download manager plugin before version 3.3.07 does not prevent directory listing on web servers that don&#39;t use htaccess, allowing unauthorized access to files stored in the download-manager-files directory. cve-2024-13126 ritikchaddha cve cve2024 directory-listing download-manager vuln wordpress wp wp-plugin cwe-552" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">WordPress Download Manager &lt; 3.3.07 - Unauthenticated Data Exposure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-13126.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-13126.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 5, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/552.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-552</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-13126" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-13126</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)wp-content/plugins/download-manager/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The WordPress Download Manager plugin before version 3.3.07 does not prevent directory listing on web servers that don&#39;t use htaccess, allowing unauthorized access to files stored in the download-manager-files directory.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can access sensitive files stored in the download-manager-files directory due to directory listing, potentially exposing confidential documents or data.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update the WordPress Download Manager plugin to version 3.3.07 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">directory-listing</span><span class="nt-tag">download-manager</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wpscan.com/vulnerability/c2c69a44-4ecc-41d1-a10c-cfe9c875b803/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://research.cleantalk.org/cve-2024-13126/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-13126" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress download manager &lt;= 3.2.59 - reflected xss high identify critical remote vulnerabilities w3 eden, inc. download manager plugin &lt;= 3.2.59 contains a reflected cross-site scripting caused by insufficient input sanitization, letting attackers execute scripts in the context of the victim&#39;s browser, exploit requires attacker to craft a malicious link. cve-2022-45836 shivam kamboj cve cve2022 wordpress wp-plugin xss download-manager wpdm wp cwe-79" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">WordPress Download Manager &lt;= 3.2.59 - Reflected XSS</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-45836.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-45836.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Shivam Kamboj</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 6, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-79</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-45836" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-45836</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/download-manager/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">W3 Eden, Inc. Download Manager plugin &lt;= 3.2.59 contains a reflected cross-site scripting caused by insufficient input sanitization, letting attackers execute scripts in the context of the victim&#39;s browser, exploit requires attacker to craft a malicious link.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can execute arbitrary scripts in the victim&#39;s browser, potentially leading to session hijacking or defacement.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest version of the plugin where the vulnerability is fixed.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">xss</span><span class="nt-tag">download-manager</span><span class="nt-tag">wpdm</span><span class="nt-tag">wp</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-45836" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://patchstack.com/database/wordpress/plugin/download-manager/vulnerability/wordpress-download-manager-plugin-3-2-59-reflected-cross-site-scripting-xss-vulnerability" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress duplicator 1.3.24 &amp; 1.3.26 - local file inclusion high identify critical remote vulnerabilities wordpress duplicator 1.3.24 &amp; 1.3.26 are vulnerable to local file inclusion vulnerabilities that could allow attackers to download arbitrary files, such as the wp-config.php file. according to the vendor, the vulnerability was only in two
versions v1.3.24 and v1.3.26, the vulnerability wasn&#39;t
present in versions 1.3.22 and before. cve-2020-11738 dwisiswant0 cve cve2020 kev lfi packetstorm snapcreek tenable vkev vuln wordpress wp-plugin cwe-22" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">WordPress Duplicator 1.3.24 &amp; 1.3.26 - Local File Inclusion</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2020/CVE-2020-11738.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2020-11738.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dwisiswant0</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2020-11738" target="_blank" rel="noopener" class="nt-cve-link">CVE-2020-11738</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;service.product&#34;] == &#34;WordPress&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">WordPress Duplicator 1.3.24 &amp; 1.3.26 are vulnerable to local file inclusion vulnerabilities that could allow attackers to download arbitrary files, such as the wp-config.php file. According to the vendor, the vulnerability was only in two
versions v1.3.24 and v1.3.26, the vulnerability wasn&#39;t
present in versions 1.3.22 and before.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability can lead to unauthorized access to sensitive files, remote code execution, and potential compromise of the entire WordPress installation.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update the WordPress Duplicator plugin to the latest version (1.3.27 or higher) to mitigate the vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2020</span><span class="nt-tag">kev</span><span class="nt-tag">lfi</span><span class="nt-tag">packetstorm</span><span class="nt-tag">snapcreek</span><span class="nt-tag">tenable</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp-plugin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.tenable.com/blog/duplicator-wordpress-plugin-vulnerability-exploited-in-the-wild" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://snapcreek.com/duplicator/docs/changelog/?lite" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.wordfence.com/blog/2020/02/active-attack-on-recently-patched-duplicator-plugin-vulnerability-affects-over-1-million-sites/" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="http://packetstormsecurity.com/files/160621/WordPress-Duplicator-1.3.26-Directory-Traversal-File-Read.html" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2020-11738" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress end-of-life - detect info identify web-based control panels detected wordpress versions that have reached end-of-life (eol) and no longer receive security updates. shivam kamboj tech wordpress eol" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">WordPress End-of-Life - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/technologies/eol/wordpress-eol.yaml" target="_blank" rel="noopener" class="nt-source-link">wordpress-eol.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Shivam Kamboj</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 4, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;product&#34;] contains &#34;WordPress:WordPress&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detected WordPress versions that have reached End-of-Life (EOL) and no longer receive security updates.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">tech</span><span class="nt-tag">wordpress</span><span class="nt-tag">eol</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://endoflife.date/wordpress" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://wordpress.org/documentation/article/wordpress-versions/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress eventin (themewinter) ≤ 4.0.26 - arbitrary file download high identify critical remote vulnerabilities themewinter eventin contains a path traversal caused by relative path manipulation, letting attackers access arbitrary files on the server, exploit requires no specific privileges or user interaction. cve-2025-47445 hnd3884 cve cve2025 eventin lfi vkev wordpress wp wp-event-solution wp-plugin cwe-23" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">WordPress Eventin (Themewinter) ≤ 4.0.26 - Arbitrary File Download</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-47445.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-47445.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> hnd3884</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 3, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/23.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-23</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-47445" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-47445</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)wp-event-solution&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Themewinter Eventin contains a path traversal caused by relative path manipulation, letting attackers access arbitrary files on the server, exploit requires no specific privileges or user interaction.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can access sensitive files on the server, potentially leading to information disclosure or system compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest version of Eventin, version 4.0.27 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">eventin</span><span class="nt-tag">lfi</span><span class="nt-tag">vkev</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-event-solution</span><span class="nt-tag">wp-plugin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://patchstack.com/database/wordpress/plugin/wp-event-solution/vulnerability/wordpress-eventin-4-0-26-arbitrary-file-download-vulnerability?_s_id=cve" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/advisories/GHSA-c3pr-284f-8x9f" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-47445" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress events calendar 6.8.2.1 - information disclosure medium identify critical remote vulnerabilities the events calendar wordpress plugin 6.8.2.1 contains missing access checks in the rest api, letting unauthenticated users access information about password protected events, exploit requires no authentication. cve-2024-5333 dhiyaneshdk cve cve2024 disclosure the-events-calendar wordpress wp wp-plugin cwe-639" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">WordPress Events Calendar 6.8.2.1 - Information Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-5333.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-5333.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 23, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/639.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-639</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-5333" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-5333</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/the-events-calendar/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The Events Calendar WordPress plugin 6.8.2.1 contains missing access checks in the REST API, letting unauthenticated users access information about password protected events, exploit requires no authentication.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated users can access sensitive event information, potentially leading to information disclosure.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to version 6.8.2.1 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">disclosure</span><span class="nt-tag">the-events-calendar</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wpscan.com/vulnerability/764b5a23-8b51-4882-b899-beb54f684984/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-5333" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress events manager - full path disclosure low identify critical remote vulnerabilities wordpress wp super cache plugin files are publicly accessible without abspath protection, exposing sensitive server path information through php error messages when accessed directly. dhiyaneshdk debug wordpress fpd vuln events-manager wp-plugin" data-nt-sev="low">
  <div class="nt-card-header">
    <div class="nt-title">WordPress Events Manager - Full Path Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/misconfiguration/wordpress/wordpress-events-manager-fpd.yaml" target="_blank" rel="noopener" class="nt-source-link">wordpress-events-manager-fpd.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 5, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/plugins/events-manager/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">WordPress WP Super Cache plugin files are publicly accessible without ABSPATH protection, exposing sensitive server path information through PHP error messages when accessed directly.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">debug</span><span class="nt-tag">wordpress</span><span class="nt-tag">fpd</span><span class="nt-tag">vuln</span><span class="nt-tag">events-manager</span><span class="nt-tag">wp-plugin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wordpress.org/plugins/events-manager/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress file upload &lt;= 4.24.11 - arbitrary file read critical identify critical remote vulnerabilities the wordpress file upload plugin for wordpress is vulnerable to path traversal in all versions up to, and including, 4.24.11 via wfu_file_downloader.php. this makes it possible for unauthenticated attackers to read or delete files outside of the originally intended directory. successful exploitation requires the targeted wordpress installation to be using php 7.4 or earlier. cve-2024-9047 s4e-io,s9n3x cve cve2024 lfi vkev vuln wordpress wp wp-file-upload wp-plugin cwe-22" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">WordPress File Upload &lt;= 4.24.11 - Arbitrary File Read</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-9047.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-9047.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> s4e-io,S9n3x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 2, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-9047" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-9047</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/wp-file-upload/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The WordPress File Upload plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 4.24.11 via wfu_file_downloader.php. This makes it possible for unauthenticated attackers to read or delete files outside of the originally intended directory. Successful exploitation requires the targeted WordPress installation to be using PHP 7.4 or earlier.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can read or delete arbitrary files outside the intended directory on WordPress sites running PHP 7.4 or earlier, potentially exposing sensitive configuration files, credentials, and causing system disruption.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update WordPress File Upload plugin to version 4.24.12 or later to address the path traversal vulnerability in wfu_file_downloader.php, or upgrade PHP to version 8.0 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">lfi</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-file-upload</span><span class="nt-tag">wp-plugin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/iSee857/CVE-2024-9047-PoC" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/cve-2024-9047" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://plugins.trac.wordpress.org/changeset/3164449/wp-file-upload" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/554a314c-9e8e-4691-9792-d086790ef40f?source=cve" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/wy876/POC" target="_blank" rel="noopener" class="nt-ref-link">[5]</a> <a href="https://www.usom.gov.tr/bildirim/tr-24-1670" target="_blank" rel="noopener" class="nt-ref-link">[6]</a> <a href="https://sploitus.com/exploit?id=3358E6CC-BC63-56E4-A4C4-1F70903C34D5" target="_blank" rel="noopener" class="nt-ref-link">[7]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress gamipress &lt;= 2.5.7 - sql injection critical identify critical remote vulnerabilities the gamipress plugin for wordpress is vulnerable to sql injection in versions up to, and including, 2.5.7 due to insufficient escaping on the user supplied parameter &#39;$qv[$field_id]&#39; and lack of sufficient preparation on the existing sql query. this makes it possible for unauthenticated attackers to append additional sql queries into already existing queries that can be used to extract sensitive information from the database. cve-2023-24000 shivam kamboj cve cve2023 gamipress sqli vkev wordpress wp wp-plugin cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">WordPress GamiPress &lt;= 2.5.7 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-24000.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-24000.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Shivam Kamboj</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 6, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-24000" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-24000</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/gamipress/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The GamiPress plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.5.7 due to insufficient escaping on the user supplied parameter &#39;$qv[$field_id]&#39; and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can execute arbitrary SQL commands, potentially leading to data theft, data tampering, or database compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest version of GamiPress, version 2.5.8 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">gamipress</span><span class="nt-tag">sqli</span><span class="nt-tag">vkev</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-24000" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress gift voucher &lt;4.1.8 - blind sql injection critical identify critical remote vulnerabilities wordpress gift vouchers plugin before 4.1.8 contains a blind sql injection vulnerability via the template_id parameter in a wp-admin/admin-ajax.php wpgv_doajax_front_template request. an attacker can possibly obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site. cve-2018-16159 theamanrawat codemenschen cve cve2018 edb gift-voucher sqli time-based-sqli unauth vkev vuln wordpress wp wp-plugin wpscan cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">WordPress Gift Voucher &lt;4.1.8 - Blind SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2018/CVE-2018-16159.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2018-16159.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> theamanrawat</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2018-16159" target="_blank" rel="noopener" class="nt-cve-link">CVE-2018-16159</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/gift-voucher/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">WordPress Gift Vouchers plugin before 4.1.8 contains a blind SQL injection vulnerability via the template_id parameter in a wp-admin/admin-ajax.php wpgv_doajax_front_template request. An attacker can possibly obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to extract sensitive information from the database.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Fixed in version 4.1.8.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">codemenschen</span><span class="nt-tag">cve</span><span class="nt-tag">cve2018</span><span class="nt-tag">edb</span><span class="nt-tag">gift-voucher</span><span class="nt-tag">sqli</span><span class="nt-tag">time-based-sqli</span><span class="nt-tag">unauth</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">wpscan</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wpscan.com/vulnerability/9117" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://wordpress.org/plugins/gift-voucher/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.exploit-db.com/exploits/45255/" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2018-16159" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://wpvulndb.com/vulnerabilities/9117" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress grow by tradedoubler plugin &lt; 2.0.22 - unauthenticated local file inclusion critical identify critical remote vulnerabilities the grow by tradedoubler wordpress plugin through version 2.0.21 is vulnerable to local file inclusion via the component parameter. this makes it possible for attackers to include and execute php files on the server, allowing the execution of any php code in those files. cve-2024-6460 ritikchaddha cve cve2024 lfi tradedoubler-affiliate-tracker vuln wordpress wp wp-plugin cwe-22" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">WordPress Grow by Tradedoubler Plugin &lt; 2.0.22 - Unauthenticated Local File Inclusion</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-6460.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-6460.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 13, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-6460" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-6460</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)wp-content/plugins/tradedoubler-affiliate-tracker/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The Grow by Tradedoubler WordPress plugin through version 2.0.21 is vulnerable to Local File Inclusion via the component parameter. This makes it possible for attackers to include and execute PHP files on the server, allowing the execution of any PHP code in those files.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can exploit local file inclusion to read sensitive files like wp-config.php and potentially execute arbitrary PHP code.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update Grow by Tradedoubler plugin to version 2.0.22 or later to address the local file inclusion vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">lfi</span><span class="nt-tag">tradedoubler-affiliate-tracker</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wpscan.com/vulnerability/ba2f53e0-30be-4f37-91bc-5fa151f1eee7" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-6460" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress html5 video player - sql injection critical identify critical remote vulnerabilities wordpress html5 video player plugin is vulnerable to sql injection. an unauthenticated attacker can exploit this vulnerability to perform sql injection attacks. cve-2024-1061 xxcdd bplugins cve cve2024 html5-video-player sqli time-based-sqli vkev vuln wordpress wp wp-plugin cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">WordPress HTML5 Video Player - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-1061.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-1061.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> xxcdd</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 31, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-1061" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-1061</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)html5-video-player&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">WordPress HTML5 Video Player plugin is vulnerable to SQL injection. An unauthenticated attacker can exploit this vulnerability to perform SQL injection attacks.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to perform SQL injection attacks, potentially leading to unauthorized access, data leakage, or further compromise of the WordPress site.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Vendor did not acknowledge vulnerability but the issue seems to have been fixed in version 2.5.25.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">bplugins</span><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">html5-video-player</span><span class="nt-tag">sqli</span><span class="nt-tag">time-based-sqli</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.tenable.com/security/research/tra-2024-02" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://wordpress.org/plugins/html5-video-player" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-1061" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/tanjiti/sec_profile" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/JoshuaMart/JoshuaMart" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress header footer elementor - full path disclosure low identify critical remote vulnerabilities wordpress header footer elementor plugin (also known as ultimate addons for elementor - lite) contains php files that lack proper abspath protection, allowing direct access that reveals sensitive server path information via php error messages. ritikchaddha wp wordpress wp-plugin fpd header-footer-elementor" data-nt-sev="low">
  <div class="nt-card-header">
    <div class="nt-title">WordPress Header Footer Elementor - Full Path Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/misconfiguration/wordpress/wp-header-footer-elementor-fpd.yaml" target="_blank" rel="noopener" class="nt-source-link">wp-header-footer-elementor-fpd.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 21, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)wp-content/plugins/header-footer-elementor/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">WordPress Header Footer Elementor plugin (also known as Ultimate Addons for Elementor - Lite) contains PHP files that lack proper ABSPATH protection, allowing direct access that reveals sensitive server path information via PHP error messages.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">wp</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">fpd</span><span class="nt-tag">header-footer-elementor</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wordpress.org/plugins/header-footer-elementor/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress hummingbird &lt;= 3.18.0 - sensitive information exposure via log file high identify critical remote vulnerabilities hummingbird performance wordpress plugin &lt;= 3.18.0 contains a sensitive information exposure caused by improper handling in the &#39;request&#39; function, letting unauthenticated attackers extract sensitive data including cloudflare api credentials, exploit requires no authentication. cve-2025-14437 pussycat0x cloudflare cve cve2025 exposure hummingbird vkev wordpress wp-plugin wpmudev cwe-532" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">WordPress Hummingbird &lt;= 3.18.0 - Sensitive Information Exposure via Log File</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-14437.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-14437.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 8, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/532.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-532</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-14437" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-14437</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/hummingbird-performance&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Hummingbird Performance WordPress plugin &lt;= 3.18.0 contains a sensitive information exposure caused by improper handling in the &#39;request&#39; function, letting unauthenticated attackers extract sensitive data including Cloudflare API credentials, exploit requires no authentication.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can extract sensitive credentials, leading to potential account compromise and further attacks.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest version beyond 3.18.0.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cloudflare</span><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">exposure</span><span class="nt-tag">hummingbird</span><span class="nt-tag">vkev</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">wpmudev</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/hummingbird-performance/hummingbird-3180-unauthenticated-sensitive-information-exposure-via-log-files" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://wpscan.com/vulnerability/cve-2025-14437" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://plugins.trac.wordpress.org/changeset/3421187/hummingbird-performance" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress js archive list &lt;= 6.1.5 - sql injection high identify critical remote vulnerabilities miguel useche js archive list contains an sql injection caused by improper neutralization of special elements in sql commands, letting attackers execute arbitrary sql queries, exploit requires crafted input. cve-2025-54726 shivam kamboj cve cve2025 jquery-archive-list-widget sqli unauth vkev wordpress wp wp-plugin cwe-89" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">WordPress JS Archive List &lt;= 6.1.5 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-54726.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-54726.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Shivam Kamboj</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 13, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-54726" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-54726</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/jquery-archive-list-widget/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Miguel Useche JS Archive List contains an sql injection caused by improper neutralization of special elements in SQL commands, letting attackers execute arbitrary SQL queries, exploit requires crafted input.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can execute arbitrary SQL commands, potentially leading to data disclosure, modification, or deletion.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest version.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">jquery-archive-list-widget</span><span class="nt-tag">sqli</span><span class="nt-tag">unauth</span><span class="nt-tag">vkev</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/jquery-archive-list-widget/js-archive-list-615-unauthenticated-sql-injection" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://patchstack.com/database/wordpress/plugin/jquery-archive-list-widget/vulnerability/wordpress-js-archive-list-plugin-6-1-6-sql-injection-vulnerability" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54726" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress job portal &lt; 2.0.6 - sql injection high identify critical remote vulnerabilities the wp job portal wordpress plugin before 2.0.6 does not sanitise and escape the city parameter before using it in a sql statement,leading to a sql injection vulnerability that is exploitable by unauthenticated users. this vulnerability can be used to extractsensitive data from the database or potentially compromise the wordpress installation. cve-2023-4490 paresh_parmar1,configtea cve cve2023 sqli time-based-sqli vkev vuln wordpress wp wp-job-portal wp-plugin cwe-89" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">WordPress Job Portal &lt; 2.0.6 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-4490.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-4490.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> paresh_parmar1,Configtea</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 4, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-4490" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-4490</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/wp-job-portal&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The WP Job Portal WordPress plugin before 2.0.6 does not sanitise and escape the city parameter before using it in a SQL statement,leading to a SQL injection vulnerability that is exploitable by unauthenticated users. This vulnerability can be used to extractsensitive data from the database or potentially compromise the WordPress installation.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can execute SQL injection through the city parameter to extract the complete WordPress database including user credentials and job portal data.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to version 2.0.6 or later</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">sqli</span><span class="nt-tag">time-based-sqli</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-job-portal</span><span class="nt-tag">wp-plugin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wpscan.com/vulnerability/986024f0-3c8d-44d8-a9c9-1dd284d7db0d/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-4490" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress kali forms &lt;= 2.4.9 - remote code execution critical identify critical remote vulnerabilities kali forms wordpress plugin &lt;= 2.4.9 contains a remote code execution caused by unsafe user input handling in &#39;form_process&#39; and &#39;prepare_post_data&#39; functions, letting unauthenticated attackers execute code on the server, exploit requires no authentication. cve-2026-3584 pussycat0x cve cve2026 kali-forms rce unauth vkev wordpress wp-plugin cwe-94" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">WordPress Kali Forms &lt;= 2.4.9 - Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2026/CVE-2026-3584.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2026-3584.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 9, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/94.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-94</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2026-3584" target="_blank" rel="noopener" class="nt-cve-link">CVE-2026-3584</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/kali-forms/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Kali Forms WordPress plugin &lt;= 2.4.9 contains a remote code execution caused by unsafe user input handling in &#39;form_process&#39; and &#39;prepare_post_data&#39; functions, letting unauthenticated attackers execute code on the server, exploit requires no authentication.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can execute arbitrary code on the server, potentially leading to full system compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest version beyond 2.4.9.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2026</span><span class="nt-tag">kali-forms</span><span class="nt-tag">rce</span><span class="nt-tag">unauth</span><span class="nt-tag">vkev</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp-plugin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wordpress.org/plugins/kali-forms/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/kali-forms/kali-forms-249-unauthenticated-remote-code-execution-via-form-process" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress list site contributors &lt; 1.1.8 - reflected xss medium identify critical remote vulnerabilities wordpress list site contributors plugin &lt; 1.1.8 contains a reflected xss caused by insufficient sanitization and escaping of the &#39;alpha&#39; parameter, letting unauthenticated attackers inject scripts, exploit requires user interaction. m4sh_wacker cve cve2026 wordpress wp wp-plugin list-site-contributors xss" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">WordPress List Site Contributors &lt; 1.1.8 - Reflected XSS</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2026/CVE-2026-0594.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2026-0594.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> m4sh_wacker</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 23, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/plugins/list-site-contributors/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">WordPress List Site Contributors plugin &lt; 1.1.8 contains a reflected XSS caused by insufficient sanitization and escaping of the &#39;alpha&#39; parameter, letting unauthenticated attackers inject scripts, exploit requires user interaction.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can inject scripts that execute in users browsers, potentially stealing data or performing actions on their behalf.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to a version later than 1.1.8 or the latest available version.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2026</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">list-site-contributors</span><span class="nt-tag">xss</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/m4sh-wacker/CVE-2026-0594-ListSiteContributors-Plugin-Exploit" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/026a2e0d-4d30-4133-9118-055026aa9f4a?source=cve" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress mstore api &lt;= 4.0.1 - unauthenticated sql injection critical identify critical remote vulnerabilities mstore api plugin for wordpress up to version 4.0.1 contains an unauthenticated blind sql injection caused by insufficient escaping of &#39;id&#39; parameter in sql queries, letting attackers execute arbitrary sql commands without authentication, exploit requires sending crafted requests with malicious &#39;id&#39; parameter. shivam kamboj cve cve2023 wordpress wp-plugin wp sqli mstore-api wp unauth time-based" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">WordPress MStore API &lt;= 4.0.1 - Unauthenticated SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-3197.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-3197.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Shivam Kamboj</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 6, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/mstore-api/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">MStore API plugin for WordPress up to version 4.0.1 contains an unauthenticated blind SQL injection caused by insufficient escaping of &#39;id&#39; parameter in SQL queries, letting attackers execute arbitrary SQL commands without authentication, exploit requires sending crafted requests with malicious &#39;id&#39; parameter.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can extract sensitive database information, potentially leading to data breach and compromise of the website.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest version of the plugin where the vulnerability is fixed.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">wp</span><span class="nt-tag">sqli</span><span class="nt-tag">mstore-api</span><span class="nt-tag">wp</span><span class="nt-tag">unauth</span><span class="nt-tag">time-based</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-3197" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/30aab1af-a78f-4bac-b3c5-30ea854ccef7?source=cve" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress managewp worker - full path disclosure low identify critical remote vulnerabilities wordpress managewp worker plugin files are publicly accessible without abspath protection, exposing sensitive server path information through php error messages when accessed directly. dhiyaneshdk debug wordpress fpd vuln" data-nt-sev="low">
  <div class="nt-card-header">
    <div class="nt-title">WordPress ManageWP Worker - Full Path Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/misconfiguration/wordpress/wp-worker-fpd.yaml" target="_blank" rel="noopener" class="nt-source-link">wp-worker-fpd.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 7, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/plugins/worker/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">WordPress ManageWP Worker plugin files are publicly accessible without ABSPATH protection, exposing sensitive server path information through PHP error messages when accessed directly.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">debug</span><span class="nt-tag">wordpress</span><span class="nt-tag">fpd</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wordpress.org/plugins/worker/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress members / membership &amp; user role editor plugin - error log disclosure low identify critical remote vulnerabilities wordpress members plugin is vulnerable to error log disclosure via direct access to plugin files. ritikchaddha wp wordpress wp-plugin fpd members exposure error-log" data-nt-sev="low">
  <div class="nt-card-header">
    <div class="nt-title">WordPress Members / Membership &amp; User Role Editor Plugin - Error Log Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/misconfiguration/wordpress/wp-members-error-log-disclosure.yaml" target="_blank" rel="noopener" class="nt-source-link">wp-members-error-log-disclosure.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 17, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/members/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">WordPress Members plugin is vulnerable to error log disclosure via direct access to plugin files.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">wp</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">fpd</span><span class="nt-tag">members</span><span class="nt-tag">exposure</span><span class="nt-tag">error-log</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wordpress.org/plugins/members/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress members plugin - debug/error log disclosure low identify critical remote vulnerabilities the wordpress members plugin exposes error/debug log files that may contain sensitive information. ritikchaddha wordpress wp-plugin members exposure logs" data-nt-sev="low">
  <div class="nt-card-header">
    <div class="nt-title">WordPress Members Plugin - Debug/Error Log Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/misconfiguration/wordpress/wp-members-log-disclosure.yaml" target="_blank" rel="noopener" class="nt-source-link">wp-members-log-disclosure.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 25, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/members&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The WordPress Members plugin exposes error/debug log files that may contain sensitive information.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">wordpress</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">members</span><span class="nt-tag">exposure</span><span class="nt-tag">logs</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wordpress.org/plugins/members/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://pentest-tools.com/vulnerabilities-exploits/wordpress-members-membership-and-user-role-editor-plugin-error-log-disclosure_28354" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress my calendar &lt;3.4.22 - sql injection critical identify critical remote vulnerabilities wordpress my calendar plugin versions before 3.4.22 are vulnerable to an unauthenticated sql injection within the &#39;from&#39; and &#39;to&#39; parameters of the &#39;/my-calendar/v1/events&#39; rest route. cve-2023-6360 xxcdd cve cve2023 joedolson my-calendar sqli vkev vuln wordpress wp wp-plugin wpscan cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">WordPress My Calendar &lt;3.4.22 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-6360.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-6360.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> xxcdd</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 31, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-6360" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-6360</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)wp-content/plugins/my-calendar&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">WordPress My Calendar plugin versions before 3.4.22 are vulnerable to an unauthenticated SQL injection within the &#39;from&#39; and &#39;to&#39; parameters of the &#39;/my-calendar/v1/events&#39; REST route.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to perform SQL injection attacks, which could lead to data theft, database compromise, or further attack vectors.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to My Calendar plugin version 3.4.22 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">joedolson</span><span class="nt-tag">my-calendar</span><span class="nt-tag">sqli</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">wpscan</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.tenable.com/security/research/tra-2023-40" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.joedolson.com/2023/11/my-calendar-3-4-22-security-release/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://wordpress.org/plugins/my-calendar/" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-6360" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/JoshuaMart/JoshuaMart" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress newsletter - log file exposure medium identify critical remote vulnerabilities the newsletters plugin for wordpress is vulnerable to sensitive information exposure in all versions up to, and including, 4.9.5. this makes it possible for unauthenticated attackers to extract potentially sensitive information from log files. pussycat0x wordpress wp-plugin newsletter logs" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">WordPress Newsletter - Log File Exposure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposures/logs/wp-newsletter-log-exposure.yaml" target="_blank" rel="noopener" class="nt-source-link">wp-newsletter-log-exposure.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 30, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/newsletter/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The Newsletters plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.9.5. This makes it possible for unauthenticated attackers to extract potentially sensitive information from log files.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">wordpress</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">newsletter</span><span class="nt-tag">logs</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wpscan.com/vulnerability/334e02e9-fcbd-47fe-b7ab-079dd525b396/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress nextgen gallery pro - error log disclosure medium identify critical remote vulnerabilities the nextgen gallery pro plugin for wordpress may expose debug/error log files that contain sensitive information including file paths, database queries, and potentially credentials. these log files are accessible without authentication. ritikchaddha wordpress wp wp-plugin nextgen-gallery-pro log exposure cwe-532" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">WordPress NextGEN Gallery Pro - Error Log Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/misconfiguration/wordpress/nextgen-gallery-pro-error-log.yaml" target="_blank" rel="noopener" class="nt-source-link">nextgen-gallery-pro-error-log.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 22, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/532.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-532</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/plugins/nextgen-gallery-pro&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The NextGEN Gallery Pro plugin for WordPress may expose debug/error log files that contain sensitive information including file paths, database queries, and potentially credentials. These log files are accessible without authentication.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">nextgen-gallery-pro</span><span class="nt-tag">log</span><span class="nt-tag">exposure</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wpscan.com/plugin/nextgen-gallery/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.acunetix.com/vulnerabilities/web/wordpress-plugin-nextgen-gallery-wordpress-gallery-information-disclosure-1-9-11/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress oceanwp - full path disclosure low identify critical remote vulnerabilities wordpress oceanwp theme is vulnerable to full path disclosure via direct access to theme files. ritikchaddha wp wordpress wp-theme fpd oceanwp exposure" data-nt-sev="low">
  <div class="nt-card-header">
    <div class="nt-title">WordPress OceanWP - Full Path Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/misconfiguration/wordpress/wp-oceanwp-fpd.yaml" target="_blank" rel="noopener" class="nt-source-link">wp-oceanwp-fpd.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 17, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/themes/oceanwp/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">WordPress OceanWP theme is vulnerable to full path disclosure via direct access to theme files.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">wp</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp-theme</span><span class="nt-tag">fpd</span><span class="nt-tag">oceanwp</span><span class="nt-tag">exposure</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wordpress.org/themes/oceanwp/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress phpmailer &lt; 5.2.18 - remote code execution critical identify critical remote vulnerabilities wordpress phpmailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a &#34; (backslash double quote) in a crafted sender property in ismail transport. cve-2016-10033 princechaddha cve cve2016 edb kev phpmailer_project rce seclists vkev vuln wordpress cwe-88" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">WordPress PHPMailer &lt; 5.2.18 - Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2016/CVE-2016-10033.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2016-10033.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> princechaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/88.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-88</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2016-10033" target="_blank" rel="noopener" class="nt-cve-link">CVE-2016-10033</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;product&#34;] contains &#34;WordPress:WordPress&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">WordPress PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a &#34; (backslash double quote) in a crafted Sender property in isMail transport.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability can lead to unauthorized remote code execution on the affected WordPress website.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade PHPMailer to version 5.2.18 or higher to mitigate this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2016</span><span class="nt-tag">edb</span><span class="nt-tag">kev</span><span class="nt-tag">phpmailer_project</span><span class="nt-tag">rce</span><span class="nt-tag">seclists</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://exploitbox.io/vuln/WordPress-Exploit-4-6-RCE-CODE-EXEC-CVE-2016-10033.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2016-10033" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.exploit-db.com/exploits/40970/" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://www.exploit-db.com/exploits/40968/" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="http://seclists.org/fulldisclosure/2016/Dec/78" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress post smtp mailer &lt;= 2.8.7 - authorization bypass critical identify critical remote vulnerabilities the post smtp mailer – email log, delivery failure notifications and best mail smtp for wordpress plugin for wordpress is vulnerable to unauthorized access of data and modification of data due to a type juggling issue on the connect-app rest endpoint in all versions up to, and including, 2.8.7. cve-2023-6875 iamnoooob,rootxharsh,pdresearch auth-bypass cve cve2023 mailer smtp vkev vuln wordpress wp wp-plugin wpexperts cwe-862" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">WordPress POST SMTP Mailer &lt;= 2.8.7 - Authorization Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-6875.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-6875.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> iamnoooob,rootxharsh,pdresearch</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 17, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/862.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-862</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-6875" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-6875</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/post-smtp&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a type juggling issue on the connect-app REST endpoint in all versions up to, and including, 2.8.7.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can exploit type juggling vulnerabilities in the connect-app REST endpoint to access and modify sensitive email configuration data.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Fixed in 2.8.8</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">mailer</span><span class="nt-tag">smtp</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">wpexperts</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://plugins.trac.wordpress.org/browser/post-smtp/trunk/Postman/Mobile/includes/rest-api/v1/rest-api.php#L60" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://plugins.trac.wordpress.org/changeset/3016051/post-smtp/trunk?contextall=1&amp;old=3012318&amp;old_path=%2Fpost-smtp%2Ftrunk" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e675d64c-cbb8-4f24-9b6f-2597a97b49af?source=cve" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-6875" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/UlyssesSaicha/CVE-2023-6875" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress paid memberships pro &lt;2.6.7 - blind sql injection critical identify critical remote vulnerabilities wordpress paid memberships pro plugin before 2.6.7 is susceptible to blind sql injection. the plugin does not escape the discount_code in one of its rest routes before using it in a sql statement. an attacker can possibly obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site. cve-2021-25114 theamanrawat cve cve2021 paid-memberships-pro sqli strangerstudios time-based-sqli vkev vuln wordpress wp wp-plugin wpscan cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">WordPress Paid Memberships Pro &lt;2.6.7 - Blind SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2021/CVE-2021-25114.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2021-25114.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> theamanrawat</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2021-25114" target="_blank" rel="noopener" class="nt-cve-link">CVE-2021-25114</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/paid-memberships-pro/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">WordPress Paid Memberships Pro plugin before 2.6.7 is susceptible to blind SQL injection. The plugin does not escape the discount_code in one of its REST routes before using it in a SQL statement. An attacker can possibly obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to extract sensitive information from the database.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to WordPress Paid Memberships Pro version 2.6.7 or later to mitigate this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2021</span><span class="nt-tag">paid-memberships-pro</span><span class="nt-tag">sqli</span><span class="nt-tag">strangerstudios</span><span class="nt-tag">time-based-sqli</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">wpscan</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wpscan.com/vulnerability/6c25a5f0-a137-4ea5-9422-8ae393d7b76b" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://wordpress.org/plugins/paid-memberships-pro/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2021-25114" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://www.paidmembershipspro.com/pmpro-update-2-6-7-security-release/" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/ARPSyndicate/kenzer-templates" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress paid memberships pro &lt;2.9.8 - blind sql injection critical identify critical remote vulnerabilities wordpress paid memberships pro plugin before 2.9.8 contains a blind sql injection vulnerability in the &#39;code&#39; parameter of the /pmpro/v1/order rest route. an attacker can possibly obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site. cve-2023-23488 dwisiswant0 cve cve2023 packetstorm paid-memberships-pro sqli strangerstudios tenable time-based-sqli vkev vuln wordpress wp wp-plugin cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">WordPress Paid Memberships Pro &lt;2.9.8 - Blind SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-23488.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-23488.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dwisiswant0</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-23488" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-23488</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/paid-memberships-pro/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">WordPress Paid Memberships Pro plugin before 2.9.8 contains a blind SQL injection vulnerability in the &#39;code&#39; parameter of the /pmpro/v1/order REST route. An attacker can possibly obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to extract sensitive information from the database.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to WordPress Paid Memberships Pro version 2.9.8 or later to mitigate this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">packetstorm</span><span class="nt-tag">paid-memberships-pro</span><span class="nt-tag">sqli</span><span class="nt-tag">strangerstudios</span><span class="nt-tag">tenable</span><span class="nt-tag">time-based-sqli</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.tenable.com/security/research/tra-2023-2" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://wordpress.org/plugins/paid-memberships-pro/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-23488" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="http://packetstormsecurity.com/files/171661/WordPress-Paid-Memberships-Pro-2.9.8-SQL-Injection.html" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/CVEDB/PoC-List" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress perfect images (wp retina 2x) &lt; 6.4.6 - sensitive information exposure medium identify critical remote vulnerabilities jordy meow perfect images (manage image sizes, thumbnails, replace, retina) versions up to 6.4.5 contain a vulnerability that exposes sensitive information to unauthorized actors, letting attackers access confidential data, exploit requires no specific conditions. cve-2023-44982 pussycat0x cve cve2023 wordpress wp-plugin wp-retina-2x cwe-200" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">WordPress Perfect Images (WP Retina 2x) &lt; 6.4.6 - Sensitive Information Exposure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-44982.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-44982.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 7, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-44982" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-44982</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/wp-retina-2x/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Jordy Meow Perfect Images (Manage Image Sizes, Thumbnails, Replace, Retina) versions up to 6.4.5 contain a vulnerability that exposes sensitive information to unauthorized actors, letting attackers access confidential data, exploit requires no specific conditions.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthorized actors can access sensitive information, leading to privacy breaches and potential data misuse.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to version 6.4.6 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">wp-retina-2x</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wpscan.com/vulnerability/aba0c4a1-e253-4b5b-b46d-239567567b16/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress plugin gdpr cookie consent - full path disclosure low identify critical remote vulnerabilities wordpress gdpr cookie consent (cookie-law-info) plugin is vulnerable to full path disclosure via direct access to plugin files. ritikchaddha wp wordpress wp-plugin fpd gdpr cookie exposure" data-nt-sev="low">
  <div class="nt-card-header">
    <div class="nt-title">WordPress Plugin GDPR Cookie Consent - Full Path Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/misconfiguration/wordpress/wp-cookie-law-info-fpd.yaml" target="_blank" rel="noopener" class="nt-source-link">wp-cookie-law-info-fpd.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 17, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/cookie-law-info/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">WordPress GDPR Cookie Consent (cookie-law-info) plugin is vulnerable to full path disclosure via direct access to plugin files.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">wp</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">fpd</span><span class="nt-tag">gdpr</span><span class="nt-tag">cookie</span><span class="nt-tag">exposure</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wordpress.org/plugins/cookie-law-info/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress plugin google tag manager - full path disclosure low identify critical remote vulnerabilities wordpress plugin google tag manager files are publicly accessible without abspath protection, exposing sensitive server path information through php error messages when accessed directly. dhiyaneshdk debug wordpress fpd vuln duracelltomi-google-tag-manager wp-plugin" data-nt-sev="low">
  <div class="nt-card-header">
    <div class="nt-title">WordPress Plugin Google Tag Manager - Full Path Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/misconfiguration/wordpress/wp-duracelltomi-google-tag-manager-fpd.yaml" target="_blank" rel="noopener" class="nt-source-link">wp-duracelltomi-google-tag-manager-fpd.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 7, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/plugins/duracelltomi-google-tag-manager/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">WordPress Plugin Google Tag Manager files are publicly accessible without ABSPATH protection, exposing sensitive server path information through PHP error messages when accessed directly.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">debug</span><span class="nt-tag">wordpress</span><span class="nt-tag">fpd</span><span class="nt-tag">vuln</span><span class="nt-tag">duracelltomi-google-tag-manager</span><span class="nt-tag">wp-plugin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wordpress.org/plugins/duracelltomi-google-tag-manager/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress plugin imsanity - full path disclosure low identify critical remote vulnerabilities wordpress imsanity plugin is vulnerable to full path disclosure via direct access to plugin files. ritikchaddha wp wordpress wp-plugin fpd imsanity exposure" data-nt-sev="low">
  <div class="nt-card-header">
    <div class="nt-title">WordPress Plugin Imsanity - Full Path Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/misconfiguration/wordpress/wordpress-imsanity-fpd.yaml" target="_blank" rel="noopener" class="nt-source-link">wordpress-imsanity-fpd.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 17, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/imsanity/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">WordPress Imsanity plugin is vulnerable to full path disclosure via direct access to plugin files.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">wp</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">fpd</span><span class="nt-tag">imsanity</span><span class="nt-tag">exposure</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wordpress.org/plugins/imsanity/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress plugin infinitewp client - full path disclosure low identify critical remote vulnerabilities wordpress infinitewp client plugin is vulnerable to full path disclosure via direct access to plugin files. ritikchaddha wp wordpress wp-plugin fpd iwp-client exposure" data-nt-sev="low">
  <div class="nt-card-header">
    <div class="nt-title">WordPress Plugin InfiniteWP Client - Full Path Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/misconfiguration/wordpress/wp-iwp-client-fpd.yaml" target="_blank" rel="noopener" class="nt-source-link">wp-iwp-client-fpd.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 17, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/iwp-client/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">WordPress InfiniteWP Client plugin is vulnerable to full path disclosure via direct access to plugin files.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">wp</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">fpd</span><span class="nt-tag">iwp-client</span><span class="nt-tag">exposure</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wordpress.org/plugins/iwp-client/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress plugin layerslider 7.9.11-7.10.0 - sql injection high identify critical remote vulnerabilities the layerslider plugin for wordpress is vulnerable to sql injection via the ls_get_popup_markup action in versions 7.9.11 and 7.10.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing sql query.  this makes it possible for unauthenticated attackers to append additional sql queries into already existing queries that can be used to extract sensitive information from the database. cve-2024-2879 d4ly cve cve2024 layerslider sqli time-based-sqli vkev vuln wordpress wp wp-plugin cwe-89" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">WordPress Plugin LayerSlider 7.9.11-7.10.0 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-2879.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-2879.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> d4ly</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 5, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-2879" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-2879</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/LayerSlider/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The LayerSlider plugin for WordPress is vulnerable to SQL Injection via the ls_get_popup_markup action in versions 7.9.11 and 7.10.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Authenticated attackers can execute arbitrary SQL queries, potentially extracting sensitive data or compromising the database.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update LayerSlider plugin to version 7.10.1 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">layerslider</span><span class="nt-tag">sqli</span><span class="nt-tag">time-based-sqli</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-2879" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.securityblue.team/blog/posts/Critical-Vulnerability-in-WordPress-Plugin-LayerSlider" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.wordfence.com/blog/2024/04/5500-bounty-awarded-for-unauthenticated-sql-injection-vulnerability-patched-in-layerslider-wordpress-plugin/" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://layerslider.com/release-log/" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/3fddf96e-029c-4753-ba82-043ca64b78d3?source=cve" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress plugin max mega menu (megamenu) - full path disclosure low identify critical remote vulnerabilities wordpress plugin max mega menu plugin files are publicly accessible without abspath protection, exposing sensitive server path information through php error messages when accessed directly. dhiyaneshdk debug wordpress fpd megamenu wp-plugin" data-nt-sev="low">
  <div class="nt-card-header">
    <div class="nt-title">WordPress Plugin Max Mega Menu (megamenu) - Full Path Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/misconfiguration/wordpress/wp-megamenu-fpd.yaml" target="_blank" rel="noopener" class="nt-source-link">wp-megamenu-fpd.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 7, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/plugins/megamenu&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">WordPress Plugin Max Mega Menu plugin files are publicly accessible without ABSPATH protection, exposing sensitive server path information through PHP error messages when accessed directly.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">debug</span><span class="nt-tag">wordpress</span><span class="nt-tag">fpd</span><span class="nt-tag">megamenu</span><span class="nt-tag">wp-plugin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wordpress.org/plugins/megamenu/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress plugin newsletter - full path disclosure low identify critical remote vulnerabilities wordpress plugin newsletter plugin files are publicly accessible without abspath protection, exposing sensitive server path information through php error messages when accessed directly. dhiyaneshdk debug wordpress fpd vuln" data-nt-sev="low">
  <div class="nt-card-header">
    <div class="nt-title">WordPress Plugin Newsletter - Full Path Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/misconfiguration/wordpress/wp-newsletter-fpd.yaml" target="_blank" rel="noopener" class="nt-source-link">wp-newsletter-fpd.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 7, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/plugins/newsletter/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">WordPress Plugin Newsletter plugin files are publicly accessible without ABSPATH protection, exposing sensitive server path information through PHP error messages when accessed directly.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">debug</span><span class="nt-tag">wordpress</span><span class="nt-tag">fpd</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wordpress.org/plugins/newsletter/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress plugin sg optimizer - full path disclosure low identify critical remote vulnerabilities wordpress plugin sg optimizer plugin files are publicly accessible without abspath protection, exposing sensitive server path information through php error messages when accessed directly. dhiyaneshdk debug wordpress fpd vuln sg-cachepress wp-plugin" data-nt-sev="low">
  <div class="nt-card-header">
    <div class="nt-title">WordPress Plugin SG Optimizer - Full Path Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/misconfiguration/wordpress/wp-sg-cachepress-fpd.yaml" target="_blank" rel="noopener" class="nt-source-link">wp-sg-cachepress-fpd.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 7, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/plugins/sg-cachepress/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">WordPress Plugin SG Optimizer Plugin files are publicly accessible without ABSPATH protection, exposing sensitive server path information through PHP error messages when accessed directly.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">debug</span><span class="nt-tag">wordpress</span><span class="nt-tag">fpd</span><span class="nt-tag">vuln</span><span class="nt-tag">sg-cachepress</span><span class="nt-tag">wp-plugin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wordpress.org/plugins/sg-cachepress/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress plugin ssl insecure content fixer - full path disclosure low identify critical remote vulnerabilities wordpress ssl insecure content fixer plugin files are publicly accessible without abspath protection, exposing sensitive server path information through php error messages when accessed directly. dhiyaneshdk debug wordpress fpd vuln ssl-insecure-content-fixer wp-plugin" data-nt-sev="low">
  <div class="nt-card-header">
    <div class="nt-title">WordPress Plugin SSL Insecure Content Fixer - Full Path Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/misconfiguration/wordpress/wp-ssl-insecure-content-fixer-fpd.yaml" target="_blank" rel="noopener" class="nt-source-link">wp-ssl-insecure-content-fixer-fpd.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 7, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/ssl-insecure-content-fixer/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">WordPress SSL Insecure Content Fixer plugin files are publicly accessible without ABSPATH protection, exposing sensitive server path information through PHP error messages when accessed directly.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">debug</span><span class="nt-tag">wordpress</span><span class="nt-tag">fpd</span><span class="nt-tag">vuln</span><span class="nt-tag">ssl-insecure-content-fixer</span><span class="nt-tag">wp-plugin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wordpress.org/plugins/ssl-insecure-content-fixer/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress plugin safe svg - full path disclosure low identify critical remote vulnerabilities wordpress safe svg plugin is vulnerable to full path disclosure via direct access to plugin files. ritikchaddha wp wordpress wp-plugin fpd safe-svg exposure" data-nt-sev="low">
  <div class="nt-card-header">
    <div class="nt-title">WordPress Plugin Safe SVG - Full Path Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/misconfiguration/wordpress/wp-safe-svg-fpd.yaml" target="_blank" rel="noopener" class="nt-source-link">wp-safe-svg-fpd.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 17, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/safe-svg/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">WordPress Safe SVG plugin is vulnerable to full path disclosure via direct access to plugin files.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">wp</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">fpd</span><span class="nt-tag">safe-svg</span><span class="nt-tag">exposure</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wordpress.org/plugins/safe-svg/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress plugin table of contents plus - full path disclosure low identify critical remote vulnerabilities the table of contents plus wordpress plugin is vulnerable to full path disclosure. this vulnerability allows attackers to view the full server path by accessing certain files or triggering error conditions, which can aid in further attacks such as directory traversal or local file inclusion. ritikchaddha wp wordpress wp-plugin table-of-contents-plus fpd exposure" data-nt-sev="low">
  <div class="nt-card-header">
    <div class="nt-title">WordPress Plugin Table of Contents Plus - Full Path Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/misconfiguration/wordpress/wp-toc-plus-fpd.yaml" target="_blank" rel="noopener" class="nt-source-link">wp-toc-plus-fpd.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 19, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)wp-content/plugins/table-of-contents-plus&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The Table of Contents Plus WordPress plugin is vulnerable to Full Path Disclosure. This vulnerability allows attackers to view the full server path by accessing certain files or triggering error conditions, which can aid in further attacks such as directory traversal or local file inclusion.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can exploit this vulnerability to gain insights into the server&#39;s directory structure, which can be leveraged to perform further attacks such as directory traversal or local file inclusion.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update the Table of Contents Plus plugin to the latest version. Ensure error reporting is disabled in production environments and implement proper error handling that doesn&#39;t expose full paths.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">wp</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">table-of-contents-plus</span><span class="nt-tag">fpd</span><span class="nt-tag">exposure</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wordpress.org/plugins/table-of-contents-plus/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://wpscan.com/plugins/table-of-contents-plus/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress plugin wp statistics &lt;= 13.1.5 - sql injection high identify critical remote vulnerabilities the wp statistics wordpress plugin is vulnerable to sql injection due to insufficient escaping and parameterization of the ip parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers without authentication to inject arbitrary sql queries to obtain sensitive information, in versions up to and including 13.1.5. cve-2022-25149 theamanrawat cve cve2022 sqli time-based-sqli veronalabs vuln wordpress wp wp-plugin wp-statistics wpscan cwe-89" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">WordPress Plugin WP Statistics &lt;= 13.1.5 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-25149.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-25149.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> theamanrawat</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 17, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-25149" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-25149</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/wp-statistics/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the IP parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers without authentication to inject arbitrary SQL queries to obtain sensitive information, in versions up to and including 13.1.5.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can execute time-based blind SQL injection through the IP parameter to extract sensitive database information including user credentials, posts, comments, and WordPress configuration data.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update WP Statistics plugin to version 13.1.6 or later that properly escapes and parameterizes the IP parameter.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">sqli</span><span class="nt-tag">time-based-sqli</span><span class="nt-tag">veronalabs</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">wp-statistics</span><span class="nt-tag">wpscan</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wordpress.org/plugins/wp-statistics/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://gist.github.com/Xib3rR4dAr/5dbd58b7f57a5037fe461fba8e696042" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-25149" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;old=2679983%40wp-statistics&amp;new=2679983%40wp-statistics&amp;sfp_email=&amp;sfph_mail=" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://www.wordfence.com/vulnerability-advisories/#CVE-2022-25149" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress plugin wp statistics &lt;= 13.1.5 - sql injection critical identify critical remote vulnerabilities the wp statistics wordpress plugin is vulnerable to sql injection due to insufficient escaping and parameterization of the current_page_id parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers without authentication to inject arbitrary sql queries to obtain sensitive information, in versions up to and including 13.1.5. cve-2022-25148 theamanrawat cve cve2022 packetstorm sqli time-based-sqli veronalabs vuln wordpress wp wp-plugin wp-statistics wpscan cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">WordPress Plugin WP Statistics &lt;= 13.1.5 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-25148.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-25148.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> theamanrawat</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 17, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-25148" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-25148</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/wp-statistics/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the current_page_id parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers without authentication to inject arbitrary SQL queries to obtain sensitive information, in versions up to and including 13.1.5.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can execute time-based SQL injection through the current_page_id parameter to extract the complete WordPress database including user credentials, visitor statistics, and site analytics data.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update wp-statistics plugin to version 13.1.6, or newer.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">packetstorm</span><span class="nt-tag">sqli</span><span class="nt-tag">time-based-sqli</span><span class="nt-tag">veronalabs</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">wp-statistics</span><span class="nt-tag">wpscan</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wordpress.org/plugins/wp-statistics/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://gist.github.com/Xib3rR4dAr/5dbd58b7f57a5037fe461fba8e696042" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-25148" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="http://packetstormsecurity.com/files/174482/WordPress-WP-Statistics-13.1.5-SQL-Injection.html" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;old=2679983%40wp-statistics&amp;new=2679983%40wp-statistics&amp;sfp_email=&amp;sfph_mail=" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress plugin wp statistics &lt;= 13.1.5 - sql injection high identify critical remote vulnerabilities the wp statistics wordpress plugin is vulnerable to sql injection due to insufficient escaping and parameterization of the current_page_type parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers without authentication to inject arbitrary sql queries to obtain sensitive information, in versions up to and including 13.1.5. cve-2022-0651 theamanrawat cve cve2022 sqli time-based-sqli veronalabs vuln wordpress wp wp-plugin wp-statistics cwe-89" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">WordPress Plugin WP Statistics &lt;= 13.1.5 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-0651.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-0651.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> theamanrawat</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 17, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-0651" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-0651</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/wp-statistics/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the current_page_type parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers without authentication to inject arbitrary SQL queries to obtain sensitive information, in versions up to and including 13.1.5.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can exploit time-based blind SQL injection to extract sensitive database contents including user credentials and statistics data.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update wp-statistics plugin to version 13.1.6, or newer.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">sqli</span><span class="nt-tag">time-based-sqli</span><span class="nt-tag">veronalabs</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">wp-statistics</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wordpress.org/plugins/wp-statistics/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://gist.github.com/Xib3rR4dAr/5dbd58b7f57a5037fe461fba8e696042" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-0651" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;old=2679983%40wp-statistics&amp;new=2679983%40wp-statistics&amp;sfp_email=&amp;sfph_mail=" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://www.wordfence.com/vulnerability-advisories/#CVE-2022-0651" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress plugin woocommerce admin (woocommerce-admin) full path disclosure low identify critical remote vulnerabilities wordpress plugin woocommerce admin plugin files are publicly accessible without abspath protection, exposing sensitive server path information through php error messages when accessed directly. dhiyaneshdk debug wordpress fpd woocommerce-admin wp-plugin" data-nt-sev="low">
  <div class="nt-card-header">
    <div class="nt-title">WordPress Plugin WooCommerce Admin (woocommerce-admin) Full Path Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/misconfiguration/wordpress/wp-woocommerce-admin-fpd.yaml" target="_blank" rel="noopener" class="nt-source-link">wp-woocommerce-admin-fpd.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 7, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/plugins/woocommerce-admin&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">WordPress Plugin WooCommerce Admin plugin files are publicly accessible without ABSPATH protection, exposing sensitive server path information through PHP error messages when accessed directly.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">debug</span><span class="nt-tag">wordpress</span><span class="nt-tag">fpd</span><span class="nt-tag">woocommerce-admin</span><span class="nt-tag">wp-plugin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wordpress.org/plugins/woocommerce-admin/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress plugin ithemes security - full path disclosure low identify critical remote vulnerabilities wordpress plugin ithemes security files are publicly accessible without abspath protection, exposing sensitive server path information through php error messages when accessed directly. dhiyaneshdk debug wordpress fpd vuln better-wp-security wp-plugin" data-nt-sev="low">
  <div class="nt-card-header">
    <div class="nt-title">WordPress Plugin iThemes Security - Full Path Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/misconfiguration/wordpress/wp-better-wp-security-fpd.yaml" target="_blank" rel="noopener" class="nt-source-link">wp-better-wp-security-fpd.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 7, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/plugins/better-wp-security/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">WordPress Plugin iThemes Security files are publicly accessible without ABSPATH protection, exposing sensitive server path information through PHP error messages when accessed directly.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">debug</span><span class="nt-tag">wordpress</span><span class="nt-tag">fpd</span><span class="nt-tag">vuln</span><span class="nt-tag">better-wp-security</span><span class="nt-tag">wp-plugin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wordpress.org/plugins/better-wp-security/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress plugin recaptcha by bestwebsoft (google-captcha) - full path disclosure low identify critical remote vulnerabilities wordpress managewp worker plugin files are publicly accessible without abspath protection, exposing sensitive server path information through php error messages when accessed directly. dhiyaneshdk debug wordpress fpd vuln" data-nt-sev="low">
  <div class="nt-card-header">
    <div class="nt-title">WordPress Plugin reCaptcha by BestWebSoft (google-captcha) - Full Path Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/misconfiguration/wordpress/wp-googlecaptcha-fpd.yaml" target="_blank" rel="noopener" class="nt-source-link">wp-googlecaptcha-fpd.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 7, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/plugins/google-captcha&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">WordPress ManageWP Worker plugin files are publicly accessible without ABSPATH protection, exposing sensitive server path information through PHP error messages when accessed directly.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">debug</span><span class="nt-tag">wordpress</span><span class="nt-tag">fpd</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wordpress.org/plugins/google-captcha/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress pretty links - full path disclosure low identify critical remote vulnerabilities wordpress pretty links plugin is vulnerable to full path disclosure via direct access to plugin files. ritikchaddha wp wordpress wp-plugin fpd pretty-links exposure" data-nt-sev="low">
  <div class="nt-card-header">
    <div class="nt-title">WordPress Pretty Links - Full Path Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/misconfiguration/wordpress/wp-pretty-links-fpd.yaml" target="_blank" rel="noopener" class="nt-source-link">wp-pretty-links-fpd.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 17, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/pretty-link/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">WordPress Pretty Links plugin is vulnerable to full path disclosure via direct access to plugin files.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">wp</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">fpd</span><span class="nt-tag">pretty-links</span><span class="nt-tag">exposure</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wordpress.org/plugins/pretty-link/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress print invoice &amp; delivery notes for woocommerce &lt;= 5.8.0 - remote code execution critical identify critical remote vulnerabilities print invoice &amp; delivery notes for woocommerce plugin for wordpress &lt;= 5.8.0 contains a remote code execution caused by missing capability check, php enabled in dompdf, and missing escape in template.php, letting unauthenticated attackers execute code on the server. cve-2025-13773 pikajuna-ops cve cve2025 passive rce vkev woocommerce-delivery-notes wordpress wp-plugin cwe-94" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">WordPress Print Invoice &amp; Delivery Notes for WooCommerce &lt;= 5.8.0 - Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-13773.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-13773.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> PikaJuna-ops</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 4, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/94.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-94</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-13773" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-13773</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;/wp-content/plugins/woocommerce-delivery-notes/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Print Invoice &amp; Delivery Notes for WooCommerce plugin for WordPress &lt;= 5.8.0 contains a remote code execution caused by missing capability check, PHP enabled in Dompdf, and missing escape in template.php, letting unauthenticated attackers execute code on the server.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can execute arbitrary code on the server, potentially leading to full system compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest version beyond 5.8.0.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">passive</span><span class="nt-tag">rce</span><span class="nt-tag">vkev</span><span class="nt-tag">woocommerce-delivery-notes</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp-plugin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e52b34fe-2414-4d6f-bf43-9c5b65ebf769" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://plugins.trac.wordpress.org/changeset/3426119/woocommerce-delivery-notes" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-13773" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress realtyna organic idx plugin &lt;= 4.14.4 - unauthenticated sql injection critical identify critical remote vulnerabilities the realtyna organic idx plugin plugin for wordpress is vulnerable to sql injection in versions up to, and including, 4.14.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing sql query. this makes it possible for unauthenticated attackers to append additional sql queries into already existing queries that can be used to extract sensitive information from the database. cve-2024-32128 shivam kamboj cve cve2024 wordpress wp-plugin sqli realtyna wp unauth real-estate-listing-realtyna-wpl info-leak vuln cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">WordPress Realtyna Organic IDX Plugin &lt;= 4.14.4 - Unauthenticated SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-32128.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-32128.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Shivam Kamboj</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 6, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-32128" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-32128</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/real-estate-listing-realtyna-wpl(?:-pro)?/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The Realtyna Organic IDX plugin plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.14.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can execute arbitrary SQL commands, potentially leading to data theft, data tampering, or database compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest version of the plugin, version 4.14.5 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">sqli</span><span class="nt-tag">realtyna</span><span class="nt-tag">wp</span><span class="nt-tag">unauth</span><span class="nt-tag">real-estate-listing-realtyna-wpl</span><span class="nt-tag">info-leak</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-32128" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://patchstack.com/database/wordpress/plugin/real-estate-listing-realtyna-wpl/vulnerabilities" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress seo plugin rank math - full path disclosure low identify critical remote vulnerabilities wordpress rank math seo plugin is vulnerable to full path disclosure via direct access to plugin files. ritikchaddha,dhiyaneshdk wp wordpress wp-plugin fpd rank-math seo exposure" data-nt-sev="low">
  <div class="nt-card-header">
    <div class="nt-title">WordPress SEO Plugin Rank Math - Full Path Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/misconfiguration/wordpress/wp-rank-math-seo-fpd.yaml" target="_blank" rel="noopener" class="nt-source-link">wp-rank-math-seo-fpd.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha,DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 17, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/seo-by-rank-math/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">WordPress Rank Math SEO plugin is vulnerable to full path disclosure via direct access to plugin files.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">wp</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">fpd</span><span class="nt-tag">rank-math</span><span class="nt-tag">seo</span><span class="nt-tag">exposure</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wordpress.org/plugins/seo-by-rank-math/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress svg support - full path disclosure low identify critical remote vulnerabilities the wordpress svg support plugin was detected to have publicly accessible php files without abspath protection, which exposed sensitive server path information. direct access to vendor/composer files triggered php fatal errors that revealed the full wordpress filesystem path. pussycat0x wordpress fpd disclosure wp wp-plugin svg-support" data-nt-sev="low">
  <div class="nt-card-header">
    <div class="nt-title">WordPress SVG Support - Full Path Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/misconfiguration/wordpress/wp-svg-support-fpd.yaml" target="_blank" rel="noopener" class="nt-source-link">wp-svg-support-fpd.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 23, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/svg-support/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The WordPress SVG Support plugin was detected to have publicly accessible PHP files without ABSPATH protection, which exposed sensitive server path information. Direct access to vendor/composer files triggered PHP fatal errors that revealed the full WordPress filesystem path.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">wordpress</span><span class="nt-tag">fpd</span><span class="nt-tag">disclosure</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">svg-support</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wordpress.org/plugins/svg-support/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress simple job board - unauthorized data access medium identify critical remote vulnerabilities the simple job board plugin for wordpress is vulnerable to unauthorized data access due to insufficient authorization checking in the fetch_quick_job() function in all versions up to and including 2.10.8. this makes it possible for unauthenticated attackers to fetch arbitrary posts, which can be password protected or private and contain sensitive information. cve-2024-0593 zer0p0int cve cve2024 exposure simple-job-board vuln wordpress wp wp-plugin cwe-862" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">WordPress Simple Job Board - Unauthorized Data Access</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-0593.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-0593.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> zer0p0int</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 22, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/862.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-862</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-0593" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-0593</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/simple-job-board&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The Simple Job Board plugin for WordPress is vulnerable to unauthorized data access due to insufficient authorization checking in the fetch_quick_job() function in all versions up to and including 2.10.8. This makes it possible for unauthenticated attackers to fetch arbitrary posts, which can be password protected or private and contain sensitive information.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can access password-protected or private posts containing sensitive information without authorization, potentially exposing confidential job postings or internal data.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to Simple Job Board version 2.10.9 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">exposure</span><span class="nt-tag">simple-job-board</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0a28a161-3dbc-4ef0-a2ce-4c102cf3cbb0" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://plugins.trac.wordpress.org/changeset/3038476/simple-job-board/trunk/includes/class-simple-job-board-ajax.php" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-0593" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress statistics &lt;13.0.8 - blind sql injection high identify critical remote vulnerabilities wordpress statistic plugin versions prior to version 13.0.8 are affected by an unauthenticated time-based blind sql injection vulnerability. cve-2021-24340 lotusdll,j4vaovo blind cve cve2021 edb sqli time-based-sqli unauth veronalabs vuln wordpress wp-plugin wpscan cwe-89" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">WordPress Statistics &lt;13.0.8 - Blind SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2021/CVE-2021-24340.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2021-24340.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> lotusdll,j4vaovo</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2021-24340" target="_blank" rel="noopener" class="nt-cve-link">CVE-2021-24340</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/wp-statistics/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">WordPress Statistic plugin versions prior to version 13.0.8 are affected by an unauthenticated time-based blind SQL injection vulnerability.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can extract database contents via time-based blind SQL injection, potentially exposing sensitive WordPress configuration and user data.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to WordPress Statistics plugin version 13.0.8 or later to mitigate the vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">blind</span><span class="nt-tag">cve</span><span class="nt-tag">cve2021</span><span class="nt-tag">edb</span><span class="nt-tag">sqli</span><span class="nt-tag">time-based-sqli</span><span class="nt-tag">unauth</span><span class="nt-tag">veronalabs</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">wpscan</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.exploit-db.com/exploits/49894" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.wordfence.com/blog/2021/05/over-600000-sites-impacted-by-wp-statistics-patch/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/Udyz/WP-Statistics-BlindSQL" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://wpscan.com/vulnerability/d2970cfb-0aa9-4516-9a4b-32971f41a19c" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2021-24340" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress storefront theme - full path disclosure low identify critical remote vulnerabilities the storefront theme for wordpress was detected to be vulnerable to full path disclosure, allowing unauthenticated attackers to obtain the full application path that could aid other attacks when combined with another vulnerability. pussycat0x wordpress wp wp-theme fpd disclosure storefront woocommerce" data-nt-sev="low">
  <div class="nt-card-header">
    <div class="nt-title">WordPress Storefront Theme - Full Path Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/misconfiguration/wordpress/wordpress-storefront-fpd.yaml" target="_blank" rel="noopener" class="nt-source-link">wordpress-storefront-fpd.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 23, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/themes/storefront/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The Storefront theme for WordPress was detected to be vulnerable to Full Path Disclosure, allowing unauthenticated attackers to obtain the full application path that could aid other attacks when combined with another vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-theme</span><span class="nt-tag">fpd</span><span class="nt-tag">disclosure</span><span class="nt-tag">storefront</span><span class="nt-tag">woocommerce</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wordpress.org/themes/storefront/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://woocommerce.com/products/storefront/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress ti woocommerce wishlist plugin &lt;= 2.8.2 - sql injection critical identify critical remote vulnerabilities in the latest version (2.8.2 as of writing the article) and below, the plugin is vulnerable to a sql injection vulnerability that allows any users to execute arbitrary sql queries in the database of the wordpress site. no privileges are required to exploit the issue. the vulnerability is unpatched on the latest version and is tracked as the cve-2024-43917. cve-2024-43917 iamnoooob,rootxharsh,pdresearch cve cve2024 sqli ti-woocommerce-wishlist time-based-sqli vkev vuln wordpress wp wp-plugin cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">WordPress TI WooCommerce Wishlist Plugin &lt;= 2.8.2 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-43917.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-43917.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> iamnoooob,rootxharsh,pdresearch</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 1, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-43917" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-43917</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/ti-woocommerce-wishlist/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">In the latest version (2.8.2 as of writing the article) and below, the plugin is vulnerable to a SQL injection vulnerability that allows any users to execute arbitrary SQL queries in the database of the WordPress site. No privileges are required to exploit the issue. The vulnerability is unpatched on the latest version and is tracked as the CVE-2024-43917.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can execute time-based SQL injection to extract sensitive data from the WordPress database.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update TI WooCommerce Wishlist plugin to a version that patches CVE-2024-43917.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">sqli</span><span class="nt-tag">ti-woocommerce-wishlist</span><span class="nt-tag">time-based-sqli</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://patchstack.com/articles/unpatched-sql-injection-vulnerability-in-ti-woocommerce-wishlist-plugin/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://patchstack.com/database/vulnerability/ti-woocommerce-wishlist/wordpress-ti-woocommerce-wishlist-plugin-2-8-2-sql-injection-vulnerability?_s_id=cve" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-43917" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress table of contents plus - full path disclosure low identify critical remote vulnerabilities wordpress table of contents plus plugin is vulnerable to full path disclosure via direct access to plugin files. ritikchaddha wp wordpress wp-plugin fpd toc exposure" data-nt-sev="low">
  <div class="nt-card-header">
    <div class="nt-title">WordPress Table of Contents Plus - Full Path Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/misconfiguration/wordpress/wp-table-of-contents-plus-fpd.yaml" target="_blank" rel="noopener" class="nt-source-link">wp-table-of-contents-plus-fpd.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 17, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/table-of-contents-plus/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">WordPress Table of Contents Plus plugin is vulnerable to full path disclosure via direct access to plugin files.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">wp</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">fpd</span><span class="nt-tag">toc</span><span class="nt-tag">exposure</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wordpress.org/plugins/table-of-contents-plus/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress the events calendar - full path disclosure low identify critical remote vulnerabilities wordpress the events calendar plugin is vulnerable to full path disclosure via direct access to plugin files. ritikchaddha wp wordpress wp-plugin fpd events-calendar exposure" data-nt-sev="low">
  <div class="nt-card-header">
    <div class="nt-title">WordPress The Events Calendar - Full Path Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/misconfiguration/wordpress/wp-the-events-calendar-fpd.yaml" target="_blank" rel="noopener" class="nt-source-link">wp-the-events-calendar-fpd.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 17, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/the-events-calendar/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">WordPress The Events Calendar plugin is vulnerable to full path disclosure via direct access to plugin files.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">wp</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">fpd</span><span class="nt-tag">events-calendar</span><span class="nt-tag">exposure</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wordpress.org/plugins/the-events-calendar/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress tourfic plugin &lt;= 2.11.7 - cross-site scripting high identify critical remote vulnerabilities the tourfic plugin for wordpress is vulnerable to reflected cross-site scripting (xss) in versions up to and including 2.11.7 due to insufficient input sanitization and output escaping in the &#39;place&#39; parameter. cve-2024-29137 shivam kamboj cve cve2024 tourfic unauth vkev wordpress wp-plugin xss cwe-79" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">WordPress Tourfic Plugin &lt;= 2.11.7 - Cross-Site Scripting</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-29137.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-29137.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Shivam Kamboj</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 7, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-79</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-29137" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-29137</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/tourfic/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The Tourfic plugin for WordPress is vulnerable to Reflected Cross-Site Scripting (XSS) in versions up to and including 2.11.7 due to insufficient input sanitization and output escaping in the &#39;place&#39; parameter.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can execute malicious scripts in users&#39; browsers, potentially stealing cookies, session tokens, or performing actions on behalf of users.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to Tourfic version 2.11.8 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">tourfic</span><span class="nt-tag">unauth</span><span class="nt-tag">vkev</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">xss</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-29137" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://patchstack.com/database/vulnerability/tourfic/wordpress-tourfic-plugin-2-11-7-reflected-cross-site-scripting-xss-vulnerability" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/tourfic/tourfic-2117-reflected-cross-site-scripting" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://wpscan.com/vulnerability/f93321c7-d4e3-470c-9fd9-8e65c2284c5d/" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress ultimate member 2.1.3 - 2.8.2 – sql injection critical identify critical remote vulnerabilities the ultimate member - user profile, registration, login, member directory, content restriction &amp; membership plugin plugin for wordpress is vulnerable to sql injection via the ‘sorting’ parameter in versions 2.1.3 to 2.8.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing sql query. this makes it possible for unauthenticated attackers to append additional sql queries into already existing queries that can be used to extract sensitive information from the database. cve-2024-1071 dhiyaneshdk,iamnooob cve cve2024 sqli time-based-sqli ultimate-member vkev vuln wordpress wp-plugin wpscan cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">WordPress Ultimate Member 2.1.3 - 2.8.2 – SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-1071.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-1071.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK,iamnooob</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 29, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-1071" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-1071</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/ultimate-member&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The Ultimate Member - User Profile, Registration, Login, Member Directory, Content Restriction &amp; Membership Plugin plugin for WordPress is vulnerable to SQL Injection via the ‘sorting’ parameter in versions 2.1.3 to 2.8.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can execute time-based SQL injection through the sorting parameter in the member directory to extract the complete WordPress database including user credentials, member profiles, and sensitive site data.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Fixed in 2.8.3</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">sqli</span><span class="nt-tag">time-based-sqli</span><span class="nt-tag">ultimate-member</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">wpscan</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.wordfence.com/blog/2024/02/2063-bounty-awarded-for-unauthenticated-sql-injection-vulnerability-patched-in-ultimate-member-wordpress-plugin/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://securityonline.info/cve-2024-1071-wordpress-ultimate-member-plugin-under-active-attack/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://plugins.trac.wordpress.org/browser/ultimate-member/tags/2.8.2/includes/core/class-member-directory-meta.php?rev=3022076" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://plugins.trac.wordpress.org/browser/ultimate-member/tags/2.8.2/includes/core/class-member-directory-meta.php?rev=3022076#L666" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://plugins.trac.wordpress.org/browser/ultimate-member/tags/2.8.2/includes/core/class-member-directory-meta.php?rev=3022076#L858" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress updraftplus - full path disclosure low identify critical remote vulnerabilities wordpress plugin updraftplus files are publicly accessible without abspath protection, exposing sensitive server path information through php error messages when accessed directly. dhiyaneshdk wp wordpress wp-plugin fpd updraftplus misconfig" data-nt-sev="low">
  <div class="nt-card-header">
    <div class="nt-title">WordPress UpdraftPlus - Full Path Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/misconfiguration/wordpress/wp-updraftplus-fpd.yaml" target="_blank" rel="noopener" class="nt-source-link">wp-updraftplus-fpd.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 12, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/updraftplus&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">WordPress Plugin UpdraftPlus files are publicly accessible without ABSPATH protection, exposing sensitive server path information through PHP error messages when accessed directly.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">wp</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">fpd</span><span class="nt-tag">updraftplus</span><span class="nt-tag">misconfig</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wordpress.org/plugins/updraftplus/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress user registration &amp; membership plugin detection info identify web-based control panels detected wordpress user registration &amp; membership plugin and its version information. omarkurt wordpress wp-plugin user-registration tech wp" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">WordPress User Registration &amp; Membership Plugin Detection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/technologies/wordpress/plugins/user-registration.yaml" target="_blank" rel="noopener" class="nt-source-link">user-registration.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> omarkurt</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 10, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/user-registration/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detected WordPress User Registration &amp; Membership plugin and its version information.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">wordpress</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">user-registration</span><span class="nt-tag">tech</span><span class="nt-tag">wp</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wordpress.org/plugins/user-registration/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress visitor statistics &lt;=5.7 - sql injection critical identify critical remote vulnerabilities wordpress visitor statistics plugin through 5.7 contains multiple unauthenticated sql injection vulnerabilities. an attacker can possibly obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site. cve-2022-33965 theamanrawat cve cve2022 plugins-market sqli time-based-sqli unauth vuln wordpress wp wp-plugin wp-stats-manager cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">WordPress Visitor Statistics &lt;=5.7 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-33965.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-33965.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> theamanrawat</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-33965" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-33965</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)wp-stats-manager&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">WordPress Visitor Statistics plugin through 5.7 contains multiple unauthenticated SQL injection vulnerabilities. An attacker can possibly obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized access, data leakage, or further compromise of the WordPress site.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest version of the WordPress Visitor Statistics plugin (&gt;=5.8) to mitigate the SQL Injection vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">plugins-market</span><span class="nt-tag">sqli</span><span class="nt-tag">time-based-sqli</span><span class="nt-tag">unauth</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">wp-stats-manager</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://patchstack.com/database/vulnerability/wp-stats-manager/wordpress-wp-visitor-statistics-plugin-5-7-multiple-unauthenticated-sql-injection-sqli-vulnerabilities" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://wordpress.org/plugins/wp-stats-manager/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://wordpress.org/plugins/wp-stats-manager/#developers" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-33965" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/20142995/sectool" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress w3 total cache - cache files exposure high identify critical remote vulnerabilities detects publicly accessible w3 total cache database cache files in the wp-content/w3tc/dbcache/ directory. when database caching to disk is enabled, these files contain raw sql query results, potentially exposing sensitive data such as user details, password hashes, emails, or other database content if the directory is not properly protected. pussycat0x wordpress wp-plugin w3-total-cache exposure cache misconfig" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">WordPress W3 Total Cache - Cache Files Exposure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposures/files/wp-w3-total-cache-exposure.yaml" target="_blank" rel="noopener" class="nt-source-link">wp-w3-total-cache-exposure.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 22, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/w3tc/dbcache/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detects publicly accessible W3 Total Cache database cache files in the wp-content/w3tc/dbcache/ directory. When database caching to disk is enabled, these files contain raw SQL query results, potentially exposing sensitive data such as user details, password hashes, emails, or other database content if the directory is not properly protected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">wordpress</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">w3-total-cache</span><span class="nt-tag">exposure</span><span class="nt-tag">cache</span><span class="nt-tag">misconfig</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.acunetix.com/vulnerabilities/web/wordpress-w3-total-cache-plugin-predictable-cache-filenames/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.openwall.com/lists/oss-security/2012/12/30/3 (CVE-2012-6077 related discussion)" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://siteground.com/blog/w3-total-cache-vulnerability/" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress wp clone &lt;= 2.4.2 - database backup exposure critical identify critical remote vulnerabilities clone wordpress plugin &lt; 2.4.3 contains a buffer overflow caused by storing in-progress backup information in publicly accessible buffer files at a static file path, letting attackers access sensitive backup data, exploit requires no special privileges cve-2023-6750 pussycat0x backup cve cve2023 wordpress wp wp-clone wp-plugin cwe-200" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">WordPress WP Clone &lt;= 2.4.2 - Database Backup Exposure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-6750.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-6750.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 9, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-6750" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-6750</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/wp-clone-by-wp-academy/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Clone WordPress plugin &lt; 2.4.3 contains a buffer overflow caused by storing in-progress backup information in publicly accessible buffer files at a static file path, letting attackers access sensitive backup data, exploit requires no special privileges</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can access sensitive backup information, potentially leading to data disclosure or manipulation.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to version 2.4.3 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">backup</span><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-clone</span><span class="nt-tag">wp-plugin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-clone-by-wp-academy/clone-242-sensitive-information-exposure" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://plugins.trac.wordpress.org/changeset/3012647/wp-clone-by-wp-academy" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-6750" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress wp mail smtp - full path disclosure low identify critical remote vulnerabilities wordpress wp mail smtp plugin is vulnerable to full path disclosure via direct access to plugin files. ritikchaddha wp wordpress wp-plugin fpd wp-mail-smtp exposure" data-nt-sev="low">
  <div class="nt-card-header">
    <div class="nt-title">WordPress WP Mail SMTP - Full Path Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/misconfiguration/wordpress/wp-wp-mail-smtp-fpd.yaml" target="_blank" rel="noopener" class="nt-source-link">wp-wp-mail-smtp-fpd.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 17, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/wp-mail-smtp/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">WordPress WP Mail SMTP plugin is vulnerable to full path disclosure via direct access to plugin files.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">wp</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">fpd</span><span class="nt-tag">wp-mail-smtp</span><span class="nt-tag">exposure</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wordpress.org/plugins/wp-mail-smtp/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress wp maintenance mode - full path disclosure low identify critical remote vulnerabilities wordpress wp maintenance mode plugin is vulnerable to full path disclosure via direct access to plugin files. ritikchaddha wp wordpress wp-plugin fpd maintenance-mode exposure" data-nt-sev="low">
  <div class="nt-card-header">
    <div class="nt-title">WordPress WP Maintenance Mode - Full Path Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/misconfiguration/wordpress/wp-maintenance-mode-fpd.yaml" target="_blank" rel="noopener" class="nt-source-link">wp-maintenance-mode-fpd.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 17, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/wp-maintenance-mode/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">WordPress WP Maintenance Mode plugin is vulnerable to full path disclosure via direct access to plugin files.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">wp</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">fpd</span><span class="nt-tag">maintenance-mode</span><span class="nt-tag">exposure</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wordpress.org/plugins/wp-maintenance-mode/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress wp migrate db - full path disclosure low identify critical remote vulnerabilities the wp migrate db (wp migrate lite - wordpress migration made easy) plugin for wordpress was detected to be vulnerable to full path disclosure, allowing unauthenticated attackers to obtain the full application path that could aid other attacks when combined with another vulnerability. pussycat0x wordpress wp wp-plugin fpd wp-migrate-db wpmdb" data-nt-sev="low">
  <div class="nt-card-header">
    <div class="nt-title">WordPress WP Migrate DB - Full Path Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/misconfiguration/wordpress/wp-migrate-db-fpd.yaml" target="_blank" rel="noopener" class="nt-source-link">wp-migrate-db-fpd.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 23, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/wp-migrate-db/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The WP Migrate DB (WP Migrate Lite - WordPress Migration Made Easy) plugin for WordPress was detected to be vulnerable to Full Path Disclosure, allowing unauthenticated attackers to obtain the full application path that could aid other attacks when combined with another vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">fpd</span><span class="nt-tag">wp-migrate-db</span><span class="nt-tag">wpmdb</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wordpress.org/plugins/wp-migrate-db/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress wp-advanced-search &lt;= 3.3.9 - sql injection critical identify critical remote vulnerabilities the wordpress wp-advanced-search plugin for wordpress is vulnerable to sql injection in all versions up to, and including, 3.3.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing sql query. this makes it possible for unauthenticated attackers to append additional sql queries into already existing queries that can be used to extract sensitive information from the database. cve-2024-9796 s4e-io cve cve2024 sqli vuln wordpress wp wp-advanced-search wp-plugin cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">WordPress WP-Advanced-Search &lt;= 3.3.9 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-9796.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-9796.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> s4e-io</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 23, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-9796" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-9796</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/wp-advanced-search/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The WordPress WP-Advanced-Search plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 3.3.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can exploit SQL injection through the autocompletion endpoint to extract sensitive database information including user credentials, posts, comments, and configuration data.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update WP-Advanced-Search plugin to a version later than 3.3.9 that properly escapes user supplied parameters and uses prepared SQL statements in autocompletion-PHP5.5.php.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">sqli</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-advanced-search</span><span class="nt-tag">wp-plugin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wpscan.com/vulnerability/2ddd6839-6bcb-4bb8-97e0-1516b8c2b99b/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/RandomRobbieBF/CVE-2024-9796" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-9796" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress wp-pagenavi - full path disclosure low identify critical remote vulnerabilities wordpress wp-pagenavi plugin files are publicly accessible without abspath protection, exposing sensitive server path information through php error messages when accessed directly. dhiyaneshdk debug wp wp-plugin wordpress fpd vuln wp-pagenavi" data-nt-sev="low">
  <div class="nt-card-header">
    <div class="nt-title">WordPress WP-PageNavi - Full Path Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/misconfiguration/wordpress/wp-pagenavi-fpd.yaml" target="_blank" rel="noopener" class="nt-source-link">wp-pagenavi-fpd.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 7, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/plugins/wp-pagenavi/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">WordPress WP-PageNavi plugin files are publicly accessible without ABSPATH protection, exposing sensitive server path information through PHP error messages when accessed directly.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">debug</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">wordpress</span><span class="nt-tag">fpd</span><span class="nt-tag">vuln</span><span class="nt-tag">wp-pagenavi</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wordpress.org/plugins/wp-pagenavi/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress wpforms - full path disclosure low identify critical remote vulnerabilities wordpress plugin wpforms files are publicly accessible without abspath protection, exposing sensitive server path information through php error messages when accessed directly. dhiyaneshdk wp wordpress wp-plugin fpd wpforms-lite misconfig" data-nt-sev="low">
  <div class="nt-card-header">
    <div class="nt-title">WordPress WPForms - Full Path Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/misconfiguration/wordpress/wp-wpforms-lite-fpd.yaml" target="_blank" rel="noopener" class="nt-source-link">wp-wpforms-lite-fpd.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 12, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/wpforms-lite&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">WordPress Plugin WPForms files are publicly accessible without ABSPATH protection, exposing sensitive server path information through PHP error messages when accessed directly.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">wp</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">fpd</span><span class="nt-tag">wpforms-lite</span><span class="nt-tag">misconfig</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wordpress.org/plugins/wpforms-lite/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress wpml multilingual cms &lt; 4.6.1 - cross-site scripting high identify critical remote vulnerabilities the wpml multilingual cms plugin for wordpress is vulnerable to reflected cross-site scripting (xss) in versions prior to 4.6.1. the plugin does not escape some url attributes before outputting them to a page, allowing attackers to inject malicious javascript which may be executed in the browser of an unsuspecting user. ritikchaddha wordpress wp wp-plugin wpml xss sitepress-multilingual-cms cwe-79" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">WordPress WPML Multilingual CMS &lt; 4.6.1 - Cross-Site Scripting</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/vulnerabilities/wordpress/wpml-multilingual-cms-xss.yaml" target="_blank" rel="noopener" class="nt-source-link">wpml-multilingual-cms-xss.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 12, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-79</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/sitepress-multilingual-cms/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The WPML Multilingual CMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting (XSS) in versions prior to 4.6.1. The plugin does not escape some URL attributes before outputting them to a page, allowing attackers to inject malicious JavaScript which may be executed in the browser of an unsuspecting user.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">wpml</span><span class="nt-tag">xss</span><span class="nt-tag">sitepress-multilingual-cms</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wpscan.com/vulnerability/b9cc519c-7ec2-42c3-9f42-01e928e12139/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress wordfence - configuration file disclosure medium identify critical remote vulnerabilities the wordfence security plugin for wordpress stores configuration files in the /wp-content/wflogs/ directory. these files may be accessible without authentication and can expose sensitive configuration data, firewall rules, attack logs, and internal paths. ritikchaddha wordpress wp wp-plugin wordfence config exposure cwe-200" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">WordPress Wordfence - Configuration File Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/misconfiguration/wordpress/wordfence-config-disclosure.yaml" target="_blank" rel="noopener" class="nt-source-link">wordfence-config-disclosure.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 22, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/plugins/wordfence&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The Wordfence Security plugin for WordPress stores configuration files in the /wp-content/wflogs/ directory. These files may be accessible without authentication and can expose sensitive configuration data, firewall rules, attack logs, and internal paths.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">wordfence</span><span class="nt-tag">config</span><span class="nt-tag">exposure</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wordpress.org/support/topic/files-created-in-wflogs-before-plugin-activated/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://forum.ait-pro.com/forums/topic/wordfence-firewall-wp-contentwflogsconfig-php-file-quarantined/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress wordfence - rules file disclosure medium identify critical remote vulnerabilities the wordfence security plugin for wordpress stores configuration files in the /wp-content/wflogs/ directory. these files may be accessible without authentication and can expose sensitive configuration data, firewall rules, attack logs, and internal paths. ritikchaddha wordpress wp-plugin wordfence rules disclosure exposure cwe-200" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">WordPress Wordfence - Rules File Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/misconfiguration/wordpress/wordfence-rules-disclosure.yaml" target="_blank" rel="noopener" class="nt-source-link">wordfence-rules-disclosure.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 22, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/plugins/wordfence&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The Wordfence Security plugin for WordPress stores configuration files in the /wp-content/wflogs/ directory. These files may be accessible without authentication and can expose sensitive configuration data, firewall rules, attack logs, and internal paths.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">wordpress</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">wordfence</span><span class="nt-tag">rules</span><span class="nt-tag">disclosure</span><span class="nt-tag">exposure</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wordpress.org/support/topic/files-created-in-wflogs-before-plugin-activated/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://forum.ait-pro.com/forums/topic/wordfence-firewall-wp-contentwflogsconfig-php-file-quarantined/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress wordfence - waf logs and data disclosure low identify critical remote vulnerabilities the wordfence security plugin creates various log and data files in the wflogs directory. if directory listing is enabled or files are directly accessible, sensitive information about blocked attacks, ip addresses, and firewall configuration may be exposed. ritikchaddha wordpress wp wp-plugin wordfence logs exposure cwe-538" data-nt-sev="low">
  <div class="nt-card-header">
    <div class="nt-title">WordPress Wordfence - WAF Logs and Data Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/misconfiguration/wordpress/wordfence-waf-logs-disclosure.yaml" target="_blank" rel="noopener" class="nt-source-link">wordfence-waf-logs-disclosure.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 22, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/538.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-538</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/plugins/wordfence&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The Wordfence Security plugin creates various log and data files in the wflogs directory. If directory listing is enabled or files are directly accessible, sensitive information about blocked attacks, IP addresses, and firewall configuration may be exposed.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">wordfence</span><span class="nt-tag">logs</span><span class="nt-tag">exposure</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wordpress.org/support/topic/detect-suspicious-content-in-word-fence-wflogs-in-my-site/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://wordpress.org/support/topic/syn_sent-in-wflogs-filename-php/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress yith woocommerce wishlist - full path disclosure low identify critical remote vulnerabilities wordpress yith woocommerce wishlist plugin is vulnerable to full path disclosure via direct access to plugin files. ritikchaddha wp wordpress wp-plugin fpd yith woocommerce wishlist exposure" data-nt-sev="low">
  <div class="nt-card-header">
    <div class="nt-title">WordPress YITH WooCommerce Wishlist - Full Path Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/misconfiguration/wordpress/wp-yith-woocommerce-wishlist-fpd.yaml" target="_blank" rel="noopener" class="nt-source-link">wp-yith-woocommerce-wishlist-fpd.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 17, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/yith-woocommerce-wishlist/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">WordPress YITH WooCommerce Wishlist plugin is vulnerable to full path disclosure via direct access to plugin files.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">wp</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">fpd</span><span class="nt-tag">yith</span><span class="nt-tag">woocommerce</span><span class="nt-tag">wishlist</span><span class="nt-tag">exposure</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wordpress.org/plugins/yith-woocommerce-wishlist/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress yoast seo - full path disclosure low identify critical remote vulnerabilities wordpress yoast seo plugin is vulnerable to full path disclosure via direct access to plugin files. ritikchaddha wp wordpress wp-plugin fpd yoast seo exposure" data-nt-sev="low">
  <div class="nt-card-header">
    <div class="nt-title">WordPress Yoast SEO - Full Path Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/misconfiguration/wordpress/wp-yoast-seo-fpd.yaml" target="_blank" rel="noopener" class="nt-source-link">wp-yoast-seo-fpd.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 17, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/wordpress-seo/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">WordPress Yoast SEO plugin is vulnerable to full path disclosure via direct access to plugin files.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">wp</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">fpd</span><span class="nt-tag">yoast</span><span class="nt-tag">seo</span><span class="nt-tag">exposure</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wordpress.org/plugins/wordpress-seo/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress wp-links-opml.php - version disclosure info identify critical remote vulnerabilities wordpress wp-links-opml.php file was publicly accessible and expossed the wordpress version in the generator tag. princechaddha exposure wordpress wp version files" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">WordPress wp-links-opml.php - Version Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposures/files/wp-links-opml.yaml" target="_blank" rel="noopener" class="nt-source-link">wp-links-opml.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> princechaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 30, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;product&#34;] contains &#34;WordPress:WordPress&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">WordPress wp-links-opml.php file was publicly accessible and expossed the WordPress version in the generator tag.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">exposure</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">version</span><span class="nt-tag">files</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.acunetix.com/vulnerabilities/web/wordpress-version-disclosed/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://wordpress.org/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress gift cards &lt;= 4.3.1 - sql injection critical identify critical remote vulnerabilities the gift cards (gift vouchers and packages) wordpress plugin, version &lt;= 4.3.1, is affected by an unauthenticated sql injection vulnerability in the template parameter in the wpgv_doajax_voucher_pdf_save_func action. cve-2023-28662 xxcdd codemenschen cve cve2023 gift-voucher sqli time-based-sqli unauth vuln wordpress wp wp-plugin cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Wordpress Gift Cards &lt;= 4.3.1 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-28662.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-28662.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> xxcdd</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 4, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-28662" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-28662</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/gift-voucher/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The Gift Cards (Gift Vouchers and Packages) WordPress Plugin, version &lt;= 4.3.1, is affected by an unauthenticated SQL injection vulnerability in the template parameter in the wpgv_doajax_voucher_pdf_save_func action.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to perform SQL injection attacks, potentially leading to unauthorized access, data leakage, or further compromise of the WordPress site.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update the Gift Cards (Gift Vouchers and Packages) WordPress Plugin to the latest version available.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">codemenschen</span><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">gift-voucher</span><span class="nt-tag">sqli</span><span class="nt-tag">time-based-sqli</span><span class="nt-tag">unauth</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.tenable.com/security/research/tra-2023-2" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://wordpress.org/plugins/gift-voucher/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/ARPSyndicate/cvemon" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/JoshuaMart/JoshuaMart" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress polls widget &lt; 1.5.3 - sql injection critical identify critical remote vulnerabilities the poll, survey, questionnaire and voting system wordpress plugin before 1.5.3 did not sanitise, escape or validate the date_answers[] post parameter before using it in a sql statement when sending a poll result, allowing unauthenticated users to perform sql injection attacks cve-2021-24442 ritikchaddha cve cve2021 polls-widget sqli time-based-sqli vkev vuln wordpress wp wp-plugin wpdevart wpscan cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Wordpress Polls Widget &lt; 1.5.3 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2021/CVE-2021-24442.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2021-24442.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 13, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2021-24442" target="_blank" rel="noopener" class="nt-cve-link">CVE-2021-24442</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/polls-widget/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The Poll, Survey, Questionnaire and Voting system WordPress plugin before 1.5.3 did not sanitise, escape or validate the date_answers[] POST parameter before using it in a SQL statement when sending a Poll result, allowing unauthenticated users to perform SQL Injection attacks</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can execute SQL injection to manipulate database contents, potentially gaining unauthorized access to all WordPress data including user credentials.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Fixed in 1.5.3</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2021</span><span class="nt-tag">polls-widget</span><span class="nt-tag">sqli</span><span class="nt-tag">time-based-sqli</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">wpdevart</span><span class="nt-tag">wpscan</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wpscan.com/vulnerability/7376666e-9b2a-4239-b11f-8544435b444a/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2021-24442" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://wordpress.org/plugins/polls-widget/" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wordpress wpmobile.app &gt;= 11.42 - cross-site scripting high identify critical remote vulnerabilities wpmobile.app versions up to 11.41 contain a reflected cross-site scripting (xss) caused by improper input neutralization during web page generation, letting attackers execute scripts in the victim&#39;s browser, exploit requires attacker to craft malicious input. cve-2024-35694 sourabh-sahu cve cve2024 vkev wordpress wp wp-plugin wpmobileapp xss cwe-79" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Wordpress WPMobile.App &gt;= 11.42 - Cross-Site Scripting</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-35694.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-35694.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Sourabh-Sahu</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 8, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-79</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-35694" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-35694</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/wpappninja&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">WPMobile.App versions up to 11.41 contain a reflected cross-site scripting (XSS) caused by improper input neutralization during web page generation, letting attackers execute scripts in the victim&#39;s browser, exploit requires attacker to craft malicious input.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can execute arbitrary scripts in the victim&#39;s browser, potentially stealing cookies, session tokens, or performing actions on behalf of the user.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Implement proper input sanitization and output encoding, and update to the latest version of WPMobile.App.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">vkev</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">wpmobileapp</span><span class="nt-tag">xss</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;old=3082701%40wpappninja&amp;new=3082701%40wpappninja&amp;sfp_email=&amp;sfph_mail=" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="worpress backup migration &lt;= 1.3.7 - unauthenticated remote code execution critical identify critical remote vulnerabilities the backup migration plugin for wordpress is vulnerable to remote code execution in all versions up to, and including, 1.3.7 via the /includes/backup-heart.php file. this is due to an attacker being able to control the values passed to an include, and subsequently leverage that to achieve remote code execution. this makes it possible for unauthenticated threat actors to easily execute code on the server. cve-2023-6553 flx backupbliss cve cve2023 packetstorm rce unauth vkev vuln wordpress wp wp-plugin" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Worpress Backup Migration &lt;= 1.3.7 - Unauthenticated Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-6553.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-6553.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> FLX</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 14, 2023</span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-6553" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-6553</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/backup-backup/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The Backup Migration plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.7 via the /includes/backup-heart.php file. This is due to an attacker being able to control the values passed to an include, and subsequently leverage that to achieve remote code execution. This makes it possible for unauthenticated threat actors to easily execute code on the server.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can leverage file inclusion via backup-heart.php to achieve arbitrary code execution, potentially compromising the entire WordPress site and server.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade Backup Migration plugin to version 1.3.8 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">backupbliss</span><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">packetstorm</span><span class="nt-tag">rce</span><span class="nt-tag">unauth</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.wordfence.com/blog/2023/12/critical-unauthenticated-remote-code-execution-found-in-backup-migration-plugin/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/Chocapikk/CVE-2023-6553" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="http://packetstormsecurity.com/files/176638/WordPress-Backup-Migration-1.3.7-Remote-Command-Execution.html" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://www.synacktiv.com/en/publications/php-filters-chain-what-is-it-and-how-to-use-it" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/3511ba64-56a3-43d7-8ab8-c6e40e3b686e?source=cve" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wowza streaming engine manager 4.7.4.01 - directory traversal critical identify critical remote vulnerabilities wowza streaming engine 4.7.4.01 allows traversal of the directory structure and retrieval of a file via a remote, specifically crafted http request to the rest api. cve-2018-19365 0x_akoko cve cve2018 lfi vkev vuln wowza cwe-22" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Wowza Streaming Engine Manager 4.7.4.01 - Directory Traversal</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2018/CVE-2018-19365.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2018-19365.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_Akoko</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2018-19365" target="_blank" rel="noopener" class="nt-cve-link">CVE-2018-19365</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)manager\&#34; product:\&#34;wowza streaming engine&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Wowza Streaming Engine 4.7.4.01 allows traversal of the directory structure and retrieval of a file via a remote, specifically crafted HTTP request to the REST API.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can exploit this vulnerability to read arbitrary files on the server, potentially leading to unauthorized access or disclosure of sensitive information.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to the latest version of Wowza Streaming Engine Manager or apply the necessary patches to fix the directory traversal vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2018</span><span class="nt-tag">lfi</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">wowza</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://blog.gdssecurity.com/labs/2019/2/11/wowza-streaming-engine-manager-directory-traversal-and-local.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2018-19365" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://raw.githubusercontent.com/WowzaMediaSystems/public_cve/main/wowza-streaming-engine/CVE-2018-19365.txt" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/ARPSyndicate/kenzer-templates" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wowza streaming engine manager panel - detect info identify web-based control panels wowza streaming engine manager panel was detected. dhiyaneshdk discovery panel wowza" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Wowza Streaming Engine Manager Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/wowza-streaming-engine.yaml" target="_blank" rel="noopener" class="nt-source-link">wowza-streaming-engine.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)manager&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Wowza Streaming Engine Manager panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">wowza</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="wpstickybar &lt;= 2.1.0 - sql injection high identify critical remote vulnerabilities the plugin does not properly sanitise and escape a parameter before using it in a sql statement via an ajax action available to unauthenticated users, leading to a sql injection cve-2024-5765 theamanrawat cve cve2024 sqli time-based-sqli unauth vuln wordpress wp wp-plugin wpscan wpstickybar cwe-89" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">WpStickyBar &lt;= 2.1.0 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-5765.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-5765.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> theamanrawat</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 31, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-5765" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-5765</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/plugins/wpstickybar-sticky-bar-sticky-header&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The plugin does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can execute time-based SQL injection attacks to extract sensitive database information including user credentials and configuration data.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update WpStickyBar plugin to version 2.1.1 or later to address the SQL injection vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">sqli</span><span class="nt-tag">time-based-sqli</span><span class="nt-tag">unauth</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">wpscan</span><span class="nt-tag">wpstickybar</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wpscan.com/vulnerability/0b73f84c-611e-4681-b362-35e721478ba4/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://wordpress.org/plugins/wpstickybar-sticky-bar-sticky-header/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-5765" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="x-ui - default login high identify default logins in web-based control panels x-ui contains default credentials. an attacker can obtain access to user accounts and access sensitive information, modify data, and/or execute unauthorized operations. dali default-login vuln x-ui cwe-798" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">X-UI - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/xui/xui-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">xui-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dali</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 27, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/798.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-798</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;X-UI Login&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">X-UI contains default credentials. An attacker can obtain access to user accounts and access sensitive information, modify data, and/or execute unauthorized operations.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">vuln</span><span class="nt-tag">x-ui</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/vaxilu/x-ui" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://seakfind.github.io/2021/10/10/X-UI/#:~:text=By%20default%2C%20the%20login%20user,the%20password%20is%20also%20admin%20." target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="xampp php info page - detect low identify critical remote vulnerabilities xampphpinfo page was detected. the output of the phpinfo() command can reveal sensitive and detailed php environment information. pussycat0x config exposure phpinfo vuln xampp" data-nt-sev="low">
  <div class="nt-card-header">
    <div class="nt-title">XAMPP PHP info Page - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposures/configs/xampp-phpinfo-detect.yaml" target="_blank" rel="noopener" class="nt-source-link">xampp-phpinfo-detect.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 10, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)XAMPP&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">XAMPPHPinfo page was detected. The output of the phpinfo() command can reveal sensitive and detailed PHP environment information.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Remove PHP Info pages from publicly accessible sites, or restrict access to authorized users only.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">config</span><span class="nt-tag">exposure</span><span class="nt-tag">phpinfo</span><span class="nt-tag">vuln</span><span class="nt-tag">xampp</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="xds-amr status login panel - detect info identify web-based control panels xds-amr status login panel was detected. pussycat0x panel tech xamr xds discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">XDS-AMR Status Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/xds-amr-status.yaml" target="_blank" rel="noopener" class="nt-source-link">xds-amr-status.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)XDS-AMR - status&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">XDS-AMR Status login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">tech</span><span class="nt-tag">xamr</span><span class="nt-tag">xds</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="xnat - default login high identify default logins in web-based control panels xnat contains an admin default login vulnerability. an attacker can obtain access to user accounts and access sensitive information, modify data, and/or execute unauthorized operations. 0x_akoko default-login vuln xnat cwe-522" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">XNAT - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/xnat/xnat-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">xnat-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_Akoko</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/522.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-522</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;XNAT&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">XNAT contains an admin default login vulnerability. An attacker can obtain access to user accounts and access sensitive information, modify data, and/or execute unauthorized operations.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">vuln</span><span class="nt-tag">xnat</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wiki.xnat.org/documentation/xnat-administration/xnat-setup-first-time-configuration#:~:text=Log%20in%20with%20the%20username%20admin%20and%20password%20admin" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="xnat login panel - detect info identify web-based control panels xnat login panel was detected. 0x_akoko discovery panel xnat cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">XNAT Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/xnat-login.yaml" target="_blank" rel="noopener" class="nt-source-link">xnat-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_Akoko</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)xnat&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">XNAT login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">xnat</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="xspeeder login - detect info identify web-based control panels detects the presence of xspeeder router login panels. rxerium panel xspeeder router login detect" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">XSpeeder Login - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/xspeeder-login.yaml" target="_blank" rel="noopener" class="nt-source-link">xspeeder-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 27, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)神行者路由&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detects the presence of XSpeeder router login panels.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">xspeeder</span><span class="nt-tag">router</span><span class="nt-tag">login</span><span class="nt-tag">detect</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.xspeeder.com/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="xvr login panel - detect info identify web-based control panels xvr login panel was detected. dhiyaneshdk dahuasecurity discovery panel xvr cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">XVR Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/xvr-login.yaml" target="_blank" rel="noopener" class="nt-source-link">xvr-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)xvr login&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">XVR login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">dahuasecurity</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">xvr</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="xwiki - cross-site scripting medium identify critical remote vulnerabilities xwiki platform is a generic wiki platform offering runtime services for applications built on top of it. users are able to forge an url with a payload allowing to inject javascript in the page (xss). cve-2023-35155 ritikchaddha cve cve2023 vuln xss xwiki cwe-79" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">XWiki - Cross-Site Scripting</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-35155.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-35155.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 4, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-79</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-35155" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-35155</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)data-xwiki-reference&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Users are able to forge an URL with a payload allowing to inject Javascript in the page (XSS).</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation could lead to unauthorized access to sensitive information or account takeover</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches provided by XWiki to mitigate the vulnerability</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">vuln</span><span class="nt-tag">xss</span><span class="nt-tag">xwiki</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://jira.xwiki.org/browse/XWIKI-20370" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-35155" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="xwiki - cross-site scripting medium identify critical remote vulnerabilities xwiki platform is a generic wiki platform offering runtime services for applications built on top of it. users are able to forge an url with a payload allowing to inject javascript in the page (xss). it&#39;s possible to exploit the restore template to perform a xss, e.g. by using url such as: &gt; /xwiki/bin/view/xwiki/main?xpage=restore&amp;showbatch=true&amp;xredirect=javascript:alert(document.domain). this vulnerability exists since xwiki 9.4-rc-1. the vulnerability has been patched in xwiki 14.10.5 and 15.1-rc-1. cve-2023-35158 ritikchaddha cve cve2023 vuln xss xwiki cwe-87" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">XWiki - Cross-Site Scripting</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-35158.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-35158.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 15, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/87.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-87</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-35158" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-35158</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)data-xwiki-reference&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Users are able to forge an URL with a payload allowing to inject Javascript in the page (XSS). It&#39;s possible to exploit the restore template to perform a XSS, e.g. by using URL such as: &gt; /xwiki/bin/view/XWiki/Main?xpage=restore&amp;showBatch=true&amp;xredirect=javascript:alert(document.domain). This vulnerability exists since XWiki 9.4-rc-1. The vulnerability has been patched in XWiki 14.10.5 and 15.1-rc-1.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation could allow an attacker to execute malicious scripts in the context of the victim&#39;s browser.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update XWiki to the latest version to mitigate the Reflected XSS vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">vuln</span><span class="nt-tag">xss</span><span class="nt-tag">xwiki</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-35158" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="xwiki - hql injection high identify critical remote vulnerabilities xwiki is vulnerable to hibernate query language (hql) injection in the wiki and space search rest api starting in version 4.3-milestone-1 and prior to versions 16.10.9, 17.4.2, and 17.5.0. the vulnerability allows attackers to inject malicious hql queries through the orderfield parameter, potentially leading to data extraction, authentication bypass, or remote code execution depending on database backend and configuration. cve-2025-52472 ritikchaddha cve cve2025 hqli sqli vkev xwiki cwe-89" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">XWiki - HQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-52472.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-52472.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 3, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-52472" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-52472</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)data-xwiki-reference&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">XWiki is vulnerable to Hibernate Query Language (HQL) injection in the wiki and space search REST API starting in version 4.3-milestone-1 and prior to versions 16.10.9, 17.4.2, and 17.5.0. The vulnerability allows attackers to inject malicious HQL queries through the orderField parameter, potentially leading to data extraction, authentication bypass, or remote code execution depending on database backend and configuration.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can inject malicious HQL queries through the orderField parameter, potentially leading to complete database compromise, data extraction, authentication bypass, or remote code execution.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update XWiki to a version that patches this vulnerability. Review and sanitize all user-controlled parameters that are used in database queries, especially those passed to HQL queries.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">hqli</span><span class="nt-tag">sqli</span><span class="nt-tag">vkev</span><span class="nt-tag">xwiki</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://jira.xwiki.org/browse/XWIKI-23247" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-52472" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="xwiki - information disclosure high identify critical remote vulnerabilities xwiki 16.7.0 to 16.10.11, 17.4.4, and 17.7.0 using xjetty contains an information disclosure vulnerability caused by exposed context allowing static access to files in webapp/ folder, letting attackers access sensitive files, exploit requires use of xjetty package. cve-2025-55749 dhiyaneshdk cve cve2025 exposure vkev vuln xwiki cwe-284" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">XWiki - Information Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-55749.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-55749.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 11, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/284.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-284</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-55749" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-55749</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)data-xwiki-reference&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">XWiki 16.7.0 to 16.10.11, 17.4.4, and 17.7.0 using XJetty contains an information disclosure vulnerability caused by exposed context allowing static access to files in webapp/ folder, letting attackers access sensitive files, exploit requires use of XJetty package.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can access sensitive files including credentials, leading to information disclosure.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to versions 16.10.11, 17.4.4, or 17.7.0 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">exposure</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">xwiki</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-53gx-j3p6-2rw9" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-55749" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="xwiki &lt; 12.10.11, 13.4.4 &amp; 13.9-rc-1 - information disclosure medium identify critical remote vulnerabilities an unauthenticated user can retrieve a list of users and their full names through a publicly accessible url in xwiki. the issue affects versions before 12.10.11, 13.4.4, and 13.9-rc-1. cve-2022-24819 ritikchaddha cve cve2022 exposure vuln xwiki cwe-359" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">XWiki &lt; 12.10.11, 13.4.4 &amp; 13.9-rc-1 - Information Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-24819.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-24819.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 2, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/359.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-359</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-24819" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-24819</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)data-xwiki-reference&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An unauthenticated user can retrieve a list of users and their full names through a publicly accessible URL in XWiki. The issue affects versions before 12.10.11, 13.4.4, and 13.9-rc-1.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Information disclosure could lead to unauthorized access to sensitive data.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade XWiki to the latest version to mitigate CVE-2022-24819.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">exposure</span><span class="nt-tag">vuln</span><span class="nt-tag">xwiki</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-97jg-43c9-q6pf" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="xwiki &lt; 14.10.14 - cross-site scripting medium identify critical remote vulnerabilities xwiki is vulnerable to reflected cross-site scripting (rxss) via the rev parameter that is used in the content of the content menu without escaping. if an attacker can convince a user to visit a link with a crafted parameter, this allows the attacker to execute arbitrary actions in the name of the user, including remote code (groovy) execution in the case of a user with programming right, compromising the confidentiality, integrity and availability of the whole xwiki installation. cve-2023-46732 ritikchaddha cve cve2023 vkev vuln xss xwiki cwe-79" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">XWiki &lt; 14.10.14 - Cross-Site Scripting</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-46732.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-46732.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 20, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-79</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-46732" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-46732</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)data-xwiki-reference&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">XWiki is vulnerable to reflected cross-site scripting (RXSS) via the rev parameter that is used in the content of the content menu without escaping. If an attacker can convince a user to visit a link with a crafted parameter, this allows the attacker to execute arbitrary actions in the name of the user, including remote code (Groovy) execution in the case of a user with programming right, compromising the confidentiality, integrity and availability of the whole XWiki installation.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation could lead to cross-site scripting attack.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">This has been patched in XWiki 15.6 RC1, 15.5.1 and 14.10.14.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">xss</span><span class="nt-tag">xwiki</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://jira.xwiki.org/browse/XWIKI-21095" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-46732" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="xwiki &lt; 14.10.14 - cross-site scripting medium identify critical remote vulnerabilities xwiki platform is a generic wiki platform offering runtime services for applications built on top of it. when document names are validated according to a name strategy (disabled by default), xwiki starting in version 12.0-rc-1 and prior to versions 12.10.12 and 15.5-rc-1 is vulnerable to a reflected cross-site scripting attack in the page creation form. this allows an attacker to execute arbitrary actions with the rights of the user opening the malicious link. cve-2023-45136 ritikchaddha cve cve2023 vuln xss xwiki cwe-79" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">XWiki &lt; 14.10.14 - Cross-Site Scripting</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-45136.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-45136.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 20, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-79</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-45136" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-45136</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)data-xwiki-reference&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. When document names are validated according to a name strategy (disabled by default), XWiki starting in version 12.0-rc-1 and prior to versions 12.10.12 and 15.5-rc-1 is vulnerable to a reflected cross-site scripting attack in the page creation form. This allows an attacker to execute arbitrary actions with the rights of the user opening the malicious link.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation could lead to cross-site scripting attack.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">This has been patched in XWiki 14.10.12 and 15.5-rc-1 by adding appropriate escaping.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">vuln</span><span class="nt-tag">xss</span><span class="nt-tag">xwiki</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://jira.xwiki.org/browse/XWIKI-20854" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-45136" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="xwiki &lt; 14.10.5 - cross-site scripting medium identify critical remote vulnerabilities xwiki platform is vulnerable to reflected xss via the previewactions template. an attacker can inject javascript through the xcontinue parameter. cve-2023-35162 ritikchaddha cve cve2023 vuln xss xwiki cwe-79" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">XWiki &lt; 14.10.5 - Cross-Site Scripting</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-35162.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-35162.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 6, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-79</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-35162" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-35162</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)data-xwiki-reference&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">XWiki Platform is vulnerable to reflected XSS via the previewactions template. An attacker can inject JavaScript through the xcontinue parameter.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation could lead to unauthorized access or data theft.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest patches provided by XWiki to mitigate the vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">vuln</span><span class="nt-tag">xss</span><span class="nt-tag">xwiki</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://jira.xwiki.org/browse/XWIKI-20342" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/xwiki/xwiki-platform/blob/244dbbaa0738a0c40b19929c0369c8b62ae5236e/xwiki-platform-core/xwiki-platform-flamingo/xwiki-platform-flamingo-skin/xwiki-platform-flamingo-skin-resources/src/main/resources/flamingo/previewactions.vm#L48" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-35162" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="xwiki &lt; 4.10.15 - email disclosure medium identify critical remote vulnerabilities the solr-based search in xwiki discloses the email addresses of users even when obfuscation of email addresses is enabled. to demonstrate the vulnerability, search for objcontent:email* using xwiki&#39;s regular search interface. cve-2023-50720 ritikchaddha cve cve2023 email exposure vuln xwiki cwe-200" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">XWiki &lt; 4.10.15 - Email Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-50720.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-50720.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 18, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-50720" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-50720</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)data-xwiki-reference&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The Solr-based search in XWiki discloses the email addresses of users even when obfuscation of email addresses is enabled. To demonstrate the vulnerability, search for objcontent:email* using XWiki&#39;s regular search interface.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation could lead to disclosure of the email of all the users.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">This has been fixed in XWiki 14.10.15, 15.5.2 and 15.7RC1 by not indexing email address properties when obfuscation is enabled.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">email</span><span class="nt-tag">exposure</span><span class="nt-tag">vuln</span><span class="nt-tag">xwiki</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://jira.xwiki.org/browse/XWIKI-20371" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-50720" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="xwiki &lt; 4.10.15 - information disclosure high identify critical remote vulnerabilities the solr-based search suggestion provider that also duplicates as generic javascript api for search results in xwiki exposes the content of all documents of all wikis to anybody who has access to it, by default it is public. this exposes all information stored in the wiki (but not some protected information like password hashes). while there is a right check normally, the right check can be circumvented by explicitly requesting fields from solr that don&#39;t include the data for the right check. this can be reproduced by opening &lt;xwiki-server&gt;/xwiki/bin/get/xwiki/suggestsolrservice?outputsyntax=plain&amp;media=json&amp;nb=1000&amp;query=q%3d*%3a*%0aq.op%3dand%0afq%3dtype%3adocument%0afl%3dtitle_%2c+reference%2c+links%2c+doccontentraw_%2c+objcontent__&amp;input=+ where &lt;xwiki-server&gt; is the url of the xwiki installation. if this displays any results, the wiki is vulnerable. cve-2023-48241 ritikchaddha cve cve2023 exposure vuln xwiki cwe-285" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">XWiki &lt; 4.10.15 - Information Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-48241.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-48241.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 18, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/285.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-285</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-48241" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-48241</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)data-xwiki-reference&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The Solr-based search suggestion provider that also duplicates as generic JavaScript API for search results in XWiki exposes the content of all documents of all wikis to anybody who has access to it, by default it is public. This exposes all information stored in the wiki (but not some protected information like password hashes). While there is a right check normally, the right check can be circumvented by explicitly requesting fields from Solr that don&#39;t include the data for the right check. This can be reproduced by opening &lt;xwiki-server&gt;/xwiki/bin/get/XWiki/SuggestSolrService?outputSyntax=plain&amp;media=json&amp;nb=1000&amp;query=q%3D*%3A*%0Aq.op%3DAND%0Afq%3Dtype%3ADOCUMENT%0Afl%3Dtitle_%2C+reference%2C+links%2C+doccontentraw_%2C+objcontent__&amp;input=+ where &lt;xwiki-server&gt; is the URL of the XWiki installation. If this displays any results, the wiki is vulnerable.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation could lead to disclosure of content of all documents of all wikis.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">This has been fixed in XWiki 15.6RC1, 15.5.1 and 14.10.15 by not listing documents whose rights cannot be checked.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">exposure</span><span class="nt-tag">vuln</span><span class="nt-tag">xwiki</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://jira.xwiki.org/browse/XWIKI-21138" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-48241" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="xwiki &lt; 4.10.15 - sensitive information disclosure high identify critical remote vulnerabilities xwiki platform is a generic wiki platform. starting in 7.2-milestone-2 and prior to versions 14.10.15, 15.5.2, and 15.7-rc-1, the solr-based search in xwiki discloses the password hashes of all users to anyone with view right on the respective user profiles. by default, all user profiles are public. this vulnerability also affects any configurations used by extensions that contain passwords like api keys that are viewable for the attacker. normally, such passwords aren&#39;t accessible but this vulnerability would disclose them as plain text. this has been patched in xwiki 14.10.15, 15.5.2 and 15.7rc1. there are no known workarounds for this vulnerability. cve-2023-50719 ritikchaddha cve cve2023 exposure password vuln xwiki cwe-359" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">XWiki &lt; 4.10.15 - Sensitive Information Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-50719.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-50719.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 18, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/359.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-359</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-50719" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-50719</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)data-xwiki-reference&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">XWiki Platform is a generic wiki platform. Starting in 7.2-milestone-2 and prior to versions 14.10.15, 15.5.2, and 15.7-rc-1, the Solr-based search in XWiki discloses the password hashes of all users to anyone with view right on the respective user profiles. By default, all user profiles are public. This vulnerability also affects any configurations used by extensions that contain passwords like API keys that are viewable for the attacker. Normally, such passwords aren&#39;t accessible but this vulnerability would disclose them as plain text. This has been patched in XWiki 14.10.15, 15.5.2 and 15.7RC1. There are no known workarounds for this vulnerability.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation could lead to disclosure of the password hashes of all users.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">This has been patched in XWiki 14.10.15, 15.5.2 and 15.7RC1.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">exposure</span><span class="nt-tag">password</span><span class="nt-tag">vuln</span><span class="nt-tag">xwiki</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://jira.xwiki.org/browse/XWIKI-21208" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-50719" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="xwiki &lt; 4.10.20 - remote code execution critical identify critical remote vulnerabilities xwiki platform is a generic wiki platform. starting in version 2.4-milestone-1 and prior to versions 4.10.20, 15.5.4, and 15.10-rc-1, xwiki&#39;s database search allows remote code execution through the search text. this allows remote code execution for any visitor of a public wiki or user of a closed wiki as the database search is by default accessible for all users. this impacts the confidentiality, integrity and availability of the whole xwiki installation. this vulnerability has been patched in xwiki 14.10.20, 15.5.4 and 15.10rc1. as a workaround, one may manually apply the patch to the page `main.databasesearch`. alternatively, unless database search is explicitly used by users, this page can be deleted as this is not the default search interface of xwiki. cve-2024-31982 ritikchaddha cve cve2024 rce vkev vuln xwiki cwe-95" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">XWiki &lt; 4.10.20 - Remote code execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-31982.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-31982.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 18, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/95.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-95</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-31982" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-31982</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)data-xwiki-reference&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">XWiki Platform is a generic wiki platform. Starting in version 2.4-milestone-1 and prior to versions 4.10.20, 15.5.4, and 15.10-rc-1, XWiki&#39;s database search allows remote code execution through the search text. This allows remote code execution for any visitor of a public wiki or user of a closed wiki as the database search is by default accessible for all users. This impacts the confidentiality, integrity and availability of the whole XWiki installation. This vulnerability has been patched in XWiki 14.10.20, 15.5.4 and 15.10RC1. As a workaround, one may manually apply the patch to the page `Main.DatabaseSearch`. Alternatively, unless database search is explicitly used by users, this page can be deleted as this is not the default search interface of XWiki.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation could lead to remote code execution.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the vendor-supplied patch or upgrade to a 14.10.20 ,15.5.4, 15.10-rc-1.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">rce</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">xwiki</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://jira.xwiki.org/browse/XWIKI-21472" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-2858-8cfx-69m9" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://jira.xwiki.org/browse/XWIKI-21110" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="xwiki &gt;= 13.10.8 - cross-site scripting medium identify critical remote vulnerabilities reflected xss vulnerability in xwiki authenticate endpoints allows execution of arbitrary javascript. cve-2023-29506 ritikchaddha cve cve2023 vuln xss xwiki cwe-79" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">XWiki &gt;= 13.10.8 - Cross-Site Scripting</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-29506.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-29506.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 29, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-79</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-29506" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-29506</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)data-xwiki-reference&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Reflected XSS vulnerability in XWiki authenticate endpoints allows execution of arbitrary JavaScript.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation could allow an attacker to execute malicious scripts in the context of the victim&#39;s browser.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Implement proper input validation and output encoding to prevent XSS attacks in the XWiki application.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">vuln</span><span class="nt-tag">xss</span><span class="nt-tag">xwiki</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-jjm5-5v9v-7hx2" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://jira.xwiki.org/browse/XWIKI-20335" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-29506" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="xwiki &gt;= 2.5-milestone-2 - cross-site scripting medium identify critical remote vulnerabilities xwiki platform is a generic wiki platform offering runtime services for applications built on top of it. users are able to forge an url with a payload allowing to inject javascript in the page (xss). it&#39;s possible to exploit the resubmit template to perform a xss, e.g. by using url such as: &gt; xwiki/bin/view/xwiki/main xpage=resubmit&amp;resubmit=javascript:alert(document.domain)&amp;xback=javascript:alert(document.domain). this vulnerability exists since xwiki 2.5-milestone-2. the vulnerability has been patched in xwiki 14.10.5 and 15.1-rc-1. cve-2023-35160 ritikchaddha cve cve2023 vuln xss xwiki cwe-79" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">XWiki &gt;= 2.5-milestone-2 - Cross-Site Scripting</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-35160.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-35160.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 4, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-79</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-35160" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-35160</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)data-xwiki-reference&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Users are able to forge an URL with a payload allowing to inject Javascript in the page (XSS). It&#39;s possible to exploit the resubmit template to perform a XSS, e.g. by using URL such as: &gt; xwiki/bin/view/XWiki/Main xpage=resubmit&amp;resubmit=javascript:alert(document.domain)&amp;xback=javascript:alert(document.domain). This vulnerability exists since XWiki 2.5-milestone-2. The vulnerability has been patched in XWiki 14.10.5 and 15.1-rc-1.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation could lead to cross-site scripting.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">This vulnerability has been patched in XWiki 14.10.5,15.1-rc-1.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">vuln</span><span class="nt-tag">xss</span><span class="nt-tag">xwiki</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://jira.xwiki.org/browse/XWIKI-20343" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-35160" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="xwiki &gt;= 3.4-milestone-1 - cross-site scripting medium identify critical remote vulnerabilities xwiki platform is a generic wiki platform offering runtime services for applications built on top of it. users are able to forge an url with a payload allowing to inject javascript in the page (xss). it&#39;s possible to exploit the deletespace template to perform a xss, e.g. by using url such as: &gt; xwiki/bin/deletespace/sandbox/?xredirect=javascript:alert(document.domain). cve-2023-35159 ritikchaddha cve cve2023 vuln xss xwiki cwe-79" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">XWiki &gt;= 3.4-milestone-1 - Cross-Site Scripting</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-35159.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-35159.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 4, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-79</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-35159" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-35159</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)data-xwiki-reference&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Users are able to forge an URL with a payload allowing to inject Javascript in the page (XSS). It&#39;s possible to exploit the deletespace template to perform a XSS, e.g. by using URL such as: &gt; xwiki/bin/deletespace/Sandbox/?xredirect=javascript:alert(document.domain).</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation could lead to cross-site scripting.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">This vulnerability has been patched in XWiki 14.10.5,15.1-rc-1.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">vuln</span><span class="nt-tag">xss</span><span class="nt-tag">xwiki</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://jira.xwiki.org/browse/XWIKI-20612" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-35159" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="xwiki &gt;= 6.0-rc-1 - cross-site scripting medium identify critical remote vulnerabilities xwiki platform is a generic wiki platform offering runtime services for applications built on top of it. users are able to forge an url with a payload allowing to inject javascript in the page (xss). it&#39;s possible to exploit the delete template to perform a xss, e.g. by using url such as: &gt; xwiki/bin/get/flamingothemes/cerulean?xpage=xpart&amp;vm=delete.vm&amp;xredirect=javascript:alert(document.domain). this vulnerability exists since xwiki 6.0-rc-1. cve-2023-35156 ritikchaddha cve cve2023 vuln xss xwiki cwe-79" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">XWiki &gt;= 6.0-rc-1 - Cross-Site Scripting</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-35156.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-35156.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 4, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-79</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-35156" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-35156</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)data-xwiki-reference&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Users are able to forge an URL with a payload allowing to inject Javascript in the page (XSS). It&#39;s possible to exploit the delete template to perform a XSS, e.g. by using URL such as: &gt; xwiki/bin/get/FlamingoThemes/Cerulean?xpage=xpart&amp;vm=delete.vm&amp;xredirect=javascript:alert(document.domain). This vulnerability exists since XWiki 6.0-rc-1.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation could lead to cross-site scripting.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">This vulnerability has been patched in XWiki 14.10.6,15.1.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">vuln</span><span class="nt-tag">xss</span><span class="nt-tag">xwiki</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://jira.xwiki.org/browse/XWIKI-20341" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-35156" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="xwiki &gt;= 6.2-milestone-1 - cross-site scripting medium identify critical remote vulnerabilities xwiki platform is a generic wiki platform offering runtime services for applications built on top of it. users are able to forge an url with a payload allowing to inject javascript in the page (xss). it&#39;s possible to exploit the deleteapplication page to perform a xss, e.g. by using url such as: &gt; xwiki/bin/view/appwithinminutes/deleteapplication?appname=menu&amp;resolve=true&amp;xredirect=javascript:alert(document.domain). this vulnerability exists since xwiki 6.2-milestone-1. the vulnerability has been patched in xwiki 14.10.5 and 15.1-rc-1. cve-2023-35161 ritikchaddha cve cve2023 vuln xss xwiki cwe-79" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">XWiki &gt;= 6.2-milestone-1 - Cross-Site Scripting</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-35161.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-35161.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 4, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-79</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-35161" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-35161</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)data-xwiki-reference&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Users are able to forge an URL with a payload allowing to inject Javascript in the page (XSS). It&#39;s possible to exploit the DeleteApplication page to perform a XSS, e.g. by using URL such as: &gt; xwiki/bin/view/AppWithinMinutes/DeleteApplication?appName=Menu&amp;resolve=true&amp;xredirect=javascript:alert(document.domain). This vulnerability exists since XWiki 6.2-milestone-1. The vulnerability has been patched in XWiki 14.10.5 and 15.1-rc-1.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation could lead to cross-site scripting.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">This vulnerability has been patched in XWiki 14.10.5,15.1-rc-1.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">vuln</span><span class="nt-tag">xss</span><span class="nt-tag">xwiki</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://jira.xwiki.org/browse/XWIKI-20614" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-35161" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="xwiki deleteapplication - cross-site scripting medium identify critical remote vulnerabilities xwiki platform is a generic wiki platform offering runtime services for applications built on top of it. versions 6.2-milestone-1 through 16.10.9 and 17.0.0-rc-1 through 17.4.1 of both xwiki platform flamingo skin resources and xwiki platform web templates are vulnerable to a reflected xss attack through a deletion confirmation message. the attacker-supplied script is executed when the victim clicks the &#34;no&#34; button. this issue is fixed in versions 16.10.10 and 17.4.2 of both xwiki platform flamingo skin resources and xwiki platform web templates. cve-2025-66472 ritikchaddha cve cve2025 xss xwiki cwe-80" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">XWiki DeleteApplication - Cross-Site Scripting</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-66472.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-66472.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 15, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/80.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-80</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-66472" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-66472</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)data-xwiki-reference&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Versions 6.2-milestone-1 through 16.10.9 and 17.0.0-rc-1 through 17.4.1 of both XWiki Platform Flamingo Skin Resources and XWiki Platform Web Templates are vulnerable to a reflected XSS attack through a deletion confirmation message. The attacker-supplied script is executed when the victim clicks the &#34;No&#34; button. This issue is fixed in versions 16.10.10 and 17.4.2 of both XWiki Platform Flamingo Skin Resources and XWiki Platform Web Templates.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can execute arbitrary JavaScript in the victim&#39;s browser, leading to potential session hijacking, data theft, or further attacks.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to XWiki 14.10.14, 15.5.1, 15.8-rc-1 or above. Do not interact with suspiciously crafted links.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">xss</span><span class="nt-tag">xwiki</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-7vpr-jm38-wr7w" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66472" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="xwiki platform - cross-site scripting medium identify critical remote vulnerabilities xwiki platform versions &gt;= 4.2-milestone-3 and &lt; 16.4.8, &gt;= 16.5.0-rc-1 and &lt; 16.10.6, and &gt;= 17.0.0-rc-1 and &lt; 17.3.0-rc-1 are vulnerable to reflected xss in two templates. the vulnerability allows an attacker to execute malicious javascript code in the context of the victim&#39;s session by getting the victim to visit an attacker-controlled url. cve-2025-32430 ritikchaddha cve cve2025 vuln xss xwiki cwe-79" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">XWiki Platform - Cross-Site Scripting</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-32430.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-32430.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 5, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-79</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-32430" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-32430</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)data-xwiki-reference&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">XWiki Platform versions &gt;= 4.2-milestone-3 and &lt; 16.4.8, &gt;= 16.5.0-rc-1 and &lt; 16.10.6, and &gt;= 17.0.0-rc-1 and &lt; 17.3.0-rc-1 are vulnerable to reflected XSS in two templates. The vulnerability allows an attacker to execute malicious JavaScript code in the context of the victim&#39;s session by getting the victim to visit an attacker-controlled URL.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can execute malicious JavaScript in victim sessions by crafting URLs with XSS payloads in translationPrefix, extensionId, or extensionVersionConstraint parameters.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to XWiki Platform version 16.4.8, 16.10.6, or 17.3.0-rc-1 or later that properly sanitizes user input in templates.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">vuln</span><span class="nt-tag">xss</span><span class="nt-tag">xwiki</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-m9x4-w7p9-mxhx" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://jira.xwiki.org/browse/XWIKI-23096" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-32430" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="xwiki platform - information disclosure high identify critical remote vulnerabilities xwiki platform is a generic wiki platform offering runtime services for applications built on top of it. in versions 6.1-milestone-2 through 16.10.6, configuration files are accessible through the webjars api. cve-2025-55747 redmomn cve cve2025 lfi vkev vuln xwiki cwe-23" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">XWiki Platform - Information Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-55747.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-55747.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Redmomn</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 17, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/23.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-23</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-55747" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-55747</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)data-xwiki-reference&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions 6.1-milestone-2 through 16.10.6, configuration files are accessible through the webjars API.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Remote attackers can access sensitive configuration files, potentially exposing critical information.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to version 16.10.7 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">lfi</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">xwiki</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://jira.xwiki.org/browse/XWIKI-19350" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-55747" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="xwiki platform - path traversal high identify critical remote vulnerabilities xwiki platform 4.2-milestone-2 through 16.10.6 contains a path traversal caused by improper access control in jsx and sx endpoints, letting remote attackers read configuration files, exploit requires no special privileges. cve-2025-55748 redmomn cve cve2025 lfi vkev vuln xwiki cwe-23" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">XWiki Platform - Path Traversal</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-55748.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-55748.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Redmomn</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 17, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/23.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-23</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-55748" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-55748</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)data-xwiki-reference&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">XWiki Platform 4.2-milestone-2 through 16.10.6 contains a path traversal caused by improper access control in jsx and sx endpoints, letting remote attackers read configuration files, exploit requires no special privileges.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Remote attackers can read sensitive configuration files, potentially exposing critical system information.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to version 16.10.7 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">lfi</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">xwiki</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-m63c-3rmg-r2cf" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/xwiki/xwiki-platform/commit/9e7b4c03f2143978d891109a17159f73d4cdd318#diff-ee78930a9ac5ea586179fe8ab88a5fd58e369d175927d1e88a0b4dbc3ebcbf1eR62" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-55748" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="xwiki platform - remote code execution high identify critical remote vulnerabilities xwiki platform is a generic wiki platform offering runtime services for applications built on top of it. improper escaping in the document `skinscode.xwikiskinssheet` leads to an injection vector from view right on that document to programming rights, or in other words, it is possible to execute arbitrary script macros including groovy and python macros that allow remote code execution including unrestricted read and write access to all wiki contents. the attack works by opening a non-existing page with a name crafted to contain a dangerous payload. it is possible to check if an existing installation is vulnerable cve-2023-37462 parthmalhotra,pdresearch cve cve2023 rce vuln xwiki cwe-74" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">XWiki Platform - Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-37462.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-37462.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> parthmalhotra,pdresearch</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 21, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/74.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-74</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-37462" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-37462</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)data-xwiki-reference&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Improper escaping in the document `SkinsCode.XWikiSkinsSheet` leads to an injection vector from view right on that document to programming rights, or in other words, it is possible to execute arbitrary script macros including Groovy and Python macros that allow remote code execution including unrestricted read and write access to all wiki contents. The attack works by opening a non-existing page with a name crafted to contain a dangerous payload. It is possible to check if an existing installation is vulnerable</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">This issue has been patched in XWiki 14.4.8, 14.10.4 and 15.0-rc-1. Users are advised to upgrade.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">rce</span><span class="nt-tag">vuln</span><span class="nt-tag">xwiki</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/xwiki/xwiki-platform/commit/d9c88ddc4c0c78fa534bd33237e95dea66003d29" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-h4vp-69r8-gvjg" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://jira.xwiki.org/browse/XWIKI-20457" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/fkie-cad/nvd-json-data-feeds" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="xwiki platform - remote code execution critical identify critical remote vulnerabilities any guest can perform arbitrary remote code execution through a request to solrsearch. this impacts the confidentiality, integrity, and availability of the whole xwiki installation. this vulnerability has been patched in xwiki 15.10.11, 16.4.1, and 16.5.0rc1. cve-2025-24893 iamnoooob,rootxharsh,pdresearch cve cve2025 kev rce vkev vuln xwiki cwe-94,cwe-95" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">XWiki Platform - Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-24893.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-24893.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> iamnoooob,rootxharsh,pdresearch</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 25, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/94,CWE-95.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-94,CWE-95</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-24893" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-24893</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)data-xwiki-reference&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Any guest can perform arbitrary remote code execution through a request to SolrSearch. This impacts the confidentiality, integrity, and availability of the whole XWiki installation. This vulnerability has been patched in XWiki 15.10.11, 16.4.1, and 16.5.0RC1.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can execute arbitrary code on the server, leading to a complete compromise of the XWiki instance.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to XWiki 15.10.11, 16.4.1, or 16.5.0RC1 to mitigate this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">kev</span><span class="nt-tag">rce</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">xwiki</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/advisories/GHSA-rr6p-3pfg-562j" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24893" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="xwiki platform - sql injection critical identify critical remote vulnerabilities xwiki platform is a generic wiki platform offering runtime services for applications built on top of it. in versions 9.4-rc-1 through 16.10.5 and 17.0.0-rc-1 through 17.2.2, it&#39;s possible for anyone to inject sql using the parameter sort of the getdeleteddocuments.vm. it&#39;s injected as is as an order by value. cve-2025-32429 ritikchaddha cve cve2025 hqli sqli vkev xwiki cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">XWiki Platform - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-32429.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-32429.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 3, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-32429" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-32429</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)data-xwiki-reference&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions 9.4-rc-1 through 16.10.5 and 17.0.0-rc-1 through 17.2.2, it&#39;s possible for anyone to inject SQL using the parameter sort of the getdeleteddocuments.vm. It&#39;s injected as is as an ORDER BY value.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Authenticated attackers with access to the deleted documents trash feature could inject SQL code, leading to data leakage, database modification, or further compromise of the application.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to XWiki Platform version 16.10.6 and 17.3.0-rc-1. (or newer) which addresses this vulnerability. Always validate and sanitize user-controlled input for query parameters.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">hqli</span><span class="nt-tag">sqli</span><span class="nt-tag">vkev</span><span class="nt-tag">xwiki</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://jira.xwiki.org/browse/XWIKI-23093" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-32429" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="xwiki platform - unauthorized document history access medium identify critical remote vulnerabilities a vulnerability in xwiki platform&#39;s rest api allows unauthorized users to access document history information. the rest api endpoint exposes the history of any page including modification times, version numbers, author details (username and display name), and version comments, regardless of access rights configuration, even on private wikis. cve-2024-45591 pd-bot cve cve2024 exposure rest-api vuln xwiki cwe-359,cwe-862" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">XWiki Platform - Unauthorized Document History Access</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-45591.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-45591.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pd-bot</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 11, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/359,CWE-862.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-359,CWE-862</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-45591" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-45591</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)data-xwiki-reference&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A vulnerability in XWiki Platform&#39;s REST API allows unauthorized users to access document history information. The REST API endpoint exposes the history of any page including modification times, version numbers, author details (username and display name), and version comments, regardless of access rights configuration, even on private wikis.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can access document history of any known page</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to XWiki Platform version 15.10.9 or 16.3.0-rc-1 or later. No workarounds are available for earlier versions</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">exposure</span><span class="nt-tag">rest-api</span><span class="nt-tag">vuln</span><span class="nt-tag">xwiki</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-pvmm-55r5-g3mm" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://jira.xwiki.org/browse/XWIKI-22052" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/cve-2024-45591" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="xwiki platform distribution flavor main - cross-site scripting medium identify critical remote vulnerabilities xwiki platform distribution flavor main versions prior to 17.6.0 are vulnerable to reflected cross-site scripting (xss) due to improper sanitization of user-supplied input in the extensionid parameter. an attacker can exploit this issue by injecting malicious javascript, which will be executed in the context of the victim&#39;s browser, potentially leading to session hijacking or other attacks. cve-2026-24128 ritikchaddha cve cve2026 xss xwiki cwe-79" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">XWiki Platform Distribution Flavor Main - Cross-Site Scripting</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2026/CVE-2026-24128.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2026-24128.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 28, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-79</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2026-24128" target="_blank" rel="noopener" class="nt-cve-link">CVE-2026-24128</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)data-xwiki-reference&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">XWiki Platform Distribution Flavor Main versions prior to 17.6.0 are vulnerable to reflected cross-site scripting (XSS) due to improper sanitization of user-supplied input in the extensionId parameter. An attacker can exploit this issue by injecting malicious JavaScript, which will be executed in the context of the victim&#39;s browser, potentially leading to session hijacking or other attacks.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2026</span><span class="nt-tag">xss</span><span class="nt-tag">xwiki</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://jira.xwiki.org/browse/XWIKI-23462" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24128" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="xwiki rest api - attachments disclosure high identify critical remote vulnerabilities a vulnerability in xwiki&#39;s rest api allows unauthenticated users to access attachments list and metadata through the attachments endpoint. this could lead to disclosure of sensitive information stored in attachments metadata. cve-2025-46554 ritikchaddha cve cve2025 xwiki rest-api exposure vkev vuln cwe-285" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">XWiki REST API - Attachments Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-46554.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-46554.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 28, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/285.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-285</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-46554" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-46554</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)data-xwiki-reference&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A vulnerability in XWiki&#39;s REST API allows unauthenticated users to access attachments list and metadata through the attachments endpoint. This could lead to disclosure of sensitive information stored in attachments metadata.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated users can access attachment lists and metadata through the REST API attachments endpoint, potentially exposing sensitive information.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to the latest XWiki version that implements proper authorization checks for the attachments REST API endpoint.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">xwiki</span><span class="nt-tag">rest-api</span><span class="nt-tag">exposure</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://jira.xwiki.org/browse/XWIKI-22424" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-46554" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="xwiki rest api - private pages disclosure high identify critical remote vulnerabilities a vulnerability in xwiki&#39;s rest api allows unauthenticated users to access information about private pages through the pages endpoint. this could lead to disclosure of sensitive information and page metadata. cve-2025-29925 ritikchaddha cve cve2025 xwiki rest-api exposure vkev vuln cwe-285" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">XWiki REST API - Private Pages Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-29925.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-29925.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 28, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/285.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-285</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-29925" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-29925</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)data-xwiki-reference&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A vulnerability in XWiki&#39;s REST API allows unauthenticated users to access information about private pages through the pages endpoint. This could lead to disclosure of sensitive information and page metadata.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated users can access private page information through the REST API pages endpoint, potentially exposing sensitive metadata and page content.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to XWiki version that implements proper authorization checks for the REST API pages endpoint.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">xwiki</span><span class="nt-tag">rest-api</span><span class="nt-tag">exposure</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="xwiki rest api query - sql injection critical identify critical remote vulnerabilities a sql injection vulnerability exists in xwiki&#39;s rest api query endpoint. an unauthenticated attacker can execute arbitrary sql queries through the &#39;q&#39; parameter by manipulating the hql query, potentially leading to data exfiltration or system compromise. cve-2025-32969 ritikchaddha cve cve2025 rest-api sqli vkev vuln xwiki cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">XWiki REST API Query - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-32969.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-32969.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 28, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-32969" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-32969</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)data-xwiki-reference&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A SQL injection vulnerability exists in XWiki&#39;s REST API query endpoint. An unauthenticated attacker can execute arbitrary SQL queries through the &#39;q&#39; parameter by manipulating the HQL query, potentially leading to data exfiltration or system compromise.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can execute arbitrary SQL queries through the REST API query endpoint, potentially leading to complete database compromise and data exfiltration.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to the latest XWiki version that properly sanitizes HQL query parameters in the REST API.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">rest-api</span><span class="nt-tag">sqli</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">xwiki</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-f69v-xrj8-rhxf" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-32969" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="xwiki xml view - sensitive information exposure high identify critical remote vulnerabilities a vulnerability in xwiki&#39;s xml view functionality exposes sensitive information such as passwords and email addresses that are stored in custom fields not explicitly named as password or email. this information disclosure occurs when accessing user profiles with the xml.vm template. ritikchaddha cve cve2025 exposure vkev vuln xwiki cwe-359" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">XWiki XML View - Sensitive Information Exposure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-54125.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-54125.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 28, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/359.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-359</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)data-xwiki-reference&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A vulnerability in XWiki&#39;s XML view functionality exposes sensitive information such as passwords and email addresses that are stored in custom fields not explicitly named as password or email. This information disclosure occurs when accessing user profiles with the xml.vm template.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can access sensitive information including passwords and email addresses stored in custom user profile fields through the XML view functionality.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade XWiki to the latest version that properly protects sensitive custom fields in XML view outputs.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">exposure</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">xwiki</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://jira.xwiki.org/browse/XWIKI-22810" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54125" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="xxl-job default login high identify default logins in web-based control panels xxl-job default admin credentials were discovered. pdteam,ritikchaddha default-login vuln xxljob cwe-522" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">XXL-JOB Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/xxljob/xxljob-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">xxljob-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pdteam,ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/522.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-522</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1691956220&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">XXL-JOB default admin credentials were discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">vuln</span><span class="nt-tag">xxljob</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/xuxueli/xxl-job" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="xxljob admin login panel - detect info identify web-based control panels xxljob admin login panel was detected. pdteam,daffainfo,ritikchaddha panel xxljob login xuxueli discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">XXLJOB Admin Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/xxljob-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">xxljob-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pdteam,daffainfo,ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1691956220&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">XXLJOB admin login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">xxljob</span><span class="nt-tag">login</span><span class="nt-tag">xuxueli</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="xeams admin console login panel - detect info identify web-based control panels xeams admin console login panel was detected. theamanrawat admin console discovery panel synametrics xeams cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Xeams Admin Console Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/xeams-admin-console.yaml" target="_blank" rel="noopener" class="nt-source-link">xeams-admin-console.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> theamanrawat</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)xeams admin&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Xeams Admin Console login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">admin</span><span class="nt-tag">console</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">synametrics</span><span class="nt-tag">xeams</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="xerox fuji/versalink login - panel info identify web-based control panels xerox fuji / versalink login panel was discovered dhiyaneshdk panel xerox discovery login cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Xerox Fuji/VersaLink Login - Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/xerox-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">xerox-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 23, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/XUX-nwave/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Xerox Fuji / VersaLink Login Panel was discovered</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">xerox</span><span class="nt-tag">discovery</span><span class="nt-tag">login</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="xfinity panel - detect info identify web-based control panels xfinity panel was detected. hardik-solanki panel xfinity discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Xfinity Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/xfinity-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">xfinity-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Hardik-Solanki</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)xfinity&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Xfinity panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">xfinity</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="xiaomi wireless router admin panel - detect info identify web-based control panels xiaomi wireless router admin panel was detected. lu4nx discovery panel xiaomi cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Xiaomi Wireless Router Admin Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/xiaomi-wireless-router-login.yaml" target="_blank" rel="noopener" class="nt-source-link">xiaomi-wireless-router-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> lu4nx</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)小米路由器&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Xiaomi Wireless router admin panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">xiaomi</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.mi.com/shop/search?keyword=%E8%B7%AF%E7%94%B1%E5%99%A8" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="xibo cms login panel - detect info identify web-based control panels xibo cms login panel was detected. ritikchaddha,daffainfo discovery panel xibocms cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Xibo CMS Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/xibocms-login.yaml" target="_blank" rel="noopener" class="nt-source-link">xibocms-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha,daffainfo</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/xibosignage/xibo-cms&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Xibo CMS login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">xibocms</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="xinference panel - detect info identify web-based control panels xinference (xorbits inference) is a powerful and versatile library designed to
serve language, speech recognition, and multimodal models rxerium ai detect discovery inference llm panel xinference" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Xinference Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/xinference-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">xinference-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 27, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;Xinference&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Xinference (Xorbits Inference) is a powerful and versatile library designed to
serve language, speech recognition, and multimodal models</div></div></div>
  <div class="nt-tags"><span class="nt-tag">ai</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">inference</span><span class="nt-tag">llm</span><span class="nt-tag">panel</span><span class="nt-tag">xinference</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/xorbitsai/inference" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://inference.readthedocs.io" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="xploitspy - default login high identify default logins in web-based control panels default login and password to access administrator panel andreluna default-login vuln xploitspy" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">XploitSPY - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/xploitspy/xploitspy-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">xploitspy-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> andreluna</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 8, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;XploitSPY&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Default login and password to access administrator panel</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">vuln</span><span class="nt-tag">xploitspy</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/XploitWizer-Community/XploitSPY" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="xymon - exposure low identify web-based control panels detected the exposure of the xymon monitoring system interface. theamanrawat xymon exposure monitoring panel" data-nt-sev="low">
  <div class="nt-card-header">
    <div class="nt-title">Xymon - Exposure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/xymon-exposure.yaml" target="_blank" rel="noopener" class="nt-source-link">xymon-exposure.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> theamanrawat</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 19, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Xymon&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detected the exposure of the Xymon monitoring system interface.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">xymon</span><span class="nt-tag">exposure</span><span class="nt-tag">monitoring</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://xymon.com/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="yarpp &lt;= 5.30.10 - missing authorization critical identify critical remote vulnerabilities the yarpp yet another related posts plugin plugin for wordpress is vulnerable to unauthorized access due to a missing capability check in the ~/includes/yarpp_pro_set_display_types.php file in all versions up to, and including, 5.30.10. this makes it possible for unauthenticated attackers to set display types. cve-2024-43919 s4e-io auth-bypass cve cve2024 vuln wordpress wp wp-plugin yet-another-related-posts-plugin cwe-862" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">YARPP &lt;= 5.30.10 - Missing Authorization</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-43919.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-43919.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> s4e-io</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 28, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/862.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-862</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-43919" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-43919</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)wp-content/plugins/yet-another-related-posts-plugin/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The YARPP Yet Another Related Posts Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check in the ~/includes/yarpp_pro_set_display_types.php file in all versions up to, and including, 5.30.10. This makes it possible for unauthenticated attackers to set display types.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can modify display types in the YARPP plugin without proper authorization.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update YARPP plugin to a version later than 5.30.10 that patches the missing authorization vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">yet-another-related-posts-plugin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/RandomRobbieBF/CVE-2024-43919" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/yet-another-related-posts-plugin/yarpp-53010-missing-authorization" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://patchstack.com/database/vulnerability/yet-another-related-posts-plugin/wordpress-yet-another-related-posts-plugin-yarpp-plugin-5-30-10-broken-access-control-vulnerability?_s_id=cve" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-43919" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="ypareo panel - detect info identify web-based control panels ypareo was detected — an enterprise resource planning system. righettod panel ymag login detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">YPAREO Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/ypareo-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">ypareo-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 11, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)ypareo&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">YPAREO was detected — an Enterprise Resource Planning system.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">ymag</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.ypareo.com/legacy" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.ymag.fr/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="yacht - default login high identify default logins in web-based control panels yacht is a web interface for managing docker containers. this template detects instances with default admin credentials (admin@yacht.local:pass), which could allow unauthorized access to the docker environment, potentially leading to container manipulation, data exposure, or even host system compromise. fur1na default-login misconfig vuln yacht" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Yacht - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/yacht/yacht-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">yacht-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Fur1na</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 23, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-503392394&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Yacht is a web interface for managing Docker containers. This template detects instances with default admin credentials (admin@yacht.local:pass), which could allow unauthorized access to the Docker environment, potentially leading to container manipulation, data exposure, or even host system compromise.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">misconfig</span><span class="nt-tag">vuln</span><span class="nt-tag">yacht</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/SelfhostedPro/Yacht" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://dev.yacht.sh/docs/Installation/Getting_Started" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="yealink dm 3.6.0.20 - remote command injection critical identify critical remote vulnerabilities yealink device management (dm) 3.6.0.20 allows command injection as root via the /sm/api/v1/firewall/zone/services uri, without authentication. cve-2021-27561 shifacyclewala,hackergautam cve cve2021 kev mirai rce vkev vuln yealink cwe-78" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">YeaLink DM 3.6.0.20 - Remote Command Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2021/CVE-2021-27561.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2021-27561.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> shifacyclewala,hackergautam</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/78.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-78</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2021-27561" target="_blank" rel="noopener" class="nt-cve-link">CVE-2021-27561</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] contains &#34;sorry but ydmp doesn&#39;t work properly without JavaScript enabled&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Yealink Device Management (DM) 3.6.0.20 allows command injection as root via the /sm/api/v1/firewall/zone/services URI, without authentication.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability allows remote attackers to execute arbitrary commands on the affected device.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest firmware version provided by the vendor to mitigate this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2021</span><span class="nt-tag">kev</span><span class="nt-tag">mirai</span><span class="nt-tag">rce</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">yealink</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://ssd-disclosure.com/ssd-advisory-yealink-dm-pre-auth-root-level-rce/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=2021-27561" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://ssd-disclosure.com/?p=4688" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/ARPSyndicate/cvemon" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/ARPSyndicate/kenzer-templates" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="yellow pencil visual theme customizer &lt; 7.2.1 - privilege escalation high identify critical remote vulnerabilities the waspthemes visual css style editor (aka yellow-pencil-visual-theme-customizer) plugin before 7.2.1 for wordpress allows yp_option_update csrf, as demonstrated by use of yp_remote_get to obtain admin access. cve-2019-11886 daffainfo cve cve2019 vkev vuln wordpress wp wp-plugin yellow-pencil-visual-theme-customizer cwe-352" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Yellow Pencil Visual Theme Customizer &lt; 7.2.1 - Privilege Escalation</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2019/CVE-2019-11886.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2019-11886.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> daffainfo</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 18, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/352.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-352</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2019-11886" target="_blank" rel="noopener" class="nt-cve-link">CVE-2019-11886</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)wp-content/plugins/yellow-pencil-visual-theme-customizer/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The WaspThemes Visual CSS Style Editor (aka yellow-pencil-visual-theme-customizer) plugin before 7.2.1 for WordPress allows yp_option_update CSRF, as demonstrated by use of yp_remote_get to obtain admin access.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can exploit CSRF to escalate privileges to administrator level, gaining complete control over the WordPress site including content manipulation and user management.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to Yellow Pencil Visual Theme Customizer version 7.2.1 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2019</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">yellow-pencil-visual-theme-customizer</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.wordfence.com/blog/2019/04/zero-day-vulnerability-in-yellow-pencil-visual-theme-customizer-exploited-in-the-wild/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://web.archive.org/web/20190410184502/https://www.pluginvulnerabilities.com/2019/04/09/recently-closed-visual-css-style-editor-wordpress-plugin-contains-privilege-escalation-vulnerability-that-leads-to-option-update-vulnerability/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2019-11886" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="yellowfin information collaboration - detect info identify web-based control panels  dhiyaneshdk yellowfin panel login discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Yellowfin Information Collaboration - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/yellowfin-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">yellowfin-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Yellowfin Information Collaboration&#34;})</code></div>
  <div class="nt-tags"><span class="nt-tag">yellowfin</span><span class="nt-tag">panel</span><span class="nt-tag">login</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="yeswiki &lt; 4.5.4 - cross-site scripting medium identify critical remote vulnerabilities yeswiki &lt; 4.5.4 contains a reflected cross-site scripting caused by unsanitized `idformulaire` parameter in `/?bazar` endpoint, letting attackers steal cookies and hijack sessions, exploit requires user to click malicious link. cve-2025-46550 muhammadwaseem cve cve2025 vuln xss yeswiki cwe-79" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">YesWiki &lt; 4.5.4 - Cross-Site Scripting</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-46550.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-46550.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> MuhammadWaseem</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 12, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-79</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-46550" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-46550</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)yeswiki&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">YesWiki &lt; 4.5.4 contains a reflected cross-site scripting caused by unsanitized `idformulaire` parameter in `/?BazaR` endpoint, letting attackers steal cookies and hijack sessions, exploit requires user to click malicious link.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can steal cookies, hijack user sessions, deface website, or embed malicious content.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to version 4.5.4 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">vuln</span><span class="nt-tag">xss</span><span class="nt-tag">yeswiki</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/YesWiki/yeswiki/security/advisories/GHSA-ggqx-43h2-55jp" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-46550" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="yeswiki &lt;2022-07-07 - sql injection critical identify critical remote vulnerabilities yeswiki before 2022-07-07 contains a sql injection vulnerability via the id parameter in the accueil url. an attacker can possibly obtain sensitive information from a database, modify data, and execute unauthorized administrative operations in the context of the affected site. arafatansari huntr sqli vuln yeswiki cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">YesWiki &lt;2022-07-07 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/vulnerabilities/other/yeswiki-sql.yaml" target="_blank" rel="noopener" class="nt-source-link">yeswiki-sql.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> arafatansari</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)yeswiki&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">YesWiki before 2022-07-07 contains a SQL injection vulnerability via the id parameter in the AccueiL URL. An attacker can possibly obtain sensitive information from a database, modify data, and execute unauthorized administrative operations in the context of the affected site.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">huntr</span><span class="nt-tag">sqli</span><span class="nt-tag">vuln</span><span class="nt-tag">yeswiki</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://huntr.dev/bounties/32e27955-376a-48fe-9984-87dd77e24985" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="yeswiki reflected xss via file upload high identify critical remote vulnerabilities yeswiki is a wiki system written in php. prior to version 4.5.4, yeswiki is vulnerable to reflected xss in the file upload form. this vulnerability allows any malicious unauthenticated user to create a link that can be clicked on by the victim to perform arbitrary actions. this issue has been patched in version 4.5.4. cve-2025-46349 mahmoud gamal cve cve2025 xss yeswiki" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">YesWiki Reflected XSS via File Upload</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-46349.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-46349.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Mahmoud Gamal</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 29, 2025</span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-46349" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-46349</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)yeswiki&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">YesWiki is a wiki system written in PHP. Prior to version 4.5.4, YesWiki is vulnerable to reflected XSS in the file upload form. This vulnerability allows any malicious unauthenticated user to create a link that can be clicked on by the victim to perform arbitrary actions. This issue has been patched in version 4.5.4.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can execute arbitrary scripts in the victim&#39;s browser, potentially leading to session hijacking or defacement.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to version 4.5.4 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">xss</span><span class="nt-tag">yeswiki</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/YesWiki/yeswiki/security/advisories/GHSA-2f8p-qqx2-gwr2" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-46349" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="yeswiki &lt; 4.5.2 - unauthenticated path traversal high identify critical remote vulnerabilities yeswiki is a wiki system written in php. the squelette parameter is vulnerable to path traversal attacks, enabling read access to arbitrary files on the server. cve-2025-31131 iamnoooob,rootxharsh,pdresearch cve cve2025 lfi vuln yeswiki cwe-22" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Yeswiki &lt; 4.5.2 - Unauthenticated Path Traversal</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-31131.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-31131.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> iamnoooob,rootxharsh,pdresearch</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 2, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-31131" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-31131</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)yeswiki&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">YesWiki is a wiki system written in PHP. The squelette parameter is vulnerable to path traversal attacks, enabling read access to arbitrary files on the server.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can exploit path traversal through the squelette parameter to read arbitrary files from the YesWiki server, potentially exposing sensitive configuration and data files.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">This vulnerability is fixed in 4.5.2.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">lfi</span><span class="nt-tag">vuln</span><span class="nt-tag">yeswiki</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/advisories/GHSA-w34w-fvp3-68xm" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/YesWiki/yeswiki/commit/f78c915369a60c74ab8f38561ae93a4aaca9b989" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/YesWiki/yeswiki/security/advisories/GHSA-w34w-fvp3-68xm" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="yonyou ufida erp-nc v5.0 - cross-site scripting medium identify critical remote vulnerabilities yonyou ufida erp-nc v5.0 is vulnerable to reflected cross-site scripting (xss) via the langcode parameter in /help/systop.jsp and /help/top.jsp. unsanitized user input is reflected in the response, allowing arbitrary javascript execution. cve-2025-2712 ritikchaddha cve cve2025 erp-nc ufida vkev vuln xss yonyou cwe-79" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Yonyou UFIDA ERP-NC V5.0 - Cross-Site Scripting</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-2712.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-2712.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 16, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-79</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-2712" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-2712</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1085941792&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Yonyou UFIDA ERP-NC V5.0 is vulnerable to reflected cross-site scripting (XSS) via the langcode parameter in /help/systop.jsp and /help/top.jsp. Unsanitized user input is reflected in the response, allowing arbitrary JavaScript execution.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can inject malicious JavaScript through the langcode parameter in help pages, potentially stealing user credentials, session cookies, or executing unauthorized actions.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to Yonyou UFIDA ERP-NC version 5.1 or later that properly sanitizes the langcode parameter.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">erp-nc</span><span class="nt-tag">ufida</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">xss</span><span class="nt-tag">yonyou</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-2712" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="yonyou yonbip - path traversal high identify critical remote vulnerabilities yonyou yonbip v3 and before contains a path traversal caused by improper validation in the loginwithv8 interface of the series data application service system, letting unauthorized attackers access sensitive information. cve-2025-66744 dhiyaneshdk cve cve2025 lfi vkev yonbip" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Yonyou YonBIP - Path Traversal</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-66744.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-66744.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 10, 2026</span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-66744" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-66744</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)YonBIP \\| 数据应用服务&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Yonyou YonBIP v3 and before contains a path traversal caused by improper validation in the LoginWithV8 interface of the series data application service system, letting unauthorized attackers access sensitive information.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthorized attackers can access sensitive system information, potentially leading to data exposure.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest version beyond v3.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">lfi</span><span class="nt-tag">vkev</span><span class="nt-tag">yonbip</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66744" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/iSee857/YonYouBip-path-travel" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="yopass panel - detect info identify web-based control panels yopass panel was detected. adam crosser panel yopass discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Yopass Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/yopass-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">yopass-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Adam Crosser</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Yopass&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Yopass panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">yopass</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="youphptube encoder 2.3 - command injection critical identify critical remote vulnerabilities exploitable unauthenticated command injections exist in youphptube encoder 2.3 a plugin for providing encoder functionality in youphptube.the parameter base64url in /objects/getimagemp4.php is vulnerable to a command injection attack. cve-2019-5129 pussycat0x cve cve2019 encoder rce vkev vuln youphptube cwe-78" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">YouPHPTube Encoder 2.3 - Command Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2019/CVE-2019-5129.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2019-5129.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 21, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/78.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-78</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2019-5129" target="_blank" rel="noopener" class="nt-cve-link">CVE-2019-5129</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-276846707&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Exploitable unauthenticated command injections exist in YouPHPTube Encoder 2.3 a plugin for providing encoder functionality in YouPHPTube.The parameter base64Url in /objects/getImageMP4.php is vulnerable to a command injection attack.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can execute arbitrary system commands through command injection, leading to complete server compromise and potential access to all media content.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to YouPHPTube Encoder version 2.4 or later, or apply vendor-provided security patches.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2019</span><span class="nt-tag">encoder</span><span class="nt-tag">rce</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">youphptube</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://xz.aliyun.com/news/6312" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="youzify &lt; 1.2.0 - unauthenticated sqli critical identify critical remote vulnerabilities the youzify wordpress plugin before 1.2.0 does not sanitise and escape a parameter before using it in a sql statement via an ajax action available to unauthenticated users, leading to an unauthenticated sql injection cve-2022-1950 dhiyaneshdk cve cve2022 sqli time-based-sqli vkev vuln wordpress wp wp-plugin youzify cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Youzify &lt; 1.2.0 - Unauthenticated SQLi</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-1950.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-1950.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 20, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-1950" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-1950</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/youzify&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The Youzify WordPress plugin before 1.2.0 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to an unauthenticated SQL injection</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can execute time-based blind SQL injection via AJAX actions to extract database contents, potentially exposing all Youzify media and user data.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Fixed in 1.2.0</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">sqli</span><span class="nt-tag">time-based-sqli</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">youzify</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wpscan.com/vulnerability/4352283f-dd43-4827-b417-0c55d0f4637d/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="yunohost admin panel - detect info identify web-based control panels yunohost admin panel was discovered. s4e-io panel login yunohost detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">YunoHost Admin Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/yunohost-admin-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">yunohost-admin-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> s4e-io</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 13, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)YunoHost Admin&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">YunoHost Admin panel was discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">login</span><span class="nt-tag">yunohost</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://yunohost.org/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/YunoHost/yunohost" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="yzmcms login panel - detect info identify web-based control panels yzmcms login panel was detected. pikpikcu,daffainfo discovery login panel yzmcms cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">YzmCMS Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/yzmcms-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">yzmcms-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pikpikcu,daffainfo</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)yzmcms&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">YzmCMS login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">login</span><span class="nt-tag">panel</span><span class="nt-tag">yzmcms</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="z-blogphp admin login panel - detect info identify web-based control panels z-blogphp admin login panel was detected. aayush vishnoi discovery panel zblog zblogcn cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Z-BlogPHP Admin Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/zblog-exposed-admin-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">zblog-exposed-admin-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Aayush Vishnoi</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)zblog&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Z-BlogPHP admin login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">zblog</span><span class="nt-tag">zblogcn</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/zblogcn/zblogphp" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="z-blogphp panel - detect info identify web-based control panels z-blogphp panel was detected. princechaddha discovery panel zblogphp cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Z-BlogPHP Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/zblogphp-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">zblogphp-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> princechaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Z-BlogPHP&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Z-BlogPHP panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">zblogphp</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="zerof web server 2.0 - sql injection critical identify critical remote vulnerabilities zerof web server 2.0 allows sql injection via the /handleevent endpoint. attackers can exploit this vulnerability by manipulating the request parameters to execute arbitrary sql queries. cve-2022-25322 daffainfo cve cve2022 sqli vkev vuln zerof cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">ZEROF Web Server 2.0 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-25322.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-25322.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> daffainfo</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 23, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-25322" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-25322</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.head.server&#34;] matches &#34;ZEROF Web Server&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">ZEROF Web Server 2.0 allows SQL Injection via the /HandleEvent endpoint. Attackers can exploit this vulnerability by manipulating the request parameters to execute arbitrary SQL queries.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized access, data leakage, or data manipulation.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches or updates provided by the vendor to fix the SQL Injection vulnerability in ZEROF Web Server 2.0.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">sqli</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">zerof</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/landigv/research/blob/main/cve/CVE-2022-25322.md" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-25322" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="zitadel panel - detect info identify web-based control panels detected zitadel was an open-source identity infrastructure platform providing oidc, oauth 2.0, saml and machine-user iam. chrisjr404 detect iam oidc panel zitadel" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">ZITADEL Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/zitadel-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">zitadel-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ChrisJr404</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 6, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)ZITADEL&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detected ZITADEL was an open-source identity infrastructure platform providing OIDC, OAuth 2.0, SAML and machine-user IAM.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">detect</span><span class="nt-tag">iam</span><span class="nt-tag">oidc</span><span class="nt-tag">panel</span><span class="nt-tag">zitadel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/zitadel/zitadel" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://zitadel.com/docs" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="zkteco biotime &lt;= 9.0.1 - privilege escalation high identify critical remote vulnerabilities biotime default employee credentials (password 123456) allow login. sessions are not role-validated, enabling privilege escalation to perform admin actions and enumerate backup files. cve-2023-38952 riteshs4hu auth-bypass biotime cve cve2023 priv-esc vkev zkteco cwe-552" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">ZKTeco BioTime &lt;= 9.0.1 - Privilege Escalation</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-38952.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-38952.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> riteshs4hu</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 10, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/552.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-552</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-38952" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-38952</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)ZKTeco Security&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">BioTime default employee credentials (password 123456) allow login. Sessions are not role-validated, enabling privilege escalation to perform admin actions and enumerate backup files.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can access sensitive files and credentials, leading to data breach and potential system compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Implement proper authentication and access controls for static file resources, and update to the latest version if available.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">biotime</span><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">priv-esc</span><span class="nt-tag">vkev</span><span class="nt-tag">zkteco</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-38951" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://krashconsulting.com/fury-of-fingers-biotime-rce/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/omair2084/biotime-rce-8.5.5/blob/main/biotime_enum.py" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="zkteco biotime v8.5.5 - path traversal high identify critical remote vulnerabilities a path traversal vulnerability in the iclock api of zkteco biotime v8.5.5 allows unauthenticated attackers to read arbitrary files via supplying a crafted payload. cve-2023-38950 iamnoooob,pdresearch biotime cve cve2023 kev lfr vkev vuln zkteco cwe-22" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">ZKTeco BioTime v8.5.5 - Path Traversal</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-38950.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-38950.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> iamnoooob,pdresearch</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 29, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-38950" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-38950</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)biotime&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A path traversal vulnerability in the iclock API of ZKTeco BioTime v8.5.5 allows unauthenticated attackers to read arbitrary files via supplying a crafted payload.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can read arbitrary files from the server through path traversal in the iclock API url parameter, potentially exposing employee biometric data, attendance records, and system credentials.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update ZKTeco BioTime to a version newer than 8.5.5 that validates file paths in the iclock API and restricts access to authorized files only.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">biotime</span><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">kev</span><span class="nt-tag">lfr</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">zkteco</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/advisories/GHSA-4m8x-4g54-h49v" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="http://zkteco.com" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://claroty.com/team82/disclosure-dashboard/cve-2023-38950" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://www.fortinet.com/content/dam/fortinet/assets/reports/report-incident-response-middle-east.pdf" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-38950" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="zoho manageengine adaudit/admanager panel - detect info identify web-based control panels zoho manageengine adaudit/admanager panel was detected. dhiyaneshdk,pr3r00t,idealphase discovery manageengine panel zoho zohocorp cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">ZOHO ManageEngine ADAudit/ADManager Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/zoho/manageengine-adaudit.yaml" target="_blank" rel="noopener" class="nt-source-link">manageengine-adaudit.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDK,PR3R00T,idealphase</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)adaudit plus&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">ZOHO ManageEngine ADAudit/ADManager panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">manageengine</span><span class="nt-tag">panel</span><span class="nt-tag">zoho</span><span class="nt-tag">zohocorp</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.manageengine.com/products/active-directory-audit/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.manageengine.com/products/ad-manager/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="zoho manageengine adselfservice plus - detect info identify web-based control panels zoho manageengine adselfservice panel was detected. dhiyaneshdk,sak1 discovery manageengine panel zoho zohocorp cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">ZOHO ManageEngine ADSelfService Plus - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/zoho/manageengine-adselfservice.yaml" target="_blank" rel="noopener" class="nt-source-link">manageengine-adselfservice.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDK,SaK1</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)adselfservice plus&#34;}) || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)manageengine&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">ZOHO ManageEngine ADSelfService panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">manageengine</span><span class="nt-tag">panel</span><span class="nt-tag">zoho</span><span class="nt-tag">zohocorp</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="zoho manageengine apex it help-desk panel - detect info identify web-based control panels zoho mangageengine apex panel was detected. dhiyaneshdk discovery manageengine panel zoho zohocorp cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">ZOHO ManageEngine APEX IT Help-Desk Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/zoho/manageengine-apex-helpdesk.yaml" target="_blank" rel="noopener" class="nt-source-link">manageengine-apex-helpdesk.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)apex it help desk&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">ZOHO MangageEngine APEX panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">manageengine</span><span class="nt-tag">panel</span><span class="nt-tag">zoho</span><span class="nt-tag">zohocorp</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="zoho manageengine analytics plus panel - detect info identify web-based control panels zoho manageengine analytics plus panel was detected. dhiyaneshdk discovery manageengine panel zoho zohocorp cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">ZOHO ManageEngine Analytics Plus Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/zoho/manageengine-analytics.yaml" target="_blank" rel="noopener" class="nt-source-link">manageengine-analytics.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)apex it help desk&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">ZOHO ManageEngine analytics plus panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">manageengine</span><span class="nt-tag">panel</span><span class="nt-tag">zoho</span><span class="nt-tag">zohocorp</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="zoho manageengine assetexplorer panel - detect info identify web-based control panels zoho manageengine assetexplorer panel was detected. dhiyaneshdk discovery manageengine panel zoho zohocorp cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">ZOHO ManageEngine AssetExplorer Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/zoho/manageengine-assetexplorer.yaml" target="_blank" rel="noopener" class="nt-source-link">manageengine-assetexplorer.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)manageengine assetexplorer&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">ZOHO ManageEngine AssetExplorer panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">manageengine</span><span class="nt-tag">panel</span><span class="nt-tag">zoho</span><span class="nt-tag">zohocorp</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="zoho manageengine desktop panel - detect info identify web-based control panels zoho manageengine desktop panel was detected. dhiyaneshdk discovery manageengine panel zoho zohocorp cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">ZOHO ManageEngine Desktop Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/zoho/manageengine-desktop.yaml" target="_blank" rel="noopener" class="nt-source-link">manageengine-desktop.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)manageengine desktop central 10&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">ZOHO ManageEngine desktop panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">manageengine</span><span class="nt-tag">panel</span><span class="nt-tag">zoho</span><span class="nt-tag">zohocorp</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="zoho manageengine exchange reporter plus panel - detect info identify web-based control panels zoho manageengine exchange reporter plus panel was detected. darses discovery login manageengine panel zoho zohocorp" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">ZOHO ManageEngine Exchange Reporter Plus Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/zoho/manageengine-exchangereporter.yaml" target="_blank" rel="noopener" class="nt-source-link">manageengine-exchangereporter.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> darses</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 9, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)ManageEngine - Exchange Reporter Plus&#34;}) || service[&#34;favicon.ico.image.mmh3&#34;] == &#34;230963457&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">ZOHO ManageEngine Exchange Reporter Plus panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">login</span><span class="nt-tag">manageengine</span><span class="nt-tag">panel</span><span class="nt-tag">zoho</span><span class="nt-tag">zohocorp</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.manageengine.com/products/exchange-reports/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="zoho manageengine opmanager panel - detect info identify web-based control panels zoho manageengine opmanager panel was detected. dhiyaneshdk,daffainfo discovery manageengine panel zoho zohocorp cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">ZOHO ManageEngine OpManager Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/zoho/manageengine-opmanager.yaml" target="_blank" rel="noopener" class="nt-source-link">manageengine-opmanager.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDK,daffainfo</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)opmanager plus&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">ZOHO ManageEngine OpManager panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">manageengine</span><span class="nt-tag">panel</span><span class="nt-tag">zoho</span><span class="nt-tag">zohocorp</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.manageengine.com/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="zoho manageengine servicedesk panel - detect info identify web-based control panels zoho manageengine servicedesk panel was detected. dhiyaneshdk,righettod discovery manageengine panel zoho zohocorp cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">ZOHO ManageEngine ServiceDesk Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/zoho/manageengine-servicedesk.yaml" target="_blank" rel="noopener" class="nt-source-link">manageengine-servicedesk.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDK,righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)manageengine servicedesk plus&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">ZOHO ManageEngine ServiceDesk panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">manageengine</span><span class="nt-tag">panel</span><span class="nt-tag">zoho</span><span class="nt-tag">zohocorp</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="zoho manageengine supportcenter panel - detect info identify web-based control panels zoho manageengine supportcenter panel was detected. dhiyaneshdk discovery manageengine panel zoho zohocorp cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">ZOHO ManageEngine SupportCenter Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/zoho/manageengine-supportcenter.yaml" target="_blank" rel="noopener" class="nt-source-link">manageengine-supportcenter.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)manageengine supportcenter plus&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">ZOHO ManageEngine SupportCenter panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">manageengine</span><span class="nt-tag">panel</span><span class="nt-tag">zoho</span><span class="nt-tag">zohocorp</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="zte panel - detect info identify web-based control panels zte panel was detected. zte corporation is a global leader in telecommunications and information technology. founded in 1985 and listed on both the hong kong and shenzhen stock exchanges, the company has been committed to providing innovative technologies and integrated solutions for global operators, government and enterprise, and consumers from over 160 countries across the globe. zte corporation is a global leader in telecommunications and information technology. founded in 1985 and listed on both the hong kong and shenzhen stock exchanges, the company has been committed to providing innovative technologies and integrated solutions for global operators, government and enterprise, and consumers from over 160 countries across the globe. its0x08,idealphase discovery panel zte cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">ZTE Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/zte-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">zte-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> its0x08,idealphase</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)ZTE Corporation&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">ZTE panel was detected. ZTE Corporation is a global leader in telecommunications and information technology. Founded in 1985 and listed on both the Hong Kong and Shenzhen Stock Exchanges, the company has been committed to providing innovative technologies and integrated solutions for global operators, government and enterprise, and consumers from over 160 countries across the globe. ZTE Corporation is a global leader in telecommunications and information technology. Founded in 1985 and listed on both the Hong Kong and Shenzhen Stock Exchanges, the company has been committed to providing innovative technologies and integrated solutions for global operators, government and enterprise, and consumers from over 160 countries across the globe.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">zte</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.zte.com.cn/global/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="zte router panel - detect critical network-backdoor multiple zte router panels were detected. these routers have a telnet-hardcoded backdoor account that spawns root shell. its0x08 backdoor edb network router tcp telnet vuln zte cwe-912" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">ZTE Router Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/network/backdoor/backdoored-zte.yaml" target="_blank" rel="noopener" class="nt-source-link">backdoored-zte.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> its0x08</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 21, 2022</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/912.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-912</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)ZTE Corporation&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Multiple ZTE router panels were detected. These routers have a telnet-hardcoded backdoor account that spawns root shell.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">backdoor</span><span class="nt-tag">edb</span><span class="nt-tag">network</span><span class="nt-tag">router</span><span class="nt-tag">tcp</span><span class="nt-tag">telnet</span><span class="nt-tag">vuln</span><span class="nt-tag">zte</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.exploit-db.com/ghdb/7179" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">network-backdoor</span></span></div>
</div>
<div class="nt-card" data-nt-search="zte zxhn-f660t/f660a - default credentials high identify critical remote vulnerabilities zxhn-f660t and zxhn-f660a provided by zte japan k.k. use a common credential for all installations. with the knowledge of the credential, an attacker may log in to the affected devices. cve-2025-53558 dhiyaneshdk cve cve2025 default-login vkev vuln zte cwe-1391" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">ZTE ZXHN-F660T/F660A - Default Credentials</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-53558.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-53558.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 3, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/1391.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-1391</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-53558" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-53558</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)F660&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">ZXHN-F660T and ZXHN-F660A provided by ZTE Japan K.K. use a common credential for all installations. With the knowledge of the credential, an attacker may log in to the affected devices.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers with knowledge of common credentials can access ZTE device management interfaces, potentially gaining control over network equipment and configurations.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Change default credentials immediately and restrict access to the web management interface to trusted administrators only.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">default-login</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">zte</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53558" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://jvn.jp/en/jp/JVN66546573/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="zabbix - saml sso authentication bypass critical identify critical remote vulnerabilities when saml sso authentication is enabled (non-default), session data can be modified by a malicious actor because a user login stored in the session was not verified. cve-2022-23131 for3stco1d,spac3wh1te auth-bypass cve cve2022 kev saml sso vkev vuln zabbix cwe-290" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Zabbix - SAML SSO Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-23131.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-23131.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> For3stCo1d,spac3wh1te</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/290.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-290</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-23131" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-23131</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;892542951&#34; || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)zabbix-server&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">When SAML SSO authentication is enabled (non-default), session data can be modified by a malicious actor because a user login stored in the session was not verified.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability can lead to unauthorized access to sensitive information and potential compromise of the Zabbix monitoring system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to 5.4.9rc2, 6.0.0beta1, 6.0 (plan) or higher.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">kev</span><span class="nt-tag">saml</span><span class="nt-tag">sso</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">zabbix</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://support.zabbix.com/browse/ZBX-20350" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://blog.sonarsource.com/zabbix-case-study-of-unsafe-session-storage" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-23131" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/1mxml/CVE-2022-23131" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/20142995/sectool" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="zabbix - sql injection critical identify critical remote vulnerabilities zabbix before 2.2.14 and 3.0 before 3.0.4 allows remote attackers to execute arbitrary sql commands via the toggle_ids array parameter in latest.php and perform sql injection attacks. cve-2016-10134 princechaddha cve cve2016 sqli vulhub vuln zabbix cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Zabbix - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2016/CVE-2016-10134.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2016-10134.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> princechaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2016-10134" target="_blank" rel="noopener" class="nt-cve-link">CVE-2016-10134</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;892542951&#34; || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)zabbix-server&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Zabbix before 2.2.14 and 3.0 before 3.0.4 allows remote attackers to execute arbitrary SQL commands via the toggle_ids array parameter in latest.php and perform SQL injection attacks.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could lead to unauthorized access, data leakage, and potential compromise of the Zabbix application and underlying systems.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches or upgrade to a patched version of Zabbix to mitigate the SQL Injection vulnerability (CVE-2016-10134).</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2016</span><span class="nt-tag">sqli</span><span class="nt-tag">vulhub</span><span class="nt-tag">vuln</span><span class="nt-tag">zabbix</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/vulhub/vulhub/tree/master/zabbix/CVE-2016-10134" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2016-10134" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://support.zabbix.com/browse/ZBX-11023" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=850936" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="http://www.debian.org/security/2017/dsa-3802" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="zabbix &lt;=4.4 - authentication bypass critical identify critical remote vulnerabilities zabbix through 4.4 is susceptible to an authentication bypass vulnerability via zabbix.php?action=dashboard.view&amp;dashboardid=1. an attacker can bypass the login page and access the dashboard page, and then create a dashboard, report, screen, or map without any username/password (i.e., anonymously). all created elements (dashboard/report/screen/map) are accessible by other users and by an admin. cve-2019-17382 harshbothra_ auth-bypass cve cve2019 edb login vuln zabbix cwe-639" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Zabbix &lt;=4.4 - Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2019/CVE-2019-17382.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2019-17382.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> harshbothra_</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/639.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-639</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2019-17382" target="_blank" rel="noopener" class="nt-cve-link">CVE-2019-17382</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;892542951&#34; || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)zabbix-server&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Zabbix through 4.4 is susceptible to an authentication bypass vulnerability via zabbix.php?action=dashboard.view&amp;dashboardid=1. An attacker can bypass the login page and access the dashboard page, and then create a Dashboard, Report, Screen, or Map without any Username/Password (i.e., anonymously). All created elements (Dashboard/Report/Screen/Map) are accessible by other users and by an admin.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability allows an attacker to bypass authentication and gain unauthorized access to the Zabbix application.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to a patched version of Zabbix (&gt;=4.4) to mitigate this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2019</span><span class="nt-tag">edb</span><span class="nt-tag">login</span><span class="nt-tag">vuln</span><span class="nt-tag">zabbix</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.exploit-db.com/exploits/47467" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2019-17382" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://lists.debian.org/debian-lts-announce/2023/08/msg00027.html" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/huimzjty/vulwiki" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/merlinepedra25/nuclei-templates" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="zabbix default login high identify default logins in web-based control panels zabbix default admin credentials were discovered. pdteam default-login vuln zabbix cwe-522" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Zabbix Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/zabbix/zabbix-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">zabbix-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pdteam</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/522.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-522</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;892542951&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Zabbix default admin credentials were discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">vuln</span><span class="nt-tag">zabbix</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://openbaton.github.io/documentation/zabbix-server-configuration-3.0/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="zabbix login panel - detect info identify web-based control panels zabbix login panel was detected. dhiyaneshdk discovery panel zabbix cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Zabbix Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/zabbix-server-login.yaml" target="_blank" rel="noopener" class="nt-source-link">zabbix-server-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;892542951&#34; || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)zabbix-server&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Zabbix login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">zabbix</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="zabbix setup configuration authentication bypass medium identify critical remote vulnerabilities after the initial setup process, some steps of setup.php file are reachable not only by super-administrators but also by unauthenticated users. a malicious actor can pass step checks and potentially change the configuration of zabbix frontend. cve-2022-23134 bananabr auth-bypass cve cve2022 kev vkev vuln zabbix cwe-284,cwe-287" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Zabbix Setup Configuration Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-23134.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-23134.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> bananabr</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/284,CWE-287.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-284,CWE-287</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-23134" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-23134</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)zabbix-server&#34;}) || service[&#34;favicon.ico.image.mmh3&#34;] == &#34;892542951&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">After the initial setup process, some steps of setup.php file are reachable not only by super-administrators but also by unauthenticated users. A malicious actor can pass step checks and potentially change the configuration of Zabbix Frontend.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability can lead to unauthorized access to sensitive information and potential compromise of the Zabbix setup configuration.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches or updates provided by Zabbix to fix the authentication bypass vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">kev</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">zabbix</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://blog.sonarsource.com/zabbix-case-study-of-unsafe-session-storage" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-23134" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://support.zabbix.com/browse/ZBX-20384" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6SZYHXINBKCY42ITFSNCYE7KCSF33VRA/" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://lists.debian.org/debian-lts-announce/2022/02/msg00008.html" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="zammad helpdesk panel - detect info identify web-based control panels zammad is an open source helpdesk and customer support system that provides ticket management, live chat, and knowledge base functionality. this template detects exposed zammad installations. righettod panel zammad detect helpdesk ticketing discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Zammad Helpdesk Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/zammad-helpdesk-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">zammad-helpdesk-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 19, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Zammad Helpdesk&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Zammad is an open source helpdesk and customer support system that provides ticket management, live chat, and knowledge base functionality. This template detects exposed Zammad installations.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">zammad</span><span class="nt-tag">detect</span><span class="nt-tag">helpdesk</span><span class="nt-tag">ticketing</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/zammad/zammad" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://zammad.org/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="zebra - default login high identify default logins in web-based control panels zebra default login credentials was discovered. y0no default-login misconfig printer vuln zebra" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Zebra - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/zebra/zebra-printer-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">zebra-printer-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> y0no</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 16, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;Zebra&#34;}) || service[&#34;http.body&#34;] matches &#34;Zebra Technologies&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Zebra default login credentials was discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">misconfig</span><span class="nt-tag">printer</span><span class="nt-tag">vuln</span><span class="nt-tag">zebra</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="zebra printer detect info identify web-based control panels zebra printer panel was detected. gy741 iot zebra printer discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Zebra Printer Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/iot/zebra-printer-detect.yaml" target="_blank" rel="noopener" class="nt-source-link">zebra-printer-detect.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> gy741</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;Zebra&#34;}) || service[&#34;http.body&#34;] matches &#34;Zebra Technologies&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Zebra Printer panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">iot</span><span class="nt-tag">zebra</span><span class="nt-tag">printer</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.zebra.com/kr/ko/products/printers.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="zenml dashboard panel - detect info identify web-based control panels  dhiyaneshdk zenml panel login discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">ZenML Dashboard Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/zenml-dashboard-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">zenml-dashboard-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 8, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-2028554187&#34;</code></div>
  <div class="nt-tags"><span class="nt-tag">zenml</span><span class="nt-tag">panel</span><span class="nt-tag">login</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="zenml zenml server - improper authentication critical identify critical remote vulnerabilities zenml server in the zenml machine learning package before 0.46.7 for python allows remote privilege escalation because the /api/v1/users/{user_name_or_id}/activate rest api endpoint allows access on the basis of a valid username along with a new password in the request body. cve-2024-25723 david botelho mariano auth-bypass cve cve2024 passive vuln zenml cwe-284" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">ZenML ZenML Server - Improper Authentication</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-25723.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-25723.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> David Botelho Mariano</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 24, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/284.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-284</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-25723" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-25723</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-2028554187&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">ZenML Server in the ZenML machine learning package before 0.46.7 for Python allows remote privilege escalation because the /api/v1/users/{user_name_or_id}/activate REST API endpoint allows access on the basis of a valid username along with a new password in the request body.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation could lead to unauthorized access to sensitive data.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Implement proper authentication mechanisms and ensure access controls are correctly configured.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">passive</span><span class="nt-tag">vuln</span><span class="nt-tag">zenml</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.zenml.io/blog/critical-security-update-for-zenml-users" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/zenml-io/zenml" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/zenml-io/zenml/compare/0.42.1...0.42.2" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/zenml-io/zenml/compare/0.43.0...0.43.1" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/zenml-io/zenml/compare/0.44.3...0.44.4" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="zeroshell &lt;= 1.0beta11 remote code execution critical identify critical remote vulnerabilities zeroshell 1.0beta11 and earlier via cgi-bin/kerbynet allows remote attackers to execute arbitrary commands through shell metacharacters in the type parameter in a noauthreq x509list action. cve-2009-0545 geeknik cve cve2009 edb kerbynet rce vkev vuln zeroshell cwe-20" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">ZeroShell &lt;= 1.0beta11 Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2009/CVE-2009-0545.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2009-0545.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> geeknik</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/20.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-20</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2009-0545" target="_blank" rel="noopener" class="nt-cve-link">CVE-2009-0545</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)zeroshell&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">ZeroShell 1.0beta11 and earlier via cgi-bin/kerbynet allows remote attackers to execute arbitrary commands through shell metacharacters in the type parameter in a NoAuthREQ x509List action.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability allows remote attackers to execute arbitrary code on the affected system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to a patched version of ZeroShell.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2009</span><span class="nt-tag">edb</span><span class="nt-tag">kerbynet</span><span class="nt-tag">rce</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">zeroshell</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.exploit-db.com/exploits/8023" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2009-0545" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="http://www.zeroshell.net/eng/announcements/" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="http://www.ikkisoft.com/stuff/LC-2009-01.txt" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="http://www.vupen.com/english/advisories/2009/0385" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="zeroshell panel - detect info identify web-based control panels zeroshell panel was detected. dhiyaneshdk discovery panel zeroshell cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">ZeroShell Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/zeroshell-login.yaml" target="_blank" rel="noopener" class="nt-source-link">zeroshell-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)zeroshell&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">ZeroShell panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">zeroshell</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="zeroshell 3.9.0 - remote command execution critical identify critical remote vulnerabilities zeroshell 3.9.0 is prone to a remote command execution vulnerability. specifically, this issue occurs because the web application mishandles a few http parameters. an unauthenticated attacker can exploit this issue by injecting os commands inside the vulnerable parameters. cve-2019-12725 dwisiswant0,akincibor cve cve2019 packetstorm rce vkev vuln zeroshell cwe-78" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Zeroshell 3.9.0 - Remote Command Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2019/CVE-2019-12725.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2019-12725.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dwisiswant0,akincibor</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/78.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-78</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2019-12725" target="_blank" rel="noopener" class="nt-cve-link">CVE-2019-12725</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)zeroshell&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web application mishandles a few HTTP parameters. An unauthenticated attacker can exploit this issue by injecting OS commands inside the vulnerable parameters.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability allows remote attackers to execute arbitrary commands on the target system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to 3.9.5. Be aware this product is no longer supported.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2019</span><span class="nt-tag">packetstorm</span><span class="nt-tag">rce</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">zeroshell</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.zeroshell.org/new-release-and-critical-vulnerability/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.tarlogic.com/advisories/zeroshell-rce-root.txt" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/X-C3LL/PoC-CVEs/blob/master/CVE-2019-12725/ZeroShell-RCE-EoP.py" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://zeroshell.org/blog/" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="http://packetstormsecurity.com/files/160211/ZeroShell-3.9.0-Remote-Command-Execution.html" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="zeroshell 3.9.3 - command injection critical identify critical remote vulnerabilities zeroshell 3.9.3 contains a command injection vulnerability in the /cgi-bin/kerbynet startsessionsubmit parameter that could allow an unauthenticated attacker to execute a system command by using shell metacharacters and the %0a character. cve-2020-29390 dhiyaneshdk cve cve2020 rce router vkev vuln zeroshell cwe-78" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Zeroshell 3.9.3 - Command Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2020/CVE-2020-29390.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2020-29390.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 16, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/78.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-78</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2020-29390" target="_blank" rel="noopener" class="nt-cve-link">CVE-2020-29390</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)zeroshell&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Zeroshell 3.9.3 contains a command injection vulnerability in the /cgi-bin/kerbynet StartSessionSubmit parameter that could allow an unauthenticated attacker to execute a system command by using shell metacharacters and the %0a character.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability allows remote attackers to execute arbitrary commands on the target system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to the latest version of Zeroshell or apply security patches provided by the vendor.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2020</span><span class="nt-tag">rce</span><span class="nt-tag">router</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">zeroshell</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://web.archive.org/web/20210303043709/https://blog.quake.so/post/zeroshell_linux_router_rce/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.exploit-db.com/exploits/41040" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2020-29390" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="zimaos - authentication bypass critical identify critical remote vulnerabilities zimaos &lt;= 1.5.0 contains a broken authentication caused by improper password validation for known system service accounts in the login function, letting attackers authenticate with any password for these accounts, exploit requires knowledge of common usernames. cve-2026-21891 dhiyaneshdk auth-bypass broken-auth cve cve2026 vkev zimaos cwe-287" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">ZimaOS - Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2026/CVE-2026-21891.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2026-21891.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Feb 12, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/287.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-287</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2026-21891" target="_blank" rel="noopener" class="nt-cve-link">CVE-2026-21891</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)ZimaOS&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">ZimaOS &lt;= 1.5.0 contains a broken authentication caused by improper password validation for known system service accounts in the login function, letting attackers authenticate with any password for these accounts, exploit requires knowledge of common usernames.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can gain authenticated access to system service accounts without valid passwords, potentially compromising the system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to a fixed version when available or apply patches to properly validate passwords for system service accounts.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">broken-auth</span><span class="nt-tag">cve</span><span class="nt-tag">cve2026</span><span class="nt-tag">vkev</span><span class="nt-tag">zimaos</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/IceWhaleTech/ZimaOS/security/advisories/GHSA-xj93-qw9p-jxq4" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21891" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="zimbra - cross-site scripting via ics files medium identify critical remote vulnerabilities detects zimbra collaboration suite versions vulnerable to cve-2025-27915, a stored xss vulnerability in the classic web client due to insufficient sanitization of html content in ics files. when a user views an email with a malicious ics entry, embedded javascript executes via an ontoggle event inside a details tag, allowing attackers to perform unauthorized actions like email redirection and data exfiltration. cve-2025-27915 snbig,ehsancreator,eliotworkspac-max cve cve2025 ics kev vkev xss zimbra cwe-79" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Zimbra - Cross-Site Scripting via ICS Files</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-27915.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-27915.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Snbig,EhsanCreator,eliotworkspac-max</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 13, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-79</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-27915" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-27915</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Zimbra Collaboration Suite&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detects Zimbra Collaboration Suite versions vulnerable to CVE-2025-27915, a stored XSS vulnerability in the Classic Web Client due to insufficient sanitization of HTML content in ICS files. When a user views an email with a malicious ICS entry, embedded JavaScript executes via an ontoggle event inside a details tag, allowing attackers to perform unauthorized actions like email redirection and data exfiltration.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Authenticated users viewing malicious ICS files can have JavaScript executed in their browser context through stored XSS, potentially leading to session hijacking and data exfiltration.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to Zimbra Collaboration Suite version 9.0.1, 10.0.13, or 10.1.5 or later that properly sanitizes HTML content in ICS files.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">ics</span><span class="nt-tag">kev</span><span class="nt-tag">vkev</span><span class="nt-tag">xss</span><span class="nt-tag">zimbra</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wiki.zimbra.com/wiki/Security_Center" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-27915" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="zimbra collaboration (zcs) - cross site scripting medium identify critical remote vulnerabilities a reflected cross-site scripting (xss) vulnerability in the /public/launchnewwindow.jsp component of zimbra collaboration (aka zcs) 9.0 allows unauthenticated attackers to execute arbitrary web script or html via request parameters. cve-2022-27926 rootxharsh,iamnoooob,pdresearch cve cve2022 kev vkev vuln xss zimbra cwe-79" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Zimbra Collaboration (ZCS) - Cross Site Scripting</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-27926.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-27926.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rootxharsh,iamnoooob,pdresearch</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-79</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-27926" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-27926</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1624375939&#34; || service[&#34;favicon.ico.image.mmh3&#34;] == &#34;475145467&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A reflected cross-site scripting (XSS) vulnerability in the /public/launchNewWindow.jsp component of Zimbra Collaboration (aka ZCS) 9.0 allows unauthenticated attackers to execute arbitrary web script or HTML via request parameters.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute arbitrary script code in the context of the victim&#39;s browser, potentially leading to session hijacking, defacement, or theft of sensitive information.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches or updates provided by Zimbra to fix the XSS vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">kev</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">xss</span><span class="nt-tag">zimbra</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-27926" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://wiki.zimbra.com/wiki/Security_Center" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://wiki.zimbra.com/wiki/Zimbra_Releases/9.0.0/P24" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/ARPSyndicate/cvemon" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="zimbra collaboration - cross-site scripting (xss) medium identify critical remote vulnerabilities an issue was discovered in zimbra collaboration (zcs) 9.0 and 10.0. a cross-site scripting (xss) vulnerability exists in the calendarinvite feature of the zimbra webmail classic user interface, because of improper input validation in the handling of the calendar header. an attacker can exploit this via an email message containing a crafted calendar header with an embedded xss payload. cve-2024-27443 rxerium cve cve2024 kev passive vkev xss zimbra cwe-79" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Zimbra Collaboration - Cross-Site Scripting (XSS)</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-27443.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-27443.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 9, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-79</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-27443" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-27443</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1624375939&#34; || service[&#34;http.body&#34;] matches &#34;(?i)zimbra collaboration suite web client&#34; || service[&#34;favicon.ico.image.mmh3&#34;] == &#34;475145467&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. A Cross-Site Scripting (XSS) vulnerability exists in the CalendarInvite feature of the Zimbra webmail classic user interface, because of improper input validation in the handling of the calendar header. An attacker can exploit this via an email message containing a crafted calendar header with an embedded XSS payload.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can execute arbitrary JavaScript via crafted calendar headers in emails, potentially stealing user credentials or session data.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update Zimbra Collaboration to version 9.0.0 P39 or 10.0.7 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">kev</span><span class="nt-tag">passive</span><span class="nt-tag">vkev</span><span class="nt-tag">xss</span><span class="nt-tag">zimbra</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wiki.zimbra.com/wiki/Zimbra_Releases/10.0.7#Security_Fixes" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://wiki.zimbra.com/wiki/Zimbra_Releases/9.0.0/P39#Security_Fixes" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-27443" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="zimbra collaboration - local file inclusion high identify critical remote vulnerabilities zimbra collaboration (zcs) 10.0 and 10.1 contain a local file inclusion caused by improper handling of user-supplied parameters in the restfilter servlet, letting unauthenticated remote attackers include arbitrary files from webroot, exploit requires crafted requests to /h/rest endpoint. cve-2025-68645 dhiyaneshdk,sirifu4k1 cve cve2025 zimbra zcs lfi vkev kev cwe-98" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Zimbra Collaboration - Local File Inclusion</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-68645.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-68645.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk,sirifu4k1</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 31, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/98.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-98</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-68645" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-68645</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;product&#34;] contains &#34;Zimbra:Collaboration&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Zimbra Collaboration (ZCS) 10.0 and 10.1 contain a local file inclusion caused by improper handling of user-supplied parameters in the RestFilter servlet, letting unauthenticated remote attackers include arbitrary files from WebRoot, exploit requires crafted requests to /h/rest endpoint.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated remote attackers can include arbitrary files from the WebRoot directory, potentially exposing sensitive information.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest version of Zimbra Collaboration.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">zimbra</span><span class="nt-tag">zcs</span><span class="nt-tag">lfi</span><span class="nt-tag">vkev</span><span class="nt-tag">kev</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://x.com/sirifu4k1/status/2006031417088639064" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://x.com/sirifu4k1/status/2007279822050078906?s=12&amp;amp;t=ovaWmJElNlGyzadE74ZOgQ" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68645" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="zimbra collaboration - unrestricted file upload critical identify critical remote vulnerabilities an issue was discovered in zimbra collaboration (zcs) 8.8.15 and 9.0. an attacker can upload arbitrary files through amavis via a cpio loophole (extraction to /opt/zimbra/jetty/webapps/zimbra/public) that can lead to incorrect access to any other user accounts. zimbra recommends pax over cpio. also, pax is in the prerequisites of zimbra on ubuntu; however, pax is no longer part of a default red hat installation after rhel 6 (or centos 6). once pax is installed, amavis automatically prefers it over cpio. cve-2022-41352 rxerium cve cve2022 file-upload kev passive vkev vuln zimbra cwe-22" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Zimbra Collaboration - Unrestricted File Upload</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-41352.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-41352.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 24, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-41352" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-41352</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1624375939&#34; || service[&#34;http.body&#34;] matches &#34;(?i)Zimbra Collaboration Suite Web Client&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through amavis via a cpio loophole (extraction to /opt/zimbra/jetty/webapps/zimbra/public) that can lead to incorrect access to any other user accounts. Zimbra recommends pax over cpio. Also, pax is in the prerequisites of Zimbra on Ubuntu; however, pax is no longer part of a default Red Hat installation after RHEL 6 (or CentOS 6). Once pax is installed, amavis automatically prefers it over cpio.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can upload arbitrary files through amavis via a cpio loophole that extracts to the webapps directory, potentially achieving remote code execution and unauthorized access to other user accounts in Zimbra Collaboration Suite.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Install pax package and ensure amavis is configured to use pax instead of cpio. Update to the latest patched version of Zimbra Collaboration Suite.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">file-upload</span><span class="nt-tag">kev</span><span class="nt-tag">passive</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">zimbra</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.secpod.com/blog/unpatched-rce-bug-in-zimbra-collaboration-suite-exploited-in-wild/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-41352" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="zimbra collaboration server 7.2.2/8.0.2 local file inclusion medium identify critical remote vulnerabilities a directory traversal vulnerability in /res/i18nmsg,ajxmsg,zmsg,zmmsg,ajxkeys,zmkeys,zdmsg,ajx%20templatemsg.js.zgz in zimbra 7.2.2 and 8.0.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the skin parameter. this can be leveraged to execute arbitrary code by obtaining ldap credentials and accessing the service/admin/soap api. cve-2013-7091 rubina119 cve cve2013 edb lfi packetstorm synacor vkev vuln zimbra cwe-22" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Zimbra Collaboration Server 7.2.2/8.0.2 Local File Inclusion</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2013/CVE-2013-7091.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2013-7091.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rubina119</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2013-7091" target="_blank" rel="noopener" class="nt-cve-link">CVE-2013-7091</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)zimbra collaboration suite&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A directory traversal vulnerability in /res/I18nMsg,AjxMsg,ZMsg,ZmMsg,AjxKeys,ZmKeys,ZdMsg,Ajx%20TemplateMsg.js.zgz in Zimbra 7.2.2 and 8.0.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the skin parameter. This can be leveraged to execute arbitrary code by obtaining LDAP credentials and accessing the service/admin/soap API.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to read sensitive files on the server, potentially leading to unauthorized access or information disclosure.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches or upgrade to a newer version of Zimbra Collaboration Server to mitigate the LFI vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2013</span><span class="nt-tag">edb</span><span class="nt-tag">lfi</span><span class="nt-tag">packetstorm</span><span class="nt-tag">synacor</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">zimbra</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2013-7091" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.exploit-db.com/exploits/30085" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.exploit-db.com/exploits/30472" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="http://www.exploit-db.com/exploits/30085" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="http://packetstormsecurity.com/files/124321" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="zimbra collaboration suite - memcached command injection high identify critical remote vulnerabilities zimbra collaboration suite versions 8.8.15 and 9.0 contain a memcached command injection vulnerability that allows an unauthenticated attacker to inject arbitrary memcache commands into a targeted instance, leading to cache poisoning and potential credential theft. cve-2022-27924 rxerium cve cve2022 injection kev passive vkev vuln zimbra" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Zimbra Collaboration Suite - Memcached Command Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-27924.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-27924.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 22, 2025</span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-27924" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-27924</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)zimbra collaboration suite&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Zimbra Collaboration Suite versions 8.8.15 and 9.0 contain a memcached command injection vulnerability that allows an unauthenticated attacker to inject arbitrary memcache commands into a targeted instance, leading to cache poisoning and potential credential theft.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation allows attackers to overwrite arbitrary cached entries and steal user credentials in cleartext without user interaction. With valid credentials, attackers can perform spear phishing, social engineering, and business email compromise attacks, or maintain persistent access via webshells.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to Zimbra Collaboration Suite version 8.8.15 Patch 31 or 9.0.0 Patch 24.1 or later. Implement multi-factor authentication to mitigate credential theft impact.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">injection</span><span class="nt-tag">kev</span><span class="nt-tag">passive</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">zimbra</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-27924" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="zimbra collaboration suite - ssrf high identify critical remote vulnerabilities zimbra collaboration suite before 8.6 patch 13, 8.7.x before 8.7.11 patch 10, and 8.8.x before 8.8.10 patch 7 or 8.8.x before 8.8.11 patch 3 allows ssrf via the proxyservlet component. cve-2019-9621 riteshs4hu collaboration-server cve cve2019 kev oast oob vkev vuln xxe zimbra cwe-918" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Zimbra Collaboration Suite - SSRF</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2019/CVE-2019-9621.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2019-9621.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> riteshs4hu</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 26, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/918.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-918</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2019-9621" target="_blank" rel="noopener" class="nt-cve-link">CVE-2019-9621</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Zimbra Collaboration Suite Web Client&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Zimbra Collaboration Suite before 8.6 patch 13, 8.7.x before 8.7.11 patch 10, and 8.8.x before 8.8.10 patch 7 or 8.8.x before 8.8.11 patch 3 allows SSRF via the ProxyServlet component.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can perform SSRF, potentially leading to internal network access or further exploitation.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest patched versions: 8.6 patch 13, 8.7.11 patch 10, 8.8.10 patch 7, or 8.8.11 patch 3 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">collaboration-server</span><span class="nt-tag">cve</span><span class="nt-tag">cve2019</span><span class="nt-tag">kev</span><span class="nt-tag">oast</span><span class="nt-tag">oob</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">xxe</span><span class="nt-tag">zimbra</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/zimbra_xxe_rce.rb" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/cve-2019-9621" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="http://packetstormsecurity.com/files/153190/Zimbra-XML-Injection-Server-Side-Request-Forgery.html" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://blog.tint0.com/2019/03/a-saga-of-code-executions-on-zimbra.html" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://bugzilla.zimbra.com/show_bug.cgi?id=109127" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="zimbra collaboration suite 8.8.15/9.0 - remote code execution critical identify critical remote vulnerabilities zimbra collaboration suite (zcs) 8.8.15 and 9.0 has mboximport functionality that receives a zip archive and extracts files from it. by bypassing authentication (i.e., not having an authtoken), an attacker can upload arbitrary files to the system, leading to directory traversal and remote code execution. note: this issue exists because of an incomplete fix for cve-2022-27925. cve-2022-37042 _0xf4n9x_,for3stco1d cve cve2022 kev rce unauth vkev vuln zimbra cwe-22" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Zimbra Collaboration Suite 8.8.15/9.0 - Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-37042.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-37042.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> _0xf4n9x_,For3stCo1d</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-37042" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-37042</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1624375939&#34; || service[&#34;favicon.ico.image.mmh3&#34;] == &#34;475145467&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. By bypassing authentication (i.e., not having an authtoken), an attacker can upload arbitrary files to the system, leading to directory traversal and remote code execution. NOTE: this issue exists because of an incomplete fix for CVE-2022-27925.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can bypass authentication and upload arbitrary files through the mboximport functionality, achieving directory traversal and remote code execution on Zimbra Collaboration Suite servers, potentially compromising email systems and sensitive communications.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches or upgrade to a non-vulnerable version of Zimbra Collaboration Suite.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">kev</span><span class="nt-tag">rce</span><span class="nt-tag">unauth</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">zimbra</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.volexity.com/blog/2022/08/10/mass-exploitation-of-unauthenticated-zimbra-rce-cve-2022-27925/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://blog.zimbra.com/2022/08/authentication-bypass-in-mailboximportservlet-vulnerability/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/vnhacker1337/CVE-2022-27925-PoC" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-37042" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://wiki.zimbra.com/wiki/Security_Center" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="zimbra collaboration suite &lt; 8.8.15 - improper encoding medium identify critical remote vulnerabilities an issue was discovered in the calendar feature in zimbra collaboration suite 8.8.x before 8.8.15 patch 30 (update 1), as exploited in the wild starting in december 2021. an attacker could place html containing executable javascript inside element attributes. this markup becomes unescaped, causing arbitrary markup to be injected into the document. cve-2022-24682 rxerium collaboration cve cve2022 kev passive vkev vuln xss zimbra cwe-116" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Zimbra Collaboration Suite &lt; 8.8.15 - Improper Encoding</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-24682.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-24682.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 9, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/116.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-116</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-24682" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-24682</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1624375939&#34; || service[&#34;http.body&#34;] matches &#34;(?i)Zimbra Collaboration Suite Web Client&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An issue was discovered in the Calendar feature in Zimbra Collaboration Suite 8.8.x before 8.8.15 patch 30 (update 1), as exploited in the wild starting in December 2021. An attacker could place HTML containing executable JavaScript inside element attributes. This markup becomes unescaped, causing arbitrary markup to be injected into the document.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can inject malicious JavaScript through the Calendar feature that executes in victims&#39; browsers, potentially stealing session tokens and accessing email communications of Zimbra users.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update Zimbra Collaboration Suite to version 8.8.15 patch 30 or later that properly escapes HTML in Calendar feature attributes.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">collaboration</span><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">kev</span><span class="nt-tag">passive</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">xss</span><span class="nt-tag">zimbra</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-24682" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-228a" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="zimbra collaboration suite login panel - detect info identify web-based control panels zimbra collaboration suite panel was detected. zimbra collaboration suite simplifies the communication environment, connects people over multiple channels, and provides a single place to manage collaboration and communication. powerexploit discovery panel synacor zimbra cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Zimbra Collaboration Suite Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/zimbra-web-login.yaml" target="_blank" rel="noopener" class="nt-source-link">zimbra-web-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> powerexploit</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)zimbra collaboration suite&#34;}) || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)zimbra web client sign in&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Zimbra Collaboration Suite panel was detected. Zimbra Collaboration Suite simplifies the communication environment, connects people over multiple channels, and provides a single place to manage collaboration and communication.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">synacor</span><span class="nt-tag">zimbra</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.zimbra.com/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="zimbra panel - detect info identify web-based control panels zimbra panel was detected. zimbra provides open source server and client software for messaging and collaboration. dhiyaneshdk,idealphase discovery edb panel synacor zimbra cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Zimbra Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/zimbra-web-client.yaml" target="_blank" rel="noopener" class="nt-source-link">zimbra-web-client.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDk,idealphase</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)zimbra collaboration suite&#34;}) || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)zimbra web client sign in&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Zimbra panel was detected. Zimbra provides open source server and client software for messaging and collaboration.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">edb</span><span class="nt-tag">panel</span><span class="nt-tag">synacor</span><span class="nt-tag">zimbra</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.exploit-db.com/ghdb/7409" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.zimbra.com/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="zipkin login panel - detect info identify web-based control panels zipkin login panel was detected. pdteam panel zipkin discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Zipkin Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/zipkin-exposure.yaml" target="_blank" rel="noopener" class="nt-source-link">zipkin-exposure.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pdteam</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)webpackJsonpzipkin-lens&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Zipkin login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">zipkin</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="zitadel - user registration bypass high identify critical remote vulnerabilities the open-source identity infrastructure software zitadel allows administrators to disable the user self-registration. due to a missing security check in versions prior to 2.64.0, 2.63.5, 2.62.7, 2.61.4, 2.60.4, 2.59.5, and 2.58.7, disabling the &#34;user registration allowed&#34; option only hid the registration button on the login page. users could bypass this restriction by directly accessing the registration url (/ui/login/loginname) and register a user that way. versions 2.64.0, 2.63.5, 2.62.7, 2.61.4, 2.60.4, 2.59.5, and 2.58.7 contain a patch. no known workarounds are available. cve-2024-49757 sujal tuladhar cve cve2024 register vuln zitadel cwe-287" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Zitadel - User Registration Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-49757.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-49757.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Sujal Tuladhar</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 28, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/287.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-287</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-49757" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-49757</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Zitadel&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The open-source identity infrastructure software Zitadel allows administrators to disable the user self-registration. Due to a missing security check in versions prior to 2.64.0, 2.63.5, 2.62.7, 2.61.4, 2.60.4, 2.59.5, and 2.58.7, disabling the &#34;User Registration allowed&#34; option only hid the registration button on the login page. Users could bypass this restriction by directly accessing the registration URL (/ui/login/loginname) and register a user that way. Versions 2.64.0, 2.63.5, 2.62.7, 2.61.4, 2.60.4, 2.59.5, and 2.58.7 contain a patch. No known workarounds are available.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated users can bypass the disabled user registration restriction and register accounts.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update Zitadel to version 2.64.0, 2.63.5, 2.62.7, 2.61.4, 2.60.4, 2.59.5, or 2.58.7 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">register</span><span class="nt-tag">vuln</span><span class="nt-tag">zitadel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/zitadel/zitadel/releases/tag/v2.62.7" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-49757" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="zoho manageengine - access control bypass critical identify critical remote vulnerabilities zoho manageengine access manager plus before 4302, password manager pro before 12007, and pam360 before 5401 are vulnerable to access-control bypass on a few rest api urls (for ssoutaction. sslaction. licensemgr. getproductdetails. getdashboard. fetchevents. and synchronize) via the ../restapi substring. cve-2022-29081 0xanis auth-bypass cve cve2022 manageengine vkev zoho cwe-22" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Zoho ManageEngine - Access Control Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-29081.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-29081.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0xanis</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Nov 19, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-29081" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-29081</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)manageengine&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Zoho ManageEngine Access Manager Plus before 4302, Password Manager Pro before 12007, and PAM360 before 5401 are vulnerable to access-control bypass on a few Rest API URLs (for SSOutAction. SSLAction. LicenseMgr. GetProductDetails. GetDashboard. FetchEvents. and Synchronize) via the ../RestAPI substring.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can bypass access controls on REST API endpoints, potentially leading to unauthorized data access or manipulation.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest versions of Access Manager Plus, Password Manager Pro, and PAM360 that address this issue.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">manageengine</span><span class="nt-tag">vkev</span><span class="nt-tag">zoho</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.tenable.com/security/research/tra-2022-14" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.manageengine.com/privileged-session-management/advisory/cve-2022-29081.html" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-29081" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="zoho manageengine - internal hostname disclosure medium identify critical remote vulnerabilities zoho manageengine desktop central before 10.1.2137.8 exposes the installed server name to anyone. the internal hostname can be discovered by reading http redirect responses. cve-2022-23779 cckuailong cve cve2022 exposure vuln zoho zohocorp cwe-200" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Zoho ManageEngine - Internal Hostname Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-23779.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-23779.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> cckuailong</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-23779" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-23779</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)manageengine desktop central 10&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Zoho ManageEngine Desktop Central before 10.1.2137.8 exposes the installed server name to anyone. The internal hostname can be discovered by reading HTTP redirect responses.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker could use the disclosed internal hostnames to plan targeted attacks, gain unauthorized access, or perform reconnaissance on the internal network.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patch or update provided by Zoho ManageEngine to fix the internal hostname disclosure vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">exposure</span><span class="nt-tag">vuln</span><span class="nt-tag">zoho</span><span class="nt-tag">zohocorp</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.manageengine.com/products/desktop-central/cve-2022-23779.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/fbusr/CVE-2022-23779" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-23779" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/soosmile/POC" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/zecool/cve" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="zoho manageengine - remote code execution critical identify critical remote vulnerabilities zoho manageengine password manager pro, pam 360, and access manager plus are susceptible to unauthenticated remote code execution via xml-rpc. an attacker can execute malware, obtain sensitive information, modify data, and/or gain full control over a compromised system without entering necessary credentials. cve-2022-35405 viniciuspereiras,true13 cve cve2022 deserialization kev msf passwordmanager rce unauth vkev vuln zoho zohocorp cwe-502" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Zoho ManageEngine - Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-35405.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-35405.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> viniciuspereiras,true13</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/502.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-502</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-35405" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-35405</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)manageengine&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Zoho ManageEngine Password Manager Pro, PAM 360, and Access Manager Plus are susceptible to unauthenticated remote code execution via XML-RPC. An attacker can execute malware, obtain sensitive information, modify data, and/or gain full control over a compromised system without entering necessary credentials.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patch or update provided by Zoho ManageEngine to fix the vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">deserialization</span><span class="nt-tag">kev</span><span class="nt-tag">msf</span><span class="nt-tag">passwordmanager</span><span class="nt-tag">rce</span><span class="nt-tag">unauth</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">zoho</span><span class="nt-tag">zohocorp</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/http/zoho_password_manager_pro_xml_rpc_rce.rb" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://xz.aliyun.com/t/11578" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.manageengine.com/products/passwordmanagerpro/advisory/cve-2022-35405.html" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://www.bigous.me/2022/09/06/CVE-2022-35405.html" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-35405" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="zoho manageengine desktop central - remote code execution critical identify critical remote vulnerabilities zoho manageengine desktop central contains an authentication bypass vulnerability that could allow an attacker to execute arbitrary code in the desktop central msp server. cve-2021-44515 adam crosser cve cve2021 kev manageengine rce vkev vuln zoho zohocorp cwe-287" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Zoho ManageEngine Desktop Central - Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2021/CVE-2021-44515.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2021-44515.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Adam Crosser</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/287.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-287</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2021-44515" target="_blank" rel="noopener" class="nt-cve-link">CVE-2021-44515</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)manageengine desktop central 10&#34;}) || service[&#34;http.body&#34;] matches &#34;(?i)manageengine desktop central 10&#34; || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)manageengine desktop central&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Zoho ManageEngine Desktop Central contains an authentication bypass vulnerability that could allow an attacker to execute arbitrary code in the Desktop Central MSP server.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">For Enterprise builds 10.1.2127.17 and earlier, upgrade to 10.1.2127.18. For Enterprise builds 10.1.2128.0 through 10.1.2137.2, upgrade to 10.1.2137.3. For MSP builds 10.1.2127.17 and earlier, upgrade to 10.1.2127.18. For MSP builds 10.1.2128.0 through 10.1.2137.2, upgrade to 10.1.2137.3.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2021</span><span class="nt-tag">kev</span><span class="nt-tag">manageengine</span><span class="nt-tag">rce</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">zoho</span><span class="nt-tag">zohocorp</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.cisa.gov/uscert/ncas/current-activity/2021/12/10/cisa-adds-13-known-exploited-vulnerabilities-catalog" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://srcincite.io/blog/2022/01/20/zohowned-a-critical-authentication-bypass-on-zoho-manageengine-desktop-central.html" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://attackerkb.com/topics/rJw4DFI2RQ/cve-2021-44515/rapid7-analysis" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://pitstop.manageengine.com/portal/en/community/topic/an-authentication-bypass-vulnerability-identified-and-fixed-in-desktop-central-and-desktop-central-msp" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2021-44515" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="zoho manageengine network configuration manager panel - detect info identify web-based control panels zoho manageengine network configuration manager was detected. righettod discovery manageengine panel zoho zohocorp cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Zoho ManageEngine Network Configuration Manager Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/zoho/manageengine-network-config.yaml" target="_blank" rel="noopener" class="nt-source-link">manageengine-network-config.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)network configuration manager&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">ZOHO ManageEngine Network Configuration Manager was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">manageengine</span><span class="nt-tag">panel</span><span class="nt-tag">zoho</span><span class="nt-tag">zohocorp</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="zoho manageengine opmanager - sql injection high identify critical remote vulnerabilities zoho manageengine opmanager before 12.3 build 123196 does not require authentication for /oputilsservlet requests, as demonstrated by a /oputilsservlet?action=getapikey request that can be leveraged against firewall analyzer to add an admin user via /api/json/v2/admin/adduser or conduct a sql injection attack via the /api/json/device/setmanaged name parameter. cve-2018-17283 dhiyaneshdk cve cve2018 opmanager oputils sqli time-based-sqli vkev vuln zoho cwe-89" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">Zoho ManageEngine OpManager - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2018/CVE-2018-17283.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2018-17283.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 19, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2018-17283" target="_blank" rel="noopener" class="nt-cve-link">CVE-2018-17283</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)OpManager&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Zoho ManageEngine OpManager before 12.3 Build 123196 does not require authentication for /oputilsServlet requests, as demonstrated by a /oputilsServlet?action=getAPIKey request that can be leveraged against Firewall Analyzer to add an admin user via /api/json/v2/admin/addUser or conduct a SQL Injection attack via the /api/json/device/setManaged name parameter.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can execute SQL injection attacks to access or modify database contents, add administrator users, or extract sensitive information including credentials.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to ManageEngine OpManager version 12.3 Build 123196 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2018</span><span class="nt-tag">opmanager</span><span class="nt-tag">oputils</span><span class="nt-tag">sqli</span><span class="nt-tag">time-based-sqli</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">zoho</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/x-f1v3/forcve/issues/4" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2018-17283" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="zoho manageengine opmanager &lt; 12.5.329 - remote code execution critical identify critical remote vulnerabilities zoho manageengine opmanager before 12.5.329 contains a remote code execution caused by a general bypass in the deserialization class, letting unauthenticated attackers execute arbitrary code, exploit requires no authentication cve-2021-3287 theamanrawat cve cve2021 deserialization opmanager passive rce vkev cwe-502" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Zoho ManageEngine OpManager &lt; 12.5.329 - Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2021/CVE-2021-3287.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2021-3287.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> theamanrawat</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 21, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/502.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-502</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2021-3287" target="_blank" rel="noopener" class="nt-cve-link">CVE-2021-3287</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)opmanager plus&#34;}) || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)opmanager&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Zoho ManageEngine OpManager before 12.5.329 contains a remote code execution caused by a general bypass in the deserialization class, letting unauthenticated attackers execute arbitrary code, exploit requires no authentication</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can execute arbitrary code remotely, leading to full system compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to version 12.5.329 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2021</span><span class="nt-tag">deserialization</span><span class="nt-tag">opmanager</span><span class="nt-tag">passive</span><span class="nt-tag">rce</span><span class="nt-tag">vkev</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="http://packetstormsecurity.com/files/164231/ManageEngine-OpManager-SumPDU-Java-Deserialization.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2021-3287" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="zoho manageengine servicedesk plus - authentication bypass critical identify critical remote vulnerabilities zoho manageengine servicedesk plus before 11302 is vulnerable to authentication bypass that allows a few rest-api urls without authentication. cve-2021-37415 daffainfo,jjcho auth-bypass cve cve2021 kev manageenggine manageengine_servicedesk_plus vkev vuln zohocorp cwe-306" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Zoho ManageEngine ServiceDesk Plus - Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2021/CVE-2021-37415.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2021-37415.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> daffainfo,jjcho</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 9, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/306.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-306</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2021-37415" target="_blank" rel="noopener" class="nt-cve-link">CVE-2021-37415</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)manageengine servicedesk plus&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs without authentication.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can access sensitive functionalities and data without authentication, potentially leading to data disclosure or unauthorized actions.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to version 11302 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2021</span><span class="nt-tag">kev</span><span class="nt-tag">manageenggine</span><span class="nt-tag">manageengine_servicedesk_plus</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">zohocorp</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.manageengine.com/products/service-desk/on-premises/readme.html#11302" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2021-37415" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="zoho manageengine servicedesk plus - remote code execution critical identify critical remote vulnerabilities zoho manageengine servicedesk plus before 11306, servicedesk plus msp before 10530, and supportcenter plus before 11014 are vulnerable to unauthenticated remote code execution. cve-2021-44077 adam crosser,gy741 cve cve2021 kev manageengine msf rce vkev vuln zoho zohocorp cwe-306" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Zoho ManageEngine ServiceDesk Plus - Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2021/CVE-2021-44077.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2021-44077.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Adam Crosser,gy741</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/306.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-306</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2021-44077" target="_blank" rel="noopener" class="nt-cve-link">CVE-2021-44077</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)manageengine servicedesk plus&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthenticated remote code execution.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patch or upgrade to a patched version of Zoho ManageEngine ServiceDesk Plus.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2021</span><span class="nt-tag">kev</span><span class="nt-tag">manageengine</span><span class="nt-tag">msf</span><span class="nt-tag">rce</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">zoho</span><span class="nt-tag">zohocorp</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.cisa.gov/uscert/ncas/alerts/aa21-336a" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://unit42.paloaltonetworks.com/tiltedtemple-manageengine-servicedesk-plus/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/horizon3ai/CVE-2021-44077" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/http/manageengine_servicedesk_plus_cve_2021_44077.rb" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2021-44077" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="zoneminder - sql injection critical identify critical remote vulnerabilities zoneminder is a free, open source closed-circuit television software application. zoneminder is affected by a time-based sql injection vulnerability. this vulnerability is fixed in 1.36.34 and 1.37.61. cve-2024-43360 s4e-io cve cve2024 sqli vkev vuln zoneminder cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">ZoneMinder - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-43360.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-43360.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> s4e-io</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 10, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-43360" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-43360</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-1218152116&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">ZoneMinder is a free, open source closed-circuit television software application. ZoneMinder is affected by a time-based SQL Injection vulnerability. This vulnerability is fixed in 1.36.34 and 1.37.61.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can exploit time-based SQL injection to extract sensitive database information from ZoneMinder.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update ZoneMinder to version 1.36.34 or 1.37.61 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">sqli</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">zoneminder</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/ZoneMinder/zoneminder/security/advisories/GHSA-9cmr-7437-v9fj" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://medium.com/techpioneers/cve-2024-43360-in-depth-analysis-and-implications-for-security-75ceccc746b4" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-43360" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="zoneminder login panel - detect info identify web-based control panels zoneminder panel was detected. princechaddha panel zoneminder discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">ZoneMinder Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/zoneminder-login.yaml" target="_blank" rel="noopener" class="nt-source-link">zoneminder-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> princechaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)zm - login&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">ZoneMinder panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">zoneminder</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="zoraxy login panel - detect info identify web-based control panels zoraxy products was detected. righettod panel zoraxy login discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Zoraxy Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/zoraxy-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">zoraxy-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 1, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Login \\| Zoraxy&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Zoraxy products was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">zoraxy</span><span class="nt-tag">login</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/tobychui/zoraxy" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://zoraxy.aroz.org/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="zuul panel - detect info identify web-based control panels zuul panel was detected. yuzhe-zhang-0 cicd discovery oss panel zuul cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Zuul Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/zuul-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">zuul-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Yuzhe-zhang-0</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-1127895693&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">ZUUL panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cicd</span><span class="nt-tag">discovery</span><span class="nt-tag">oss</span><span class="nt-tag">panel</span><span class="nt-tag">zuul</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://opendev.org/zuul/zuul" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="zyxel router login panel - detect info identify web-based control panels zyxel router login panel was detected. arafatansari discovery iot panel router zyxel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">ZyXel Router Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/zyxel-router-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">zyxel-router-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> arafatansari</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)web-based configurator&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">ZyXel Router login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">iot</span><span class="nt-tag">panel</span><span class="nt-tag">router</span><span class="nt-tag">zyxel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="zyxel usg - hardcoded credentials critical identify critical remote vulnerabilities a hardcoded credential vulnerability was identified in the &#39;zyfwp&#39; user account in some zyxel firewalls and ap controllers. the account was designed to deliver automatic firmware updates to connected access points through ftp. cve-2020-29583 canberbamber bypass cve cve2020 ftp-backdoor kev vkev vuln zyxel cwe-522" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">ZyXel USG - Hardcoded Credentials</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2020/CVE-2020-29583.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2020-29583.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> canberbamber</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 25, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/522.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-522</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2020-29583" target="_blank" rel="noopener" class="nt-cve-link">CVE-2020-29583</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)usg flex 100&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A hardcoded credential vulnerability was identified in the &#39;zyfwp&#39; user account in some Zyxel firewalls and AP controllers. The account was designed to deliver automatic firmware updates to connected access points through FTP.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can exploit this vulnerability to gain unauthorized access to the affected device, potentially leading to further compromise of the network.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update the firmware of the ZyXel USG device to the latest version, which addresses the hardcoded credentials issue.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2020</span><span class="nt-tag">ftp-backdoor</span><span class="nt-tag">kev</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">zyxel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.zyxel.com/support/CVE-2020-29583.shtml" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://support.zyxel.eu/hc/en-us/articles/360018524720-Zyxel-security-advisory-for-hardcoded-credential-vulnerability-CVE-2020-29583" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2020-29583" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://www.eyecontrol.nl/blog/undocumented-user-account-in-zyxel-products.html" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="http://ftp.zyxel.com/USG40/firmware/USG40_4.60(AALA.1)C0_2.pdf" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="zyxel - authentication bypass critical identify critical remote vulnerabilities an authentication bypass vulnerability in the cgi program of zyxel usg/zywall series firmware versions 4.20 through 4.70, usg flex series firmware versions 4.50 through 5.20, atp series firmware versions 4.32 through 5.20, vpn series firmware versions 4.30 through 5.20, and nsg series firmware versions v1.20 through v1.33 patch 4, which could allow an attacker to bypass the web authentication and obtain administrative access of the device. cve-2022-0342 sleepingbag945,powerexploit auth-bypass cve cve2022 router vkev vuln zyxel cwe-287" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Zyxel - Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-0342.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-0342.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> SleepingBag945,Powerexploit</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 15, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/287.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-287</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-0342" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-0342</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/2fa-access\\.cgi&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An authentication bypass vulnerability in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.20 through 4.70, USG FLEX series firmware versions 4.50 through 5.20, ATP series firmware versions 4.32 through 5.20, VPN series firmware versions 4.30 through 5.20, and NSG series firmware versions V1.20 through V1.33 Patch 4, which could allow an attacker to bypass the web authentication and obtain administrative access of the device.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can bypass web authentication and obtain administrative access to Zyxel devices, potentially gaining complete control over firewalls and network security configurations.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply security updates provided by Zyxel for affected USG/ZyWALL, USG FLEX, ATP, VPN, and NSG series devices.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">router</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">zyxel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/gobysec/GobyVuls/blob/master/CVE-2022-0342.md" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-0342" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.zyxel.com/support/Zyxel-security-advisory-for-authentication-bypass-vulnerability-of-firewalls.shtml" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/f1tao/awesome-iot-security-resource" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/murchie85/twitterCyberMonitor" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="zyxel firewall panel - detect info identify web-based control panels zyxel firewall panel was detected. 0x240x23elu discovery firewall panel xyxel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Zyxel Firewall Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/zyxel/zyxel-firewall-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">zyxel-firewall-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x240x23elu</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-440644339&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Zyxel Firewall panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">firewall</span><span class="nt-tag">panel</span><span class="nt-tag">xyxel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="zyxel nas firmware 5.21- remote code execution critical identify critical remote vulnerabilities multiple zyxel network-attached storage (nas) devices running firmware version 5.21 contain a pre-authentication command injection vulnerability, which may allow a remote, unauthenticated attacker to execute arbitrary code on a vulnerable device. zyxel nas devices achieve authentication by using the weblogin.cgi cgi executable. this program fails to properly sanitize the username parameter that is passed to it. if the username parameter contains certain characters, it can allow command injection with the privileges of the web server that runs on the zyxel device. although the web server does not run as the root user, zyyxel devices include a setuid utility that can be leveraged to run any command with root privileges. as such, it should be assumed that exploitation of this vulnerability can lead to remote code execution with root privileges. by sending a specially-crafted http post or get request to a vulnerable zyyxel device, a remote, unauthenticated attacker may be able to execute arbitrary code on the device. this may happen by directly connecting to a device if it is directly exposed to an attacker.   however, there are ways to trigger such crafted requests even if an attacker does not have direct connectivity to a vulnerable devices. for example, simply visiting a website can result in the compromise of any zyyxel device that is reachable from the client system. affected products include: nas326 before firmware v5.21(aazf.7)c0 nas520 before firmware v5.21(aasz.3)c0 nas540 before firmware v5.21(aatb.4)c0 nas542 before firmware v5.21(abag.4)c0 zyyxel has made firmware updates available for nas326, nas520, nas540, and nas542 devices. affected models that are end-of-support: nsa210, nsa220, nsa220+, nsa221, nsa310, nsa310s, nsa320, nsa320s, nsa325 and nsa325v2. cve-2020-9054 dhiyaneshdk cve cve2020 injection kev rce vkev vuln zyxel cwe-78" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Zyxel NAS Firmware 5.21- Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2020/CVE-2020-9054.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2020-9054.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/78.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-78</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2020-9054" target="_blank" rel="noopener" class="nt-cve-link">CVE-2020-9054</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;943925975&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Multiple Zyxel network-attached storage (NAS) devices running firmware version 5.21 contain a pre-authentication command injection vulnerability, which may allow a remote, unauthenticated attacker to execute arbitrary code on a vulnerable device. Zyxel NAS devices achieve authentication by using the weblogin.cgi CGI executable. This program fails to properly sanitize the username parameter that is passed to it. If the username parameter contains certain characters, it can allow command injection with the privileges of the web server that runs on the Zyxel device. Although the web server does not run as the root user, Zyyxel devices include a setuid utility that can be leveraged to run any command with root privileges. As such, it should be assumed that exploitation of this vulnerability can lead to remote code execution with root privileges. By sending a specially-crafted HTTP POST or GET request to a vulnerable Zyyxel device, a remote, unauthenticated attacker may be able to execute arbitrary code on the device. This may happen by directly connecting to a device if it is directly exposed to an attacker.   However, there are ways to trigger such crafted requests even if an attacker does not have direct connectivity to a vulnerable devices. For example, simply visiting a website can result in the compromise of any Zyyxel device that is reachable from the client system. Affected products include: NAS326 before firmware V5.21(AAZF.7)C0 NAS520 before firmware V5.21(AASZ.3)C0 NAS540 before firmware V5.21(AATB.4)C0 NAS542 before firmware V5.21(ABAG.4)C0 Zyyxel has made firmware updates available for NAS326, NAS520, NAS540, and NAS542 devices. Affected models that are end-of-support: NSA210, NSA220, NSA220+, NSA221, NSA310, NSA310S, NSA320, NSA320S, NSA325 and NSA325v2.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected device.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest firmware update provided by Zyxel to mitigate this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2020</span><span class="nt-tag">injection</span><span class="nt-tag">kev</span><span class="nt-tag">rce</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">zyxel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://krebsonsecurity.com/2020/02/zyxel-fixes-0day-in-network-storage-devices/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.zyxel.com/support/remote-code-execution-vulnerability-of-NAS-products.shtml" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2020-9054" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://kb.cert.org/vuls/id/498544/" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://cwe.mitre.org/data/definitions/78.html" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="zyxel vmg1312-b10d - login detection info identify web-based control panels  princechaddha discovery modem panel router tech zyxel" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Zyxel VMG1312-B10D - Login Detection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/zyxel/zyxel-vmg1312b10d-login.yaml" target="_blank" rel="noopener" class="nt-source-link">zyxel-vmg1312b10d-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> princechaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)vmg1312-b10d&#34;</code></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">modem</span><span class="nt-tag">panel</span><span class="nt-tag">router</span><span class="nt-tag">tech</span><span class="nt-tag">zyxel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="zyxel vsg1432-b101 - login detection info identify web-based control panels  princechaddha tech zyxel modem router panel discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">Zyxel VSG1432-B101 - Login Detection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/zyxel/zyxel-vsg1432b101-login.yaml" target="_blank" rel="noopener" class="nt-source-link">zyxel-vsg1432b101-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> princechaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)VSG1432-B101&#34;</code></div>
  <div class="nt-tags"><span class="nt-tag">tech</span><span class="nt-tag">zyxel</span><span class="nt-tag">modem</span><span class="nt-tag">router</span><span class="nt-tag">panel</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="zyxel zywall uag/usg - account creation access critical identify critical remote vulnerabilities zyxel uag, usg, and zywall devices allows a remote attacker to generate guest accounts by directly accessing the account generator via the &#34;free time&#34; component. this can lead to unauthorized network access or dos attacks. cve-2019-12583 n-thumann,daffainfo cve cve2019 vuln xss zywall zyxel cwe-425" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">Zyxel ZyWall UAG/USG - Account Creation Access</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2019/CVE-2019-12583.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2019-12583.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> n-thumann,daffainfo</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/425.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-425</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2019-12583" target="_blank" rel="noopener" class="nt-cve-link">CVE-2019-12583</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)zywall&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Zyxel UAG, USG, and ZyWall devices allows a remote attacker to generate guest accounts by directly accessing the account generator via the &#34;Free Time&#34; component. This can lead to unauthorized network access or DoS attacks.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">An attacker can exploit this vulnerability to create unauthorized accounts with administrative privileges.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest firmware update provided by Zyxel to fix the vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2019</span><span class="nt-tag">vuln</span><span class="nt-tag">xss</span><span class="nt-tag">zywall</span><span class="nt-tag">zyxel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.zyxel.com/support/vulnerabilities-related-to-the-Free-Time-feature.shtml" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://n-thumann.de/blog/zyxel-gateways-missing-access-control-in-account-generator-xss/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2019-12583" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/ARPSyndicate/kenzer-templates" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/StarCrossPortal/scalpel" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="aapanel linux panel - detect info identify web-based control panels detected aapanel linux management panel login interface. th3l0newolf aapanel detect linux panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">aaPanel Linux Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/aapanel-linux-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">aapanel-linux-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Th3l0newolf</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 27, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)aaPanel Linux panel&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detected aaPanel Linux management panel login interface.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">aapanel</span><span class="nt-tag">detect</span><span class="nt-tag">linux</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="aircube dashboard login panel - detect info identify web-based control panels aircube dashboard login panel was detected. theamanrawat aircube discovery panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">airCube Dashboard Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/aircube-dashboard-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">aircube-dashboard-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> theamanrawat</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)AirCube Dashboard&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">airCube Dashboard login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">aircube</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="aircube login - detect info identify web-based control panels aircube login panel was detected. dhiyaneshdk aircube discovery panel ubiquiti cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">airCube Login - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/aircube-login.yaml" target="_blank" rel="noopener" class="nt-source-link">aircube-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1249285083&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">airCube login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">aircube</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">ubiquiti</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="big-agi panel - detect info identify web-based control panels big-agi is a generative ai suite for power users, teams, and developers. it provides
an ai chat interface with support for multiple llm providers rxerium ai big-agi chat detect discovery llm panel" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">big-AGI Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/big-agi-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">big-agi-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 27, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;big-AGI&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">big-AGI is a generative AI suite for power users, teams, and developers. It provides
an AI chat interface with support for multiple LLM providers</div></div></div>
  <div class="nt-tags"><span class="nt-tag">ai</span><span class="nt-tag">big-agi</span><span class="nt-tag">chat</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">llm</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/enricoros/big-AGI" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://big-agi.com" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="bloofoxcms - default login high identify default logins in web-based control panels bloofoxcms contains default credentials. an attacker can obtain access to user accounts and access sensitive information, modify data, and/or execute unauthorized operations. theamanrawat bloofox cms default-login vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">bloofoxCMS - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/bloofoxcms-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">bloofoxcms-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> theamanrawat</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 7, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Powered by bloofoxCMS&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">bloofoxCMS contains default credentials. An attacker can obtain access to user accounts and access sensitive information, modify data, and/or execute unauthorized operations.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">bloofox</span><span class="nt-tag">cms</span><span class="nt-tag">default-login</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.bloofox.com/automated_setup.113.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.bloofox.com" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="cpanel &amp; whm - authentication bypass via session-file crlf injection critical identify critical remote vulnerabilities cpanel and whm versions prior to 11.110.0.97, 11.118.0.63, 11.126.0.54, 11.132.0.29, 11.134.0.20, and 11.136.0.5 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel. watchtowr,hadrian.io,dhiyaneshdk auth-bypass cpanel crlf cve cve2026 kev vkev whm" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">cPanel &amp; WHM - Authentication Bypass via Session-File CRLF Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2026/CVE-2026-41940.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2026-41940.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> watchtowr,hadrian.io,DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 4, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)(?:cPanel|WHM) Login&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">cPanel and WHM versions prior to 11.110.0.97, 11.118.0.63, 11.126.0.54, 11.132.0.29, 11.134.0.20, and 11.136.0.5 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated remote attackers can gain unauthorized access to the control panel, compromising system security.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to version 11.110.0.97, 11.118.0.63, 11.126.0.54, 11.132.0.29, 11.134.0.20, 11.136.0.5 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">cpanel</span><span class="nt-tag">crlf</span><span class="nt-tag">cve</span><span class="nt-tag">cve2026</span><span class="nt-tag">kev</span><span class="nt-tag">vkev</span><span class="nt-tag">whm</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://support.cpanel.net/hc/en-us/articles/40073787579671-cPanel-WHM-Security-Update-04-28-2026" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://labs.watchtowr.com/the-internet-is-falling-down-falling-down-falling-down-cpanel-whm-authentication-bypass-cve-2026-41940/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/watchtowrlabs/watchTowr-vs-cPanel-WHM-AuthBypass-to-RCE.py" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://hadrian.io/blog/cve-2026-41940-a-critical-authentication-bypass-in-cpanel" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41940" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="cpanel api codes panel - detect info identify web-based control panels cpanel api codes panel was detected. dhiyaneshdk cpanel discovery panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">cPanel API Codes Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/cpanel-api-codes.yaml" target="_blank" rel="noopener" class="nt-source-link">cpanel-api-codes.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)cpanel - api codes&#34;}) || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)cpanel&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">cPanel API Codes panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cpanel</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="cgit &lt; 1.2.1 - directory traversal high identify critical remote vulnerabilities cgit &lt; 1.2.1 via cgit_clone_objects has a directory traversal vulnerability when `enable-http-clone=1` is not turned off, as demonstrated by a cgit/cgit.cgi/git/objects/?path=../ request. cve-2018-14912 0x_akoko cgit cgit_project cve cve2018 lfi vkev vuln cwe-22" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">cgit &lt; 1.2.1 - Directory Traversal</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2018/CVE-2018-14912.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2018-14912.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_Akoko</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2018-14912" target="_blank" rel="noopener" class="nt-cve-link">CVE-2018-14912</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)git repository browser&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">cGit &lt; 1.2.1 via cgit_clone_objects has a directory traversal vulnerability when `enable-http-clone=1` is not turned off, as demonstrated by a cgit/cgit.cgi/git/objects/?path=../ request.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can access arbitrary files on the server through path traversal in cgit when HTTP clone functionality is enabled, potentially exposing sensitive repository data, source code, configuration files, and credentials.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade cgit to version 1.2.1 or later to mitigate the vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cgit</span><span class="nt-tag">cgit_project</span><span class="nt-tag">cve</span><span class="nt-tag">cve2018</span><span class="nt-tag">lfi</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://cxsecurity.com/issue/WLB-2018080034" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2018-14912" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://lists.zx2c4.com/pipermail/cgit/2018-August/004176.html" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://bugs.chromium.org/p/project-zero/issues/detail?id=1627" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://lists.debian.org/debian-lts-announce/2018/08/msg00005.html" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="corebos panel - detect info identify web-based control panels corebos panel was detected. arafatansari panel corebos discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">coreBOS Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/corebos-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">corebos-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> arafatansari</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)corebos&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">coreBOS panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">corebos</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="dbt docs panel - detect info identify web-based control panels dbt docs panel was detected. johnk3r panel dbt discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">dbt Docs Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/dbt-docs-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">dbt-docs-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> johnk3r</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 21, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)dbt Docs&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">dbt Docs panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">dbt</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="dotadmin login panel- detect info identify web-based control panels dotadmin login panel was detected. impramodsargar panel dotcms cms discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">dotAdmin Login Panel- Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/dotcms-admin-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">dotcms-admin-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> impramodsargar</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)dotcms&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">dotAdmin login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">dotcms</span><span class="nt-tag">cms</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="draw.io flowchart maker panel - detect info identify web-based control panels draw.io flowchart maker panel was detected. princechaddha diagrams discovery drawio oss panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">draw.io Flowchart Maker Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/drawio-flowchartmaker-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">drawio-flowchartmaker-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> princechaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)flowchart maker&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">draw.io Flowchart Maker panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">diagrams</span><span class="nt-tag">discovery</span><span class="nt-tag">drawio</span><span class="nt-tag">oss</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/jgraph/drawio" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="earcu panel - detect info identify web-based control panels earcu was detected. righettod panel earcu detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">eArcu Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/earcu-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">earcu-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 25, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)&#39;content=\&#34;eArcu&#39;&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">eArcu was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">earcu</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.earcu.com/products" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="emerge e3 1.00-06 - local file inclusion high identify critical remote vulnerabilities linear emerge e3-series devices are vulnerable to local file inclusion. cve-2019-7254 0x_akoko cve cve2019 edb emerge lfi nortekcontrol packetstorm vkev vuln cwe-22" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">eMerge E3 1.00-06 - Local File Inclusion</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2019/CVE-2019-7254.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2019-7254.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_Akoko</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2019-7254" target="_blank" rel="noopener" class="nt-cve-link">CVE-2019-7254</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)emerge&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Linear eMerge E3-Series devices are vulnerable to local file inclusion.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability can lead to unauthorized access to sensitive information, remote code execution, and potential compromise of the affected system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patch or update to a non-vulnerable version of eMerge E3.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2019</span><span class="nt-tag">edb</span><span class="nt-tag">emerge</span><span class="nt-tag">lfi</span><span class="nt-tag">nortekcontrol</span><span class="nt-tag">packetstorm</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.exploit-db.com/exploits/47616" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://applied-risk.com/labs/advisories" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.applied-risk.com/resources/ar-2019-005" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="http://packetstormsecurity.com/files/155252/Linear-eMerge-E3-1.00-06-Directory-Traversal.html" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2019-7254" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="emerge e3 1.00-06 - remote code execution critical identify critical remote vulnerabilities linear emerge e3-series devices are susceptible to remote code execution vulnerabilities. cve-2019-7256 pikpikcu cve cve2019 edb emerge kev nortekcontrol rce vkev vuln cwe-78" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">eMerge E3 1.00-06 - Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2019/CVE-2019-7256.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2019-7256.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pikpikcu</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/78.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-78</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2019-7256" target="_blank" rel="noopener" class="nt-cve-link">CVE-2019-7256</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)emerge&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Linear eMerge E3-Series devices are susceptible to remote code execution vulnerabilities.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patch or update to a non-vulnerable version of eMerge E3.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2019</span><span class="nt-tag">edb</span><span class="nt-tag">emerge</span><span class="nt-tag">kev</span><span class="nt-tag">nortekcontrol</span><span class="nt-tag">rce</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.exploit-db.com/exploits/47619" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="http://linear-solutions.com/nsc_family/e3-series/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2019-7256" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://applied-risk.com/labs/advisories" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://www.applied-risk.com/resources/ar-2019-005" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="emessage login panel - detect info identify web-based control panels emessage login panel was detected. ffffffff0x panel emessage discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">eMessage Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/emessage-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">emessage-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ffffffff0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)emessage&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">eMessage login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">emessage</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="ez publish login panel - detect info identify web-based control panels ez publish login panel was detected. ritikchaddha discovery ez panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">eZ Publish Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/ez-publish-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">ez-publish-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)eZ Publish&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">eZ Publish login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">ez</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="eyoucms v.1.6.5 - cross-site scripting medium identify critical remote vulnerabilities cross site scripting (xss) vulnerability in the func parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted url. cve-2024-22927 ritikchaddha cms cve cve2024 eyoucms vkev vuln xss cwe-79" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">eyoucms v.1.6.5 - Cross-Site Scripting</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-22927.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-22927.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 6, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-79</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-22927" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-22927</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)eyoucms&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Cross Site Scripting (XSS) vulnerability in the func parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted URL.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Allows attackers to execute malicious scripts on the victim&#39;s browser.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade eyoucms to version 1.6.6 or later to fix the XSS vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cms</span><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">eyoucms</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">xss</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/weng-xianhu/eyoucms/issues/57" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-22927" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="iclock automatic data master server admin panel - detect info identify web-based control panels an iclock automatic data master server admin login panel was detected. defr0ggy panel iclock login admin discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">iClock Automatic Data Master Server Admin Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/iclock-admin-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">iclock-admin-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> deFr0ggy</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 14, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)iClock Automatic&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An iClock Automatic Data Master Server Admin login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">iclock</span><span class="nt-tag">login</span><span class="nt-tag">admin</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="isams panel - detect info identify web-based control panels isams was detected. righettod panel isams login discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">iSAMS Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/isams-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">isams-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 26, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-81573405&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">iSAMS was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">isams</span><span class="nt-tag">login</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.isams.com/platform/the-platform" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="ispy 7.2.2.0 - authentication bypass critical identify critical remote vulnerabilities ispy 7.2.2.0 contains an authentication bypass vulnerability. an attacker can craft a url and possibly obtain sensitive information, modify data, and/or execute unauthorized operations. cve-2022-29775 arafatansari auth-bypass cve cve2022 ispy ispyconnect vuln cwe-287" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">iSpy 7.2.2.0 - Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-29775.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-29775.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> arafatansari</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/287.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-287</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-29775" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-29775</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)ispy is running&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">iSpy 7.2.2.0 contains an authentication bypass vulnerability. An attacker can craft a URL and possibly obtain sensitive information, modify data, and/or execute unauthorized operations.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability can lead to unauthorized access to sensitive information and potential compromise of the system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to the latest version of iSpy (7.2.2.1 or higher) which includes a fix for the authentication bypass vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">ispy</span><span class="nt-tag">ispyconnect</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://gist.github.com/securylight/79f673aa3a453c80c0e78f356a8f650b" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/securylight/CVES_write_ups/blob/main/iSpy_connect.pdf" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=2022-29775" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-29775" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/securylight/CVES_write_ups" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="itop - user enumeration via rest endpoint medium identify critical remote vulnerabilities from the webservices/rest.php file, several operations are accessible from an unauthenticated user. one of them is `do_reset_pwd`, allowing to reset a user password. this feature can be abused to perform user enumeration when a non-existent user is provided. cve-2024-51739 dhiyaneshdk cve cve2024 enum itop unauth vuln cwe-200" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">iTop - User Enumeration via REST Endpoint</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-51739.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-51739.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 23, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-51739" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-51739</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i) itop login&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">From the webservices/rest.php file, several operations are accessible from an unauthenticated user. One of them is `do_reset_pwd`, allowing to reset a user password. This feature can be abused to perform user enumeration when a non-existent user is provided.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can exploit this vulnerability to compromise system security.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply security patches to address CVE-2024-51739.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">enum</span><span class="nt-tag">itop</span><span class="nt-tag">unauth</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.synacktiv.com/en/advisories/multiple-vulnerabilities-on-itop" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/Combodo/iTop/security/advisories/GHSA-2hmf-p27w-phf9" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-51739" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="itop hub connector - information disclosure medium identify critical remote vulnerabilities combodo itop is a simple, web based it service management tool. server, os, dbms, php, and itop info (name, version and parameters) can be read by anyone having access to itop uri. this issue has been patched in versions 2.7.11, 3.0.5, 3.1.2, and 3.2.0. cve-2024-32870 dhiyaneshdk cve cve2024 disclosure exposure itop unauth vkev vuln cwe-200" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">iTop Hub Connector - Information Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-32870.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-32870.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 23, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-32870" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-32870</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)iTop login&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Combodo iTop is a simple, web based IT Service Management tool. Server, OS, DBMS, PHP, and iTop info (name, version and parameters) can be read by anyone having access to iTop URI. This issue has been patched in versions 2.7.11, 3.0.5, 3.1.2, and 3.2.0.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can access sensitive server, database, and iTop configuration information.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update iTop to version 2.7.11, 3.0.5, 3.1.2, or 3.2.0 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">disclosure</span><span class="nt-tag">exposure</span><span class="nt-tag">itop</span><span class="nt-tag">unauth</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.synacktiv.com/en/advisories/multiple-vulnerabilities-on-itop" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/Combodo/iTop/security/advisories/GHSA-rfjh-2f5x-qxmx" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-32870" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="ixbus login panel - detect info identify web-based control panels ixbus login panel was detected. podalirius panel ixbusweb cms discovery cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">iXBus Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/ixbus/ixbusweb-version.yaml" target="_blank" rel="noopener" class="nt-source-link">ixbusweb-version.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Podalirius</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)iXBus&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">iXBus login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">ixbusweb</span><span class="nt-tag">cms</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="idccms v1.60 - cross-site scripting medium identify critical remote vulnerabilities idccms v1.60 is vulnerable to reflected cross-site scripting (xss) via the idname parameter in read.php. unsanitized user input is reflected in the response, allowing arbitrary javascript execution. cve-2024-11587 ritikchaddha cve cve2024 idccms vkev vuln xss cwe-79" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">idcCMS V1.60 - Cross-Site Scripting</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-11587.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-11587.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 16, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-79</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-11587" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-11587</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)idcCMS&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">idcCMS V1.60 is vulnerable to reflected cross-site scripting (XSS) via the idName parameter in read.php. Unsanitized user input is reflected in the response, allowing arbitrary JavaScript execution.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this XSS vulnerability allows attackers to execute arbitrary JavaScript code in victims&#39; browsers, potentially leading to session hijacking, credential theft, or other malicious activities.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update idcCMS to the latest version. Implement proper input validation and output encoding for all user-supplied data, especially the idName parameter in read.php.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">idccms</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">xss</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/Hebing123/cve/issues/75" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-11587" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="iptime a2004 - unauthorized access medium identify critical remote vulnerabilities an access control issue exists in the component /login/hostinfo2.cgi of iptime a2004 v12.17.0 that allows attackers to obtain sensitive information without authentication. the vulnerability allows unauthenticated access to device settings and configuration information. cve-2024-54764 ritikchaddha cve cve2024 exposure iptime router unauth vkev vuln cwe-284" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">ipTIME A2004 - Unauthorized Access</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-54764.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-54764.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 11, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/284.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-284</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-54764" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-54764</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)ipTIME&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An access control issue exists in the component /login/hostinfo2.cgi of ipTIME A2004 v12.17.0 that allows attackers to obtain sensitive information without authentication. The vulnerability allows unauthenticated access to device settings and configuration information.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can access sensitive device settings and configuration information through the hostinfo2.cgi endpoint.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update ipTIME A2004 router to a version later than 12.17.0 that addresses the unauthorized access vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">exposure</span><span class="nt-tag">iptime</span><span class="nt-tag">router</span><span class="nt-tag">unauth</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/Shuanunio/CVE_Requests/blob/main/ipTIME/A2004/ipTIME_A2004_unauthorized_access_vulnerability_second.md" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-54764" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="iptime a2004 - unauthorized access medium identify critical remote vulnerabilities an access control issue in the component /login/hostinfo.cgi of iptime a2004 v12.17.0 allows attackers to obtain sensitive information without authentication. cve-2024-54763 ritikchaddha cve cve2024 exposure iptime router unauth vkev vuln cwe-284" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">ipTIME A2004 - Unauthorized Access</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-54763.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-54763.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 11, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/284.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-284</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-54763" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-54763</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)ipTIME&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An access control issue in the component /login/hostinfo.cgi of ipTIME A2004 v12.17.0 allows attackers to obtain sensitive information without authentication.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can access sensitive device configuration information through the hostinfo.cgi endpoint without authentication.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update ipTIME A2004 router to a version later than 12.17.0 that addresses the unauthorized access vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">exposure</span><span class="nt-tag">iptime</span><span class="nt-tag">router</span><span class="nt-tag">unauth</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/Shuanunio/CVE_Requests/blob/main/ipTIME/A2004/ipTIME_A2004_unauthorized_access_vulnerability_first.md" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-54763" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="kkfileview panel - detect info identify web-based control panels kkfileview panel was detected. arafatansari discovery kkfileview panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">kkFileView Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/kkfileview-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">kkfileview-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> arafatansari</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)kkFileView&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">kkFileView panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">kkfileview</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="mtheme unus &lt; 2.3 - directory traversal high identify critical remote vulnerabilities the mtheme-unus theme for wordpress, prior to version 2.3, contained a directory traversal flaw that let attackers access arbitrary files. this was possible by exploiting the files parameter in css/css.php with .. sequences. cve-2015-9406 pussycat0x,dhiyaneshdk cve cve2015 lfi mtheme-unus vkev vuln wordpress wp wp-theme wpscan cwe-22" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">mTheme Unus &lt; 2.3 - Directory Traversal</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2015/CVE-2015-9406.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2015-9406.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x,dhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 24, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2015-9406" target="_blank" rel="noopener" class="nt-cve-link">CVE-2015-9406</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)wp-content/themes/mTheme-Unus/&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The mTheme-Unus theme for WordPress, prior to version 2.3, contained a directory traversal flaw that let attackers access arbitrary files. This was possible by exploiting the files parameter in css/css.php with .. sequences.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can read sensitive files including database credentials and configuration files, potentially leading to full site compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to 2.3 or later version</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2015</span><span class="nt-tag">lfi</span><span class="nt-tag">mtheme-unus</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-theme</span><span class="nt-tag">wpscan</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://wpscan.com/vulnerability/d54b6b63-f280-412e-8c8f-17186727ac36/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://wpscan.com/vulnerability/bc036ee3-9648-49db-ae52-3a58fdeb82eb/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://wpvulndb.com/vulnerabilities/9890" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://packetstormsecurity.com/files/133778/" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="macos server panel - detect info identify web-based control panels  dhiyaneshdk panel login macos-server detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">macOS Server Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/macos-server-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">macos-server-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 8, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)macOS Server&#34;})</code></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">login</span><span class="nt-tag">macos-server</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="mantisbt - anonymous login medium identify default logins in web-based control panels mantisbt anonymous login were discovered. pussycat0x default-logins anonymous mantisbt default-login vuln" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">mantisbt - Anonymous Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/mantisbt/mantisbt-anonymous-login.yaml" target="_blank" rel="noopener" class="nt-source-link">mantisbt-anonymous-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 21, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;662709064&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">mantisbt Anonymous login were discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-logins</span><span class="nt-tag">anonymous</span><span class="nt-tag">mantisbt</span><span class="nt-tag">default-login</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="modoboa  2.0.4 - admin takeover critical identify critical remote vulnerabilities authentication bypass by primary weakness in github repository modoboa/modoboa prior to 2.0.4. cve-2023-0777 r3y3r53 cve cve2023 default-login huntr modoboa packetstorm vuln cwe-305,nvd-cwe-other" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">modoboa  2.0.4 - Admin TakeOver</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-0777.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-0777.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> r3Y3r53</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 17, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/305,NVD-CWE-OTHER.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-305,NVD-CWE-OTHER</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-0777" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-0777</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)modoboa&#34; || service[&#34;favicon.ico.image.mmh3&#34;] == &#34;1949005079&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Authentication Bypass by Primary Weakness in GitHub repository modoboa/modoboa prior to 2.0.4.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can exploit authentication bypass using default credentials to gain administrator access and completely compromise Modoboa email server installations.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">update to version 2.0.4</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">default-login</span><span class="nt-tag">huntr</span><span class="nt-tag">modoboa</span><span class="nt-tag">packetstorm</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://huntr.dev/bounties/a17e7a9f-0fee-4130-a522-5a0466fc17c7/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="http://packetstormsecurity.com/files/171744/modoboa-2.0.4-Admin-Takeover.html" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/modoboa/modoboa/commit/47d17ac6643f870719691073956a26e4be0a4806" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/7h3h4ckv157/7h3h4ckv157" target="_blank" rel="noopener" class="nt-ref-link">[4]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="mylittleadmin login panel - detect info identify web-based control panels mylittleadmin login panel was detected. nullfuzz discovery login mylittleadmin panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">myLittleAdmin Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/mylittleadmin-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">mylittleadmin-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> nullfuzz</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)myLittleAdmin&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">myLittleAdmin login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">login</span><span class="nt-tag">mylittleadmin</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="http://mylittleadmin.com/en/overview.aspx" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="mylittlebackup panel - detect info identify web-based control panels mylittlebackup panel was detected. nullfuzz discovery mylittlebackup panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">myLittleBackup Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/mylittlebackup-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">mylittlebackup-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> nullfuzz</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)myLittleBackup&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">myLittleBackup panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">mylittlebackup</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="http://www.mylittlebackup.com/mlb/en/overview.aspx" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="n8n panel - detect info identify web-based control panels the worlds most popular workflow automation platform for technical teams userdehghani,rxerium panel n8n login detect discovery ai" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">n8n Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/n8n-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">n8n-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> userdehghani,rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 13, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;-831756631&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The worlds most popular workflow automation platform for technical teams</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">n8n</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">ai</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://n8n.io/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="n8n webhooks - remote code execution critical identify critical remote vulnerabilities n8n is an open source workflow automation platform. versions starting with 1.65.0 and below 1.121.0 enable an attacker to access files on the underlying server through execution of certain form-based workflows. a vulnerable workflow could grant access to an unauthenticated remote attacker, resulting in exposure of sensitive information stored on the system and may enable further compromise depending on deployment configuration and workflow usage. this issue is fixed in version 1.121.0. cve-2026-21858 rxerium cve cve2026 n8n passive rce vkev workflow cwe-20" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">n8n Webhooks - Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2026/CVE-2026-21858.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2026-21858.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> rxerium</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 8, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/20.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-20</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2026-21858" target="_blank" rel="noopener" class="nt-cve-link">CVE-2026-21858</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches `(?i)^n8n[.]io\s*-\s*Workflow\s+Automation`})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">n8n is an open source workflow automation platform. Versions starting with 1.65.0 and below 1.121.0 enable an attacker to access files on the underlying server through execution of certain form-based workflows. A vulnerable workflow could grant access to an unauthenticated remote attacker, resulting in exposure of sensitive information stored on the system and may enable further compromise depending on deployment configuration and workflow usage. This issue is fixed in version 1.121.0.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated remote attackers can access sensitive files, potentially leading to information disclosure and further system compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to version 1.121.0 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2026</span><span class="nt-tag">n8n</span><span class="nt-tag">passive</span><span class="nt-tag">rce</span><span class="nt-tag">vkev</span><span class="nt-tag">workflow</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://thehackernews.com/2026/01/critical-n8n-vulnerability-cvss-100.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21858" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="nmon panel - detect info identify web-based control panels nmon login interface was discovered. th3l0newolf detect login nmon panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">nMon Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/nmon-login-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">nmon-login-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Th3l0newolf</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 27, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;^nMon&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">nMon login interface was discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">detect</span><span class="nt-tag">login</span><span class="nt-tag">nmon</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="ngsurvey login panel - detect info identify web-based control panels ngsurvey products was detected. righettod panel ngsurvey login detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">ngSurvey Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/ngsurvey-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">ngsurvey-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jun 5, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)ngSurvey enterprise survey software&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">ngSurvey products was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">ngsurvey</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.ngsurvey.com/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="nginxwebui ≤ 3.5.0 - remote command execution critical identify critical remote vulnerabilities there is a command execution vulnerability in the nginxwebui backend. after logging in to the backend, the attacker can execute any command to obtain server permissions. ritikchaddha nginx nginxwebui webui rce vuln" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">nginxWebUI ≤ 3.5.0 - Remote Command Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/vulnerabilities/other/nginx-webui-rce.yaml" target="_blank" rel="noopener" class="nt-source-link">nginx-webui-rce.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 19, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)nginxwebui&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">There is a command execution vulnerability in the nginxWebUI backend. After logging in to the backend, the attacker can execute any command to obtain server permissions.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">nginx</span><span class="nt-tag">nginxwebui</span><span class="nt-tag">webui</span><span class="nt-tag">rce</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://forum.butian.net/article/243" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="nginxwebui ≤ 3.5.0 runcmd - remote command execution critical identify critical remote vulnerabilities nginxwebui’s runcmd feature and is caused by incomplete validation of user input. attackers can exploit the vulnerability by crafting malicious data to execute arbitrary commands on a vulnerable server without authorization. dhiyaneshdk nginx nginxwebui rce vuln" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">nginxWebUI ≤ 3.5.0 runCmd - Remote Command Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/vulnerabilities/other/nginxwebui-runcmd-rce.yaml" target="_blank" rel="noopener" class="nt-source-link">nginxwebui-runcmd-rce.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 27, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)nginxWebUI&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">nginxWebUI’s runCmd feature and is caused by incomplete validation of user input. Attackers can exploit the vulnerability by crafting malicious data to execute arbitrary commands on a vulnerable server without authorization.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">nginx</span><span class="nt-tag">nginxwebui</span><span class="nt-tag">rce</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/qingchenhh/qc_poc/blob/main/Goby/nginxWebUI_runCmd_rce.go" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.ctfiot.com/124166.html" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.sangfor.com/farsight-labs-threat-intelligence/cybersecurity/nginxwebui-runcmd-remote-command-execution-vulnerability" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="novnc login panel - detect info identify web-based control panels novnc login panel was detected. tess discovery novnc panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">noVNC Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/novnc-login-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">novnc-login-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> tess</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)noVNC&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">noVNC login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">novnc</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="nostromo 1.9.6 - remote code execution critical identify critical remote vulnerabilities nostromo nhttpd through 1.9.6 allows an attacker to achieve remote code execution via  directory traversal in the function http_verify. cve-2019-16278 pikpikcu cve cve2019 edb kev nazgul packetstorm rce vkev vuln cwe-22" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">nostromo 1.9.6 - Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2019/CVE-2019-16278.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2019-16278.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pikpikcu</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2019-16278" target="_blank" rel="noopener" class="nt-cve-link">CVE-2019-16278</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.head.server&#34;] matches &#34;(?i)^nostromo&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">nostromo nhttpd through 1.9.6 allows an attacker to achieve remote code execution via  directory traversal in the function http_verify.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability allows an attacker to execute arbitrary code on the target system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to a patched version of nostromo web server (1.9.7 or later) or apply the vendor-supplied patch.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2019</span><span class="nt-tag">edb</span><span class="nt-tag">kev</span><span class="nt-tag">nazgul</span><span class="nt-tag">packetstorm</span><span class="nt-tag">rce</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://packetstormsecurity.com/files/155802/nostromo-1.9.6-Remote-Code-Execution.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.exploit-db.com/raw/47837" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2019-16278" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="http://www.nazgul.ch/dev/nostromo_cl.txt" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="http://packetstormsecurity.com/files/155045/Nostromo-1.9.6-Directory-Traversal-Remote-Command-Execution.html" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="ntopng - default login high identify default logins in web-based control panels detected the ntopng network traffic monitoring tool was found to be using default credentials (admin:admin). an attacker could have gained full administrative access to network traffic data, flow analysis, and system configuration. 0x_akoko ntopng default-login auth vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">ntopng - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/ntopng-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">ntopng-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_Akoko</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Mar 24, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;product&#34;] contains &#34;ntop:ntopng&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detected the ntopng network traffic monitoring tool was found to be using default credentials (admin:admin). An attacker could have gained full administrative access to network traffic data, flow analysis, and system configuration.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">ntopng</span><span class="nt-tag">default-login</span><span class="nt-tag">auth</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.ntop.org/guides/ntopng/faq.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.ntop.org/guides/ntopng/api/rest/api_v2.html" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="opensis classic v9.1 - sql injection critical identify critical remote vulnerabilities sql injection vulnerability exists in os4ed opensis-classic version 9.1, specifically in the resetuserinfo.php file. the vulnerability is due to improper input validation of the $username_stn_id parameter, which can be manipulated by an attacker to inject arbitrary sql commands. cve-2024-51211 haliteroglu cve cve2024 opensis sqli time-based-sqli vkev vuln cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">openSIS Classic v9.1 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-51211.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-51211.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Haliteroglu</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 27, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-51211" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-51211</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)openSIS&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">SQL injection vulnerability exists in OS4ED openSIS-Classic Version 9.1, specifically in the resetuserinfo.php file. The vulnerability is due to improper input validation of the $username_stn_id parameter, which can be manipulated by an attacker to inject arbitrary SQL commands.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can exploit this vulnerability to compromise system security and integrity.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches and updates to address this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">opensis</span><span class="nt-tag">sqli</span><span class="nt-tag">time-based-sqli</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/kutsa1/My-CVE/tree/main/CVE-2024-51211" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-51211" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="opensis v9.0 - path traversal high identify critical remote vulnerabilities a path traversal vulnerability exists in opensis classic community edition v9.0 via the &#39;filename&#39; parameter in downloadwindow.php. an unauthenticated remote attacker can exploit this to read arbitrary files on the server by manipulating file paths. cve-2023-38879 haliteroglu cve cve2023 lfi opensis vuln cwe-22" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">openSIS v9.0 - Path Traversal</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-38879.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-38879.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> haliteroglu</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 27, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-38879" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-38879</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)openSIS&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A path traversal vulnerability exists in openSIS Classic Community Edition v9.0 via the &#39;filename&#39; parameter in DownloadWindow.php. An unauthenticated remote attacker can exploit this to read arbitrary files on the server by manipulating file paths.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can read arbitrary files from the server by manipulating the filename parameter in DownloadWindow.php, potentially exposing student records, staff information, and database credentials.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update openSIS to a version newer than 9.0 that validates file paths in DownloadWindow.php and restricts file access to authorized directories only.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">lfi</span><span class="nt-tag">opensis</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/dub-flow/vulnerability-research/tree/main/CVE-2023-38879" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-38879" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="osticket installer panel - detect critical identify web-based control panels osticket installer panel was detected. ritikchaddha discovery install osticket panel cwe-284" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">osTicket Installer Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/osticket/osticket-install.yaml" target="_blank" rel="noopener" class="nt-source-link">osticket-install.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/284.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-284</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)osticket installer&#34;}) || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)osticket&#34;}) || service[&#34;http.body&#34;] matches &#34;(?i)powered by osticket&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">osTicket installer panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">install</span><span class="nt-tag">osticket</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="osticket login panel - detect info identify web-based control panels osticket login panel was detected. ritikchaddha discovery osticket panel cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">osTicket Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/osticket-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">osticket-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)powered by osticket&#34; || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)osticket&#34;}) || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)osticket installer&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">osTicket login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">osticket</span><span class="nt-tag">panel</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="owncloud guests - user enumeration medium identify critical remote vulnerabilities owncloud guests before 0.12.5 contains an unauthenticated user enumeration vulnerability caused by insufficient validation of the token in showpasswordform at /apps/guests/register/{email}/{token}, letting unauthenticated attackers enumerate valid guest users, exploit requires no authentication. cve-2025-59716 dhiyaneshdk cve cve2025 enum guests owncloud user-enum vkev cwe-203" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">ownCloud Guests - User Enumeration</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-59716.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-59716.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 8, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/203.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-203</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-59716" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-59716</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)ownCloud&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">ownCloud Guests before 0.12.5 contains an unauthenticated user enumeration vulnerability caused by insufficient validation of the token in showPasswordForm at /apps/guests/register/{email}/{token}, letting unauthenticated attackers enumerate valid guest users, exploit requires no authentication.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can enumerate valid guest users, potentially aiding further targeted attacks.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to version 0.12.5 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">enum</span><span class="nt-tag">guests</span><span class="nt-tag">owncloud</span><span class="nt-tag">user-enum</span><span class="nt-tag">vkev</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-59716" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://gist.github.com/thesmartshadow/64ae0449e909174d0479a4f23657147f" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://marketplace.owncloud.com/apps/guests" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="pcoweb - default-login high identify default logins in web-based control panels  ritikchaddha default-login misconfig pcoweb vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">pCOWeb - Default-Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/pcoweb/pcoweb-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">pcoweb-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 24, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;pCOWeb&#34;})</code></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">misconfig</span><span class="nt-tag">pcoweb</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://docs.librenms.org/Support/Device-Notes/Carel-pCOweb-Devices/#:~:text=Accessing%20the%20pCOWeb%20card,-Log%20on%20to&amp;text=The%20default%20username%20and%20password%20is%20admin%2Ffadmin%20." target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="pcoweb panel - detect info identify web-based control panels  ritikchaddha pcoweb panel login detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">pCOWeb Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/pcoweb-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">pcoweb-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 23, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)pCOWeb&#34;})</code></div>
  <div class="nt-tags"><span class="nt-tag">pcoweb</span><span class="nt-tag">panel</span><span class="nt-tag">login</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://docs.librenms.org/Support/Device-Notes/Carel-pCOweb-Devices/#:~:text=Accessing%20the%20pCOWeb%20card,-Log%20on%20to&amp;text=The%20default%20username%20and%20password%20is%20admin%2Ffadmin%20." target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="prest &lt; 1.5.4 - sql injection via authentication bypass critical identify critical remote vulnerabilities an authentication bypass vulnerability was introduced by changing the jwt whitelist configuration to use a regex pattern, allowing unauthorized access to any path containing /auth and leading to sql injection. mihail8531,iamnoooob,rootxharsh,pdresearch sqli prest auth-bypass sqli vuln" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">pREST &lt; 1.5.4 - SQL Injection Via Authentication Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/vulnerabilities/other/prest-sqli-auth-bypass.yaml" target="_blank" rel="noopener" class="nt-source-link">prest-sqli-auth-bypass.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> mihail8531,iamnoooob,rootxharsh,pdresearch</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Aug 28, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)authorization token is empty&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An authentication bypass vulnerability was introduced by changing the JWT whitelist configuration to use a regex pattern, allowing unauthorized access to any path containing /auth and leading to SQL Injection.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">sqli</span><span class="nt-tag">prest</span><span class="nt-tag">auth-bypass</span><span class="nt-tag">sqli</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/advisories/GHSA-wm25-j4gw-6vr3" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="pfsense - default admin credentials high identify default logins in web-based control panels detected pfsense firewall was found using default administrator credentials (admin:pfsense). an attacker could have gained full administrative access to manage firewall rules, routing, and network configuration. 0x_akoko default-login firewall network pfsense" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">pfSense - Default Admin Credentials</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/pfsense-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">pfsense-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_Akoko</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 8, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;product&#34;] contains &#34;pfSense:pfSense&#34; || service[&#34;product&#34;] contains &#34;Netgate:pfSense&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detected pfSense firewall was found using default administrator credentials (admin:pfsense). An attacker could have gained full administrative access to manage firewall rules, routing, and network configuration.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">firewall</span><span class="nt-tag">network</span><span class="nt-tag">pfsense</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://docs.netgate.com/pfsense/en/latest/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="pfsense login panel - detect info identify web-based control panels pfsense login panel was detected. idealphase discovery panel pfsense cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">pfSense Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/pfsense-login.yaml" target="_blank" rel="noopener" class="nt-source-link">pfsense-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> idealphase</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)pfsense - login&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">pfSense login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">pfsense</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.pfsense.org/download/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.pfsense.org/getting-started/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="pgadmin &lt; 6.17 - unauthenticated remote code execution critical identify critical remote vulnerabilities pgadmin prior to 6.17 contains an insecure http api caused by improper access control, letting unauthenticated users execute arbitrary external utilities via path manipulation, exploit requires no authentication. cve-2022-4223 0x_akoko cve cve2022 pgadmin rce unauth cwe-862,cwe-94" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">pgAdmin &lt; 6.17 - Unauthenticated Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2022/CVE-2022-4223.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2022-4223.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_Akoko</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 22, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/862,CWE-94.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-862,CWE-94</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2022-4223" target="_blank" rel="noopener" class="nt-cve-link">CVE-2022-4223</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)pgAdmin&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">pgAdmin prior to 6.17 contains an insecure HTTP API caused by improper access control, letting unauthenticated users execute arbitrary external utilities via path manipulation, exploit requires no authentication.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can execute arbitrary external utilities on the server, potentially leading to remote code execution or system compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to version 6.17 or later to fix the security issue.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2022</span><span class="nt-tag">pgadmin</span><span class="nt-tag">rce</span><span class="nt-tag">unauth</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/advisories/GHSA-3v6v-2x6p-32mc" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-4223" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="phpcollab login panel - detect info identify web-based control panels phpcollab login panel was detected. pikpikcu discovery login panel phpcollab cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">phpCollab Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/phpcollab-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">phpcollab-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pikpikcu</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)phpcollab&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">phpCollab login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">login</span><span class="nt-tag">panel</span><span class="nt-tag">phpcollab</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="phpldapadmin &lt;= 1.2.3 - reflected xss medium identify critical remote vulnerabilities phpldapadmin &lt;= 1.2.3 contains a reflected cross-site scripting caused by unsanitized input in htdocs/entry_chooser.php via the form, element, rdn, or container parameter, letting attackers execute malicious scripts in victim browsers, exploit requires sending crafted input. cve-2017-11107 0x_akoko cve cve2017 phpldapadmin unauth xss cwe-79" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">phpLDAPadmin &lt;= 1.2.3 - Reflected XSS</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2017/CVE-2017-11107.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2017-11107.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_Akoko</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 23, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-79</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2017-11107" target="_blank" rel="noopener" class="nt-cve-link">CVE-2017-11107</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;product&#34;] contains &#34;phpLDAPadmin Project:phpLDAPadmin&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">phpLDAPadmin &lt;= 1.2.3 contains a reflected cross-site scripting caused by unsanitized input in htdocs/entry_chooser.php via the form, element, rdn, or container parameter, letting attackers execute malicious scripts in victim browsers, exploit requires sending crafted input.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can execute malicious scripts in victim browsers, potentially leading to session hijacking or defacement.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to the latest version of phpLDAPadmin where the vulnerability is fixed.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2017</span><span class="nt-tag">phpldapadmin</span><span class="nt-tag">unauth</span><span class="nt-tag">xss</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://nvd.nist.gov/vuln/detail/CVE-2017-11107" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/leenooks/phpLDAPadmin/issues/50" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=867719" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="phpminiadmin login panel - detect info identify web-based control panels phpminiadmin login panel was detected. nullfuzz discovery panel phpminiadmin cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">phpMiniAdmin Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/phpminiadmin-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">phpminiadmin-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> nullfuzz</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)phpMiniAdmin&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">phpMiniAdmin login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">phpminiadmin</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/osalabs/phpminiadmin" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="phpmyadmin - default login high identify default logins in web-based control panels phpmyadmin contains a default login vulnerability. an attacker can obtain access to user accounts and access sensitive information, modify data, and/or execute unauthorized operations. natto97,notwhy default-login phpmyadmin vuln cwe-522" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">phpMyAdmin - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/phpmyadmin/phpmyadmin-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">phpmyadmin-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Natto97,notwhy</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/522.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-522</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;phpMyAdmin&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">phpMyAdmin contains a default login vulnerability. An attacker can obtain access to user accounts and access sensitive information, modify data, and/or execute unauthorized operations.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">phpmyadmin</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.phpmyadmin.net" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="phpmyadmin - full path disclosure low identify critical remote vulnerabilities detected potential full path disclosure (fpd) via directly accessible phpmyadmin files that may throw php errors revealing filesystem paths when error display is enabled. dhiyaneshdk exposure fpd phpmyadmin php" data-nt-sev="low">
  <div class="nt-card-header">
    <div class="nt-title">phpMyAdmin - Full Path Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/misconfiguration/phpmyadmin/phpmyadmin-fpd.yaml" target="_blank" rel="noopener" class="nt-source-link">phpmyadmin-fpd.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 1, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;product&#34;] contains &#34;phpMyAdmin:phpMyAdmin&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detected potential Full Path Disclosure (FPD) via directly accessible phpMyAdmin files that may throw PHP errors revealing filesystem paths when error display is enabled.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">exposure</span><span class="nt-tag">fpd</span><span class="nt-tag">phpmyadmin</span><span class="nt-tag">php</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="phpmyadmin panel - detect info identify web-based control panels phpmyadmin panel was detected. pdteam,righettod detect discovery panel phpmyadmin cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">phpMyAdmin Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/phpmyadmin-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">phpmyadmin-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pdteam,righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)phpmyadmin&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">phpMyAdmin panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">phpmyadmin</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="phpmyfaq - configuration backup disclosure high identify critical remote vulnerabilities phpmyfaq &lt;= 4.0.16 contains an information disclosure vulnerability caused by unauthenticated access to configuration backup zip generation and download, letting remote attackers access sensitive configuration files, exploit requires no authentication. cve-2025-69200 louay-075 backup cve cve2025 exposure phpmyfaq vkev cwe-202" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">phpMyFAQ - Configuration Backup Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-69200.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2025-69200.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Louay-075</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 31, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/202.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-202</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2025-69200" target="_blank" rel="noopener" class="nt-cve-link">CVE-2025-69200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)phpMyFAQ&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">phpMyFAQ &lt;= 4.0.16 contains an information disclosure vulnerability caused by unauthenticated access to configuration backup ZIP generation and download, letting remote attackers access sensitive configuration files, exploit requires no authentication.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Remote attackers can access sensitive configuration files, exposing database credentials and enabling further compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to version 4.0.16 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">backup</span><span class="nt-tag">cve</span><span class="nt-tag">cve2025</span><span class="nt-tag">exposure</span><span class="nt-tag">phpmyfaq</span><span class="nt-tag">vkev</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/thorsten/phpMyFAQ/security/advisories/GHSA-9cg9-4h4f-j6fg" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69200" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-69200" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="phppgadmin login panel - detect info identify web-based control panels phppgadmin login ipanel was detected. ganofins,nullfuzz discovery panel phppgadmin phppgadmin_project cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">phpPgAdmin Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/phppgadmin-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">phppgadmin-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Ganofins,Nullfuzz</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)phppgadmin&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">phpPgAdmin login ipanel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">phppgadmin</span><span class="nt-tag">phppgadmin_project</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://docs.cpanel.net/cpanel/databases/phppgadmin/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="phpvms &lt; 7.0.6 - legacy importer authorization bypass critical identify critical remote vulnerabilities phpvms &lt; 7.0.6 contains an authentication bypass caused by unauthenticated access to a legacy import feature, letting unauthenticated attackers access restricted functionality, exploit requires no special privileges. cve-2026-42569 0x_akoko auth-bypass cve cve2026 phpvms unauth cwe-284,cwe-306,cwe-862" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">phpVMS &lt; 7.0.6 - Legacy Importer Authorization Bypass</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2026/CVE-2026-42569.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2026-42569.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0x_Akoko</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 14, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/284,CWE-306,CWE-862.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-284,CWE-306,CWE-862</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2026-42569" target="_blank" rel="noopener" class="nt-cve-link">CVE-2026-42569</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)phpvms&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">phpVMS &lt; 7.0.6 contains an authentication bypass caused by unauthenticated access to a legacy import feature, letting unauthenticated attackers access restricted functionality, exploit requires no special privileges.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can access restricted import functionality, potentially leading to unauthorized data manipulation or system compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update to version 7.0.6 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth-bypass</span><span class="nt-tag">cve</span><span class="nt-tag">cve2026</span><span class="nt-tag">phpvms</span><span class="nt-tag">unauth</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/phpvms/phpvms/security/advisories/GHSA-fv26-4939-62fh" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/phpvms/phpvms/commit/f59ba8e0e8fc25c60c3faf14e526cfd49df3f7dc" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42569" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="playsms &lt;1.4.3 - remote code execution critical identify critical remote vulnerabilities playsms before version 1.4.3 is susceptible to remote code execution because it double processes a server-side template. cve-2020-8644 dbrwsky cve cve2020 kev packetstorm playsms rce ssti unauth vkev vuln cwe-94" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">playSMS &lt;1.4.3 - Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2020/CVE-2020-8644.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2020-8644.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> dbrwsky</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/94.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-94</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2020-8644" target="_blank" rel="noopener" class="nt-cve-link">CVE-2020-8644</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches `(?i)playSMS`})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">PlaySMS before version 1.4.3 is susceptible to remote code execution because it double processes a server-side template.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability allows an attacker to execute arbitrary code on the target system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade playSMS to version 1.4.4 or later to mitigate this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2020</span><span class="nt-tag">kev</span><span class="nt-tag">packetstorm</span><span class="nt-tag">playsms</span><span class="nt-tag">rce</span><span class="nt-tag">ssti</span><span class="nt-tag">unauth</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://research.nccgroup.com/2020/02/11/technical-advisory-playsms-pre-authentication-remote-code-execution-cve-2020-8644/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://playsms.org/2020/02/05/playsms-1-4-3-has-been-released/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2020-8644" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="http://packetstormsecurity.com/files/157106/PlaySMS-index.php-Unauthenticated-Template-Injection-Code-Execution.html" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://forum.playsms.org/t/playsms-1-4-3-has-been-released/2704" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="pyload flask config - access control high identify critical remote vulnerabilities pyload is the free and open-source download manager written in pure python. any unauthenticated user can browse to a specific url to expose the flask config, including the `secret_key` variable. this issue has been patched in version 0.5.0b3.dev77. cve-2024-21644 west-wise access-control cve cve2024 pip pyload python vuln cwe-284" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">pyLoad Flask Config - Access Control</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-21644.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2024-21644.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> West-wise</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 30, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/284.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-284</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2024-21644" target="_blank" rel="noopener" class="nt-cve-link">CVE-2024-21644</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)pyload&#34; || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)login - pyload&#34;}) || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)pyload&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">pyLoad is the free and open-source Download Manager written in pure Python. Any unauthenticated user can browse to a specific URL to expose the Flask config, including the `SECRET_KEY` variable. This issue has been patched in version 0.5.0b3.dev77.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can access the Flask SECRET_KEY and other sensitive configuration variables, potentially enabling session hijacking or other attacks.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update pyLoad to version 0.5.0b3.dev77 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">access-control</span><span class="nt-tag">cve</span><span class="nt-tag">cve2024</span><span class="nt-tag">pip</span><span class="nt-tag">pyload</span><span class="nt-tag">python</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/advisories/GHSA-mqpq-2p68-46fv" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/fkie-cad/nvd-json-data-feeds" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-21644" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/ltranquility/CVE-2024-21644-Poc" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/nomi-sec/PoC-in-GitHub" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="qbittorrent web ui panel - detect info identify web-based control panels  ritikchaddha detect discovery panel qbittorrent" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">qBittorrent Web UI Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/qBittorrent-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">qBittorrent-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 9, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)qbittorrent&#34;})</code></div>
  <div class="nt-tags"><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">qbittorrent</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.qbittorrent.org/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="qdpm 9.2 - directory traversal high identify critical remote vulnerabilities qdpm 9.2 allows directory traversal to list files and directories by navigating to the /uploads uri. cve-2023-45855 dhiyaneshdk cve cve2023 lfi qdpm vuln cwe-22" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">qdPM 9.2 - Directory Traversal</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-45855.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-45855.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDk</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 13, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-45855" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-45855</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;762074255&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">qdPM 9.2 allows Directory Traversal to list files and directories by navigating to the /uploads URI.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation could allow an attacker to read sensitive files on the server.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade qdPM to a non-vulnerable version to mitigate the directory traversal vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">lfi</span><span class="nt-tag">qdpm</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/SunshineOtaku/Report-CVE/blob/main/qdPM/9.2/Directory%20Traversal.md" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-45855" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://qdpm.net" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="qdpm login panel info identify web-based control panels  theamanrawat discovery login panel qdpm" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">qdPM Login Panel</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/qdpm-login-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">qdpm-login-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> theamanrawat</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jul 7, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;favicon.ico.image.mmh3&#34;] == &#34;762074255&#34;</code></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">login</span><span class="nt-tag">panel</span><span class="nt-tag">qdpm</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="rconfig - default login high identify default logins in web-based control panels rconfig contains default credentials. an attacker can obtain access to user accounts and access sensitive information, modify data, and/or execute unauthorized operations. theamanrawat default-login rconfig vuln" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">rConfig - Default Login</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/default-logins/rconfig-default-login.yaml" target="_blank" rel="noopener" class="nt-source-link">rconfig-default-login.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> theamanrawat</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 17, 2023</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;rConfig&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">rConfig contains default credentials. An attacker can obtain access to user accounts and access sensitive information, modify data, and/or execute unauthorized operations.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">default-login</span><span class="nt-tag">rconfig</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/rconfig/rconfig" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify default logins in web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="rconfig 3.9 - sql injection critical identify critical remote vulnerabilities an issue was discovered in rconfig through 3.9.4. the web interface is prone to a sql injection via the commands.inc.php searchcolumn parameter. cve-2020-10220 ritikchaddha,theamanrawat cve cve2020 packetstorm rconfig sqli vuln cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">rConfig 3.9 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2020/CVE-2020-10220.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2020-10220.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha,theamanrawat</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 1, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2020-10220" target="_blank" rel="noopener" class="nt-cve-link">CVE-2020-10220</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)rconfig&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">An issue was discovered in rConfig through 3.9.4. The web interface is prone to a SQL injection via the commands.inc.php searchColumn parameter.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized accessand data leakage.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to a patched version of rConfig or apply the vendor-supplied patch to mitigate this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2020</span><span class="nt-tag">packetstorm</span><span class="nt-tag">rconfig</span><span class="nt-tag">sqli</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="http://packetstormsecurity.com/files/156950/rConfig-3.9.4-searchField-Remote-Code-Execution.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2020-10220" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="http://packetstormsecurity.com/files/156688/rConfig-3.9-SQL-Injection.html" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="http://packetstormsecurity.com/files/156766/Rconfig-3.x-Chained-Remote-Code-Execution.html" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/v1k1ngfr/exploits-rconfig/blob/master/rconfig_CVE-2020-10220.py" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="rconfig 3.9.4 - sql injection critical identify critical remote vulnerabilities rconfig 3.9.4 and previous versions have unauthenticated compliancepolicies.inc.php sql injection. because nodes&#39; passwords are stored in cleartext by default, this vulnerability leads to lateral movement, granting an attacker access to monitored network devices. cve-2020-10546 madrobot cve cve2020 rconfig sqli vkev vuln cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">rConfig 3.9.4 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2020/CVE-2020-10546.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2020-10546.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> madrobot</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2020-10546" target="_blank" rel="noopener" class="nt-cve-link">CVE-2020-10546</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)rconfig&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">rConfig 3.9.4 and previous versions have unauthenticated compliancepolicies.inc.php SQL injection. Because nodes&#39; passwords are stored in cleartext by default, this vulnerability leads to lateral movement, granting an attacker access to monitored network devices.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability allows an attacker to execute arbitrary SQL queries, potentially leading to unauthorized access, data manipulation.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to the latest version of rConfig or apply the provided patch to fix the SQL Injection vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2020</span><span class="nt-tag">rconfig</span><span class="nt-tag">sqli</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/theguly/exploits/blob/master/CVE-2020-10546.py" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://theguly.github.io/2020/09/rconfig-3.9.4-multiple-vulnerabilities/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2020-10546" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/theguly/exploits" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/ARPSyndicate/kenzer-templates" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="rconfig 3.9.4 - sql injection critical identify critical remote vulnerabilities rconfig 3.9.4 and previous versions has unauthenticated compliancepolicyelements.inc.php sql injection. because nodes&#39; passwords are stored by default in cleartext, this vulnerability leads to lateral movement, granting an attacker access to monitored network devices. cve-2020-10547 madrobot cve cve2020 rconfig sqli vuln cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">rConfig 3.9.4 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2020/CVE-2020-10547.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2020-10547.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> madrobot</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2020-10547" target="_blank" rel="noopener" class="nt-cve-link">CVE-2020-10547</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)rconfig&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">rConfig 3.9.4 and previous versions has unauthenticated compliancepolicyelements.inc.php SQL injection. Because nodes&#39; passwords are stored by default in cleartext, this vulnerability leads to lateral movement, granting an attacker access to monitored network devices.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability allows an attacker to execute arbitrary SQL queries, potentially leading to unauthorized access, data manipulation.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to the latest version of rConfig or apply the provided patch to fix the SQL Injection vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2020</span><span class="nt-tag">rconfig</span><span class="nt-tag">sqli</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/theguly/exploits/blob/master/CVE-2020-10547.py https://theguly.github.io/2020/09/rconfig-3.9.4-multiple-vulnerabilities/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/theguly/exploits/blob/master/CVE-2020-10547.py" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://theguly.github.io/2020/09/rconfig-3.9.4-multiple-vulnerabilities/" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/theguly/exploits" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/ARPSyndicate/kenzer-templates" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="rconfig 3.9.4 - sql injection critical identify critical remote vulnerabilities rconfig 3.9.4 and previous versions have unauthenticated devices.inc.php sql injection. because nodes&#39; passwords are stored in cleartext by default, this vulnerability leads to lateral movement, granting an attacker access to monitored network devices. cve-2020-10548 madrobot cve cve2020 rconfig sqli vkev vuln cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">rConfig 3.9.4 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2020/CVE-2020-10548.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2020-10548.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> madrobot</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2020-10548" target="_blank" rel="noopener" class="nt-cve-link">CVE-2020-10548</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)rconfig&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">rConfig 3.9.4 and previous versions have unauthenticated devices.inc.php SQL injection. Because nodes&#39; passwords are stored in cleartext by default, this vulnerability leads to lateral movement, granting an attacker access to monitored network devices.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability allows an attacker to execute arbitrary SQL queries, potentially leading to unauthorized access, data manipulation.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to a patched version of rConfig or apply the necessary security patches provided by the vendor.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2020</span><span class="nt-tag">rconfig</span><span class="nt-tag">sqli</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/theguly/exploits/blob/master/CVE-2020-10548.py" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://theguly.github.io/2020/09/rconfig-3.9.4-multiple-vulnerabilities/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2020-10548" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/ARPSyndicate/kenzer-templates" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/Elsfa7-110/kenzer-templates" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="rconfig &lt;=3.9.4 - sql injection critical identify critical remote vulnerabilities rconfig 3.9.4 and prior has unauthenticated snippets.inc.php sql injection. because nodes&#39; passwords are stored in cleartext by default, this vulnerability leads to lateral movement, granting an attacker access to monitored network devices. cve-2020-10549 madrobot cve cve2020 rconfig sqli vuln cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">rConfig &lt;=3.9.4 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2020/CVE-2020-10549.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2020-10549.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> madrobot</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2020-10549" target="_blank" rel="noopener" class="nt-cve-link">CVE-2020-10549</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)rconfig&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">rConfig 3.9.4 and prior has unauthenticated snippets.inc.php SQL injection. Because nodes&#39; passwords are stored in cleartext by default, this vulnerability leads to lateral movement, granting an attacker access to monitored network devices.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability allows an attacker to execute arbitrary SQL queries, potentially leading to unauthorized access, data manipulation.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade rConfig to version &gt;3.9.4 or apply the provided patch to mitigate the SQL Injection vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2020</span><span class="nt-tag">rconfig</span><span class="nt-tag">sqli</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/theguly/exploits/blob/master/CVE-2020-10549.py" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://theguly.github.io/2020/09/rconfig-3.9.4-multiple-vulnerabilities/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2020-10549" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://github.com/ARPSyndicate/kenzer-templates" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/Elsfa7-110/kenzer-templates" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="temboard panel - detect info identify web-based control panels temboard was detected — a powerful management tool for postgresql. righettod panel temboard login discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">temBoard Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/temboard-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">temboard-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> righettod</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Dec 19, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)temBoard&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">temBoard was detected — a powerful management tool for PostgreSQL.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">temboard</span><span class="nt-tag">login</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://labs.dalibo.com/temboard" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/dalibo/temboard/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="tshirtecommerce prestashop module - sql injection high identify critical remote vulnerabilities the tshirtecommerce module for prestashop is vulnerable to unauthenticated sql injection via the tshirtecommerce_design_cart_id parameter, allowing attackers to execute arbitrary sql queries and extract sensitive information from the database. this is due to lack of input sanitization, as shown in the patch where psql() is now used. cve-2023-27638 ritikchaddha cve cve2023 prestashop sqli tshirtecommerce vkev vuln cwe-89" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">tshirtecommerce PrestaShop Module - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-27638.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-27638.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> ritikchaddha</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 29, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-27638" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-27638</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Prestashop&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">The tshirtecommerce module for PrestaShop is vulnerable to unauthenticated SQL injection via the tshirtecommerce_design_cart_id parameter, allowing attackers to execute arbitrary SQL queries and extract sensitive information from the database. This is due to lack of input sanitization, as shown in the patch where pSQL() is now used.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can execute SQL injection through the tshirtecommerce_design_cart_id parameter to extract the complete PrestaShop database including customer data and payment information.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Update the tshirtecommerce module to the latest version and apply all security patches.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">prestashop</span><span class="nt-tag">sqli</span><span class="nt-tag">tshirtecommerce</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://security.friendsofpresta.org/module/2023/03/21/tshirtecommerce_cwe-89.html" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-27638" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="txadmin panel - detect info identify web-based control panels txadmin panel was discovered. s4e-io panel login txadmin detect discovery" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">txAdmin Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/txadmin-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">txadmin-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> s4e-io</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 11, 2024</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)txAdmin Login&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">txAdmin panel was discovered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">panel</span><span class="nt-tag">login</span><span class="nt-tag">txadmin</span><span class="nt-tag">detect</span><span class="nt-tag">discovery</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="vbulletin 5.0.0-5.5.4 - remote command execution critical identify critical remote vulnerabilities vbulletin 5.0.0 through 5.5.4 is susceptible to a remote command execution vulnerability via the widgetconfig parameter in an ajax/render/widget_php routestring request. an attacker can execute malware, obtain sensitive information, modify data, and/or gain full control over a compromised system without entering necessary credentials. cve-2019-16759 madrobot cve cve2019 kev rce seclists vbulletin vkev vuln cwe-94" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">vBulletin 5.0.0-5.5.4 - Remote Command Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2019/CVE-2019-16759.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2019-16759.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> madrobot</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/94.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-94</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2019-16759" target="_blank" rel="noopener" class="nt-cve-link">CVE-2019-16759</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)powered by vbulletin&#34; || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)powered by vbulletin&#34;}) || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)vbulletin&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">vBulletin 5.0.0 through 5.5.4 is susceptible to a remote command execution vulnerability via the widgetConfig parameter in an ajax/render/widget_php routestring request. An attacker can execute malware, obtain sensitive information, modify data, and/or gain full control over a compromised system without entering necessary credentials.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute arbitrary commands on the target system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade vBulletin to a version that is not affected by CVE-2019-16759.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2019</span><span class="nt-tag">kev</span><span class="nt-tag">rce</span><span class="nt-tag">seclists</span><span class="nt-tag">vbulletin</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/vbulletin-remote-code-execution-cve-2020-7373/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://seclists.org/fulldisclosure/2019/Sep/31" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://www.theregister.co.uk/2019/09/24/vbulletin_vbug_zeroday/" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2019-16759" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/20142995/Goby" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="vbulletin 5.5.4 - 5.6.2- remote command execution critical identify critical remote vulnerabilities vbulletin versions 5.5.4 through 5.6.2 allow remote command execution via crafted subwidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request. note: this issue exists because of an incomplete fix for cve-2019-16759. cve-2020-17496 pussycat0x cve cve2020 kev rce seclists tenable vbulletin vkev vuln cwe-74" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">vBulletin 5.5.4 - 5.6.2- Remote Command Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2020/CVE-2020-17496.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2020-17496.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/74.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-74</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2020-17496" target="_blank" rel="noopener" class="nt-cve-link">CVE-2020-17496</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)powered by vbulletin&#34;}) || service[&#34;http.body&#34;] matches &#34;(?i)powered by vbulletin&#34; || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)vbulletin&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">vBulletin versions 5.5.4 through 5.6.2 allow remote command execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request. NOTE: this issue exists because of an incomplete fix for CVE-2019-16759.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability allows an attacker to execute arbitrary commands on the target system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade vBulletin to a version that is not affected by CVE-2020-17496.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2020</span><span class="nt-tag">kev</span><span class="nt-tag">rce</span><span class="nt-tag">seclists</span><span class="nt-tag">tenable</span><span class="nt-tag">vbulletin</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.tenable.com/blog/zero-day-remote-code-execution-vulnerability-in-vbulletin-disclosed" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2020-17496" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://seclists.org/fulldisclosure/2020/Aug/5" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://forum.vbulletin.com/forum/vbulletin-announcements/vbulletin-announcements_aa/4445227-vbulletin-5-6-0-5-6-1-5-6-2-security-patch" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://cwe.mitre.org/data/definitions/78.html" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="vbulletin &lt;= 4.2.3 - sql injection critical identify critical remote vulnerabilities vbulletin versions 3.6.0 through 4.2.3 are vulnerable to an sql injection vulnerability in the vbulletin core forumrunner addon. the vulnerability allows an attacker to execute arbitrary sql queries and potentially access sensitive information from the database. cve-2016-6195 mastercho cve cve2016 edb forum sqli vbulletin vkev vuln cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">vBulletin &lt;= 4.2.3 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2016/CVE-2016-6195.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2016-6195.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> MaStErChO</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 31, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2016-6195" target="_blank" rel="noopener" class="nt-cve-link">CVE-2016-6195</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)vbulletin&#34;}) || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)powered by vbulletin&#34;}) || service[&#34;http.body&#34;] matches &#34;(?i)powered by vbulletin&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">vBulletin versions 3.6.0 through 4.2.3 are vulnerable to an SQL injection vulnerability in the vBulletin core forumrunner addon. The vulnerability allows an attacker to execute arbitrary SQL queries and potentially access sensitive information from the database.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability can lead to unauthorized access, data leakage, and potential compromise of the entire system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to a patched version of vBulletin (4.2.4 or later) or apply the official patch provided by the vendor.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2016</span><span class="nt-tag">edb</span><span class="nt-tag">forum</span><span class="nt-tag">sqli</span><span class="nt-tag">vbulletin</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.cvedetails.com/cve/CVE-2016-6195/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.exploit-db.com/exploits/38489" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://enumerated.wordpress.com/2016/07/11/1/" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="http://www.vbulletin.org/forum/showthread.php?t=322848" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/drewlong/vbully" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="vbulletin &lt;= 5.6.9 - pre-authentication remote code execution critical identify critical remote vulnerabilities vbulletin before 5.6.9 pl1 allows an unauthenticated remote attacker to execute arbitrary code via a crafted http request that triggers deserialization. this occurs because verify_serialized checks that a value is serialized by calling unserialize and then checking for errors. cve-2023-25135 iamnoooob,rootxharsh,pdresearch cve cve2023 rce vbulletin vkev vuln cwe-502" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">vBulletin &lt;= 5.6.9 - Pre-authentication Remote Code Execution</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2023/CVE-2023-25135.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2023-25135.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> iamnoooob,rootxharsh,pdresearch</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 9, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/502.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-502</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2023-25135" target="_blank" rel="noopener" class="nt-cve-link">CVE-2023-25135</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)powered by vbulletin&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">vBulletin before 5.6.9 PL1 allows an unauthenticated remote attacker to execute arbitrary code via a crafted HTTP request that triggers deserialization. This occurs because verify_serialized checks that a value is serialized by calling unserialize and then checking for errors.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the target system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to the latest version to mitigate this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2023</span><span class="nt-tag">rce</span><span class="nt-tag">vbulletin</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://www.ambionics.io/blog/vbulletin-unserializable-but-unreachable" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://github.com/ambionics/vbulletin-exploits/blob/main/vbulletin-rce-cve-2023-25135.py" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-25135" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="https://forum.vbulletin.com/forum/vbulletin-announcements/vbulletin-announcements_aa/4473890-vbulletin-5-6-9-security-patch" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="https://github.com/netlas-io/netlas-dorks" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="vbulletin sql injection critical identify critical remote vulnerabilities vbulletin before 5.5.6pl1, 5.6.0 before 5.6.0pl1, and 5.6.1 before 5.6.1pl1 has incorrect access control that permits sql injection attacks. cve-2020-12720 pdteam cve cve2020 packetstorm sqli vbulletin vkev vuln cwe-306" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">vBulletin SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2020/CVE-2020-12720.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2020-12720.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pdteam</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/306.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-306</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2020-12720" target="_blank" rel="noopener" class="nt-cve-link">CVE-2020-12720</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)powered by vbulletin&#34;}) || service[&#34;http.body&#34;] matches &#34;(?i)powered by vbulletin&#34; || any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)vbulletin&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">vBulletin before 5.5.6pl1, 5.6.0 before 5.6.0pl1, and 5.6.1 before 5.6.1pl1 has incorrect access control that permits SQL injection attacks.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Successful exploitation of this vulnerability can lead to unauthorized access, data leakage, and potential compromise of the underlying system.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patch or upgrade to a non-vulnerable version of vBulletin.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2020</span><span class="nt-tag">packetstorm</span><span class="nt-tag">sqli</span><span class="nt-tag">vbulletin</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/rekter0/exploits/tree/master/CVE-2020-12720" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2020-12720" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://forum.vbulletin.com/forum/vbulletin-announcements/vbulletin-announcements_aa/4440032-vbulletin-5-6-1-security-patch-level-1" target="_blank" rel="noopener" class="nt-ref-link">[3]</a> <a href="http://packetstormsecurity.com/files/157716/vBulletin-5.6.1-SQL-Injection.html" target="_blank" rel="noopener" class="nt-ref-link">[4]</a> <a href="http://packetstormsecurity.com/files/157904/vBulletin-5.6.1-SQL-Injection.html" target="_blank" rel="noopener" class="nt-ref-link">[5]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="vcenter server - improper access control medium identify critical remote vulnerabilities rhttproxy as used in vcenter server contains a vulnerability due to improper implementation of uri normalization. a malicious actor with network access to port 443 on vcenter server may exploit this issue to bypass proxy leading to internal endpoints being accessed. cve-2021-22017 daffainfo cve cve2021 kev vcenter vkev vmware nvd-cwe-noinfo" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">vCenter Server - Improper Access Control</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2021/CVE-2021-22017.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2021-22017.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> daffainfo</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 14, 2026</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/NVD-CWE-NOINFO.html" target="_blank" rel="noopener" class="nt-cwe-link">NVD-CWE-NOINFO</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2021-22017" target="_blank" rel="noopener" class="nt-cve-link">CVE-2021-22017</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;product&#34;] contains &#34;VMware:vCenter Server&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Rhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to bypass proxy leading to internal endpoints being accessed.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Attackers can bypass proxy restrictions and access internal endpoints, potentially leading to information disclosure or further internal network compromise.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Apply the latest security patches or updates provided by VMware for vCenter Server.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2021</span><span class="nt-tag">kev</span><span class="nt-tag">vcenter</span><span class="nt-tag">vkev</span><span class="nt-tag">vmware</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/wangsir01/docs/blob/7c20bbf43ae467c1bdc54c65c9a3230ae3e81d63/CVE-2021-22017-22005%E6%A8%A1%E6%9D%BF%E6%B3%A8%E5%85%A5%E5%88%86%E6%9E%90/CVE-2021-22017-22005%E6%A8%A1%E6%9D%BF%E6%B3%A8%E5%85%A5%E5%88%86%E6%9E%90.md" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://www.vmware.com/security/advisories/VMSA-2021-0020.html" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2021-22017" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="vrealize hyperic login panel - detect info identify web-based control panels vrealize hyperic login panel was detected charles d detect discovery hyperic login panel vrealize cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">vRealize Hyperic Login Panel - Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/vrealize-hyperic-login-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">vrealize-hyperic-login-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Charles D</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> May 16, 2024</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Sign In - Hyperic&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">vRealize Hyperic login panel was detected</div></div></div>
  <div class="nt-tags"><span class="nt-tag">detect</span><span class="nt-tag">discovery</span><span class="nt-tag">hyperic</span><span class="nt-tag">login</span><span class="nt-tag">panel</span><span class="nt-tag">vrealize</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="vrealize log insight - panel detect info identify web-based control panels detect vrealize log insight login panel was detected. pussycat0x discovery panel vmware vrealize cwe-200" data-nt-sev="info">
  <div class="nt-card-header">
    <div class="nt-title">vRealize Log Insight - Panel Detect</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/exposed-panels/vrealize-loginsight-panel.yaml" target="_blank" rel="noopener" class="nt-source-link">vrealize-loginsight-panel.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pussycat0x</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-200</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)vrealize log insight&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detect vRealize Log Insight login panel was detected.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">panel</span><span class="nt-tag">vmware</span><span class="nt-tag">vrealize</span></div>
  <div class="nt-footer-row"><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify web-based control panels</span></span></div>
</div>
<div class="nt-card" data-nt-search="webp_server_go 0.4.0 - path traversal high identify critical remote vulnerabilities webp_server_go 0.4.0 contains a path traversal caused by insufficient sanitization in file handling, letting attackers read arbitrary files on the server, exploit requires attacker to send crafted requests. cve-2021-46104 pikpikcu cve cve2021 lfi vuln webp cwe-22" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">webp_server_go 0.4.0 - Path Traversal</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2021/CVE-2021-46104.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2021-46104.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> pikpikcu</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 5, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2021-46104" target="_blank" rel="noopener" class="nt-cve-link">CVE-2021-46104</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)Webp&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">webp_server_go 0.4.0 contains a path traversal caused by insufficient sanitization in file handling, letting attackers read arbitrary files on the server, exploit requires attacker to send crafted requests.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can read arbitrary files from the server including /etc/passwd via path traversal using double URL encoding.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to webp_server_go version 0.4.1 or later that properly sanitizes file paths.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2021</span><span class="nt-tag">lfi</span><span class="nt-tag">vuln</span><span class="nt-tag">webp</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/webp-sh/webp_server_go/issues/92" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="wpdiscuz &lt;= 5.3.5 - sql injection critical identify critical remote vulnerabilities a sql injection issue in the gvectors wpdiscuz plugin 5.3.5 and earlier for wordpress allows remote attackers to execute arbitrary sql commands via the order parameter of a wpdloadmorecomments request. cve-2020-13640 sourabh-sahu cve cve2020 sqli vkev vuln wordpress wp wp-plugin wpdiscuz cwe-89" data-nt-sev="critical">
  <div class="nt-card-header">
    <div class="nt-title">wpDiscuz &lt;= 5.3.5 - SQL Injection</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2020/CVE-2020-13640.yaml" target="_blank" rel="noopener" class="nt-source-link">CVE-2020-13640.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> Sourabh-Sahu</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Sep 16, 2025</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/89.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-89</a></span><span class="nt-detail"><a href="https://www.cve.org/CVERecord?id=CVE-2020-13640" target="_blank" rel="noopener" class="nt-cve-link">CVE-2020-13640</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)/wp-content/plugins/wpdiscuz&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A SQL injection issue in the gVectors wpDiscuz plugin 5.3.5 and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the order parameter of a wpdLoadMoreComments request.</div></div><div class="nt-section"><div class="nt-section-label">Impact</div><div class="nt-section-body">Unauthenticated attackers can execute arbitrary SQL commands to extract database contents including user credentials, posts, and sensitive WordPress configuration data.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to wpDiscuz version 5.3.6 or later.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">cve</span><span class="nt-tag">cve2020</span><span class="nt-tag">sqli</span><span class="nt-tag">vkev</span><span class="nt-tag">vuln</span><span class="nt-tag">wordpress</span><span class="nt-tag">wp</span><span class="nt-tag">wp-plugin</span><span class="nt-tag">wpdiscuz</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/asterite3/CVE-2020-13640" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2020-13640" target="_blank" rel="noopener" class="nt-ref-link">[2]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="x-amz-meta-s3cmd-attrs header username disclosure low identify critical remote vulnerabilities detected exposure of the x-amz-meta-s3cmd-attrs header in s3 objects, which can disclose sensitive information including the username (uname), user id (uid), group name (gname), and group id (gid) of the user who uploaded the file using s3cmd. dhiyaneshdk s3 aws exposure misconfig header" data-nt-sev="low">
  <div class="nt-card-header">
    <div class="nt-title">x-amz-meta-s3cmd-attrs Header Username Disclosure</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/misconfiguration/s3-username-disclosure.yaml" target="_blank" rel="noopener" class="nt-source-link">s3-username-disclosure.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> DhiyaneshDK</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Jan 19, 2026</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.head.xAmzMetaS3cmdAttrs&#34;] != &#34;&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">Detected exposure of the x-amz-meta-s3cmd-attrs header in S3 objects, which can disclose sensitive information including the username (uname), user ID (uid), group name (gname), and group ID (gid) of the user who uploaded the file using s3cmd.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Use s3cmd with --no-preserve flag or set preserve_attrs = False in s3cmd configuration to prevent storing filesystem attributes in S3 object metadata.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">s3</span><span class="nt-tag">aws</span><span class="nt-tag">exposure</span><span class="nt-tag">misconfig</span><span class="nt-tag">header</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://github.com/s3tools/s3cmd/issues/1173" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://hackerone.com/reports/819146" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://medium.com/@jonathanbouman/how-s3cmd-discloses-your-linux-username-to-the-world-b9e4d79cb9e3" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="zhttpd - local file inclusion high identify critical remote vulnerabilities zhttpd is vulnerable to unauthenticated local inclusion including privileged files such as /etc/shadow. an attacker can read all files on the system by using this endpoint. evergreencartoons misconfig unauth zyxel lfi msf vuln cwe-22" data-nt-sev="high">
  <div class="nt-card-header">
    <div class="nt-title">zhttpd - Local File Inclusion</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/vulnerabilities/zyxel/unauth-lfd-zhttpd.yaml" target="_blank" rel="noopener" class="nt-source-link">unauth-lfd-zhttpd.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> EvergreenCartoons</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Apr 27, 2023</span><span class="nt-detail"><a href="https://cwe.mitre.org/data/definitions/22.html" target="_blank" rel="noopener" class="nt-cwe-link">CWE-22</a></span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">service[&#34;http.body&#34;] matches &#34;(?i)VMG1312-B10D&#34;</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">zhttpd is vulnerable to unauthenticated local inclusion including privileged files such as /etc/shadow. An attacker can read all files on the system by using this endpoint.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">misconfig</span><span class="nt-tag">unauth</span><span class="nt-tag">zyxel</span><span class="nt-tag">lfi</span><span class="nt-tag">msf</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://sec-consult.com/blog/detail/enemy-within-unauthenticated-buffer-overflows-zyxel-routers/" target="_blank" rel="noopener" class="nt-ref-link">[1]</a> <a href="https://sec-consult.com/vulnerability-lab/advisory/multiple-critical-vulnerabilities-in-multiple-zyxel-devices/" target="_blank" rel="noopener" class="nt-ref-link">[2]</a> <a href="https://github.com/rapid7/metasploit-framework/pull/17388" target="_blank" rel="noopener" class="nt-ref-link">[3]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
<div class="nt-card" data-nt-search="р7-office 12.5 - cross-site scripting medium identify critical remote vulnerabilities a failure to implement proper measures to protect the structure of the web page in the p7-office corporate server could have allowed a remote attacker to perform a cross-site scripting (xss) attack. 0xpugal p7office xss vuln" data-nt-sev="medium">
  <div class="nt-card-header">
    <div class="nt-title">Р7-Office 12.5 - Cross-Site Scripting</div>
    <div class="nt-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><a href="https://github.com/runZeroInc/nuclei-templates/blob/main/http/vulnerabilities/other/p7-office-xss.yaml" target="_blank" rel="noopener" class="nt-source-link">p7-office-xss.yaml<svg class="nt-offsite-icon" viewBox="0 0 12 12" fill="none" stroke="currentColor" stroke-width="1.5"><path d="M3.5 1.5h7v7"/><path d="M10.5 1.5L1.5 10.5"/></svg></a></div>
  </div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Author:</span> 0xpugal</span><span class="nt-detail"><span class="nt-detail-label">Added:</span> Oct 5, 2025</span></div>
  <div class="nt-match-section"><span class="nt-match-label" data-tooltip="runZero precisely targets each service by comparing the runZero fingerprint to the per-template match criteria.">runzero-match</span><code class="nt-match-code">any(each(service[&#34;html.titles&#34;]), {# matches &#34;(?i)Р7-Офис&#34;})</code></div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-label">Description</div><div class="nt-section-body">A failure to implement proper measures to protect the structure of the web page in the P7-Office corporate server could have allowed a remote attacker to perform a cross-site scripting (XSS) attack.</div></div><div class="nt-section"><div class="nt-section-label">Remediation</div><div class="nt-section-body">Upgrade to the latest version to mitigate this vulnerability.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">p7office</span><span class="nt-tag">xss</span><span class="nt-tag">vuln</span></div>
  <div class="nt-footer-row"><span class="nt-footer-refs"><span class="nt-scan-option-label">References:</span> <a href="https://bdu.fstec.ru/vul/2024-04635" target="_blank" rel="noopener" class="nt-ref-link">[1]</a></span><span class="nt-scan-option"><span class="nt-scan-option-label">enabled by option:</span> <span class="nt-scan-tag">Identify critical remote vulnerabilities</span></span></div>
</div>
</template>
<script>
(function(){var t=document.getElementById('nt-grid-content');var h=document.getElementById('nt-grid-host');if(t&&h){requestAnimationFrame(function(){h.innerHTML='';h.appendChild(t.content);t.remove();})}})();
var ntActiveSevs=new Set(['critical','high','medium','low','info']);
function ntToggleSev(btn){
  var s=btn.getAttribute('data-sev');
  if(ntActiveSevs.has(s)){ntActiveSevs.delete(s);btn.classList.remove('active');}
  else{ntActiveSevs.add(s);btn.classList.add('active');}
  ntFilter();
}
function ntFilter(){
  var term=(document.querySelector('.nt-search').value||'').toLowerCase();
  var cards=document.querySelectorAll('.nt-card');
  var shown=0;
  cards.forEach(function(c){
    var textMatch=!term||c.getAttribute('data-nt-search').indexOf(term)!==-1;
    var sevMatch=ntActiveSevs.has(c.getAttribute('data-nt-sev'));
    var visible=textMatch&&sevMatch;
    c.classList.toggle('nt-hidden',!visible);
    if(visible) shown++;
  });
  document.getElementById('nt-match-count').textContent=shown;
}
</script>

<p>In addition to <a href="/docs/em-queries/">query-based</a> vulnerability reporting, runZero natively detects exposures using an embedded version of the open-source <a href="https://github.com/projectdiscovery/nuclei">Nuclei</a> vulnerability scanner and it’s YAML-based vulnerability check templates. To maintain fast scan times and minimize network disruption, runZero dynamically selects appropriate templates based on the scan’s configured categories and precise asset and service fingerprinting.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Query library]]></title>
    <link href="https://www.runzero.com/docs/em-queries/"/>
    <id>https://www.runzero.com/docs/em-queries/</id>
      
      <published>2026-04-11T16:31:16+00:00</published>
      <updated>2026-04-11T16:31:16+00:00</updated>
      <summary type="html"><![CDATA[<div class="summary-chart"><div class="summary-stats"><div class="summary-stat summary-stat-hero"><div class="summary-stat-value">228</div><div class="summary-stat-label">Queries</div></div><div class="summary-stat summary-stat-hero"><div class="summary-stat-value">8</div><div class="summary-stat-label">Categories</div></div></div><div class="summary-bar-section"><div class="summary-bar-label">Severity distribution</div><div class="summary-bar"><div class="summary-bar-seg" style="width:39.5%;background:#dc2626" title="Critical: 90 (39%)">&nbsp;</div><div class="summary-bar-seg" style="width:25.0%;background:#ea580c" title="High: 57 (25%)">&nbsp;</div><div class="summary-bar-seg" style="width:9.6%;background:#ca8a04" title="Medium: 22 (10%)">&nbsp;</div><div class="summary-bar-seg" style="width:20.2%;background:#008099" title="Low: 46 (20%)">&nbsp;</div><div class="summary-bar-seg" style="width:5.7%;background:#6b7280" title="Info: 13 (6%)">&nbsp;</div></div><div class="summary-legend"><span class="summary-legend-item"><span class="summary-legend-dot" style="background:#dc2626"></span>Critical <strong>90</strong></span><span class="summary-legend-item"><span class="summary-legend-dot" style="background:#ea580c"></span>High <strong>57</strong></span><span class="summary-legend-item"><span class="summary-legend-dot" style="background:#ca8a04"></span>Medium <strong>22</strong></span><span class="summary-legend-item"><span class="summary-legend-dot" style="background:#008099"></span>Low <strong>46</strong></span><span class="summary-legend-item"><span class="summary-legend-dot" style="background:#6b7280"></span>Info <strong>13</strong></span></div></div><div class="summary-bar-section"><div class="summary-bar-label">Categories</div><div class="summary-tags"><span class="summary-tag">Vulnerability <strong>136</strong></span><span class="summary-tag">Internet Exposure <strong>25</strong></span><span class="summary-tag">Best Practice <strong>19</strong></span><span class="summary-tag">Open Access <strong>19</strong></span><span class="summary-tag">End-of-Life <strong>15</strong></span><span class="summary-tag">Certificates <strong>5</strong></span><span class="summary-tag">Compliance <strong>5</strong></span><span class="summary-tag">Rapid Response <strong>4</strong></span></div></div></div><div class="ql-toolbar"><input type="text" class="ql-search" placeholder="Filter by name, category, or query..." oninput="qlFilter()"><div class="ql-sev-filters"><button class="fd-risk-btn fd-risk-critical active" data-sev="critical" onclick="qlToggleSev(this)">Critical</button><button class="fd-risk-btn fd-risk-high active" data-sev="high" onclick="qlToggleSev(this)">High</button><button class="fd-risk-btn fd-risk-medium active" data-sev="medium" onclick="qlToggleSev(this)">Medium</button><button class="fd-risk-btn fd-risk-low active" data-sev="low" onclick="qlToggleSev(this)">Low</button><button class="fd-risk-btn fd-risk-info active" data-sev="info" onclick="qlToggleSev(this)">Info</button></div></div><div class="ql-count"><span id="ql-match-count">228</span> of 228 queries in 8 categories</div><div id="ql-grid-host" class="ql-grid"><div class="deferred-loading">Loading queries…</div></div>
<template id="ql-grid-content">
<div class="ql-category" id="ql-best-practice">
  <button class="ql-cat-header" onclick="qlToggleCat(this)"><span class="ql-cat-title">Best Practice</span><span class="ql-cat-count">19 queries</span><span class="ql-cat-chevron">&#9660;</span></button>
  <div class="ql-cat-body">
    <div class="ql-card" data-ql-search="google workspace account without mfa source:googleworkspace isenforcedin2sv:f users best practice" data-ql-sev="medium">
      <div class="ql-card-header">
        <div class="ql-title">Google Workspace Account Without MFA</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><span class="ql-type-badge">users</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>source:googleworkspace isEnforcedIn2Sv:f</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="source:googleworkspace isEnforcedIn2Sv:f" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/users?search=source%3Agoogleworkspace+isEnforcedIn2Sv%3Af" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/users?search=source%3Agoogleworkspace+isEnforcedIn2Sv%3Af" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="source:googleworkspace isEnforcedIn2Sv:f"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="active directory account expires soon has:accountexpirests and accountexpirests:&lt;30days users best practice" data-ql-sev="low">
      <div class="ql-card-header">
        <div class="ql-title">Active Directory Account Expires Soon</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><span class="ql-type-badge">users</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>has:accountExpiresTS AND accountExpiresTS:&lt;30days</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="has:accountExpiresTS AND accountExpiresTS:&lt;30days" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/users?search=has%3AaccountExpiresTS+AND+accountExpiresTS%3A%3C30days" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/users?search=has%3AaccountExpiresTS+AND+accountExpiresTS%3A%3C30days" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="has:accountExpiresTS AND accountExpiresTS:&lt;30days"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="authenticated web service without encryption (_asset.protocol:http and not _asset.protocol:tls) and  ( html.inputs:&#34;password:&#34; or last.html.inputs:&#34;password:&#34; or has:http.head.wwwauthenticate or has:last.http.head.wwwauthenticate ) services best practice" data-ql-sev="low">
      <div class="ql-card-header">
        <div class="ql-title">Authenticated Web Service Without Encryption</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><span class="ql-type-badge">services</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>(_asset.protocol:http AND not _asset.protocol:tls) AND  ( html.inputs:&#34;password:&#34; OR last.html.inputs:&#34;password:&#34; OR has:http.head.wwwAuthenticate OR has:last.http.head.wwwAuthenticate )</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="(_asset.protocol:http AND not _asset.protocol:tls) AND  ( html.inputs:&#34;password:&#34; OR last.html.inputs:&#34;password:&#34; OR has:http.head.wwwAuthenticate OR has:last.http.head.wwwAuthenticate )" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/services?search=%28_asset.protocol%3Ahttp+AND+not+_asset.protocol%3Atls%29+AND++%28+html.inputs%3A%22password%3A%22+OR+last.html.inputs%3A%22password%3A%22+OR+has%3Ahttp.head.wwwAuthenticate+OR+has%3Alast.http.head.wwwAuthenticate+%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/services?search=%28_asset.protocol%3Ahttp+AND+not+_asset.protocol%3Atls%29+AND++%28+html.inputs%3A%22password%3A%22+OR+last.html.inputs%3A%22password%3A%22+OR+has%3Ahttp.head.wwwAuthenticate+OR+has%3Alast.http.head.wwwAuthenticate+%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="(_asset.protocol:http AND not _asset.protocol:tls) AND  ( html.inputs:&#34;password:&#34; OR last.html.inputs:&#34;password:&#34; OR has:http.head.wwwAuthenticate OR has:last.http.head.wwwAuthenticate )"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="cloud management services source:runzero and foreign_id:&#34;rz-scan-vscan-%-panel&#34; and attack_surface:cloud vulnerabilities best practice" data-ql-sev="low">
      <div class="ql-card-header">
        <div class="ql-title">Cloud Management Services</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><span class="ql-type-badge">vulnerabilities</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>source:runZero AND foreign_id:&#34;rz-scan-vscan-%-panel&#34; AND attack_surface:cloud</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="source:runZero AND foreign_id:&#34;rz-scan-vscan-%-panel&#34; AND attack_surface:cloud" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/vulnerabilities?search=source%3ArunZero+AND+foreign_id%3A%22rz-scan-vscan-%25-panel%22+AND+attack_surface%3Acloud" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/vulnerabilities?search=source%3ArunZero+AND+foreign_id%3A%22rz-scan-vscan-%25-panel%22+AND+attack_surface%3Acloud" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="source:runZero AND foreign_id:&#34;rz-scan-vscan-%-panel&#34; AND attack_surface:cloud"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="externally exposed and risky ot and iot assets (category:=ot or category:=iot) and (risk:high or risk:critical) and attack_surface:external assets best practice" data-ql-sev="low">
      <div class="ql-card-header">
        <div class="ql-title">Externally Exposed and Risky OT and IoT Assets</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><span class="ql-type-badge">assets</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>(category:=OT OR category:=IoT) AND (risk:high OR risk:critical) AND attack_surface:external</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="(category:=OT OR category:=IoT) AND (risk:high OR risk:critical) AND attack_surface:external" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/?search=%28category%3A%3DOT+OR+category%3A%3DIoT%29+AND+%28risk%3Ahigh+OR+risk%3Acritical%29+AND+attack_surface%3Aexternal" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/?search=%28category%3A%3DOT+OR+category%3A%3DIoT%29+AND+%28risk%3Ahigh+OR+risk%3Acritical%29+AND+attack_surface%3Aexternal" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="(category:=OT OR category:=IoT) AND (risk:high OR risk:critical) AND attack_surface:external"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="http directory indexing enabled _asset.protocol:=http and protocol:=http and has:html.title and (html.title:=&#34;index of /%&#34; or html.title:=&#34;hfs /%&#34; or html.title:=&#34;directory listing%&#34;) services best practice" data-ql-sev="low">
      <div class="ql-card-header">
        <div class="ql-title">HTTP Directory Indexing Enabled</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><span class="ql-type-badge">services</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>_asset.protocol:=http AND protocol:=http AND has:html.title AND (html.title:=&#34;Index of /%&#34; OR html.title:=&#34;HFS /%&#34; OR html.title:=&#34;Directory listing%&#34;)</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="_asset.protocol:=http AND protocol:=http AND has:html.title AND (html.title:=&#34;Index of /%&#34; OR html.title:=&#34;HFS /%&#34; OR html.title:=&#34;Directory listing%&#34;)" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/services?search=_asset.protocol%3A%3Dhttp+AND+protocol%3A%3Dhttp+AND+has%3Ahtml.title+AND+%28html.title%3A%3D%22Index+of+%2F%25%22+OR+html.title%3A%3D%22HFS+%2F%25%22+OR+html.title%3A%3D%22Directory+listing%25%22%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/services?search=_asset.protocol%3A%3Dhttp+AND+protocol%3A%3Dhttp+AND+has%3Ahtml.title+AND+%28html.title%3A%3D%22Index+of+%2F%25%22+OR+html.title%3A%3D%22HFS+%2F%25%22+OR+html.title%3A%3D%22Directory+listing%25%22%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="_asset.protocol:=http AND protocol:=http AND has:html.title AND (html.title:=&#34;Index of /%&#34; OR html.title:=&#34;HFS /%&#34; OR html.title:=&#34;Directory listing%&#34;)"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="interal multi-homed assets multi_home:t and attack_surface:internal assets best practice" data-ql-sev="low">
      <div class="ql-card-header">
        <div class="ql-title">Interal Multi-Homed Assets</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><span class="ql-type-badge">assets</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>multi_home:t AND attack_surface:internal</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="multi_home:t AND attack_surface:internal" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/?search=multi_home%3At+AND+attack_surface%3Ainternal" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/?search=multi_home%3At+AND+attack_surface%3Ainternal" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="multi_home:t AND attack_surface:internal"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="multi-homed assets multi_home:t assets best practice" data-ql-sev="low">
      <div class="ql-card-header">
        <div class="ql-title">Multi-Homed Assets</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><span class="ql-type-badge">assets</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>multi_home:t</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="multi_home:t" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/?search=multi_home%3At" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/?search=multi_home%3At" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="multi_home:t"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="network time protocol service with skewed clock _asset.protocol:ntp and protocol:ntp and has:ntp.skew services best practice" data-ql-sev="low">
      <div class="ql-card-header">
        <div class="ql-title">Network Time Protocol Service With Skewed Clock</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><span class="ql-type-badge">services</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>_asset.protocol:ntp and protocol:ntp and has:ntp.skew</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="_asset.protocol:ntp and protocol:ntp and has:ntp.skew" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/services?search=_asset.protocol%3Antp+and+protocol%3Antp+and+has%3Antp.skew" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/services?search=_asset.protocol%3Antp+and+protocol%3Antp+and+has%3Antp.skew" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="_asset.protocol:ntp and protocol:ntp and has:ntp.skew"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="obsolete ssl protocol (_asset.protocol:=tls or _asset.protocol:=ssl2) and (protocol:=&#34;tls&#34; or protocol:=&#34;ssl2&#34;) and tls.supportedversionnames:&#34;ssl&#34; services best practice" data-ql-sev="low">
      <div class="ql-card-header">
        <div class="ql-title">Obsolete SSL Protocol</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><span class="ql-type-badge">services</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>(_asset.protocol:=tls OR _asset.protocol:=ssl2) AND (protocol:=&#34;tls&#34; OR protocol:=&#34;ssl2&#34;) AND tls.supportedVersionNames:&#34;SSL&#34;</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="(_asset.protocol:=tls OR _asset.protocol:=ssl2) AND (protocol:=&#34;tls&#34; OR protocol:=&#34;ssl2&#34;) AND tls.supportedVersionNames:&#34;SSL&#34;" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/services?search=%28_asset.protocol%3A%3Dtls+OR+_asset.protocol%3A%3Dssl2%29+AND+%28protocol%3A%3D%22tls%22+OR+protocol%3A%3D%22ssl2%22%29+AND+tls.supportedVersionNames%3A%22SSL%22" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/services?search=%28_asset.protocol%3A%3Dtls+OR+_asset.protocol%3A%3Dssl2%29+AND+%28protocol%3A%3D%22tls%22+OR+protocol%3A%3D%22ssl2%22%29+AND+tls.supportedVersionNames%3A%22SSL%22" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="(_asset.protocol:=tls OR _asset.protocol:=ssl2) AND (protocol:=&#34;tls&#34; OR protocol:=&#34;ssl2&#34;) AND tls.supportedVersionNames:&#34;SSL&#34;"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="open wireless network auth:open wireless best practice" data-ql-sev="low">
      <div class="ql-card-header">
        <div class="ql-title">Open Wireless Network</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><span class="ql-type-badge">wireless</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>auth:open</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="auth:open" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/wireless?search=auth%3Aopen" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/wireless?search=auth%3Aopen" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="auth:open"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="smb signing not required (_asset.protocol:=smb1 or _asset.protocol:=smb2 or _asset.protocol:=smb3) and (protocol:=smb1 or protocol:=smb2 or protocol:=smb3) and has:smb.signing and not smb.signing:required services best practice" data-ql-sev="low">
      <div class="ql-card-header">
        <div class="ql-title">SMB Signing Not Required</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><span class="ql-type-badge">services</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>(_asset.protocol:=smb1 OR _asset.protocol:=smb2 OR _asset.protocol:=smb3) AND (protocol:=smb1 OR protocol:=smb2 OR protocol:=smb3) AND has:smb.signing AND NOT smb.signing:required</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="(_asset.protocol:=smb1 OR _asset.protocol:=smb2 OR _asset.protocol:=smb3) AND (protocol:=smb1 OR protocol:=smb2 OR protocol:=smb3) AND has:smb.signing AND NOT smb.signing:required" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/services?search=%28_asset.protocol%3A%3Dsmb1+OR+_asset.protocol%3A%3Dsmb2+OR+_asset.protocol%3A%3Dsmb3%29+AND+%28protocol%3A%3Dsmb1+OR+protocol%3A%3Dsmb2+OR+protocol%3A%3Dsmb3%29+AND+has%3Asmb.signing+AND+NOT+smb.signing%3Arequired" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/services?search=%28_asset.protocol%3A%3Dsmb1+OR+_asset.protocol%3A%3Dsmb2+OR+_asset.protocol%3A%3Dsmb3%29+AND+%28protocol%3A%3Dsmb1+OR+protocol%3A%3Dsmb2+OR+protocol%3A%3Dsmb3%29+AND+has%3Asmb.signing+AND+NOT+smb.signing%3Arequired" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="(_asset.protocol:=smb1 OR _asset.protocol:=smb2 OR _asset.protocol:=smb3) AND (protocol:=smb1 OR protocol:=smb2 OR protocol:=smb3) AND has:smb.signing AND NOT smb.signing:required"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="smb version 1 enabled _asset.protocol:=smb1 protocol:=smb1 services best practice" data-ql-sev="low">
      <div class="ql-card-header">
        <div class="ql-title">SMB Version 1 Enabled</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><span class="ql-type-badge">services</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>_asset.protocol:=smb1 protocol:=smb1</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="_asset.protocol:=smb1 protocol:=smb1" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/services?search=_asset.protocol%3A%3Dsmb1+protocol%3A%3Dsmb1" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/services?search=_asset.protocol%3A%3Dsmb1+protocol%3A%3Dsmb1" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="_asset.protocol:=smb1 protocol:=smb1"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="snmp default community _asset.protocol:snmp and protocol:snmp and has:snmp.defaultcommunities services best practice" data-ql-sev="low">
      <div class="ql-card-header">
        <div class="ql-title">SNMP Default Community</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><span class="ql-type-badge">services</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>_asset.protocol:snmp AND protocol:snmp AND has:snmp.defaultCommunities</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="_asset.protocol:snmp AND protocol:snmp AND has:snmp.defaultCommunities" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/services?search=_asset.protocol%3Asnmp+AND+protocol%3Asnmp+AND+has%3Asnmp.defaultCommunities" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/services?search=_asset.protocol%3Asnmp+AND+protocol%3Asnmp+AND+has%3Asnmp.defaultCommunities" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="_asset.protocol:snmp AND protocol:snmp AND has:snmp.defaultCommunities"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="services supporting tls 1.0 _asset.protocol:=tls and tls.supportedversionnames:tlsv1.0 services best practice" data-ql-sev="low">
      <div class="ql-card-header">
        <div class="ql-title">Services Supporting TLS 1.0</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><span class="ql-type-badge">services</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>_asset.protocol:=tls AND tls.supportedVersionNames:TLSv1.0</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="_asset.protocol:=tls AND tls.supportedVersionNames:TLSv1.0" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/services?search=_asset.protocol%3A%3Dtls+AND+tls.supportedVersionNames%3ATLSv1.0" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/services?search=_asset.protocol%3A%3Dtls+AND+tls.supportedVersionNames%3ATLSv1.0" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="_asset.protocol:=tls AND tls.supportedVersionNames:TLSv1.0"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="services supporting tls 1.1 _asset.protocol:=tls and tls.supportedversionnames:tlsv1.1 services best practice" data-ql-sev="low">
      <div class="ql-card-header">
        <div class="ql-title">Services Supporting TLS 1.1</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><span class="ql-type-badge">services</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>_asset.protocol:=tls AND tls.supportedVersionNames:TLSv1.1</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="_asset.protocol:=tls AND tls.supportedVersionNames:TLSv1.1" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/services?search=_asset.protocol%3A%3Dtls+AND+tls.supportedVersionNames%3ATLSv1.1" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/services?search=_asset.protocol%3A%3Dtls+AND+tls.supportedVersionNames%3ATLSv1.1" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="_asset.protocol:=tls AND tls.supportedVersionNames:TLSv1.1"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="services without hsts _asset.protocol:=tls and protocol:=http protocol:=tls not has:http.head.stricttransportsecurity services best practice" data-ql-sev="low">
      <div class="ql-card-header">
        <div class="ql-title">Services Without HSTS</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><span class="ql-type-badge">services</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>_asset.protocol:=tls AND protocol:=http protocol:=tls NOT has:http.head.strictTransportSecurity</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="_asset.protocol:=tls AND protocol:=http protocol:=tls NOT has:http.head.strictTransportSecurity" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/services?search=_asset.protocol%3A%3Dtls+AND+protocol%3A%3Dhttp+protocol%3A%3Dtls+NOT+has%3Ahttp.head.strictTransportSecurity" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/services?search=_asset.protocol%3A%3Dtls+AND+protocol%3A%3Dhttp+protocol%3A%3Dtls+NOT+has%3Ahttp.head.strictTransportSecurity" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="_asset.protocol:=tls AND protocol:=http protocol:=tls NOT has:http.head.strictTransportSecurity"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="wireless network using wep encryption enc:wep wireless best practice" data-ql-sev="low">
      <div class="ql-card-header">
        <div class="ql-title">Wireless Network Using WEP Encryption</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><span class="ql-type-badge">wireless</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>enc:wep</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="enc:wep" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/wireless?search=enc%3Awep" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/wireless?search=enc%3Awep" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="enc:wep"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="active directory account password does not expire passwordneverexpires:true users best practice" data-ql-sev="info">
      <div class="ql-card-header">
        <div class="ql-title">Active Directory Account Password Does Not Expire</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><span class="ql-type-badge">users</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>passwordNeverExpires:true</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="passwordNeverExpires:true" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/users?search=passwordNeverExpires%3Atrue" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/users?search=passwordNeverExpires%3Atrue" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="passwordNeverExpires:true"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
  </div>
</div>
<div class="ql-category" id="ql-certificates">
  <button class="ql-cat-header" onclick="qlToggleCat(this)"><span class="ql-cat-title">Certificates</span><span class="ql-cat-count">5 queries</span><span class="ql-cat-chevron">&#9660;</span></button>
  <div class="ql-cat-body">
    <div class="ql-card" data-ql-search="private key is widely shared source:runzero and (foreign_id:=rz-ioasm-pubkey-widely-shared or foreign_id:=rz-ioasm-pubkey-known-private) vulnerabilities certificates" data-ql-sev="medium">
      <div class="ql-card-header">
        <div class="ql-title">Private Key Is Widely Shared</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><span class="ql-type-badge">vulnerabilities</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>source:runzero AND (foreign_id:=rz-ioasm-pubkey-widely-shared OR foreign_id:=rz-ioasm-pubkey-known-private)</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="source:runzero AND (foreign_id:=rz-ioasm-pubkey-widely-shared OR foreign_id:=rz-ioasm-pubkey-known-private)" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/vulnerabilities?search=source%3Arunzero+AND+%28foreign_id%3A%3Drz-ioasm-pubkey-widely-shared+OR+foreign_id%3A%3Drz-ioasm-pubkey-known-private%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/vulnerabilities?search=source%3Arunzero+AND+%28foreign_id%3A%3Drz-ioasm-pubkey-widely-shared+OR+foreign_id%3A%3Drz-ioasm-pubkey-known-private%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="source:runzero AND (foreign_id:=rz-ioasm-pubkey-widely-shared OR foreign_id:=rz-ioasm-pubkey-known-private)"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="certificate with insecure public key public_key_insecure:true certificates certificates" data-ql-sev="low">
      <div class="ql-card-header">
        <div class="ql-title">Certificate With Insecure Public Key</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><span class="ql-type-badge">certificates</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>public_key_insecure:true</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="public_key_insecure:true" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/certificates?search=public_key_insecure%3Atrue" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/certificates?search=public_key_insecure%3Atrue" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="public_key_insecure:true"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="certificate with insecure signature algorithm signature_algorithm_insecure:true is_ca:false certificates certificates" data-ql-sev="low">
      <div class="ql-card-header">
        <div class="ql-title">Certificate With Insecure Signature Algorithm</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><span class="ql-type-badge">certificates</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>signature_algorithm_insecure:true is_ca:false</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="signature_algorithm_insecure:true is_ca:false" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/certificates?search=signature_algorithm_insecure%3Atrue+is_ca%3Afalse" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/certificates?search=signature_algorithm_insecure%3Atrue+is_ca%3Afalse" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="signature_algorithm_insecure:true is_ca:false"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="expired certificate on tls service _asset.protocol:tls and tls.notafterts:&lt;now services certificates" data-ql-sev="low">
      <div class="ql-card-header">
        <div class="ql-title">Expired Certificate On TLS Service</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><span class="ql-type-badge">services</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>_asset.protocol:tls AND tls.notAfterTS:&lt;now</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="_asset.protocol:tls AND tls.notAfterTS:&lt;now" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/services?search=_asset.protocol%3Atls+AND+tls.notAfterTS%3A%3Cnow" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/services?search=_asset.protocol%3Atls+AND+tls.notAfterTS%3A%3Cnow" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="_asset.protocol:tls AND tls.notAfterTS:&lt;now"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="certificate on tls service expires soon _asset.protocol:tls and tls.notafterts:&lt;6weeks and tls.notafterts:&gt;now services certificates" data-ql-sev="info">
      <div class="ql-card-header">
        <div class="ql-title">Certificate On TLS Service Expires Soon</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><span class="ql-type-badge">services</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>_asset.protocol:tls AND tls.notAfterTS:&lt;6weeks AND tls.notAfterTS:&gt;now</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="_asset.protocol:tls AND tls.notAfterTS:&lt;6weeks AND tls.notAfterTS:&gt;now" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/services?search=_asset.protocol%3Atls+AND+tls.notAfterTS%3A%3C6weeks+AND+tls.notAfterTS%3A%3Enow" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/services?search=_asset.protocol%3Atls+AND+tls.notAfterTS%3A%3C6weeks+AND+tls.notAfterTS%3A%3Enow" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="_asset.protocol:tls AND tls.notAfterTS:&lt;6weeks AND tls.notAfterTS:&gt;now"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
  </div>
</div>
<div class="ql-category" id="ql-compliance">
  <button class="ql-cat-header" onclick="qlToggleCat(this)"><span class="ql-cat-title">Compliance</span><span class="ql-cat-count">5 queries</span><span class="ql-cat-chevron">&#9660;</span></button>
  <div class="ql-cat-body">
    <div class="ql-card" data-ql-search="cisa bod 26-02 end-of-support edge devices (os_eol_extended:&gt;0 and os_eol_extended:&lt;=now) and has_public:t and not (type:server or type:desktop or type:laptop) assets compliance" data-ql-sev="critical">
      <div class="ql-card-header">
        <div class="ql-title">CISA BOD 26-02 End-Of-Support Edge Devices</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><span class="ql-type-badge">assets</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>(os_eol_extended:&gt;0 AND os_eol_extended:&lt;=now) AND has_public:t AND NOT (type:Server OR type:Desktop OR type:Laptop)</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="(os_eol_extended:&gt;0 AND os_eol_extended:&lt;=now) AND has_public:t AND NOT (type:Server OR type:Desktop OR type:Laptop)" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/?search=%28os_eol_extended%3A%3E0+AND+os_eol_extended%3A%3C%3Dnow%29+AND+has_public%3At+AND+NOT+%28type%3AServer+OR+type%3ADesktop+OR+type%3ALaptop%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/?search=%28os_eol_extended%3A%3E0+AND+os_eol_extended%3A%3C%3Dnow%29+AND+has_public%3At+AND+NOT+%28type%3AServer+OR+type%3ADesktop+OR+type%3ALaptop%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="(os_eol_extended:&gt;0 AND os_eol_extended:&lt;=now) AND has_public:t AND NOT (type:Server OR type:Desktop OR type:Laptop)"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="kaspersky lab security software edr.name:kaspersky assets compliance" data-ql-sev="info">
      <div class="ql-card-header">
        <div class="ql-title">Kaspersky Lab Security Software</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><span class="ql-type-badge">assets</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>edr.name:Kaspersky</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="edr.name:Kaspersky" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/?search=edr.name%3AKaspersky" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/?search=edr.name%3AKaspersky" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="edr.name:Kaspersky"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="kaspersky lab software vendor:=kaspersky software compliance" data-ql-sev="info">
      <div class="ql-card-header">
        <div class="ql-title">Kaspersky Lab Software</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><span class="ql-type-badge">software</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>vendor:=Kaspersky</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="vendor:=Kaspersky" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/software?search=vendor%3A%3DKaspersky" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/software?search=vendor%3A%3DKaspersky" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="vendor:=Kaspersky"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="ndaa 2019 section 889 equipment ((mac_vendor:=&#34;zte corporation&#34; or mac_vendor:huawei or mac_vendor:crrc or mac_vendor:dahua or mac_vendor:hikvision or mac_vendor:hisilicon or mac_vendor:panda or mac_vendor:dawning or mac_vendor:hangzhou or mac_vendor:hytera or mac_vendor:inspur or mac_vendor:&#34;aero engine corporation of china&#34; or mac_vendor:&#34;aviation industry corporation of china&#34; or mac_vendor:&#34;china aerospace&#34; or mac_vendor:&#34;china electronics&#34; or mac_vendor:&#34;china general nuclear power&#34; or mac_vendor:&#34;china mobile&#34; or mac_vendor:&#34;china national nuclear power&#34; or mac_vendor:&#34;china north industries group&#34; or mac_vendor:&#34;china railway&#34; or mac_vendor:&#34;china shipbuilding&#34; or mac_vendor:&#34;china south industries group&#34; or mac_vendor:&#34;china state shipbuilding&#34; or mac_vendor:&#34;china telecommunications&#34; or mac_vendor:ztec or mac_vendor:ztek or mac_vendor:&#34;z-tec&#34; or mac_vendor:5shanghai or mac_vendor:&#34;hella sonnen&#34; or mac_vendor:anhui or mac_vendor:&#34;technology sdn bhd&#34; or mac_vendor:azteq) or (hw:=&#34;zte%&#34; or hw:huawei or hw:crrc or hw:dahua or hw:hikvision or hw:hisilicon or hw:panda or hw:dawning or hw:hangzhou or hw:hytera or hw:inspur or hw:&#34;aero engine corporation of china&#34; or hw:&#34;aviation industry corporation of china&#34; or hw:&#34;china aerospace&#34; or hw:&#34;china electronics&#34; or hw:&#34;china general nuclear power&#34; or hw:&#34;china mobile&#34; or hw:&#34;china national nuclear power&#34; or hw:&#34;china north industries group&#34; or hw:&#34;china railway&#34; or hw:&#34;china shipbuilding&#34; or hw:&#34;china south industries group&#34; or hw:&#34;china state shipbuilding&#34; or hw:&#34;china telecommunications&#34; or hw:ztec or hw:ztek or hw:&#34;z-tec&#34; or hw:5shanghai or hw:&#34;hella sonnen&#34; or hw:anhui or hw:&#34;technology sdn bhd&#34; or hw:azteq)) assets compliance" data-ql-sev="info">
      <div class="ql-card-header">
        <div class="ql-title">NDAA 2019 Section 889 Equipment</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><span class="ql-type-badge">assets</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>((mac_vendor:=&#34;zte corporation&#34; OR mac_vendor:huawei OR mac_vendor:CRRC OR mac_vendor:dahua OR mac_vendor:hikvision OR mac_vendor:hisilicon OR mac_vendor:panda OR mac_vendor:dawning OR mac_vendor:hangzhou OR mac_vendor:hytera OR mac_vendor:inspur OR mac_vendor:&#34;Aero Engine Corporation of China&#34; OR mac_vendor:&#34;Aviation Industry Corporation of China&#34; OR mac_vendor:&#34;China Aerospace&#34; OR mac_vendor:&#34;China Electronics&#34; OR mac_vendor:&#34;China General Nuclear Power&#34; OR mac_vendor:&#34;China Mobile&#34; OR mac_vendor:&#34;China National Nuclear Power&#34; OR mac_vendor:&#34;China North Industries Group&#34; OR mac_vendor:&#34;China Railway&#34; OR mac_vendor:&#34;China Shipbuilding&#34; OR mac_vendor:&#34;China South Industries Group&#34; OR mac_vendor:&#34;China State Shipbuilding&#34; OR mac_vendor:&#34;China Telecommunications&#34; OR mac_vendor:ztec OR mac_vendor:ztek OR mac_vendor:&#34;z-tec&#34; OR mac_vendor:5shanghai OR mac_vendor:&#34;Hella Sonnen&#34; OR mac_vendor:anhui OR mac_vendor:&#34;technology sdn bhd&#34; OR mac_vendor:azteq) OR (hw:=&#34;ZTE%&#34; OR hw:huawei OR hw:CRRC OR hw:dahua OR hw:hikvision OR hw:hisilicon OR hw:panda OR hw:dawning OR hw:hangzhou OR hw:hytera OR hw:inspur OR hw:&#34;Aero Engine Corporation of China&#34; OR hw:&#34;Aviation Industry Corporation of China&#34; OR hw:&#34;China Aerospace&#34; OR hw:&#34;China Electronics&#34; OR hw:&#34;China General Nuclear Power&#34; OR hw:&#34;China Mobile&#34; OR hw:&#34;China National Nuclear Power&#34; OR hw:&#34;China North Industries Group&#34; OR hw:&#34;China Railway&#34; OR hw:&#34;China Shipbuilding&#34; OR hw:&#34;China South Industries Group&#34; OR hw:&#34;China State Shipbuilding&#34; OR hw:&#34;China Telecommunications&#34; OR hw:ztec OR hw:ztek OR hw:&#34;z-tec&#34; OR hw:5shanghai OR hw:&#34;Hella Sonnen&#34; OR hw:anhui OR hw:&#34;technology sdn bhd&#34; OR hw:azteq))</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="((mac_vendor:=&#34;zte corporation&#34; OR mac_vendor:huawei OR mac_vendor:CRRC OR mac_vendor:dahua OR mac_vendor:hikvision OR mac_vendor:hisilicon OR mac_vendor:panda OR mac_vendor:dawning OR mac_vendor:hangzhou OR mac_vendor:hytera OR mac_vendor:inspur OR mac_vendor:&#34;Aero Engine Corporation of China&#34; OR mac_vendor:&#34;Aviation Industry Corporation of China&#34; OR mac_vendor:&#34;China Aerospace&#34; OR mac_vendor:&#34;China Electronics&#34; OR mac_vendor:&#34;China General Nuclear Power&#34; OR mac_vendor:&#34;China Mobile&#34; OR mac_vendor:&#34;China National Nuclear Power&#34; OR mac_vendor:&#34;China North Industries Group&#34; OR mac_vendor:&#34;China Railway&#34; OR mac_vendor:&#34;China Shipbuilding&#34; OR mac_vendor:&#34;China South Industries Group&#34; OR mac_vendor:&#34;China State Shipbuilding&#34; OR mac_vendor:&#34;China Telecommunications&#34; OR mac_vendor:ztec OR mac_vendor:ztek OR mac_vendor:&#34;z-tec&#34; OR mac_vendor:5shanghai OR mac_vendor:&#34;Hella Sonnen&#34; OR mac_vendor:anhui OR mac_vendor:&#34;technology sdn bhd&#34; OR mac_vendor:azteq) OR (hw:=&#34;ZTE%&#34; OR hw:huawei OR hw:CRRC OR hw:dahua OR hw:hikvision OR hw:hisilicon OR hw:panda OR hw:dawning OR hw:hangzhou OR hw:hytera OR hw:inspur OR hw:&#34;Aero Engine Corporation of China&#34; OR hw:&#34;Aviation Industry Corporation of China&#34; OR hw:&#34;China Aerospace&#34; OR hw:&#34;China Electronics&#34; OR hw:&#34;China General Nuclear Power&#34; OR hw:&#34;China Mobile&#34; OR hw:&#34;China National Nuclear Power&#34; OR hw:&#34;China North Industries Group&#34; OR hw:&#34;China Railway&#34; OR hw:&#34;China Shipbuilding&#34; OR hw:&#34;China South Industries Group&#34; OR hw:&#34;China State Shipbuilding&#34; OR hw:&#34;China Telecommunications&#34; OR hw:ztec OR hw:ztek OR hw:&#34;z-tec&#34; OR hw:5shanghai OR hw:&#34;Hella Sonnen&#34; OR hw:anhui OR hw:&#34;technology sdn bhd&#34; OR hw:azteq))" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/?search=%28%28mac_vendor%3A%3D%22zte+corporation%22+OR+mac_vendor%3Ahuawei+OR+mac_vendor%3ACRRC+OR+mac_vendor%3Adahua+OR+mac_vendor%3Ahikvision+OR+mac_vendor%3Ahisilicon+OR+mac_vendor%3Apanda+OR+mac_vendor%3Adawning+OR+mac_vendor%3Ahangzhou+OR+mac_vendor%3Ahytera+OR+mac_vendor%3Ainspur+OR+mac_vendor%3A%22Aero+Engine+Corporation+of+China%22+OR+mac_vendor%3A%22Aviation+Industry+Corporation+of+China%22+OR+mac_vendor%3A%22China+Aerospace%22+OR+mac_vendor%3A%22China+Electronics%22+OR+mac_vendor%3A%22China+General+Nuclear+Power%22+OR+mac_vendor%3A%22China+Mobile%22+OR+mac_vendor%3A%22China+National+Nuclear+Power%22+OR+mac_vendor%3A%22China+North+Industries+Group%22+OR+mac_vendor%3A%22China+Railway%22+OR+mac_vendor%3A%22China+Shipbuilding%22+OR+mac_vendor%3A%22China+South+Industries+Group%22+OR+mac_vendor%3A%22China+State+Shipbuilding%22+OR+mac_vendor%3A%22China+Telecommunications%22+OR+mac_vendor%3Aztec+OR+mac_vendor%3Aztek+OR+mac_vendor%3A%22z-tec%22+OR+mac_vendor%3A5shanghai+OR+mac_vendor%3A%22Hella+Sonnen%22+OR+mac_vendor%3Aanhui+OR+mac_vendor%3A%22technology+sdn+bhd%22+OR+mac_vendor%3Aazteq%29+OR+%28hw%3A%3D%22ZTE%25%22+OR+hw%3Ahuawei+OR+hw%3ACRRC+OR+hw%3Adahua+OR+hw%3Ahikvision+OR+hw%3Ahisilicon+OR+hw%3Apanda+OR+hw%3Adawning+OR+hw%3Ahangzhou+OR+hw%3Ahytera+OR+hw%3Ainspur+OR+hw%3A%22Aero+Engine+Corporation+of+China%22+OR+hw%3A%22Aviation+Industry+Corporation+of+China%22+OR+hw%3A%22China+Aerospace%22+OR+hw%3A%22China+Electronics%22+OR+hw%3A%22China+General+Nuclear+Power%22+OR+hw%3A%22China+Mobile%22+OR+hw%3A%22China+National+Nuclear+Power%22+OR+hw%3A%22China+North+Industries+Group%22+OR+hw%3A%22China+Railway%22+OR+hw%3A%22China+Shipbuilding%22+OR+hw%3A%22China+South+Industries+Group%22+OR+hw%3A%22China+State+Shipbuilding%22+OR+hw%3A%22China+Telecommunications%22+OR+hw%3Aztec+OR+hw%3Aztek+OR+hw%3A%22z-tec%22+OR+hw%3A5shanghai+OR+hw%3A%22Hella+Sonnen%22+OR+hw%3Aanhui+OR+hw%3A%22technology+sdn+bhd%22+OR+hw%3Aazteq%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/?search=%28%28mac_vendor%3A%3D%22zte+corporation%22+OR+mac_vendor%3Ahuawei+OR+mac_vendor%3ACRRC+OR+mac_vendor%3Adahua+OR+mac_vendor%3Ahikvision+OR+mac_vendor%3Ahisilicon+OR+mac_vendor%3Apanda+OR+mac_vendor%3Adawning+OR+mac_vendor%3Ahangzhou+OR+mac_vendor%3Ahytera+OR+mac_vendor%3Ainspur+OR+mac_vendor%3A%22Aero+Engine+Corporation+of+China%22+OR+mac_vendor%3A%22Aviation+Industry+Corporation+of+China%22+OR+mac_vendor%3A%22China+Aerospace%22+OR+mac_vendor%3A%22China+Electronics%22+OR+mac_vendor%3A%22China+General+Nuclear+Power%22+OR+mac_vendor%3A%22China+Mobile%22+OR+mac_vendor%3A%22China+National+Nuclear+Power%22+OR+mac_vendor%3A%22China+North+Industries+Group%22+OR+mac_vendor%3A%22China+Railway%22+OR+mac_vendor%3A%22China+Shipbuilding%22+OR+mac_vendor%3A%22China+South+Industries+Group%22+OR+mac_vendor%3A%22China+State+Shipbuilding%22+OR+mac_vendor%3A%22China+Telecommunications%22+OR+mac_vendor%3Aztec+OR+mac_vendor%3Aztek+OR+mac_vendor%3A%22z-tec%22+OR+mac_vendor%3A5shanghai+OR+mac_vendor%3A%22Hella+Sonnen%22+OR+mac_vendor%3Aanhui+OR+mac_vendor%3A%22technology+sdn+bhd%22+OR+mac_vendor%3Aazteq%29+OR+%28hw%3A%3D%22ZTE%25%22+OR+hw%3Ahuawei+OR+hw%3ACRRC+OR+hw%3Adahua+OR+hw%3Ahikvision+OR+hw%3Ahisilicon+OR+hw%3Apanda+OR+hw%3Adawning+OR+hw%3Ahangzhou+OR+hw%3Ahytera+OR+hw%3Ainspur+OR+hw%3A%22Aero+Engine+Corporation+of+China%22+OR+hw%3A%22Aviation+Industry+Corporation+of+China%22+OR+hw%3A%22China+Aerospace%22+OR+hw%3A%22China+Electronics%22+OR+hw%3A%22China+General+Nuclear+Power%22+OR+hw%3A%22China+Mobile%22+OR+hw%3A%22China+National+Nuclear+Power%22+OR+hw%3A%22China+North+Industries+Group%22+OR+hw%3A%22China+Railway%22+OR+hw%3A%22China+Shipbuilding%22+OR+hw%3A%22China+South+Industries+Group%22+OR+hw%3A%22China+State+Shipbuilding%22+OR+hw%3A%22China+Telecommunications%22+OR+hw%3Aztec+OR+hw%3Aztek+OR+hw%3A%22z-tec%22+OR+hw%3A5shanghai+OR+hw%3A%22Hella+Sonnen%22+OR+hw%3Aanhui+OR+hw%3A%22technology+sdn+bhd%22+OR+hw%3Aazteq%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="((mac_vendor:=&#34;zte corporation&#34; OR mac_vendor:huawei OR mac_vendor:CRRC OR mac_vendor:dahua OR mac_vendor:hikvision OR mac_vendor:hisilicon OR mac_vendor:panda OR mac_vendor:dawning OR mac_vendor:hangzhou OR mac_vendor:hytera OR mac_vendor:inspur OR mac_vendor:&#34;Aero Engine Corporation of China&#34; OR mac_vendor:&#34;Aviation Industry Corporation of China&#34; OR mac_vendor:&#34;China Aerospace&#34; OR mac_vendor:&#34;China Electronics&#34; OR mac_vendor:&#34;China General Nuclear Power&#34; OR mac_vendor:&#34;China Mobile&#34; OR mac_vendor:&#34;China National Nuclear Power&#34; OR mac_vendor:&#34;China North Industries Group&#34; OR mac_vendor:&#34;China Railway&#34; OR mac_vendor:&#34;China Shipbuilding&#34; OR mac_vendor:&#34;China South Industries Group&#34; OR mac_vendor:&#34;China State Shipbuilding&#34; OR mac_vendor:&#34;China Telecommunications&#34; OR mac_vendor:ztec OR mac_vendor:ztek OR mac_vendor:&#34;z-tec&#34; OR mac_vendor:5shanghai OR mac_vendor:&#34;Hella Sonnen&#34; OR mac_vendor:anhui OR mac_vendor:&#34;technology sdn bhd&#34; OR mac_vendor:azteq) OR (hw:=&#34;ZTE%&#34; OR hw:huawei OR hw:CRRC OR hw:dahua OR hw:hikvision OR hw:hisilicon OR hw:panda OR hw:dawning OR hw:hangzhou OR hw:hytera OR hw:inspur OR hw:&#34;Aero Engine Corporation of China&#34; OR hw:&#34;Aviation Industry Corporation of China&#34; OR hw:&#34;China Aerospace&#34; OR hw:&#34;China Electronics&#34; OR hw:&#34;China General Nuclear Power&#34; OR hw:&#34;China Mobile&#34; OR hw:&#34;China National Nuclear Power&#34; OR hw:&#34;China North Industries Group&#34; OR hw:&#34;China Railway&#34; OR hw:&#34;China Shipbuilding&#34; OR hw:&#34;China South Industries Group&#34; OR hw:&#34;China State Shipbuilding&#34; OR hw:&#34;China Telecommunications&#34; OR hw:ztec OR hw:ztek OR hw:&#34;z-tec&#34; OR hw:5shanghai OR hw:&#34;Hella Sonnen&#34; OR hw:anhui OR hw:&#34;technology sdn bhd&#34; OR hw:azteq))"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="secure networks act section 2 equipment (hw:huawei or hw:=&#34;zte%&#34; or hw:hytera or hw:hikvision or hw:dahua or hw:&#34;china mobile&#34; or hw:&#34;china telecom&#34; or hw:&#34;china unicom&#34; or hw:&#34;pacific networks corp&#34; or hw:&#34;comnet (usa) llc&#34; or hw:zhejiang) or (mac_vendor:huawei or mac_vendor:=&#34;zte%&#34; or mac_vendor:hytera or mac_vendor:hikvision or mac_vendor:dahua or mac_vendor:&#34;china mobile&#34; or mac_vendor:&#34;china telecom&#34; or mac_vendor:&#34;china unicom&#34; or mac_vendor:&#34;pacific networks corp&#34; or mac_vendor:&#34;comnet (usa) llc&#34; or mac_vendor:&#34;zhejiang&#34;) assets compliance" data-ql-sev="info">
      <div class="ql-card-header">
        <div class="ql-title">Secure Networks Act Section 2 Equipment</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><span class="ql-type-badge">assets</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>(hw:huawei OR hw:=&#34;zte%&#34; OR hw:hytera OR hw:hikvision OR hw:dahua OR hw:&#34;china mobile&#34; OR hw:&#34;china telecom&#34; OR hw:&#34;china unicom&#34; OR hw:&#34;pacific networks corp&#34; OR hw:&#34;comnet (usa) llc&#34; OR hw:zhejiang) OR (mac_vendor:huawei OR mac_vendor:=&#34;zte%&#34; OR mac_vendor:hytera OR mac_vendor:hikvision OR mac_vendor:dahua OR mac_vendor:&#34;china mobile&#34; OR mac_vendor:&#34;china telecom&#34; OR mac_vendor:&#34;china unicom&#34; OR mac_vendor:&#34;pacific networks corp&#34; OR mac_vendor:&#34;comnet (usa) llc&#34; OR mac_vendor:&#34;zhejiang&#34;)</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="(hw:huawei OR hw:=&#34;zte%&#34; OR hw:hytera OR hw:hikvision OR hw:dahua OR hw:&#34;china mobile&#34; OR hw:&#34;china telecom&#34; OR hw:&#34;china unicom&#34; OR hw:&#34;pacific networks corp&#34; OR hw:&#34;comnet (usa) llc&#34; OR hw:zhejiang) OR (mac_vendor:huawei OR mac_vendor:=&#34;zte%&#34; OR mac_vendor:hytera OR mac_vendor:hikvision OR mac_vendor:dahua OR mac_vendor:&#34;china mobile&#34; OR mac_vendor:&#34;china telecom&#34; OR mac_vendor:&#34;china unicom&#34; OR mac_vendor:&#34;pacific networks corp&#34; OR mac_vendor:&#34;comnet (usa) llc&#34; OR mac_vendor:&#34;zhejiang&#34;)" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/?search=%28hw%3Ahuawei+OR+hw%3A%3D%22zte%25%22+OR+hw%3Ahytera+OR+hw%3Ahikvision+OR+hw%3Adahua+OR+hw%3A%22china+mobile%22+OR+hw%3A%22china+telecom%22+OR+hw%3A%22china+unicom%22+OR+hw%3A%22pacific+networks+corp%22+OR+hw%3A%22comnet+%28usa%29+llc%22+OR+hw%3Azhejiang%29+OR+%28mac_vendor%3Ahuawei+OR+mac_vendor%3A%3D%22zte%25%22+OR+mac_vendor%3Ahytera+OR+mac_vendor%3Ahikvision+OR+mac_vendor%3Adahua+OR+mac_vendor%3A%22china+mobile%22+OR+mac_vendor%3A%22china+telecom%22+OR+mac_vendor%3A%22china+unicom%22+OR+mac_vendor%3A%22pacific+networks+corp%22+OR+mac_vendor%3A%22comnet+%28usa%29+llc%22+OR+mac_vendor%3A%22zhejiang%22%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/?search=%28hw%3Ahuawei+OR+hw%3A%3D%22zte%25%22+OR+hw%3Ahytera+OR+hw%3Ahikvision+OR+hw%3Adahua+OR+hw%3A%22china+mobile%22+OR+hw%3A%22china+telecom%22+OR+hw%3A%22china+unicom%22+OR+hw%3A%22pacific+networks+corp%22+OR+hw%3A%22comnet+%28usa%29+llc%22+OR+hw%3Azhejiang%29+OR+%28mac_vendor%3Ahuawei+OR+mac_vendor%3A%3D%22zte%25%22+OR+mac_vendor%3Ahytera+OR+mac_vendor%3Ahikvision+OR+mac_vendor%3Adahua+OR+mac_vendor%3A%22china+mobile%22+OR+mac_vendor%3A%22china+telecom%22+OR+mac_vendor%3A%22china+unicom%22+OR+mac_vendor%3A%22pacific+networks+corp%22+OR+mac_vendor%3A%22comnet+%28usa%29+llc%22+OR+mac_vendor%3A%22zhejiang%22%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="(hw:huawei OR hw:=&#34;zte%&#34; OR hw:hytera OR hw:hikvision OR hw:dahua OR hw:&#34;china mobile&#34; OR hw:&#34;china telecom&#34; OR hw:&#34;china unicom&#34; OR hw:&#34;pacific networks corp&#34; OR hw:&#34;comnet (usa) llc&#34; OR hw:zhejiang) OR (mac_vendor:huawei OR mac_vendor:=&#34;zte%&#34; OR mac_vendor:hytera OR mac_vendor:hikvision OR mac_vendor:dahua OR mac_vendor:&#34;china mobile&#34; OR mac_vendor:&#34;china telecom&#34; OR mac_vendor:&#34;china unicom&#34; OR mac_vendor:&#34;pacific networks corp&#34; OR mac_vendor:&#34;comnet (usa) llc&#34; OR mac_vendor:&#34;zhejiang&#34;)"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
  </div>
</div>
<div class="ql-category" id="ql-end-of-life">
  <button class="ql-cat-header" onclick="qlToggleCat(this)"><span class="ql-cat-title">End-of-Life</span><span class="ql-cat-count">15 queries</span><span class="ql-cat-chevron">&#9660;</span></button>
  <div class="ql-cat-body">
    <div class="ql-card" data-ql-search="sangoma freepbx ((vendor:=freepbx and product:=pbx) or (vendor:=sangoma and product:=freepbx)) and ((version:&gt;=&#34;2.0.0(%)&#34; and version:&lt;&#34;3.0.0(%)&#34;) or (version:&gt;=&#34;12.0.0(%)&#34; and version:&lt;&#34;15.0.0(%)&#34;)) software end-of-life" data-ql-sev="critical">
      <div class="ql-card-header">
        <div class="ql-title">Sangoma FreePBX</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><span class="ql-type-badge">software</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>((vendor:=FreePBX AND product:=PBX) OR (vendor:=Sangoma AND product:=FreePBX)) AND ((version:&gt;=&#34;2.0.0(%)&#34; AND version:&lt;&#34;3.0.0(%)&#34;) OR (version:&gt;=&#34;12.0.0(%)&#34; AND version:&lt;&#34;15.0.0(%)&#34;))</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="((vendor:=FreePBX AND product:=PBX) OR (vendor:=Sangoma AND product:=FreePBX)) AND ((version:&gt;=&#34;2.0.0(%)&#34; AND version:&lt;&#34;3.0.0(%)&#34;) OR (version:&gt;=&#34;12.0.0(%)&#34; AND version:&lt;&#34;15.0.0(%)&#34;))" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/software?search=%28%28vendor%3A%3DFreePBX+AND+product%3A%3DPBX%29+OR+%28vendor%3A%3DSangoma+AND+product%3A%3DFreePBX%29%29+AND+%28%28version%3A%3E%3D%222.0.0%28%25%29%22+AND+version%3A%3C%223.0.0%28%25%29%22%29+OR+%28version%3A%3E%3D%2212.0.0%28%25%29%22+AND+version%3A%3C%2215.0.0%28%25%29%22%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/software?search=%28%28vendor%3A%3DFreePBX+AND+product%3A%3DPBX%29+OR+%28vendor%3A%3DSangoma+AND+product%3A%3DFreePBX%29%29+AND+%28%28version%3A%3E%3D%222.0.0%28%25%29%22+AND+version%3A%3C%223.0.0%28%25%29%22%29+OR+%28version%3A%3E%3D%2212.0.0%28%25%29%22+AND+version%3A%3C%2215.0.0%28%25%29%22%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="((vendor:=FreePBX AND product:=PBX) OR (vendor:=Sangoma AND product:=FreePBX)) AND ((version:&gt;=&#34;2.0.0(%)&#34; AND version:&lt;&#34;3.0.0(%)&#34;) OR (version:&gt;=&#34;12.0.0(%)&#34; AND version:&lt;&#34;15.0.0(%)&#34;))"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="accellion file transfer appliance hw:&#34;accellion file transfer appliance&#34; assets end-of-life" data-ql-sev="high">
      <div class="ql-card-header">
        <div class="ql-title">Accellion File Transfer Appliance</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><span class="ql-type-badge">assets</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>hw:&#34;Accellion File Transfer Appliance&#34;</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="hw:&#34;Accellion File Transfer Appliance&#34;" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/?search=hw%3A%22Accellion+File+Transfer+Appliance%22" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/?search=hw%3A%22Accellion+File+Transfer+Appliance%22" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="hw:&#34;Accellion File Transfer Appliance&#34;"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="automationdirect mb-gateway hw:=&#34;automationdirect modbus gateway&#34; or hw:=&#34;automation direct modbus gateway&#34; assets end-of-life" data-ql-sev="high">
      <div class="ql-card-header">
        <div class="ql-title">AutomationDirect MB-GATEWAY</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><span class="ql-type-badge">assets</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>hw:=&#34;AutomationDirect Modbus Gateway&#34; OR hw:=&#34;Automation Direct Modbus Gateway&#34;</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="hw:=&#34;AutomationDirect Modbus Gateway&#34; OR hw:=&#34;Automation Direct Modbus Gateway&#34;" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/?search=hw%3A%3D%22AutomationDirect+Modbus+Gateway%22+OR+hw%3A%3D%22Automation+Direct+Modbus+Gateway%22" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/?search=hw%3A%3D%22AutomationDirect+Modbus+Gateway%22+OR+hw%3A%3D%22Automation+Direct+Modbus+Gateway%22" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="hw:=&#34;AutomationDirect Modbus Gateway&#34; OR hw:=&#34;Automation Direct Modbus Gateway&#34;"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="cisco small business routers hw:&#34;cisco rv0&#34; or hw:&#34;cisco rv110w&#34; or  hw:&#34;cisco rv130&#34; or hw:&#34;cisco rv132w&#34; or hw:&#34;cisco rv134w&#34; or     hw:&#34;cisco rv160&#34; or hw:&#34;cisco rv215&#34; or hw:&#34;cisco rv260&#34; or  hw:&#34;cisco rv320&#34; or hw:&#34;cisco rv325&#34; or hw:&#34;cisco rv340&#34; or hw:&#34;cisco rv345&#34;  assets end-of-life" data-ql-sev="high">
      <div class="ql-card-header">
        <div class="ql-title">Cisco Small Business Routers</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><span class="ql-type-badge">assets</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>hw:&#34;Cisco RV0&#34; OR hw:&#34;Cisco RV110W&#34; OR  hw:&#34;Cisco RV130&#34; OR hw:&#34;Cisco RV132W&#34; OR hw:&#34;Cisco RV134W&#34; OR     hw:&#34;Cisco RV160&#34; OR hw:&#34;Cisco RV215&#34; OR hw:&#34;Cisco RV260&#34; OR  hw:&#34;Cisco RV320&#34; OR hw:&#34;Cisco RV325&#34; OR hw:&#34;Cisco RV340&#34; OR hw:&#34;Cisco RV345&#34; </code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="hw:&#34;Cisco RV0&#34; OR hw:&#34;Cisco RV110W&#34; OR  hw:&#34;Cisco RV130&#34; OR hw:&#34;Cisco RV132W&#34; OR hw:&#34;Cisco RV134W&#34; OR     hw:&#34;Cisco RV160&#34; OR hw:&#34;Cisco RV215&#34; OR hw:&#34;Cisco RV260&#34; OR  hw:&#34;Cisco RV320&#34; OR hw:&#34;Cisco RV325&#34; OR hw:&#34;Cisco RV340&#34; OR hw:&#34;Cisco RV345&#34; " title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/?search=hw%3A%22Cisco+RV0%22+OR+hw%3A%22Cisco+RV110W%22+OR++hw%3A%22Cisco+RV130%22+OR+hw%3A%22Cisco+RV132W%22+OR+hw%3A%22Cisco+RV134W%22+OR+++++hw%3A%22Cisco+RV160%22+OR+hw%3A%22Cisco+RV215%22+OR+hw%3A%22Cisco+RV260%22+OR++hw%3A%22Cisco+RV320%22+OR+hw%3A%22Cisco+RV325%22+OR+hw%3A%22Cisco+RV340%22+OR+hw%3A%22Cisco+RV345%22+" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/?search=hw%3A%22Cisco+RV0%22+OR+hw%3A%22Cisco+RV110W%22+OR++hw%3A%22Cisco+RV130%22+OR+hw%3A%22Cisco+RV132W%22+OR+hw%3A%22Cisco+RV134W%22+OR+++++hw%3A%22Cisco+RV160%22+OR+hw%3A%22Cisco+RV215%22+OR+hw%3A%22Cisco+RV260%22+OR++hw%3A%22Cisco+RV320%22+OR+hw%3A%22Cisco+RV325%22+OR+hw%3A%22Cisco+RV340%22+OR+hw%3A%22Cisco+RV345%22+" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="hw:&#34;Cisco RV0&#34; OR hw:&#34;Cisco RV110W&#34; OR  hw:&#34;Cisco RV130&#34; OR hw:&#34;Cisco RV132W&#34; OR hw:&#34;Cisco RV134W&#34; OR     hw:&#34;Cisco RV160&#34; OR hw:&#34;Cisco RV215&#34; OR hw:&#34;Cisco RV260&#34; OR  hw:&#34;Cisco RV320&#34; OR hw:&#34;Cisco RV325&#34; OR hw:&#34;Cisco RV340&#34; OR hw:&#34;Cisco RV345&#34; "><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="cisco small business switches hw:&#34;cisco&#34; and type:&#34;switch&#34; and ( hw:&#34;srw224g4-k9-&#34; or hw:&#34;srw2016-k9-&#34; or hw:&#34;sg500x-&#34; or hw:&#34;sf300-&#34; or hw:&#34;srw208g-k9-&#34; or hw:&#34;sg300-&#34; or hw:&#34;srw2048-k9-&#34; or hw:&#34;slm2048pt-&#34; or hw:&#34;srw208-k9-&#34; or hw:&#34;sf302-&#34; or hw:&#34;slm2008pt-&#34; or hw:&#34;slm224pt-&#34; or hw:&#34;sf500-&#34; or hw:&#34;slm2008t-&#34; or hw:&#34;sg500-&#34; or hw:&#34;sg200-&#34; or hw:&#34;sf200-&#34; or hw:&#34;slm224gt-&#34; or hw:&#34;slm2016t-&#34;) assets end-of-life" data-ql-sev="high">
      <div class="ql-card-header">
        <div class="ql-title">Cisco Small Business Switches</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><span class="ql-type-badge">assets</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>hw:&#34;Cisco&#34; and type:&#34;switch&#34; and ( hw:&#34;SRW224G4-K9-&#34; OR hw:&#34;SRW2016-K9-&#34; OR hw:&#34;SG500X-&#34; OR hw:&#34;SF300-&#34; OR hw:&#34;SRW208G-K9-&#34; OR hw:&#34;SG300-&#34; OR hw:&#34;SRW2048-K9-&#34; OR hw:&#34;SLM2048PT-&#34; OR hw:&#34;SRW208-K9-&#34; OR hw:&#34;SF302-&#34; OR hw:&#34;SLM2008PT-&#34; OR hw:&#34;SLM224PT-&#34; OR hw:&#34;SF500-&#34; OR hw:&#34;SLM2008T-&#34; OR hw:&#34;SG500-&#34; OR hw:&#34;SG200-&#34; OR hw:&#34;SF200-&#34; OR hw:&#34;SLM224GT-&#34; OR hw:&#34;SLM2016T-&#34;)</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="hw:&#34;Cisco&#34; and type:&#34;switch&#34; and ( hw:&#34;SRW224G4-K9-&#34; OR hw:&#34;SRW2016-K9-&#34; OR hw:&#34;SG500X-&#34; OR hw:&#34;SF300-&#34; OR hw:&#34;SRW208G-K9-&#34; OR hw:&#34;SG300-&#34; OR hw:&#34;SRW2048-K9-&#34; OR hw:&#34;SLM2048PT-&#34; OR hw:&#34;SRW208-K9-&#34; OR hw:&#34;SF302-&#34; OR hw:&#34;SLM2008PT-&#34; OR hw:&#34;SLM224PT-&#34; OR hw:&#34;SF500-&#34; OR hw:&#34;SLM2008T-&#34; OR hw:&#34;SG500-&#34; OR hw:&#34;SG200-&#34; OR hw:&#34;SF200-&#34; OR hw:&#34;SLM224GT-&#34; OR hw:&#34;SLM2016T-&#34;)" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/?search=hw%3A%22Cisco%22+and+type%3A%22switch%22+and+%28+hw%3A%22SRW224G4-K9-%22+OR+hw%3A%22SRW2016-K9-%22+OR+hw%3A%22SG500X-%22+OR+hw%3A%22SF300-%22+OR+hw%3A%22SRW208G-K9-%22+OR+hw%3A%22SG300-%22+OR+hw%3A%22SRW2048-K9-%22+OR+hw%3A%22SLM2048PT-%22+OR+hw%3A%22SRW208-K9-%22+OR+hw%3A%22SF302-%22+OR+hw%3A%22SLM2008PT-%22+OR+hw%3A%22SLM224PT-%22+OR+hw%3A%22SF500-%22+OR+hw%3A%22SLM2008T-%22+OR+hw%3A%22SG500-%22+OR+hw%3A%22SG200-%22+OR+hw%3A%22SF200-%22+OR+hw%3A%22SLM224GT-%22+OR+hw%3A%22SLM2016T-%22%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/?search=hw%3A%22Cisco%22+and+type%3A%22switch%22+and+%28+hw%3A%22SRW224G4-K9-%22+OR+hw%3A%22SRW2016-K9-%22+OR+hw%3A%22SG500X-%22+OR+hw%3A%22SF300-%22+OR+hw%3A%22SRW208G-K9-%22+OR+hw%3A%22SG300-%22+OR+hw%3A%22SRW2048-K9-%22+OR+hw%3A%22SLM2048PT-%22+OR+hw%3A%22SRW208-K9-%22+OR+hw%3A%22SF302-%22+OR+hw%3A%22SLM2008PT-%22+OR+hw%3A%22SLM224PT-%22+OR+hw%3A%22SF500-%22+OR+hw%3A%22SLM2008T-%22+OR+hw%3A%22SG500-%22+OR+hw%3A%22SG200-%22+OR+hw%3A%22SF200-%22+OR+hw%3A%22SLM224GT-%22+OR+hw%3A%22SLM2016T-%22%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="hw:&#34;Cisco&#34; and type:&#34;switch&#34; and ( hw:&#34;SRW224G4-K9-&#34; OR hw:&#34;SRW2016-K9-&#34; OR hw:&#34;SG500X-&#34; OR hw:&#34;SF300-&#34; OR hw:&#34;SRW208G-K9-&#34; OR hw:&#34;SG300-&#34; OR hw:&#34;SRW2048-K9-&#34; OR hw:&#34;SLM2048PT-&#34; OR hw:&#34;SRW208-K9-&#34; OR hw:&#34;SF302-&#34; OR hw:&#34;SLM2008PT-&#34; OR hw:&#34;SLM224PT-&#34; OR hw:&#34;SF500-&#34; OR hw:&#34;SLM2008T-&#34; OR hw:&#34;SG500-&#34; OR hw:&#34;SG200-&#34; OR hw:&#34;SF200-&#34; OR hw:&#34;SLM224GT-&#34; OR hw:&#34;SLM2016T-&#34;)"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="end-of-life operating system (os_eol_extended:&gt;0 and os_eol_extended:&lt;now) or (os_eol_extended:0 and os_eol:&lt;now) assets end-of-life" data-ql-sev="high">
      <div class="ql-card-header">
        <div class="ql-title">End-of-Life Operating System</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><span class="ql-type-badge">assets</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>(os_eol_extended:&gt;0 AND os_eol_extended:&lt;now) OR (os_eol_extended:0 AND os_eol:&lt;now)</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="(os_eol_extended:&gt;0 AND os_eol_extended:&lt;now) OR (os_eol_extended:0 AND os_eol:&lt;now)" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/?search=%28os_eol_extended%3A%3E0+AND+os_eol_extended%3A%3Cnow%29+OR+%28os_eol_extended%3A0+AND+os_eol%3A%3Cnow%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/?search=%28os_eol_extended%3A%3E0+AND+os_eol_extended%3A%3Cnow%29+OR+%28os_eol_extended%3A0+AND+os_eol%3A%3Cnow%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="(os_eol_extended:&gt;0 AND os_eol_extended:&lt;now) OR (os_eol_extended:0 AND os_eol:&lt;now)"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="zyxel cpe remote command execution hw:&#34;vmg1312-b10a&#34; or hw:&#34;vmg1312-b10b&#34; or hw:&#34;vmg1312-b10e&#34; or hw:&#34;vmg3312-b10a&#34; or hw:&#34;vmg3313-b10a&#34; or hw:&#34;vmg3926-b10b&#34; or hw:&#34;vmg4325-b10a&#34; or hw:&#34;vmg4380-b10a&#34; or hw:&#34;vmg8324-b10a&#34; or hw:&#34;vmg8924-b10a&#34; or hw:&#34;sbg3300&#34;      or hw:&#34;sbg3500&#34; assets end-of-life" data-ql-sev="high">
      <div class="ql-card-header">
        <div class="ql-title">Zyxel CPE Remote Command Execution</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><span class="ql-type-badge">assets</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>hw:&#34;VMG1312-B10A&#34; OR hw:&#34;VMG1312-B10B&#34; OR hw:&#34;VMG1312-B10E&#34; OR hw:&#34;VMG3312-B10A&#34; OR hw:&#34;VMG3313-B10A&#34; OR hw:&#34;VMG3926-B10B&#34; OR hw:&#34;VMG4325-B10A&#34; OR hw:&#34;VMG4380-B10A&#34; OR hw:&#34;VMG8324-B10A&#34; OR hw:&#34;VMG8924-B10A&#34; OR hw:&#34;SBG3300&#34;      OR hw:&#34;SBG3500&#34;</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="hw:&#34;VMG1312-B10A&#34; OR hw:&#34;VMG1312-B10B&#34; OR hw:&#34;VMG1312-B10E&#34; OR hw:&#34;VMG3312-B10A&#34; OR hw:&#34;VMG3313-B10A&#34; OR hw:&#34;VMG3926-B10B&#34; OR hw:&#34;VMG4325-B10A&#34; OR hw:&#34;VMG4380-B10A&#34; OR hw:&#34;VMG8324-B10A&#34; OR hw:&#34;VMG8924-B10A&#34; OR hw:&#34;SBG3300&#34;      OR hw:&#34;SBG3500&#34;" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/?search=hw%3A%22VMG1312-B10A%22+OR+hw%3A%22VMG1312-B10B%22+OR+hw%3A%22VMG1312-B10E%22+OR+hw%3A%22VMG3312-B10A%22+OR+hw%3A%22VMG3313-B10A%22+OR+hw%3A%22VMG3926-B10B%22+OR+hw%3A%22VMG4325-B10A%22+OR+hw%3A%22VMG4380-B10A%22+OR+hw%3A%22VMG8324-B10A%22+OR+hw%3A%22VMG8924-B10A%22+OR+hw%3A%22SBG3300%22++++++OR+hw%3A%22SBG3500%22" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/?search=hw%3A%22VMG1312-B10A%22+OR+hw%3A%22VMG1312-B10B%22+OR+hw%3A%22VMG1312-B10E%22+OR+hw%3A%22VMG3312-B10A%22+OR+hw%3A%22VMG3313-B10A%22+OR+hw%3A%22VMG3926-B10B%22+OR+hw%3A%22VMG4325-B10A%22+OR+hw%3A%22VMG4380-B10A%22+OR+hw%3A%22VMG8324-B10A%22+OR+hw%3A%22VMG8924-B10A%22+OR+hw%3A%22SBG3300%22++++++OR+hw%3A%22SBG3500%22" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="hw:&#34;VMG1312-B10A&#34; OR hw:&#34;VMG1312-B10B&#34; OR hw:&#34;VMG1312-B10E&#34; OR hw:&#34;VMG3312-B10A&#34; OR hw:&#34;VMG3313-B10A&#34; OR hw:&#34;VMG3926-B10B&#34; OR hw:&#34;VMG4325-B10A&#34; OR hw:&#34;VMG4380-B10A&#34; OR hw:&#34;VMG8324-B10A&#34; OR hw:&#34;VMG8924-B10A&#34; OR hw:&#34;SBG3300&#34;      OR hw:&#34;SBG3500&#34;"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="end-of-life assets os_eol_expired:t assets end-of-life" data-ql-sev="low">
      <div class="ql-card-header">
        <div class="ql-title">End-Of-Life Assets</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><span class="ql-type-badge">assets</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>os_eol_expired:t</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="os_eol_expired:t" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/?search=os_eol_expired%3At" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/?search=os_eol_expired%3At" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="os_eol_expired:t"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="end-of-life cloud assets os_eol_expired:t and attack_surface:cloud assets end-of-life" data-ql-sev="low">
      <div class="ql-card-header">
        <div class="ql-title">End-Of-Life Cloud Assets</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><span class="ql-type-badge">assets</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>os_eol_expired:t AND attack_surface:cloud</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="os_eol_expired:t AND attack_surface:cloud" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/?search=os_eol_expired%3At+AND+attack_surface%3Acloud" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/?search=os_eol_expired%3At+AND+attack_surface%3Acloud" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="os_eol_expired:t AND attack_surface:cloud"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="end-of-life external assets os_eol_expired:t and attack_surface:external assets end-of-life" data-ql-sev="low">
      <div class="ql-card-header">
        <div class="ql-title">End-Of-Life External Assets</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><span class="ql-type-badge">assets</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>os_eol_expired:t AND attack_surface:external</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="os_eol_expired:t AND attack_surface:external" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/?search=os_eol_expired%3At+AND+attack_surface%3Aexternal" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/?search=os_eol_expired%3At+AND+attack_surface%3Aexternal" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="os_eol_expired:t AND attack_surface:external"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="end-of-life internal assets os_eol_expired:t and attack_surface:internal assets end-of-life" data-ql-sev="low">
      <div class="ql-card-header">
        <div class="ql-title">End-Of-Life Internal Assets</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><span class="ql-type-badge">assets</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>os_eol_expired:t AND attack_surface:internal</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="os_eol_expired:t AND attack_surface:internal" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/?search=os_eol_expired%3At+AND+attack_surface%3Ainternal" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/?search=os_eol_expired%3At+AND+attack_surface%3Ainternal" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="os_eol_expired:t AND attack_surface:internal"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="d-link dns family nas fp.hw.product:=&#34;dns-320l&#34; or fp.hw.product:=&#34;dns-325&#34; or fp.hw.product:=&#34;dns-327l&#34; or fp.hw.product:=&#34;dns-340l&#34; assets end-of-life" data-ql-sev="info">
      <div class="ql-card-header">
        <div class="ql-title">D-Link DNS Family NAS</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><span class="ql-type-badge">assets</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>fp.hw.product:=&#34;DNS-320L&#34; OR fp.hw.product:=&#34;DNS-325&#34; OR fp.hw.product:=&#34;DNS-327L&#34; OR fp.hw.product:=&#34;DNS-340L&#34;</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="fp.hw.product:=&#34;DNS-320L&#34; OR fp.hw.product:=&#34;DNS-325&#34; OR fp.hw.product:=&#34;DNS-327L&#34; OR fp.hw.product:=&#34;DNS-340L&#34;" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/?search=fp.hw.product%3A%3D%22DNS-320L%22+OR+fp.hw.product%3A%3D%22DNS-325%22+OR+fp.hw.product%3A%3D%22DNS-327L%22+OR+fp.hw.product%3A%3D%22DNS-340L%22" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/?search=fp.hw.product%3A%3D%22DNS-320L%22+OR+fp.hw.product%3A%3D%22DNS-325%22+OR+fp.hw.product%3A%3D%22DNS-327L%22+OR+fp.hw.product%3A%3D%22DNS-340L%22" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="fp.hw.product:=&#34;DNS-320L&#34; OR fp.hw.product:=&#34;DNS-325&#34; OR fp.hw.product:=&#34;DNS-327L&#34; OR fp.hw.product:=&#34;DNS-340L&#34;"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="edimax ic-7100 ip camera hw:&#34;edimax ic-71%camera&#34; assets end-of-life" data-ql-sev="info">
      <div class="ql-card-header">
        <div class="ql-title">Edimax IC-7100 IP Camera</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><span class="ql-type-badge">assets</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>hw:&#34;EDIMAX IC-71%Camera&#34;</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="hw:&#34;EDIMAX IC-71%Camera&#34;" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/?search=hw%3A%22EDIMAX+IC-71%25Camera%22" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/?search=hw%3A%22EDIMAX+IC-71%25Camera%22" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="hw:&#34;EDIMAX IC-71%Camera&#34;"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="powerdns recursor vendor:=powerdns and product:=recursor and (version:&gt;0 and version:&gt;=2 and version:&lt;5.1) software end-of-life" data-ql-sev="info">
      <div class="ql-card-header">
        <div class="ql-title">PowerDNS Recursor</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><span class="ql-type-badge">software</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>vendor:=PowerDNS AND product:=Recursor AND (version:&gt;0 AND version:&gt;=2 AND version:&lt;5.1)</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="vendor:=PowerDNS AND product:=Recursor AND (version:&gt;0 AND version:&gt;=2 AND version:&lt;5.1)" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/software?search=vendor%3A%3DPowerDNS+AND+product%3A%3DRecursor+AND+%28version%3A%3E0+AND+version%3A%3E%3D2+AND+version%3A%3C5.1%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/software?search=vendor%3A%3DPowerDNS+AND+product%3A%3DRecursor+AND+%28version%3A%3E0+AND+version%3A%3E%3D2+AND+version%3A%3C5.1%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="vendor:=PowerDNS AND product:=Recursor AND (version:&gt;0 AND version:&gt;=2 AND version:&lt;5.1)"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="xen project xcp-ng os:=&#34;xen project xcp-ng&#34; and (os_version:&gt;0 and os_version:&lt;&#34;8.3&#34;) assets end-of-life" data-ql-sev="info">
      <div class="ql-card-header">
        <div class="ql-title">Xen Project XCP-ng</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><span class="ql-type-badge">assets</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>os:=&#34;Xen Project XCP-ng&#34; AND (os_version:&gt;0 AND os_version:&lt;&#34;8.3&#34;)</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="os:=&#34;Xen Project XCP-ng&#34; AND (os_version:&gt;0 AND os_version:&lt;&#34;8.3&#34;)" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/?search=os%3A%3D%22Xen+Project+XCP-ng%22+AND+%28os_version%3A%3E0+AND+os_version%3A%3C%228.3%22%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/?search=os%3A%3D%22Xen+Project+XCP-ng%22+AND+%28os_version%3A%3E0+AND+os_version%3A%3C%228.3%22%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="os:=&#34;Xen Project XCP-ng&#34; AND (os_version:&gt;0 AND os_version:&lt;&#34;8.3&#34;)"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
  </div>
</div>
<div class="ql-category" id="ql-internet-exposure">
  <button class="ql-cat-header" onclick="qlToggleCat(this)"><span class="ql-cat-title">Internet Exposure</span><span class="ql-cat-count">25 queries</span><span class="ql-cat-chevron">&#9660;</span></button>
  <div class="ql-cat-body">
    <div class="ql-card" data-ql-search="publicly exposed configuration database server service_has_public:t and (_asset.protocols:zookeeper or _asset.protocols:etcd2 or _asset.protocols:consul) and (protocol:zookeeper or protocol:etcd2 or protocol:consul) services internet exposure" data-ql-sev="high">
      <div class="ql-card-header">
        <div class="ql-title">Publicly Exposed Configuration Database Server</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><span class="ql-type-badge">services</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>service_has_public:t AND (_asset.protocols:zookeeper OR _asset.protocols:etcd2 OR _asset.protocols:consul) AND (protocol:zookeeper OR protocol:etcd2 OR protocol:consul)</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="service_has_public:t AND (_asset.protocols:zookeeper OR _asset.protocols:etcd2 OR _asset.protocols:consul) AND (protocol:zookeeper OR protocol:etcd2 OR protocol:consul)" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/services?search=service_has_public%3At+AND+%28_asset.protocols%3Azookeeper+OR+_asset.protocols%3Aetcd2+OR+_asset.protocols%3Aconsul%29+AND+%28protocol%3Azookeeper+OR+protocol%3Aetcd2+OR+protocol%3Aconsul%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/services?search=service_has_public%3At+AND+%28_asset.protocols%3Azookeeper+OR+_asset.protocols%3Aetcd2+OR+_asset.protocols%3Aconsul%29+AND+%28protocol%3Azookeeper+OR+protocol%3Aetcd2+OR+protocol%3Aconsul%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="service_has_public:t AND (_asset.protocols:zookeeper OR _asset.protocols:etcd2 OR _asset.protocols:consul) AND (protocol:zookeeper OR protocol:etcd2 OR protocol:consul)"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="potential external access to internal asset source:runzero and (foreign_id:=rz-query-rz-ioasm-internal-mac or foreign_id:=rz-query-rz-ioasm-internal-pubkey) vulnerabilities internet exposure" data-ql-sev="medium">
      <div class="ql-card-header">
        <div class="ql-title">Potential External Access To Internal Asset</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><span class="ql-type-badge">vulnerabilities</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>source:runzero AND (foreign_id:=rz-query-rz-ioasm-internal-mac OR foreign_id:=rz-query-rz-ioasm-internal-pubkey)</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="source:runzero AND (foreign_id:=rz-query-rz-ioasm-internal-mac OR foreign_id:=rz-query-rz-ioasm-internal-pubkey)" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/vulnerabilities?search=source%3Arunzero+AND+%28foreign_id%3A%3Drz-query-rz-ioasm-internal-mac+OR+foreign_id%3A%3Drz-query-rz-ioasm-internal-pubkey%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/vulnerabilities?search=source%3Arunzero+AND+%28foreign_id%3A%3Drz-query-rz-ioasm-internal-mac+OR+foreign_id%3A%3Drz-query-rz-ioasm-internal-pubkey%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="source:runzero AND (foreign_id:=rz-query-rz-ioasm-internal-mac OR foreign_id:=rz-query-rz-ioasm-internal-pubkey)"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="potential external access to remote desktop service has_public:t and service_has_public:f and ( ( _asset.protocol:rdp and protocol:rdp ) or ( _asset.protocol:vnc and protocol:vnc ) or ( _asset.protocol:teamviewer and protocol:teamviewer ) or ( _asset.protocol:spice and protocol:spice ) ) assets internet exposure" data-ql-sev="medium">
      <div class="ql-card-header">
        <div class="ql-title">Potential External Access To Remote Desktop Service</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><span class="ql-type-badge">assets</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>has_public:t AND service_has_public:f AND ( ( _asset.protocol:rdp AND protocol:rdp ) OR ( _asset.protocol:vnc AND protocol:vnc ) OR ( _asset.protocol:teamviewer AND protocol:teamviewer ) OR ( _asset.protocol:spice AND protocol:spice ) )</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="has_public:t AND service_has_public:f AND ( ( _asset.protocol:rdp AND protocol:rdp ) OR ( _asset.protocol:vnc AND protocol:vnc ) OR ( _asset.protocol:teamviewer AND protocol:teamviewer ) OR ( _asset.protocol:spice AND protocol:spice ) )" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/?search=has_public%3At+AND+service_has_public%3Af+AND+%28+%28+_asset.protocol%3Ardp+AND+protocol%3Ardp+%29+OR+%28+_asset.protocol%3Avnc+AND+protocol%3Avnc+%29+OR+%28+_asset.protocol%3Ateamviewer+AND+protocol%3Ateamviewer+%29+OR+%28+_asset.protocol%3Aspice+AND+protocol%3Aspice+%29+%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/?search=has_public%3At+AND+service_has_public%3Af+AND+%28+%28+_asset.protocol%3Ardp+AND+protocol%3Ardp+%29+OR+%28+_asset.protocol%3Avnc+AND+protocol%3Avnc+%29+OR+%28+_asset.protocol%3Ateamviewer+AND+protocol%3Ateamviewer+%29+OR+%28+_asset.protocol%3Aspice+AND+protocol%3Aspice+%29+%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="has_public:t AND service_has_public:f AND ( ( _asset.protocol:rdp AND protocol:rdp ) OR ( _asset.protocol:vnc AND protocol:vnc ) OR ( _asset.protocol:teamviewer AND protocol:teamviewer ) OR ( _asset.protocol:spice AND protocol:spice ) )"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="publicly exposed baseboard management controller haspublic:t and (type:bmc or protocol:ipmi) assets internet exposure" data-ql-sev="medium">
      <div class="ql-card-header">
        <div class="ql-title">Publicly Exposed Baseboard Management Controller</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><span class="ql-type-badge">assets</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>haspublic:t AND (type:bmc OR protocol:ipmi)</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="haspublic:t AND (type:bmc OR protocol:ipmi)" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/?search=haspublic%3At+AND+%28type%3Abmc+OR+protocol%3Aipmi%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/?search=haspublic%3At+AND+%28type%3Abmc+OR+protocol%3Aipmi%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="haspublic:t AND (type:bmc OR protocol:ipmi)"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="publicly exposed remote desktop gateway service_has_public:t and ( (_asset.protocol:dtls or _asset.protocol:http) and ((protocol:dtls or protocol:http) and has:rdg.transport) ) services internet exposure" data-ql-sev="medium">
      <div class="ql-card-header">
        <div class="ql-title">Publicly Exposed Remote Desktop Gateway</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><span class="ql-type-badge">services</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>service_has_public:t AND ( (_asset.protocol:dtls OR _asset.protocol:http) AND ((protocol:dtls OR protocol:http) AND has:rdg.transport) )</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="service_has_public:t AND ( (_asset.protocol:dtls OR _asset.protocol:http) AND ((protocol:dtls OR protocol:http) AND has:rdg.transport) )" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/services?search=service_has_public%3At+AND+%28+%28_asset.protocol%3Adtls+OR+_asset.protocol%3Ahttp%29+AND+%28%28protocol%3Adtls+OR+protocol%3Ahttp%29+AND+has%3Ardg.transport%29+%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/services?search=service_has_public%3At+AND+%28+%28_asset.protocol%3Adtls+OR+_asset.protocol%3Ahttp%29+AND+%28%28protocol%3Adtls+OR+protocol%3Ahttp%29+AND+has%3Ardg.transport%29+%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="service_has_public:t AND ( (_asset.protocol:dtls OR _asset.protocol:http) AND ((protocol:dtls OR protocol:http) AND has:rdg.transport) )"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="publicly exposed remote desktop service service_has_public:t and ( ( _asset.protocol:rdp and protocol:rdp ) or ( _asset.protocol:vnc and protocol:vnc ) or ( _asset.protocol:teamviewer and protocol:teamviewer ) or ( _asset.protocol:spice and protocol:spice ) ) assets internet exposure" data-ql-sev="medium">
      <div class="ql-card-header">
        <div class="ql-title">Publicly Exposed Remote Desktop Service</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><span class="ql-type-badge">assets</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>service_has_public:t AND ( ( _asset.protocol:rdp AND protocol:rdp ) OR ( _asset.protocol:vnc AND protocol:vnc ) OR ( _asset.protocol:teamviewer AND protocol:teamviewer ) OR ( _asset.protocol:spice AND protocol:spice ) )</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="service_has_public:t AND ( ( _asset.protocol:rdp AND protocol:rdp ) OR ( _asset.protocol:vnc AND protocol:vnc ) OR ( _asset.protocol:teamviewer AND protocol:teamviewer ) OR ( _asset.protocol:spice AND protocol:spice ) )" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/?search=service_has_public%3At+AND+%28+%28+_asset.protocol%3Ardp+AND+protocol%3Ardp+%29+OR+%28+_asset.protocol%3Avnc+AND+protocol%3Avnc+%29+OR+%28+_asset.protocol%3Ateamviewer+AND+protocol%3Ateamviewer+%29+OR+%28+_asset.protocol%3Aspice+AND+protocol%3Aspice+%29+%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/?search=service_has_public%3At+AND+%28+%28+_asset.protocol%3Ardp+AND+protocol%3Ardp+%29+OR+%28+_asset.protocol%3Avnc+AND+protocol%3Avnc+%29+OR+%28+_asset.protocol%3Ateamviewer+AND+protocol%3Ateamviewer+%29+OR+%28+_asset.protocol%3Aspice+AND+protocol%3Aspice+%29+%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="service_has_public:t AND ( ( _asset.protocol:rdp AND protocol:rdp ) OR ( _asset.protocol:vnc AND protocol:vnc ) OR ( _asset.protocol:teamviewer AND protocol:teamviewer ) OR ( _asset.protocol:spice AND protocol:spice ) )"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="publicly exposed ssh server with password authentication service_has_public:t and ( _asset.protocol:ssh and protocol:ssh and ssh.authmethods:password ) services internet exposure" data-ql-sev="medium">
      <div class="ql-card-header">
        <div class="ql-title">Publicly Exposed SSH Server With Password Authentication</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><span class="ql-type-badge">services</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>service_has_public:t AND ( _asset.protocol:ssh AND protocol:ssh AND ssh.authMethods:password )</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="service_has_public:t AND ( _asset.protocol:ssh AND protocol:ssh AND ssh.authMethods:password )" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/services?search=service_has_public%3At+AND+%28+_asset.protocol%3Assh+AND+protocol%3Assh+AND+ssh.authMethods%3Apassword+%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/services?search=service_has_public%3At+AND+%28+_asset.protocol%3Assh+AND+protocol%3Assh+AND+ssh.authMethods%3Apassword+%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="service_has_public:t AND ( _asset.protocol:ssh AND protocol:ssh AND ssh.authMethods:password )"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="publicly exposed windows management service service_has_public:t and ( ( _asset.protocol:smb and protocol:smb ) or ( _asset.protocol:epm and protocol:epm ) or ( _asset.protocol:wsman and protocol:wsman ) ) assets internet exposure" data-ql-sev="medium">
      <div class="ql-card-header">
        <div class="ql-title">Publicly Exposed Windows Management Service</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><span class="ql-type-badge">assets</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>service_has_public:t AND ( ( _asset.protocol:smb AND protocol:smb ) OR ( _asset.protocol:epm AND protocol:epm ) OR ( _asset.protocol:wsman AND protocol:wsman ) )</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="service_has_public:t AND ( ( _asset.protocol:smb AND protocol:smb ) OR ( _asset.protocol:epm AND protocol:epm ) OR ( _asset.protocol:wsman AND protocol:wsman ) )" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/?search=service_has_public%3At+AND+%28+%28+_asset.protocol%3Asmb+AND+protocol%3Asmb+%29+OR+%28+_asset.protocol%3Aepm+AND+protocol%3Aepm+%29+OR+%28+_asset.protocol%3Awsman+AND+protocol%3Awsman+%29+%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/?search=service_has_public%3At+AND+%28+%28+_asset.protocol%3Asmb+AND+protocol%3Asmb+%29+OR+%28+_asset.protocol%3Aepm+AND+protocol%3Aepm+%29+OR+%28+_asset.protocol%3Awsman+AND+protocol%3Awsman+%29+%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="service_has_public:t AND ( ( _asset.protocol:smb AND protocol:smb ) OR ( _asset.protocol:epm AND protocol:epm ) OR ( _asset.protocol:wsman AND protocol:wsman ) )"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="externally exposed database services service_has_public:t and _asset.protocol:&#34;{smb1,smb2,smb3,nfs,zookeeper,etcd2,consul,memcache,redis,mongodb,couchdb,cassandra,elasticsearch,riak,influxdb,mysql,mysqlx,postgresql,mssql,oracledb}&#34; and protocol:&#34;{smb1,smb2,smb3,nfs,zookeeper,etcd2,consul,memcache,redis,mongodb,couchdb,cassandra,elasticsearch,riak,influxdb,mysql,mysqlx,postgresql,mssql,oracledb}&#34; services internet exposure" data-ql-sev="low">
      <div class="ql-card-header">
        <div class="ql-title">Externally Exposed Database Services</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><span class="ql-type-badge">services</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>service_has_public:t AND _asset.protocol:&#34;{smb1,smb2,smb3,nfs,zookeeper,etcd2,consul,memcache,redis,mongodb,couchdb,cassandra,elasticsearch,riak,influxdb,mysql,mysqlx,postgresql,mssql,oracledb}&#34; AND protocol:&#34;{smb1,smb2,smb3,nfs,zookeeper,etcd2,consul,memcache,redis,mongodb,couchdb,cassandra,elasticsearch,riak,influxdb,mysql,mysqlx,postgresql,mssql,oracledb}&#34;</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="service_has_public:t AND _asset.protocol:&#34;{smb1,smb2,smb3,nfs,zookeeper,etcd2,consul,memcache,redis,mongodb,couchdb,cassandra,elasticsearch,riak,influxdb,mysql,mysqlx,postgresql,mssql,oracledb}&#34; AND protocol:&#34;{smb1,smb2,smb3,nfs,zookeeper,etcd2,consul,memcache,redis,mongodb,couchdb,cassandra,elasticsearch,riak,influxdb,mysql,mysqlx,postgresql,mssql,oracledb}&#34;" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/services?search=service_has_public%3At+AND+_asset.protocol%3A%22%7Bsmb1%2Csmb2%2Csmb3%2Cnfs%2Czookeeper%2Cetcd2%2Cconsul%2Cmemcache%2Credis%2Cmongodb%2Ccouchdb%2Ccassandra%2Celasticsearch%2Criak%2Cinfluxdb%2Cmysql%2Cmysqlx%2Cpostgresql%2Cmssql%2Coracledb%7D%22+AND+protocol%3A%22%7Bsmb1%2Csmb2%2Csmb3%2Cnfs%2Czookeeper%2Cetcd2%2Cconsul%2Cmemcache%2Credis%2Cmongodb%2Ccouchdb%2Ccassandra%2Celasticsearch%2Criak%2Cinfluxdb%2Cmysql%2Cmysqlx%2Cpostgresql%2Cmssql%2Coracledb%7D%22" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/services?search=service_has_public%3At+AND+_asset.protocol%3A%22%7Bsmb1%2Csmb2%2Csmb3%2Cnfs%2Czookeeper%2Cetcd2%2Cconsul%2Cmemcache%2Credis%2Cmongodb%2Ccouchdb%2Ccassandra%2Celasticsearch%2Criak%2Cinfluxdb%2Cmysql%2Cmysqlx%2Cpostgresql%2Cmssql%2Coracledb%7D%22+AND+protocol%3A%22%7Bsmb1%2Csmb2%2Csmb3%2Cnfs%2Czookeeper%2Cetcd2%2Cconsul%2Cmemcache%2Credis%2Cmongodb%2Ccouchdb%2Ccassandra%2Celasticsearch%2Criak%2Cinfluxdb%2Cmysql%2Cmysqlx%2Cpostgresql%2Cmssql%2Coracledb%7D%22" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="service_has_public:t AND _asset.protocol:&#34;{smb1,smb2,smb3,nfs,zookeeper,etcd2,consul,memcache,redis,mongodb,couchdb,cassandra,elasticsearch,riak,influxdb,mysql,mysqlx,postgresql,mssql,oracledb}&#34; AND protocol:&#34;{smb1,smb2,smb3,nfs,zookeeper,etcd2,consul,memcache,redis,mongodb,couchdb,cassandra,elasticsearch,riak,influxdb,mysql,mysqlx,postgresql,mssql,oracledb}&#34;"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="externally exposed iot assets attack_surface:external and category:=iot assets internet exposure" data-ql-sev="low">
      <div class="ql-card-header">
        <div class="ql-title">Externally Exposed IoT Assets</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><span class="ql-type-badge">assets</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>attack_surface:external AND category:=IoT</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="attack_surface:external AND category:=IoT" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/?search=attack_surface%3Aexternal+AND+category%3A%3DIoT" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/?search=attack_surface%3Aexternal+AND+category%3A%3DIoT" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="attack_surface:external AND category:=IoT"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="externally exposed management interfaces source:runzero and foreign_id:&#34;rz-scan-vscan-%-panel&#34; and attack_surface:external vulnerabilities internet exposure" data-ql-sev="low">
      <div class="ql-card-header">
        <div class="ql-title">Externally Exposed Management Interfaces</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><span class="ql-type-badge">vulnerabilities</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>source:runZero AND foreign_id:&#34;rz-scan-vscan-%-panel&#34; AND attack_surface:external</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="source:runZero AND foreign_id:&#34;rz-scan-vscan-%-panel&#34; AND attack_surface:external" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/vulnerabilities?search=source%3ArunZero+AND+foreign_id%3A%22rz-scan-vscan-%25-panel%22+AND+attack_surface%3Aexternal" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/vulnerabilities?search=source%3ArunZero+AND+foreign_id%3A%22rz-scan-vscan-%25-panel%22+AND+attack_surface%3Aexternal" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="source:runZero AND foreign_id:&#34;rz-scan-vscan-%-panel&#34; AND attack_surface:external"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="externally exposed ot assets attack_surface:external and category:=ot assets internet exposure" data-ql-sev="low">
      <div class="ql-card-header">
        <div class="ql-title">Externally Exposed OT Assets</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><span class="ql-type-badge">assets</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>attack_surface:external AND category:=OT</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="attack_surface:external AND category:=OT" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/?search=attack_surface%3Aexternal+AND+category%3A%3DOT" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/?search=attack_surface%3Aexternal+AND+category%3A%3DOT" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="attack_surface:external AND category:=OT"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="new public assets attack_surface:external and first_seen:&lt;7days assets internet exposure" data-ql-sev="low">
      <div class="ql-card-header">
        <div class="ql-title">New Public Assets</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><span class="ql-type-badge">assets</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>attack_surface:external AND first_seen:&lt;7days</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="attack_surface:external AND first_seen:&lt;7days" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/?search=attack_surface%3Aexternal+AND+first_seen%3A%3C7days" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/?search=attack_surface%3Aexternal+AND+first_seen%3A%3C7days" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="attack_surface:external AND first_seen:&lt;7days"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="potential external access to configuration database server has_public:t and service_has_public:f and (_asset.protocols:zookeeper or _asset.protocols:etcd2 or _asset.protocols:consul) and (protocol:zookeeper or protocol:etcd2 or protocol:consul) services internet exposure" data-ql-sev="low">
      <div class="ql-card-header">
        <div class="ql-title">Potential External Access To Configuration Database Server</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><span class="ql-type-badge">services</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>has_public:t AND service_has_public:f AND (_asset.protocols:zookeeper OR _asset.protocols:etcd2 OR _asset.protocols:consul) AND (protocol:zookeeper OR protocol:etcd2 OR protocol:consul)</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="has_public:t AND service_has_public:f AND (_asset.protocols:zookeeper OR _asset.protocols:etcd2 OR _asset.protocols:consul) AND (protocol:zookeeper OR protocol:etcd2 OR protocol:consul)" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/services?search=has_public%3At+AND+service_has_public%3Af+AND+%28_asset.protocols%3Azookeeper+OR+_asset.protocols%3Aetcd2+OR+_asset.protocols%3Aconsul%29+AND+%28protocol%3Azookeeper+OR+protocol%3Aetcd2+OR+protocol%3Aconsul%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/services?search=has_public%3At+AND+service_has_public%3Af+AND+%28_asset.protocols%3Azookeeper+OR+_asset.protocols%3Aetcd2+OR+_asset.protocols%3Aconsul%29+AND+%28protocol%3Azookeeper+OR+protocol%3Aetcd2+OR+protocol%3Aconsul%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="has_public:t AND service_has_public:f AND (_asset.protocols:zookeeper OR _asset.protocols:etcd2 OR _asset.protocols:consul) AND (protocol:zookeeper OR protocol:etcd2 OR protocol:consul)"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="potential external access to key-value database server has_public:t and service_has_public:f and (_asset.protocols:memcache or _asset.protocols:redis) and (protocol:memcache or protocol:redis) services internet exposure" data-ql-sev="low">
      <div class="ql-card-header">
        <div class="ql-title">Potential External Access To Key-Value Database Server</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><span class="ql-type-badge">services</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>has_public:t AND service_has_public:f AND (_asset.protocols:memcache OR _asset.protocols:redis) AND (protocol:memcache OR protocol:redis)</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="has_public:t AND service_has_public:f AND (_asset.protocols:memcache OR _asset.protocols:redis) AND (protocol:memcache OR protocol:redis)" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/services?search=has_public%3At+AND+service_has_public%3Af+AND+%28_asset.protocols%3Amemcache+OR+_asset.protocols%3Aredis%29+AND+%28protocol%3Amemcache+OR+protocol%3Aredis%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/services?search=has_public%3At+AND+service_has_public%3Af+AND+%28_asset.protocols%3Amemcache+OR+_asset.protocols%3Aredis%29+AND+%28protocol%3Amemcache+OR+protocol%3Aredis%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="has_public:t AND service_has_public:f AND (_asset.protocols:memcache OR _asset.protocols:redis) AND (protocol:memcache OR protocol:redis)"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="potential external access to nosql database server has_public:t and service_has_public:f and (_asset.protocols:mongodb or _asset.protocols:couchdb or _asset.protocols:cassandra or _asset.protocols:elasticsearch or _asset.protocols:riak or _asset.protocols:influxdb) and (protocol:mongodb or protocol:couchdb or protocol:cassandra protocol:elasticsearch or protocol:riak or protocol:influxdb) services internet exposure" data-ql-sev="low">
      <div class="ql-card-header">
        <div class="ql-title">Potential External Access To NoSQL Database Server</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><span class="ql-type-badge">services</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>has_public:t AND service_has_public:f AND (_asset.protocols:mongodb OR _asset.protocols:couchdb OR _asset.protocols:cassandra OR _asset.protocols:elasticsearch OR _asset.protocols:riak OR _asset.protocols:influxdb) AND (protocol:mongodb OR protocol:couchdb OR protocol:cassandra protocol:elasticsearch OR protocol:riak OR protocol:influxdb)</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="has_public:t AND service_has_public:f AND (_asset.protocols:mongodb OR _asset.protocols:couchdb OR _asset.protocols:cassandra OR _asset.protocols:elasticsearch OR _asset.protocols:riak OR _asset.protocols:influxdb) AND (protocol:mongodb OR protocol:couchdb OR protocol:cassandra protocol:elasticsearch OR protocol:riak OR protocol:influxdb)" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/services?search=has_public%3At+AND+service_has_public%3Af+AND+%28_asset.protocols%3Amongodb+OR+_asset.protocols%3Acouchdb+OR+_asset.protocols%3Acassandra+OR+_asset.protocols%3Aelasticsearch+OR+_asset.protocols%3Ariak+OR+_asset.protocols%3Ainfluxdb%29+AND+%28protocol%3Amongodb+OR+protocol%3Acouchdb+OR+protocol%3Acassandra+protocol%3Aelasticsearch+OR+protocol%3Ariak+OR+protocol%3Ainfluxdb%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/services?search=has_public%3At+AND+service_has_public%3Af+AND+%28_asset.protocols%3Amongodb+OR+_asset.protocols%3Acouchdb+OR+_asset.protocols%3Acassandra+OR+_asset.protocols%3Aelasticsearch+OR+_asset.protocols%3Ariak+OR+_asset.protocols%3Ainfluxdb%29+AND+%28protocol%3Amongodb+OR+protocol%3Acouchdb+OR+protocol%3Acassandra+protocol%3Aelasticsearch+OR+protocol%3Ariak+OR+protocol%3Ainfluxdb%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="has_public:t AND service_has_public:f AND (_asset.protocols:mongodb OR _asset.protocols:couchdb OR _asset.protocols:cassandra OR _asset.protocols:elasticsearch OR _asset.protocols:riak OR _asset.protocols:influxdb) AND (protocol:mongodb OR protocol:couchdb OR protocol:cassandra protocol:elasticsearch OR protocol:riak OR protocol:influxdb)"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="potential external access to operational technology service has_public:t and service_has_public:f and (_asset.protocols:bacnet or _asset.protocols:modbus or _asset.protocols:dnp3 or _asset.protocols:opcua or _asset.protocols:cip or _asset.protocols:ethernetip or _asset.protocols:profinet or _asset.protocols:prosoft or _asset.protocols:s7comm or _asset.protocols:fins or _asset.protocols:comtrol or _asset.protocols:atg) and (protocol:bacnet or protocol:modbus or protocol:dnp3 or protocol:opcua or protocol:cip or protocol:ethernetip or protocol:profinet or protocol:prosoft or protocol:s7comm or protocol:fins or protocol:comtrol or protocol:atg) services internet exposure" data-ql-sev="low">
      <div class="ql-card-header">
        <div class="ql-title">Potential External Access To Operational Technology Service</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><span class="ql-type-badge">services</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>has_public:t AND service_has_public:f AND (_asset.protocols:bacnet OR _asset.protocols:modbus OR _asset.protocols:dnp3 OR _asset.protocols:opcua OR _asset.protocols:cip OR _asset.protocols:ethernetip OR _asset.protocols:profinet OR _asset.protocols:prosoft OR _asset.protocols:s7comm OR _asset.protocols:fins OR _asset.protocols:comtrol OR _asset.protocols:atg) AND (protocol:bacnet OR protocol:modbus OR protocol:dnp3 OR protocol:opcua OR protocol:cip OR protocol:ethernetip OR protocol:profinet OR protocol:prosoft OR protocol:s7comm OR protocol:fins OR protocol:comtrol OR protocol:atg)</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="has_public:t AND service_has_public:f AND (_asset.protocols:bacnet OR _asset.protocols:modbus OR _asset.protocols:dnp3 OR _asset.protocols:opcua OR _asset.protocols:cip OR _asset.protocols:ethernetip OR _asset.protocols:profinet OR _asset.protocols:prosoft OR _asset.protocols:s7comm OR _asset.protocols:fins OR _asset.protocols:comtrol OR _asset.protocols:atg) AND (protocol:bacnet OR protocol:modbus OR protocol:dnp3 OR protocol:opcua OR protocol:cip OR protocol:ethernetip OR protocol:profinet OR protocol:prosoft OR protocol:s7comm OR protocol:fins OR protocol:comtrol OR protocol:atg)" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/services?search=has_public%3At+AND+service_has_public%3Af+AND+%28_asset.protocols%3Abacnet+OR+_asset.protocols%3Amodbus+OR+_asset.protocols%3Adnp3+OR+_asset.protocols%3Aopcua+OR+_asset.protocols%3Acip+OR+_asset.protocols%3Aethernetip+OR+_asset.protocols%3Aprofinet+OR+_asset.protocols%3Aprosoft+OR+_asset.protocols%3As7comm+OR+_asset.protocols%3Afins+OR+_asset.protocols%3Acomtrol+OR+_asset.protocols%3Aatg%29+AND+%28protocol%3Abacnet+OR+protocol%3Amodbus+OR+protocol%3Adnp3+OR+protocol%3Aopcua+OR+protocol%3Acip+OR+protocol%3Aethernetip+OR+protocol%3Aprofinet+OR+protocol%3Aprosoft+OR+protocol%3As7comm+OR+protocol%3Afins+OR+protocol%3Acomtrol+OR+protocol%3Aatg%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/services?search=has_public%3At+AND+service_has_public%3Af+AND+%28_asset.protocols%3Abacnet+OR+_asset.protocols%3Amodbus+OR+_asset.protocols%3Adnp3+OR+_asset.protocols%3Aopcua+OR+_asset.protocols%3Acip+OR+_asset.protocols%3Aethernetip+OR+_asset.protocols%3Aprofinet+OR+_asset.protocols%3Aprosoft+OR+_asset.protocols%3As7comm+OR+_asset.protocols%3Afins+OR+_asset.protocols%3Acomtrol+OR+_asset.protocols%3Aatg%29+AND+%28protocol%3Abacnet+OR+protocol%3Amodbus+OR+protocol%3Adnp3+OR+protocol%3Aopcua+OR+protocol%3Acip+OR+protocol%3Aethernetip+OR+protocol%3Aprofinet+OR+protocol%3Aprosoft+OR+protocol%3As7comm+OR+protocol%3Afins+OR+protocol%3Acomtrol+OR+protocol%3Aatg%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="has_public:t AND service_has_public:f AND (_asset.protocols:bacnet OR _asset.protocols:modbus OR _asset.protocols:dnp3 OR _asset.protocols:opcua OR _asset.protocols:cip OR _asset.protocols:ethernetip OR _asset.protocols:profinet OR _asset.protocols:prosoft OR _asset.protocols:s7comm OR _asset.protocols:fins OR _asset.protocols:comtrol OR _asset.protocols:atg) AND (protocol:bacnet OR protocol:modbus OR protocol:dnp3 OR protocol:opcua OR protocol:cip OR protocol:ethernetip OR protocol:profinet OR protocol:prosoft OR protocol:s7comm OR protocol:fins OR protocol:comtrol OR protocol:atg)"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="potential external access to relational database server has_public:t and service_has_public:f and (_asset.protocol:=mysql or _asset.protocol:=mysqlx or _asset.protocol:=postgresql or _asset.protocol:=mssql or _asset.protocol:=oracledb) and (protocol:=mysql or protocol:=mysqlx or protocol:=postgresql or protocol:=mssql or protocol:=oracledb) services internet exposure" data-ql-sev="low">
      <div class="ql-card-header">
        <div class="ql-title">Potential External Access To Relational Database Server</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><span class="ql-type-badge">services</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>has_public:t AND service_has_public:f AND (_asset.protocol:=mysql OR _asset.protocol:=mysqlx OR _asset.protocol:=postgresql OR _asset.protocol:=mssql OR _asset.protocol:=oracledb) AND (protocol:=mysql OR protocol:=mysqlx OR protocol:=postgresql OR protocol:=mssql OR protocol:=oracledb)</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="has_public:t AND service_has_public:f AND (_asset.protocol:=mysql OR _asset.protocol:=mysqlx OR _asset.protocol:=postgresql OR _asset.protocol:=mssql OR _asset.protocol:=oracledb) AND (protocol:=mysql OR protocol:=mysqlx OR protocol:=postgresql OR protocol:=mssql OR protocol:=oracledb)" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/services?search=has_public%3At+AND+service_has_public%3Af+AND+%28_asset.protocol%3A%3Dmysql+OR+_asset.protocol%3A%3Dmysqlx+OR+_asset.protocol%3A%3Dpostgresql+OR+_asset.protocol%3A%3Dmssql+OR+_asset.protocol%3A%3Doracledb%29+AND+%28protocol%3A%3Dmysql+OR+protocol%3A%3Dmysqlx+OR+protocol%3A%3Dpostgresql+OR+protocol%3A%3Dmssql+OR+protocol%3A%3Doracledb%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/services?search=has_public%3At+AND+service_has_public%3Af+AND+%28_asset.protocol%3A%3Dmysql+OR+_asset.protocol%3A%3Dmysqlx+OR+_asset.protocol%3A%3Dpostgresql+OR+_asset.protocol%3A%3Dmssql+OR+_asset.protocol%3A%3Doracledb%29+AND+%28protocol%3A%3Dmysql+OR+protocol%3A%3Dmysqlx+OR+protocol%3A%3Dpostgresql+OR+protocol%3A%3Dmssql+OR+protocol%3A%3Doracledb%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="has_public:t AND service_has_public:f AND (_asset.protocol:=mysql OR _asset.protocol:=mysqlx OR _asset.protocol:=postgresql OR _asset.protocol:=mssql OR _asset.protocol:=oracledb) AND (protocol:=mysql OR protocol:=mysqlx OR protocol:=postgresql OR protocol:=mssql OR protocol:=oracledb)"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="potential external access to remote desktop gateway has_public:t and service_has_public:f and ( (_asset.protocol:dtls or _asset.protocol:http) and ((protocol:dtls or protocol:http) and has:rdg.transport) ) services internet exposure" data-ql-sev="low">
      <div class="ql-card-header">
        <div class="ql-title">Potential External Access To Remote Desktop Gateway</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><span class="ql-type-badge">services</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>has_public:t AND service_has_public:f AND ( (_asset.protocol:dtls OR _asset.protocol:http) AND ((protocol:dtls OR protocol:http) AND has:rdg.transport) )</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="has_public:t AND service_has_public:f AND ( (_asset.protocol:dtls OR _asset.protocol:http) AND ((protocol:dtls OR protocol:http) AND has:rdg.transport) )" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/services?search=has_public%3At+AND+service_has_public%3Af+AND+%28+%28_asset.protocol%3Adtls+OR+_asset.protocol%3Ahttp%29+AND+%28%28protocol%3Adtls+OR+protocol%3Ahttp%29+AND+has%3Ardg.transport%29+%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/services?search=has_public%3At+AND+service_has_public%3Af+AND+%28+%28_asset.protocol%3Adtls+OR+_asset.protocol%3Ahttp%29+AND+%28%28protocol%3Adtls+OR+protocol%3Ahttp%29+AND+has%3Ardg.transport%29+%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="has_public:t AND service_has_public:f AND ( (_asset.protocol:dtls OR _asset.protocol:http) AND ((protocol:dtls OR protocol:http) AND has:rdg.transport) )"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="potential external access to ssh server with password authentication has_public:t and service_has_public:f and (_asset.protocol:ssh and protocol:ssh and ssh.authmethods:password) services internet exposure" data-ql-sev="low">
      <div class="ql-card-header">
        <div class="ql-title">Potential External Access To SSH Server With Password Authentication</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><span class="ql-type-badge">services</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>has_public:t AND service_has_public:f AND (_asset.protocol:ssh AND protocol:ssh AND ssh.authMethods:password)</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="has_public:t AND service_has_public:f AND (_asset.protocol:ssh AND protocol:ssh AND ssh.authMethods:password)" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/services?search=has_public%3At+AND+service_has_public%3Af+AND+%28_asset.protocol%3Assh+AND+protocol%3Assh+AND+ssh.authMethods%3Apassword%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/services?search=has_public%3At+AND+service_has_public%3Af+AND+%28_asset.protocol%3Assh+AND+protocol%3Assh+AND+ssh.authMethods%3Apassword%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="has_public:t AND service_has_public:f AND (_asset.protocol:ssh AND protocol:ssh AND ssh.authMethods:password)"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="potential external access to windows management service has_public:t and service_has_public:f and ( ( _asset.protocol:smb and protocol:smb ) or ( _asset.protocol:epm and protocol:epm ) or ( _asset.protocol:wsman and protocol:wsman ) ) assets internet exposure" data-ql-sev="low">
      <div class="ql-card-header">
        <div class="ql-title">Potential External Access To Windows Management Service</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><span class="ql-type-badge">assets</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>has_public:t AND service_has_public:f AND ( ( _asset.protocol:smb AND protocol:smb ) OR ( _asset.protocol:epm AND protocol:epm ) OR ( _asset.protocol:wsman AND protocol:wsman ) )</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="has_public:t AND service_has_public:f AND ( ( _asset.protocol:smb AND protocol:smb ) OR ( _asset.protocol:epm AND protocol:epm ) OR ( _asset.protocol:wsman AND protocol:wsman ) )" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/?search=has_public%3At+AND+service_has_public%3Af+AND+%28+%28+_asset.protocol%3Asmb+AND+protocol%3Asmb+%29+OR+%28+_asset.protocol%3Aepm+AND+protocol%3Aepm+%29+OR+%28+_asset.protocol%3Awsman+AND+protocol%3Awsman+%29+%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/?search=has_public%3At+AND+service_has_public%3Af+AND+%28+%28+_asset.protocol%3Asmb+AND+protocol%3Asmb+%29+OR+%28+_asset.protocol%3Aepm+AND+protocol%3Aepm+%29+OR+%28+_asset.protocol%3Awsman+AND+protocol%3Awsman+%29+%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="has_public:t AND service_has_public:f AND ( ( _asset.protocol:smb AND protocol:smb ) OR ( _asset.protocol:epm AND protocol:epm ) OR ( _asset.protocol:wsman AND protocol:wsman ) )"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="publicly exposed key-value database server service_has_public:t and (_asset.protocols:memcache or _asset.protocols:redis) and (protocol:memcache or protocol:redis) services internet exposure" data-ql-sev="low">
      <div class="ql-card-header">
        <div class="ql-title">Publicly Exposed Key-Value Database Server</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><span class="ql-type-badge">services</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>service_has_public:t AND (_asset.protocols:memcache OR _asset.protocols:redis) AND (protocol:memcache OR protocol:redis)</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="service_has_public:t AND (_asset.protocols:memcache OR _asset.protocols:redis) AND (protocol:memcache OR protocol:redis)" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/services?search=service_has_public%3At+AND+%28_asset.protocols%3Amemcache+OR+_asset.protocols%3Aredis%29+AND+%28protocol%3Amemcache+OR+protocol%3Aredis%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/services?search=service_has_public%3At+AND+%28_asset.protocols%3Amemcache+OR+_asset.protocols%3Aredis%29+AND+%28protocol%3Amemcache+OR+protocol%3Aredis%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="service_has_public:t AND (_asset.protocols:memcache OR _asset.protocols:redis) AND (protocol:memcache OR protocol:redis)"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="publicly exposed nosql database server service_has_public:t and  (_asset.protocols:mongodb or _asset.protocols:couchdb or _asset.protocols:cassandra or _asset.protocols:elasticsearch or _asset.protocols:riak or _asset.protocols:influxdb) and (protocol:mongodb or protocol:couchdb or protocol:cassandra protocol:elasticsearch or protocol:riak or protocol:influxdb) services internet exposure" data-ql-sev="low">
      <div class="ql-card-header">
        <div class="ql-title">Publicly Exposed NoSQL Database Server</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><span class="ql-type-badge">services</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>service_has_public:t AND  (_asset.protocols:mongodb OR _asset.protocols:couchdb OR _asset.protocols:cassandra OR _asset.protocols:elasticsearch OR _asset.protocols:riak OR _asset.protocols:influxdb) AND (protocol:mongodb OR protocol:couchdb OR protocol:cassandra protocol:elasticsearch OR protocol:riak OR protocol:influxdb)</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="service_has_public:t AND  (_asset.protocols:mongodb OR _asset.protocols:couchdb OR _asset.protocols:cassandra OR _asset.protocols:elasticsearch OR _asset.protocols:riak OR _asset.protocols:influxdb) AND (protocol:mongodb OR protocol:couchdb OR protocol:cassandra protocol:elasticsearch OR protocol:riak OR protocol:influxdb)" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/services?search=service_has_public%3At+AND++%28_asset.protocols%3Amongodb+OR+_asset.protocols%3Acouchdb+OR+_asset.protocols%3Acassandra+OR+_asset.protocols%3Aelasticsearch+OR+_asset.protocols%3Ariak+OR+_asset.protocols%3Ainfluxdb%29+AND+%28protocol%3Amongodb+OR+protocol%3Acouchdb+OR+protocol%3Acassandra+protocol%3Aelasticsearch+OR+protocol%3Ariak+OR+protocol%3Ainfluxdb%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/services?search=service_has_public%3At+AND++%28_asset.protocols%3Amongodb+OR+_asset.protocols%3Acouchdb+OR+_asset.protocols%3Acassandra+OR+_asset.protocols%3Aelasticsearch+OR+_asset.protocols%3Ariak+OR+_asset.protocols%3Ainfluxdb%29+AND+%28protocol%3Amongodb+OR+protocol%3Acouchdb+OR+protocol%3Acassandra+protocol%3Aelasticsearch+OR+protocol%3Ariak+OR+protocol%3Ainfluxdb%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="service_has_public:t AND  (_asset.protocols:mongodb OR _asset.protocols:couchdb OR _asset.protocols:cassandra OR _asset.protocols:elasticsearch OR _asset.protocols:riak OR _asset.protocols:influxdb) AND (protocol:mongodb OR protocol:couchdb OR protocol:cassandra protocol:elasticsearch OR protocol:riak OR protocol:influxdb)"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="publicly exposed operational technology service service_has_public:t and (_asset.protocols:bacnet or _asset.protocols:modbus or _asset.protocols:dnp3 or _asset.protocols:opcua or _asset.protocols:cip or _asset.protocols:ethernetip or _asset.protocols:profinet or _asset.protocols:prosoft or _asset.protocols:s7comm or _asset.protocols:fins or _asset.protocols:comtrol or _asset.protocols:atg) and (protocol:bacnet or protocol:modbus or protocol:dnp3 or protocol:opcua or protocol:cip or protocol:ethernetip or protocol:profinet or protocol:prosoft or protocol:s7comm or protocol:fins or protocol:comtrol or protocol:atg) services internet exposure" data-ql-sev="low">
      <div class="ql-card-header">
        <div class="ql-title">Publicly Exposed Operational Technology Service</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><span class="ql-type-badge">services</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>service_has_public:t AND (_asset.protocols:bacnet OR _asset.protocols:modbus OR _asset.protocols:dnp3 OR _asset.protocols:opcua OR _asset.protocols:cip OR _asset.protocols:ethernetip OR _asset.protocols:profinet OR _asset.protocols:prosoft OR _asset.protocols:s7comm OR _asset.protocols:fins OR _asset.protocols:comtrol OR _asset.protocols:atg) AND (protocol:bacnet OR protocol:modbus OR protocol:dnp3 OR protocol:opcua OR protocol:cip OR protocol:ethernetip OR protocol:profinet OR protocol:prosoft OR protocol:s7comm OR protocol:fins OR protocol:comtrol OR protocol:atg)</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="service_has_public:t AND (_asset.protocols:bacnet OR _asset.protocols:modbus OR _asset.protocols:dnp3 OR _asset.protocols:opcua OR _asset.protocols:cip OR _asset.protocols:ethernetip OR _asset.protocols:profinet OR _asset.protocols:prosoft OR _asset.protocols:s7comm OR _asset.protocols:fins OR _asset.protocols:comtrol OR _asset.protocols:atg) AND (protocol:bacnet OR protocol:modbus OR protocol:dnp3 OR protocol:opcua OR protocol:cip OR protocol:ethernetip OR protocol:profinet OR protocol:prosoft OR protocol:s7comm OR protocol:fins OR protocol:comtrol OR protocol:atg)" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/services?search=service_has_public%3At+AND+%28_asset.protocols%3Abacnet+OR+_asset.protocols%3Amodbus+OR+_asset.protocols%3Adnp3+OR+_asset.protocols%3Aopcua+OR+_asset.protocols%3Acip+OR+_asset.protocols%3Aethernetip+OR+_asset.protocols%3Aprofinet+OR+_asset.protocols%3Aprosoft+OR+_asset.protocols%3As7comm+OR+_asset.protocols%3Afins+OR+_asset.protocols%3Acomtrol+OR+_asset.protocols%3Aatg%29+AND+%28protocol%3Abacnet+OR+protocol%3Amodbus+OR+protocol%3Adnp3+OR+protocol%3Aopcua+OR+protocol%3Acip+OR+protocol%3Aethernetip+OR+protocol%3Aprofinet+OR+protocol%3Aprosoft+OR+protocol%3As7comm+OR+protocol%3Afins+OR+protocol%3Acomtrol+OR+protocol%3Aatg%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/services?search=service_has_public%3At+AND+%28_asset.protocols%3Abacnet+OR+_asset.protocols%3Amodbus+OR+_asset.protocols%3Adnp3+OR+_asset.protocols%3Aopcua+OR+_asset.protocols%3Acip+OR+_asset.protocols%3Aethernetip+OR+_asset.protocols%3Aprofinet+OR+_asset.protocols%3Aprosoft+OR+_asset.protocols%3As7comm+OR+_asset.protocols%3Afins+OR+_asset.protocols%3Acomtrol+OR+_asset.protocols%3Aatg%29+AND+%28protocol%3Abacnet+OR+protocol%3Amodbus+OR+protocol%3Adnp3+OR+protocol%3Aopcua+OR+protocol%3Acip+OR+protocol%3Aethernetip+OR+protocol%3Aprofinet+OR+protocol%3Aprosoft+OR+protocol%3As7comm+OR+protocol%3Afins+OR+protocol%3Acomtrol+OR+protocol%3Aatg%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="service_has_public:t AND (_asset.protocols:bacnet OR _asset.protocols:modbus OR _asset.protocols:dnp3 OR _asset.protocols:opcua OR _asset.protocols:cip OR _asset.protocols:ethernetip OR _asset.protocols:profinet OR _asset.protocols:prosoft OR _asset.protocols:s7comm OR _asset.protocols:fins OR _asset.protocols:comtrol OR _asset.protocols:atg) AND (protocol:bacnet OR protocol:modbus OR protocol:dnp3 OR protocol:opcua OR protocol:cip OR protocol:ethernetip OR protocol:profinet OR protocol:prosoft OR protocol:s7comm OR protocol:fins OR protocol:comtrol OR protocol:atg)"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="publicly exposed relational database server service_has_public:t and ( _asset.protocol:=mysql or _asset.protocol:=mysqlx or _asset.protocol:=postgresql or _asset.protocol:=mssql or _asset.protocol:=oracledb) and (protocol:=mysql or protocol:=mysql or protocol:=postgresql or protocol:=mssql or protocol:=oracledb) services internet exposure" data-ql-sev="low">
      <div class="ql-card-header">
        <div class="ql-title">Publicly Exposed Relational Database Server</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><span class="ql-type-badge">services</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>service_has_public:t AND ( _asset.protocol:=mysql OR _asset.protocol:=mysqlx OR _asset.protocol:=postgresql OR _asset.protocol:=mssql OR _asset.protocol:=oracledb) AND (protocol:=mysql OR protocol:=mysql OR protocol:=postgresql OR protocol:=mssql OR protocol:=oracledb)</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="service_has_public:t AND ( _asset.protocol:=mysql OR _asset.protocol:=mysqlx OR _asset.protocol:=postgresql OR _asset.protocol:=mssql OR _asset.protocol:=oracledb) AND (protocol:=mysql OR protocol:=mysql OR protocol:=postgresql OR protocol:=mssql OR protocol:=oracledb)" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/services?search=service_has_public%3At+AND+%28+_asset.protocol%3A%3Dmysql+OR+_asset.protocol%3A%3Dmysqlx+OR+_asset.protocol%3A%3Dpostgresql+OR+_asset.protocol%3A%3Dmssql+OR+_asset.protocol%3A%3Doracledb%29+AND+%28protocol%3A%3Dmysql+OR+protocol%3A%3Dmysql+OR+protocol%3A%3Dpostgresql+OR+protocol%3A%3Dmssql+OR+protocol%3A%3Doracledb%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/services?search=service_has_public%3At+AND+%28+_asset.protocol%3A%3Dmysql+OR+_asset.protocol%3A%3Dmysqlx+OR+_asset.protocol%3A%3Dpostgresql+OR+_asset.protocol%3A%3Dmssql+OR+_asset.protocol%3A%3Doracledb%29+AND+%28protocol%3A%3Dmysql+OR+protocol%3A%3Dmysql+OR+protocol%3A%3Dpostgresql+OR+protocol%3A%3Dmssql+OR+protocol%3A%3Doracledb%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="service_has_public:t AND ( _asset.protocol:=mysql OR _asset.protocol:=mysqlx OR _asset.protocol:=postgresql OR _asset.protocol:=mssql OR _asset.protocol:=oracledb) AND (protocol:=mysql OR protocol:=mysql OR protocol:=postgresql OR protocol:=mssql OR protocol:=oracledb)"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
  </div>
</div>
<div class="ql-category" id="ql-open-access">
  <button class="ql-cat-header" onclick="qlToggleCat(this)"><span class="ql-cat-title">Open Access</span><span class="ql-cat-count">19 queries</span><span class="ql-cat-chevron">&#9660;</span></button>
  <div class="ql-cat-body">
    <div class="ql-card" data-ql-search="cisco smart install service _asset.protocol:ciscosmi protocol:ciscosmi services open access" data-ql-sev="critical">
      <div class="ql-card-header">
        <div class="ql-title">Cisco Smart Install Service</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><span class="ql-type-badge">services</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>_asset.protocol:ciscosmi protocol:ciscosmi</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="_asset.protocol:ciscosmi protocol:ciscosmi" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/services?search=_asset.protocol%3Aciscosmi+protocol%3Aciscosmi" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/services?search=_asset.protocol%3Aciscosmi+protocol%3Aciscosmi" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="_asset.protocol:ciscosmi protocol:ciscosmi"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="sun solaris sadmind rpc service _asset.protocol:=rpcbind protocol:=rpcbind rpcbind.programs:&#34;100232-v10-&#34; services open access" data-ql-sev="critical">
      <div class="ql-card-header">
        <div class="ql-title">Sun Solaris sadmind RPC Service</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><span class="ql-type-badge">services</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>_asset.protocol:=rpcbind protocol:=rpcbind rpcbind.programs:&#34;100232-v10-&#34;</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="_asset.protocol:=rpcbind protocol:=rpcbind rpcbind.programs:&#34;100232-v10-&#34;" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/services?search=_asset.protocol%3A%3Drpcbind+protocol%3A%3Drpcbind+rpcbind.programs%3A%22100232-v10-%22" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/services?search=_asset.protocol%3A%3Drpcbind+protocol%3A%3Drpcbind+rpcbind.programs%3A%22100232-v10-%22" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="_asset.protocol:=rpcbind protocol:=rpcbind rpcbind.programs:&#34;100232-v10-&#34;"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="unauthenticated android debug bridge _asset.protocol:=adb and protocol:=adb and has:adb.access and adb.access:=&#34;allowed&#34; services open access" data-ql-sev="critical">
      <div class="ql-card-header">
        <div class="ql-title">Unauthenticated Android Debug Bridge</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><span class="ql-type-badge">services</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>_asset.protocol:=adb AND protocol:=adb AND has:adb.access AND adb.access:=&#34;allowed&#34;</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="_asset.protocol:=adb AND protocol:=adb AND has:adb.access AND adb.access:=&#34;allowed&#34;" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/services?search=_asset.protocol%3A%3Dadb+AND+protocol%3A%3Dadb+AND+has%3Aadb.access+AND+adb.access%3A%3D%22allowed%22" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/services?search=_asset.protocol%3A%3Dadb+AND+protocol%3A%3Dadb+AND+has%3Aadb.access+AND+adb.access%3A%3D%22allowed%22" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="_asset.protocol:=adb AND protocol:=adb AND has:adb.access AND adb.access:=&#34;allowed&#34;"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="unauthenticated apache zookeeper database _asset.protocol:zookeeper and protocol:zookeeper and zk.access:allowed services open access" data-ql-sev="critical">
      <div class="ql-card-header">
        <div class="ql-title">Unauthenticated Apache ZooKeeper Database</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><span class="ql-type-badge">services</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>_asset.protocol:zookeeper AND protocol:zookeeper AND zk.access:allowed</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="_asset.protocol:zookeeper AND protocol:zookeeper AND zk.access:allowed" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/services?search=_asset.protocol%3Azookeeper+AND+protocol%3Azookeeper+AND+zk.access%3Aallowed" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/services?search=_asset.protocol%3Azookeeper+AND+protocol%3Azookeeper+AND+zk.access%3Aallowed" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="_asset.protocol:zookeeper AND protocol:zookeeper AND zk.access:allowed"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="unauthenticated cncf etcd database _asset.protocol:etcd2 protocol:etcd2 etcd2.access:allowed services open access" data-ql-sev="critical">
      <div class="ql-card-header">
        <div class="ql-title">Unauthenticated CNCF etcd Database</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><span class="ql-type-badge">services</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>_asset.protocol:etcd2 protocol:etcd2 etcd2.access:allowed</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="_asset.protocol:etcd2 protocol:etcd2 etcd2.access:allowed" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/services?search=_asset.protocol%3Aetcd2+protocol%3Aetcd2+etcd2.access%3Aallowed" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/services?search=_asset.protocol%3Aetcd2+protocol%3Aetcd2+etcd2.access%3Aallowed" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="_asset.protocol:etcd2 protocol:etcd2 etcd2.access:allowed"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="unauthenticated distributed ruby service _asset.protocol:=drbd and protocol:=drbd services open access" data-ql-sev="critical">
      <div class="ql-card-header">
        <div class="ql-title">Unauthenticated Distributed Ruby Service</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><span class="ql-type-badge">services</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>_asset.protocol:=drbd AND protocol:=drbd</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="_asset.protocol:=drbd AND protocol:=drbd" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/services?search=_asset.protocol%3A%3Ddrbd+AND+protocol%3A%3Ddrbd" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/services?search=_asset.protocol%3A%3Ddrbd+AND+protocol%3A%3Ddrbd" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="_asset.protocol:=drbd AND protocol:=drbd"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="unauthenticated mongodb database _asset.protocol:=mongodb and protocol:=mongodb and mongodb.auth:open services open access" data-ql-sev="critical">
      <div class="ql-card-header">
        <div class="ql-title">Unauthenticated MongoDB Database</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><span class="ql-type-badge">services</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>_asset.protocol:=mongodb AND protocol:=mongodb AND mongodb.auth:open</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="_asset.protocol:=mongodb AND protocol:=mongodb AND mongodb.auth:open" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/services?search=_asset.protocol%3A%3Dmongodb+AND+protocol%3A%3Dmongodb+AND+mongodb.auth%3Aopen" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/services?search=_asset.protocol%3A%3Dmongodb+AND+protocol%3A%3Dmongodb+AND+mongodb.auth%3Aopen" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="_asset.protocol:=mongodb AND protocol:=mongodb AND mongodb.auth:open"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="zabbix agent without acl _asset.protocol:=zabbix-agent and protocol:=zabbix-agent and not zabbix.islocal:true services open access" data-ql-sev="critical">
      <div class="ql-card-header">
        <div class="ql-title">Zabbix Agent Without ACL</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><span class="ql-type-badge">services</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>_asset.protocol:=zabbix-agent AND protocol:=zabbix-agent AND NOT zabbix.isLocal:true</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="_asset.protocol:=zabbix-agent AND protocol:=zabbix-agent AND NOT zabbix.isLocal:true" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/services?search=_asset.protocol%3A%3Dzabbix-agent+AND+protocol%3A%3Dzabbix-agent+AND+NOT+zabbix.isLocal%3Atrue" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/services?search=_asset.protocol%3A%3Dzabbix-agent+AND+protocol%3A%3Dzabbix-agent+AND+NOT+zabbix.isLocal%3Atrue" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="_asset.protocol:=zabbix-agent AND protocol:=zabbix-agent AND NOT zabbix.isLocal:true"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="unauthenticated apache couchdb database _asset.protocol:=couchdb and protocol:=couchdb services open access" data-ql-sev="high">
      <div class="ql-card-header">
        <div class="ql-title">Unauthenticated Apache CouchDB Database</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><span class="ql-type-badge">services</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>_asset.protocol:=couchdb AND protocol:=couchdb</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="_asset.protocol:=couchdb AND protocol:=couchdb" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/services?search=_asset.protocol%3A%3Dcouchdb+AND+protocol%3A%3Dcouchdb" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/services?search=_asset.protocol%3A%3Dcouchdb+AND+protocol%3A%3Dcouchdb" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="_asset.protocol:=couchdb AND protocol:=couchdb"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="unauthenticated cassandra database _asset.protocol:=cassandra and protocol:=cassandra services open access" data-ql-sev="high">
      <div class="ql-card-header">
        <div class="ql-title">Unauthenticated Cassandra Database</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><span class="ql-type-badge">services</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>_asset.protocol:=cassandra AND protocol:=cassandra</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="_asset.protocol:=cassandra AND protocol:=cassandra" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/services?search=_asset.protocol%3A%3Dcassandra+AND+protocol%3A%3Dcassandra" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/services?search=_asset.protocol%3A%3Dcassandra+AND+protocol%3A%3Dcassandra" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="_asset.protocol:=cassandra AND protocol:=cassandra"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="unauthenticated elastic search database _asset.protocol:elasticsearch and protocol:elasticsearch services open access" data-ql-sev="high">
      <div class="ql-card-header">
        <div class="ql-title">Unauthenticated Elastic Search Database</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><span class="ql-type-badge">services</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>_asset.protocol:elasticsearch AND protocol:elasticsearch</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="_asset.protocol:elasticsearch AND protocol:elasticsearch" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/services?search=_asset.protocol%3Aelasticsearch+AND+protocol%3Aelasticsearch" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/services?search=_asset.protocol%3Aelasticsearch+AND+protocol%3Aelasticsearch" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="_asset.protocol:elasticsearch AND protocol:elasticsearch"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="unauthenticated hashicorp consul database _asset.protocol:consul protocol:consul has:consul.config.datacenter services open access" data-ql-sev="high">
      <div class="ql-card-header">
        <div class="ql-title">Unauthenticated HashiCorp Consul Database</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><span class="ql-type-badge">services</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>_asset.protocol:consul protocol:consul has:consul.config.datacenter</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="_asset.protocol:consul protocol:consul has:consul.config.datacenter" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/services?search=_asset.protocol%3Aconsul+protocol%3Aconsul+has%3Aconsul.config.datacenter" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/services?search=_asset.protocol%3Aconsul+protocol%3Aconsul+has%3Aconsul.config.datacenter" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="_asset.protocol:consul protocol:consul has:consul.config.datacenter"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="unauthenticated influxdb database _asset.protocol:=influxdb and protocol:=influxdb and has:influxdb.databases services open access" data-ql-sev="high">
      <div class="ql-card-header">
        <div class="ql-title">Unauthenticated InfluxDB Database</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><span class="ql-type-badge">services</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>_asset.protocol:=influxdb AND protocol:=influxdb AND has:influxdb.databases</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="_asset.protocol:=influxdb AND protocol:=influxdb AND has:influxdb.databases" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/services?search=_asset.protocol%3A%3Dinfluxdb+AND+protocol%3A%3Dinfluxdb+AND+has%3Ainfluxdb.databases" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/services?search=_asset.protocol%3A%3Dinfluxdb+AND+protocol%3A%3Dinfluxdb+AND+has%3Ainfluxdb.databases" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="_asset.protocol:=influxdb AND protocol:=influxdb AND has:influxdb.databases"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="unauthenticated memcached database _asset.protocol:memcache and protocol:memcache services open access" data-ql-sev="high">
      <div class="ql-card-header">
        <div class="ql-title">Unauthenticated Memcached Database</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><span class="ql-type-badge">services</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>_asset.protocol:memcache AND protocol:memcache</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="_asset.protocol:memcache AND protocol:memcache" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/services?search=_asset.protocol%3Amemcache+AND+protocol%3Amemcache" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/services?search=_asset.protocol%3Amemcache+AND+protocol%3Amemcache" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="_asset.protocol:memcache AND protocol:memcache"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="unauthenticated redis database _asset.protocol:redis and protocol:redis and has:redis.redisversion services open access" data-ql-sev="high">
      <div class="ql-card-header">
        <div class="ql-title">Unauthenticated Redis Database</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><span class="ql-type-badge">services</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>_asset.protocol:redis AND protocol:redis AND has:redis.redisVersion</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="_asset.protocol:redis AND protocol:redis AND has:redis.redisVersion" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/services?search=_asset.protocol%3Aredis+AND+protocol%3Aredis+AND+has%3Aredis.redisVersion" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/services?search=_asset.protocol%3Aredis+AND+protocol%3Aredis+AND+has%3Aredis.redisVersion" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="_asset.protocol:redis AND protocol:redis AND has:redis.redisVersion"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="unauthenticated riak database (_asset.protocol:riak and protocol:riak) or (_asset.protocol:riak-http and protocol:riak-http) services open access" data-ql-sev="high">
      <div class="ql-card-header">
        <div class="ql-title">Unauthenticated Riak Database</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><span class="ql-type-badge">services</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>(_asset.protocol:riak AND protocol:riak) OR (_asset.protocol:riak-http AND protocol:riak-http)</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="(_asset.protocol:riak AND protocol:riak) OR (_asset.protocol:riak-http AND protocol:riak-http)" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/services?search=%28_asset.protocol%3Ariak+AND+protocol%3Ariak%29+OR+%28_asset.protocol%3Ariak-http+AND+protocol%3Ariak-http%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/services?search=%28_asset.protocol%3Ariak+AND+protocol%3Ariak%29+OR+%28_asset.protocol%3Ariak-http+AND+protocol%3Ariak-http%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="(_asset.protocol:riak AND protocol:riak) OR (_asset.protocol:riak-http AND protocol:riak-http)"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="click modular router shell _asset.protocol:=click protocol:=click services open access" data-ql-sev="medium">
      <div class="ql-card-header">
        <div class="ql-title">Click Modular Router Shell</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><span class="ql-type-badge">services</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>_asset.protocol:=click protocol:=click</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="_asset.protocol:=click protocol:=click" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/services?search=_asset.protocol%3A%3Dclick+protocol%3A%3Dclick" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/services?search=_asset.protocol%3A%3Dclick+protocol%3A%3Dclick" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="_asset.protocol:=click protocol:=click"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="unauthenticated mongodb database (limited) _asset.protocol:mongodb and protocol:mongodb and mongodb.auth:limited services open access" data-ql-sev="medium">
      <div class="ql-card-header">
        <div class="ql-title">Unauthenticated MongoDB Database (Limited)</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><span class="ql-type-badge">services</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>_asset.protocol:mongodb AND protocol:mongodb AND mongodb.auth:limited</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="_asset.protocol:mongodb AND protocol:mongodb AND mongodb.auth:limited" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/services?search=_asset.protocol%3Amongodb+AND+protocol%3Amongodb+AND+mongodb.auth%3Alimited" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/services?search=_asset.protocol%3Amongodb+AND+protocol%3Amongodb+AND+mongodb.auth%3Alimited" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="_asset.protocol:mongodb AND protocol:mongodb AND mongodb.auth:limited"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="world-readable nfs export _asset.protocol:=mountd and protocol:=&#34;mountd&#34; and nfs.allowed:&#34;%=*&#34; services open access" data-ql-sev="medium">
      <div class="ql-card-header">
        <div class="ql-title">World-Readable NFS Export</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><span class="ql-type-badge">services</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>_asset.protocol:=mountd AND protocol:=&#34;mountd&#34; AND nfs.allowed:&#34;%=*&#34;</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="_asset.protocol:=mountd AND protocol:=&#34;mountd&#34; AND nfs.allowed:&#34;%=*&#34;" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/services?search=_asset.protocol%3A%3Dmountd+AND+protocol%3A%3D%22mountd%22+AND+nfs.allowed%3A%22%25%3D%2A%22" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/services?search=_asset.protocol%3A%3Dmountd+AND+protocol%3A%3D%22mountd%22+AND+nfs.allowed%3A%22%25%3D%2A%22" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="_asset.protocol:=mountd AND protocol:=&#34;mountd&#34; AND nfs.allowed:&#34;%=*&#34;"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
  </div>
</div>
<div class="ql-category" id="ql-rapid-response">
  <button class="ql-cat-header" onclick="qlToggleCat(this)"><span class="ql-cat-title">Rapid Response</span><span class="ql-cat-count">4 queries</span><span class="ql-cat-chevron">&#9660;</span></button>
  <div class="ql-cat-body">
    <div class="ql-card" data-ql-search="rapid response: palo alto networks pan-os globalprotect authentication bypass (cve-2026-0257) hw:=&#34;palo alto networks&#34; and os:=&#34;palo alto networks pan-os%&#34; and os_version:&gt;0 and ((os_version:&gt;=&#34;12.1.5&#34; and os_version:&lt;&#34;12.1.7&#34;) or (os_version:&gt;=&#34;12.1.2&#34; and os_version:&lt;&#34;12.1.4-h6&#34;) or (os_version:&gt;=&#34;11.2.11&#34; and os_version:&lt;&#34;11.2.12&#34;) or (os_version:&gt;=&#34;11.2.8&#34; and os_version:&lt;&#34;11.2.10-h7&#34;) or (os_version:&gt;=&#34;11.2.5&#34; and os_version:&lt;&#34;11.2.7-h14&#34;) or (os_version:&gt;=&#34;11.2.0&#34; and os_version:&lt;&#34;11.2.4-h17&#34;) or (os_version:&gt;=&#34;11.1.14&#34; and os_version:&lt;&#34;11.1.15&#34;) or (os_version:&gt;=&#34;11.1.11&#34; and os_version:&lt;&#34;11.1.13-h5&#34;) or (os_version:&gt;=&#34;11.1.8&#34; and os_version:&lt;&#34;11.1.10-h25&#34;) or (os_version:&gt;=&#34;11.1.7&#34; and os_version:&lt;&#34;11.1.7-h6&#34;) or (os_version:&gt;=&#34;11.1.5&#34; and os_version:&lt;&#34;11.1.6-h32&#34;) or (os_version:&gt;=&#34;11.1.0&#34; and os_version:&lt;&#34;11.1.4-h33&#34;) or (os_version:&gt;=&#34;10.2.17&#34; and os_version:&lt;&#34;10.2.18-h6&#34;) or (os_version:&gt;=&#34;10.2.14&#34; and os_version:&lt;&#34;10.2.16-h7&#34;) or (os_version:&gt;=&#34;10.2.11&#34; and os_version:&lt;&#34;10.2.13-h21&#34;) or (os_version:&gt;=&#34;10.2.8&#34; and os_version:&lt;&#34;10.2.10-h36&#34;) or (os_version:&gt;=&#34;10.2.0&#34; and os_version:&lt;&#34;10.2.7-h34&#34;)) assets rapid response" data-ql-sev="high">
      <div class="ql-card-header">
        <div class="ql-title">Rapid Response: Palo Alto Networks PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257)</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><span class="ql-type-badge">assets</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>hw:=&#34;Palo Alto Networks&#34; AND os:=&#34;Palo Alto Networks PAN-OS%&#34; AND os_version:&gt;0 AND ((os_version:&gt;=&#34;12.1.5&#34; AND os_version:&lt;&#34;12.1.7&#34;) OR (os_version:&gt;=&#34;12.1.2&#34; AND os_version:&lt;&#34;12.1.4-h6&#34;) OR (os_version:&gt;=&#34;11.2.11&#34; AND os_version:&lt;&#34;11.2.12&#34;) OR (os_version:&gt;=&#34;11.2.8&#34; AND os_version:&lt;&#34;11.2.10-h7&#34;) OR (os_version:&gt;=&#34;11.2.5&#34; AND os_version:&lt;&#34;11.2.7-h14&#34;) OR (os_version:&gt;=&#34;11.2.0&#34; AND os_version:&lt;&#34;11.2.4-h17&#34;) OR (os_version:&gt;=&#34;11.1.14&#34; AND os_version:&lt;&#34;11.1.15&#34;) OR (os_version:&gt;=&#34;11.1.11&#34; AND os_version:&lt;&#34;11.1.13-h5&#34;) OR (os_version:&gt;=&#34;11.1.8&#34; AND os_version:&lt;&#34;11.1.10-h25&#34;) OR (os_version:&gt;=&#34;11.1.7&#34; AND os_version:&lt;&#34;11.1.7-h6&#34;) OR (os_version:&gt;=&#34;11.1.5&#34; AND os_version:&lt;&#34;11.1.6-h32&#34;) OR (os_version:&gt;=&#34;11.1.0&#34; AND os_version:&lt;&#34;11.1.4-h33&#34;) OR (os_version:&gt;=&#34;10.2.17&#34; AND os_version:&lt;&#34;10.2.18-h6&#34;) OR (os_version:&gt;=&#34;10.2.14&#34; AND os_version:&lt;&#34;10.2.16-h7&#34;) OR (os_version:&gt;=&#34;10.2.11&#34; AND os_version:&lt;&#34;10.2.13-h21&#34;) OR (os_version:&gt;=&#34;10.2.8&#34; AND os_version:&lt;&#34;10.2.10-h36&#34;) OR (os_version:&gt;=&#34;10.2.0&#34; AND os_version:&lt;&#34;10.2.7-h34&#34;))</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="hw:=&#34;Palo Alto Networks&#34; AND os:=&#34;Palo Alto Networks PAN-OS%&#34; AND os_version:&gt;0 AND ((os_version:&gt;=&#34;12.1.5&#34; AND os_version:&lt;&#34;12.1.7&#34;) OR (os_version:&gt;=&#34;12.1.2&#34; AND os_version:&lt;&#34;12.1.4-h6&#34;) OR (os_version:&gt;=&#34;11.2.11&#34; AND os_version:&lt;&#34;11.2.12&#34;) OR (os_version:&gt;=&#34;11.2.8&#34; AND os_version:&lt;&#34;11.2.10-h7&#34;) OR (os_version:&gt;=&#34;11.2.5&#34; AND os_version:&lt;&#34;11.2.7-h14&#34;) OR (os_version:&gt;=&#34;11.2.0&#34; AND os_version:&lt;&#34;11.2.4-h17&#34;) OR (os_version:&gt;=&#34;11.1.14&#34; AND os_version:&lt;&#34;11.1.15&#34;) OR (os_version:&gt;=&#34;11.1.11&#34; AND os_version:&lt;&#34;11.1.13-h5&#34;) OR (os_version:&gt;=&#34;11.1.8&#34; AND os_version:&lt;&#34;11.1.10-h25&#34;) OR (os_version:&gt;=&#34;11.1.7&#34; AND os_version:&lt;&#34;11.1.7-h6&#34;) OR (os_version:&gt;=&#34;11.1.5&#34; AND os_version:&lt;&#34;11.1.6-h32&#34;) OR (os_version:&gt;=&#34;11.1.0&#34; AND os_version:&lt;&#34;11.1.4-h33&#34;) OR (os_version:&gt;=&#34;10.2.17&#34; AND os_version:&lt;&#34;10.2.18-h6&#34;) OR (os_version:&gt;=&#34;10.2.14&#34; AND os_version:&lt;&#34;10.2.16-h7&#34;) OR (os_version:&gt;=&#34;10.2.11&#34; AND os_version:&lt;&#34;10.2.13-h21&#34;) OR (os_version:&gt;=&#34;10.2.8&#34; AND os_version:&lt;&#34;10.2.10-h36&#34;) OR (os_version:&gt;=&#34;10.2.0&#34; AND os_version:&lt;&#34;10.2.7-h34&#34;))" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/?search=hw%3A%3D%22Palo+Alto+Networks%22+AND+os%3A%3D%22Palo+Alto+Networks+PAN-OS%25%22+AND+os_version%3A%3E0+AND+%28%28os_version%3A%3E%3D%2212.1.5%22+AND+os_version%3A%3C%2212.1.7%22%29+OR+%28os_version%3A%3E%3D%2212.1.2%22+AND+os_version%3A%3C%2212.1.4-h6%22%29+OR+%28os_version%3A%3E%3D%2211.2.11%22+AND+os_version%3A%3C%2211.2.12%22%29+OR+%28os_version%3A%3E%3D%2211.2.8%22+AND+os_version%3A%3C%2211.2.10-h7%22%29+OR+%28os_version%3A%3E%3D%2211.2.5%22+AND+os_version%3A%3C%2211.2.7-h14%22%29+OR+%28os_version%3A%3E%3D%2211.2.0%22+AND+os_version%3A%3C%2211.2.4-h17%22%29+OR+%28os_version%3A%3E%3D%2211.1.14%22+AND+os_version%3A%3C%2211.1.15%22%29+OR+%28os_version%3A%3E%3D%2211.1.11%22+AND+os_version%3A%3C%2211.1.13-h5%22%29+OR+%28os_version%3A%3E%3D%2211.1.8%22+AND+os_version%3A%3C%2211.1.10-h25%22%29+OR+%28os_version%3A%3E%3D%2211.1.7%22+AND+os_version%3A%3C%2211.1.7-h6%22%29+OR+%28os_version%3A%3E%3D%2211.1.5%22+AND+os_version%3A%3C%2211.1.6-h32%22%29+OR+%28os_version%3A%3E%3D%2211.1.0%22+AND+os_version%3A%3C%2211.1.4-h33%22%29+OR+%28os_version%3A%3E%3D%2210.2.17%22+AND+os_version%3A%3C%2210.2.18-h6%22%29+OR+%28os_version%3A%3E%3D%2210.2.14%22+AND+os_version%3A%3C%2210.2.16-h7%22%29+OR+%28os_version%3A%3E%3D%2210.2.11%22+AND+os_version%3A%3C%2210.2.13-h21%22%29+OR+%28os_version%3A%3E%3D%2210.2.8%22+AND+os_version%3A%3C%2210.2.10-h36%22%29+OR+%28os_version%3A%3E%3D%2210.2.0%22+AND+os_version%3A%3C%2210.2.7-h34%22%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/?search=hw%3A%3D%22Palo+Alto+Networks%22+AND+os%3A%3D%22Palo+Alto+Networks+PAN-OS%25%22+AND+os_version%3A%3E0+AND+%28%28os_version%3A%3E%3D%2212.1.5%22+AND+os_version%3A%3C%2212.1.7%22%29+OR+%28os_version%3A%3E%3D%2212.1.2%22+AND+os_version%3A%3C%2212.1.4-h6%22%29+OR+%28os_version%3A%3E%3D%2211.2.11%22+AND+os_version%3A%3C%2211.2.12%22%29+OR+%28os_version%3A%3E%3D%2211.2.8%22+AND+os_version%3A%3C%2211.2.10-h7%22%29+OR+%28os_version%3A%3E%3D%2211.2.5%22+AND+os_version%3A%3C%2211.2.7-h14%22%29+OR+%28os_version%3A%3E%3D%2211.2.0%22+AND+os_version%3A%3C%2211.2.4-h17%22%29+OR+%28os_version%3A%3E%3D%2211.1.14%22+AND+os_version%3A%3C%2211.1.15%22%29+OR+%28os_version%3A%3E%3D%2211.1.11%22+AND+os_version%3A%3C%2211.1.13-h5%22%29+OR+%28os_version%3A%3E%3D%2211.1.8%22+AND+os_version%3A%3C%2211.1.10-h25%22%29+OR+%28os_version%3A%3E%3D%2211.1.7%22+AND+os_version%3A%3C%2211.1.7-h6%22%29+OR+%28os_version%3A%3E%3D%2211.1.5%22+AND+os_version%3A%3C%2211.1.6-h32%22%29+OR+%28os_version%3A%3E%3D%2211.1.0%22+AND+os_version%3A%3C%2211.1.4-h33%22%29+OR+%28os_version%3A%3E%3D%2210.2.17%22+AND+os_version%3A%3C%2210.2.18-h6%22%29+OR+%28os_version%3A%3E%3D%2210.2.14%22+AND+os_version%3A%3C%2210.2.16-h7%22%29+OR+%28os_version%3A%3E%3D%2210.2.11%22+AND+os_version%3A%3C%2210.2.13-h21%22%29+OR+%28os_version%3A%3E%3D%2210.2.8%22+AND+os_version%3A%3C%2210.2.10-h36%22%29+OR+%28os_version%3A%3E%3D%2210.2.0%22+AND+os_version%3A%3C%2210.2.7-h34%22%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="hw:=&#34;Palo Alto Networks&#34; AND os:=&#34;Palo Alto Networks PAN-OS%&#34; AND os_version:&gt;0 AND ((os_version:&gt;=&#34;12.1.5&#34; AND os_version:&lt;&#34;12.1.7&#34;) OR (os_version:&gt;=&#34;12.1.2&#34; AND os_version:&lt;&#34;12.1.4-h6&#34;) OR (os_version:&gt;=&#34;11.2.11&#34; AND os_version:&lt;&#34;11.2.12&#34;) OR (os_version:&gt;=&#34;11.2.8&#34; AND os_version:&lt;&#34;11.2.10-h7&#34;) OR (os_version:&gt;=&#34;11.2.5&#34; AND os_version:&lt;&#34;11.2.7-h14&#34;) OR (os_version:&gt;=&#34;11.2.0&#34; AND os_version:&lt;&#34;11.2.4-h17&#34;) OR (os_version:&gt;=&#34;11.1.14&#34; AND os_version:&lt;&#34;11.1.15&#34;) OR (os_version:&gt;=&#34;11.1.11&#34; AND os_version:&lt;&#34;11.1.13-h5&#34;) OR (os_version:&gt;=&#34;11.1.8&#34; AND os_version:&lt;&#34;11.1.10-h25&#34;) OR (os_version:&gt;=&#34;11.1.7&#34; AND os_version:&lt;&#34;11.1.7-h6&#34;) OR (os_version:&gt;=&#34;11.1.5&#34; AND os_version:&lt;&#34;11.1.6-h32&#34;) OR (os_version:&gt;=&#34;11.1.0&#34; AND os_version:&lt;&#34;11.1.4-h33&#34;) OR (os_version:&gt;=&#34;10.2.17&#34; AND os_version:&lt;&#34;10.2.18-h6&#34;) OR (os_version:&gt;=&#34;10.2.14&#34; AND os_version:&lt;&#34;10.2.16-h7&#34;) OR (os_version:&gt;=&#34;10.2.11&#34; AND os_version:&lt;&#34;10.2.13-h21&#34;) OR (os_version:&gt;=&#34;10.2.8&#34; AND os_version:&lt;&#34;10.2.10-h36&#34;) OR (os_version:&gt;=&#34;10.2.0&#34; AND os_version:&lt;&#34;10.2.7-h34&#34;))"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="rapid response: drupal core sql injection (cve-2026-9082) vendor:=drupal and product:=drupal software rapid response" data-ql-sev="info">
      <div class="ql-card-header">
        <div class="ql-title">Rapid Response: Drupal Core SQL Injection (CVE-2026-9082)</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><span class="ql-type-badge">software</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>vendor:=Drupal AND product:=Drupal</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="vendor:=Drupal AND product:=Drupal" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/software?search=vendor%3A%3DDrupal+AND+product%3A%3DDrupal" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/software?search=vendor%3A%3DDrupal+AND+product%3A%3DDrupal" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="vendor:=Drupal AND product:=Drupal"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="rapid response: gogs git rebase argument injection rce vendor:=gogs and product:=gogs software rapid response" data-ql-sev="info">
      <div class="ql-card-header">
        <div class="ql-title">Rapid Response: Gogs Git Rebase Argument Injection RCE</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><span class="ql-type-badge">software</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>vendor:=Gogs AND product:=Gogs</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="vendor:=Gogs AND product:=Gogs" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/software?search=vendor%3A%3DGogs+AND+product%3A%3DGogs" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/software?search=vendor%3A%3DGogs+AND+product%3A%3DGogs" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="vendor:=Gogs AND product:=Gogs"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="rapid response: vercel next.js ssrf via websocket upgrades (cve-2026-44578) vendor:=vercel and product:=&#34;next.js&#34; software rapid response" data-ql-sev="info">
      <div class="ql-card-header">
        <div class="ql-title">Rapid Response: Vercel Next.js SSRF Via WebSocket Upgrades (CVE-2026-44578)</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-info fd-badge-sm">Info</span><span class="ql-type-badge">software</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>vendor:=Vercel AND product:=&#34;Next.js&#34;</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="vendor:=Vercel AND product:=&#34;Next.js&#34;" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/software?search=vendor%3A%3DVercel+AND+product%3A%3D%22Next.js%22" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/software?search=vendor%3A%3DVercel+AND+product%3A%3D%22Next.js%22" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="vendor:=Vercel AND product:=&#34;Next.js&#34;"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
  </div>
</div>
<div class="ql-category" id="ql-vulnerability">
  <button class="ql-cat-header" onclick="qlToggleCat(this)"><span class="ql-cat-title">Vulnerability</span><span class="ql-cat-count">136 queries</span><span class="ql-cat-chevron">&#9660;</span></button>
  <div class="ql-cat-body">
    <div class="ql-card" data-ql-search="adobe commerce &amp; magento session takeover with unconfirmed rce (cve-2025-54236) vendor:=adobe and product:=magento and (version:&gt;0 and version:&lt;=&#34;2.4.9-alpha2&#34;) software vulnerability" data-ql-sev="critical">
      <div class="ql-card-header">
        <div class="ql-title">Adobe Commerce &amp; Magento Session Takeover With Unconfirmed RCE (CVE-2025-54236)</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><span class="ql-type-badge">software</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>vendor:=Adobe AND product:=Magento AND (version:&gt;0 AND version:&lt;=&#34;2.4.9-alpha2&#34;)</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="vendor:=Adobe AND product:=Magento AND (version:&gt;0 AND version:&lt;=&#34;2.4.9-alpha2&#34;)" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/software?search=vendor%3A%3DAdobe+AND+product%3A%3DMagento+AND+%28version%3A%3E0+AND+version%3A%3C%3D%222.4.9-alpha2%22%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/software?search=vendor%3A%3DAdobe+AND+product%3A%3DMagento+AND+%28version%3A%3E0+AND+version%3A%3C%3D%222.4.9-alpha2%22%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="vendor:=Adobe AND product:=Magento AND (version:&gt;0 AND version:&lt;=&#34;2.4.9-alpha2&#34;)"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="airplay protocol remote code execution (airborne) hw:=&#34;apple%&#34; and protocol:airplay and ( (os:=&#34;apple macos&#34; and ((osversion:&gt;&#34;13.0&#34; and osversion:&lt;&#34;13.7.5&#34;) or (osversion:&gt;&#34;14.0&#34; and osversion:&lt;&#34;14.7.5&#34;) or (osversion:&gt;&#34;15.0&#34; and osversion:&lt;&#34;15.4&#34;))) or (os:=&#34;apple ipados&#34; and ((osversion:&gt;&#34;17.0&#34; and osversion:&lt;&#34;17.7.6&#34;) or (osversion:&gt;&#34;18.0&#34; and osversion:&lt;&#34;18.4&#34;))) or ((os:=&#34;apple tvos&#34; or os:=&#34;apple audioos&#34;) and osversion:&gt;0 and osversion:&lt;&#34;18.4&#34;) or (os:=&#34;apple ios&#34; and osversion:&gt;0 and osversion:&lt;&#34;18.4&#34;) or (os:=&#34;apple visionos&#34; and osversion:&gt;0 and osversion:&lt;&#34;2.4&#34;) ) assets vulnerability" data-ql-sev="critical">
      <div class="ql-card-header">
        <div class="ql-title">AirPlay Protocol Remote Code Execution (AirBorne)</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><span class="ql-type-badge">assets</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>hw:=&#34;apple%&#34; AND protocol:airplay AND ( (os:=&#34;apple macos&#34; AND ((osversion:&gt;&#34;13.0&#34; AND osversion:&lt;&#34;13.7.5&#34;) OR (osversion:&gt;&#34;14.0&#34; AND osversion:&lt;&#34;14.7.5&#34;) OR (osversion:&gt;&#34;15.0&#34; AND osversion:&lt;&#34;15.4&#34;))) OR (os:=&#34;apple ipados&#34; AND ((osversion:&gt;&#34;17.0&#34; AND osversion:&lt;&#34;17.7.6&#34;) OR (osversion:&gt;&#34;18.0&#34; AND osversion:&lt;&#34;18.4&#34;))) OR ((os:=&#34;apple tvos&#34; OR os:=&#34;apple audioos&#34;) AND osversion:&gt;0 AND osversion:&lt;&#34;18.4&#34;) OR (os:=&#34;apple ios&#34; AND osversion:&gt;0 AND osversion:&lt;&#34;18.4&#34;) OR (os:=&#34;apple visionos&#34; AND osversion:&gt;0 AND osversion:&lt;&#34;2.4&#34;) )</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="hw:=&#34;apple%&#34; AND protocol:airplay AND ( (os:=&#34;apple macos&#34; AND ((osversion:&gt;&#34;13.0&#34; AND osversion:&lt;&#34;13.7.5&#34;) OR (osversion:&gt;&#34;14.0&#34; AND osversion:&lt;&#34;14.7.5&#34;) OR (osversion:&gt;&#34;15.0&#34; AND osversion:&lt;&#34;15.4&#34;))) OR (os:=&#34;apple ipados&#34; AND ((osversion:&gt;&#34;17.0&#34; AND osversion:&lt;&#34;17.7.6&#34;) OR (osversion:&gt;&#34;18.0&#34; AND osversion:&lt;&#34;18.4&#34;))) OR ((os:=&#34;apple tvos&#34; OR os:=&#34;apple audioos&#34;) AND osversion:&gt;0 AND osversion:&lt;&#34;18.4&#34;) OR (os:=&#34;apple ios&#34; AND osversion:&gt;0 AND osversion:&lt;&#34;18.4&#34;) OR (os:=&#34;apple visionos&#34; AND osversion:&gt;0 AND osversion:&lt;&#34;2.4&#34;) )" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/?search=hw%3A%3D%22apple%25%22+AND+protocol%3Aairplay+AND+%28+%28os%3A%3D%22apple+macos%22+AND+%28%28osversion%3A%3E%2213.0%22+AND+osversion%3A%3C%2213.7.5%22%29+OR+%28osversion%3A%3E%2214.0%22+AND+osversion%3A%3C%2214.7.5%22%29+OR+%28osversion%3A%3E%2215.0%22+AND+osversion%3A%3C%2215.4%22%29%29%29+OR+%28os%3A%3D%22apple+ipados%22+AND+%28%28osversion%3A%3E%2217.0%22+AND+osversion%3A%3C%2217.7.6%22%29+OR+%28osversion%3A%3E%2218.0%22+AND+osversion%3A%3C%2218.4%22%29%29%29+OR+%28%28os%3A%3D%22apple+tvos%22+OR+os%3A%3D%22apple+audioos%22%29+AND+osversion%3A%3E0+AND+osversion%3A%3C%2218.4%22%29+OR+%28os%3A%3D%22apple+ios%22+AND+osversion%3A%3E0+AND+osversion%3A%3C%2218.4%22%29+OR+%28os%3A%3D%22apple+visionos%22+AND+osversion%3A%3E0+AND+osversion%3A%3C%222.4%22%29+%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/?search=hw%3A%3D%22apple%25%22+AND+protocol%3Aairplay+AND+%28+%28os%3A%3D%22apple+macos%22+AND+%28%28osversion%3A%3E%2213.0%22+AND+osversion%3A%3C%2213.7.5%22%29+OR+%28osversion%3A%3E%2214.0%22+AND+osversion%3A%3C%2214.7.5%22%29+OR+%28osversion%3A%3E%2215.0%22+AND+osversion%3A%3C%2215.4%22%29%29%29+OR+%28os%3A%3D%22apple+ipados%22+AND+%28%28osversion%3A%3E%2217.0%22+AND+osversion%3A%3C%2217.7.6%22%29+OR+%28osversion%3A%3E%2218.0%22+AND+osversion%3A%3C%2218.4%22%29%29%29+OR+%28%28os%3A%3D%22apple+tvos%22+OR+os%3A%3D%22apple+audioos%22%29+AND+osversion%3A%3E0+AND+osversion%3A%3C%2218.4%22%29+OR+%28os%3A%3D%22apple+ios%22+AND+osversion%3A%3E0+AND+osversion%3A%3C%2218.4%22%29+OR+%28os%3A%3D%22apple+visionos%22+AND+osversion%3A%3E0+AND+osversion%3A%3C%222.4%22%29+%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="hw:=&#34;apple%&#34; AND protocol:airplay AND ( (os:=&#34;apple macos&#34; AND ((osversion:&gt;&#34;13.0&#34; AND osversion:&lt;&#34;13.7.5&#34;) OR (osversion:&gt;&#34;14.0&#34; AND osversion:&lt;&#34;14.7.5&#34;) OR (osversion:&gt;&#34;15.0&#34; AND osversion:&lt;&#34;15.4&#34;))) OR (os:=&#34;apple ipados&#34; AND ((osversion:&gt;&#34;17.0&#34; AND osversion:&lt;&#34;17.7.6&#34;) OR (osversion:&gt;&#34;18.0&#34; AND osversion:&lt;&#34;18.4&#34;))) OR ((os:=&#34;apple tvos&#34; OR os:=&#34;apple audioos&#34;) AND osversion:&gt;0 AND osversion:&lt;&#34;18.4&#34;) OR (os:=&#34;apple ios&#34; AND osversion:&gt;0 AND osversion:&lt;&#34;18.4&#34;) OR (os:=&#34;apple visionos&#34; AND osversion:&gt;0 AND osversion:&lt;&#34;2.4&#34;) )"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="apache 2.4.49 &lt; 2.4.51 information disclosure _asset.protocol:=http product:httpd and version:&gt;=2.4.49 and version:&lt;2.4.51 software vulnerability" data-ql-sev="critical">
      <div class="ql-card-header">
        <div class="ql-title">Apache 2.4.49 &lt; 2.4.51 Information Disclosure</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><span class="ql-type-badge">software</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>_asset.protocol:=http product:HTTPD AND version:&gt;=2.4.49 AND version:&lt;2.4.51</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="_asset.protocol:=http product:HTTPD AND version:&gt;=2.4.49 AND version:&lt;2.4.51" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/software?search=_asset.protocol%3A%3Dhttp+product%3AHTTPD+AND+version%3A%3E%3D2.4.49+AND+version%3A%3C2.4.51" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/software?search=_asset.protocol%3A%3Dhttp+product%3AHTTPD+AND+version%3A%3E%3D2.4.49+AND+version%3A%3C2.4.51" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="_asset.protocol:=http product:HTTPD AND version:&gt;=2.4.49 AND version:&lt;2.4.51"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="apache activemq remote code execution (cve-2023-46604) _asset.protocol:=activemq and product:activemq and ((version:&gt;0 and version:&lt;5.15.16) or (version:&gt;=5.16.0 and version:&lt;5.16.7) or (version:&gt;=5.17.0 and version:&lt;5.17.6) or (version:&gt;=5.18.0 and version:&lt;5.18.3)) software vulnerability" data-ql-sev="critical">
      <div class="ql-card-header">
        <div class="ql-title">Apache ActiveMQ Remote Code Execution (CVE-2023-46604)</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><span class="ql-type-badge">software</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>_asset.protocol:=activemq AND product:ActiveMQ AND ((version:&gt;0 AND version:&lt;5.15.16) OR (version:&gt;=5.16.0 AND version:&lt;5.16.7) OR (version:&gt;=5.17.0 AND version:&lt;5.17.6) OR (version:&gt;=5.18.0 AND version:&lt;5.18.3))</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="_asset.protocol:=activemq AND product:ActiveMQ AND ((version:&gt;0 AND version:&lt;5.15.16) OR (version:&gt;=5.16.0 AND version:&lt;5.16.7) OR (version:&gt;=5.17.0 AND version:&lt;5.17.6) OR (version:&gt;=5.18.0 AND version:&lt;5.18.3))" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/software?search=_asset.protocol%3A%3Dactivemq+AND+product%3AActiveMQ+AND+%28%28version%3A%3E0+AND+version%3A%3C5.15.16%29+OR+%28version%3A%3E%3D5.16.0+AND+version%3A%3C5.16.7%29+OR+%28version%3A%3E%3D5.17.0+AND+version%3A%3C5.17.6%29+OR+%28version%3A%3E%3D5.18.0+AND+version%3A%3C5.18.3%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/software?search=_asset.protocol%3A%3Dactivemq+AND+product%3AActiveMQ+AND+%28%28version%3A%3E0+AND+version%3A%3C5.15.16%29+OR+%28version%3A%3E%3D5.16.0+AND+version%3A%3C5.16.7%29+OR+%28version%3A%3E%3D5.17.0+AND+version%3A%3C5.17.6%29+OR+%28version%3A%3E%3D5.18.0+AND+version%3A%3C5.18.3%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="_asset.protocol:=activemq AND product:ActiveMQ AND ((version:&gt;0 AND version:&lt;5.15.16) OR (version:&gt;=5.16.0 AND version:&lt;5.16.7) OR (version:&gt;=5.17.0 AND version:&lt;5.17.6) OR (version:&gt;=5.18.0 AND version:&lt;5.18.3))"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="apache solr log4shell remote code execution vendor:=apache and product:solr and ((version:&gt;=7.4.0 and version:&lt;7.7.3) or (version:&gt;=8.0.0 and version:&lt;8.11.0)) software vulnerability" data-ql-sev="critical">
      <div class="ql-card-header">
        <div class="ql-title">Apache Solr Log4Shell Remote Code Execution</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><span class="ql-type-badge">software</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>vendor:=Apache AND product:Solr AND ((version:&gt;=7.4.0 AND version:&lt;7.7.3) OR (version:&gt;=8.0.0 AND version:&lt;8.11.0))</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="vendor:=Apache AND product:Solr AND ((version:&gt;=7.4.0 AND version:&lt;7.7.3) OR (version:&gt;=8.0.0 AND version:&lt;8.11.0))" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/software?search=vendor%3A%3DApache+AND+product%3ASolr+AND+%28%28version%3A%3E%3D7.4.0+AND+version%3A%3C7.7.3%29+OR+%28version%3A%3E%3D8.0.0+AND+version%3A%3C8.11.0%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/software?search=vendor%3A%3DApache+AND+product%3ASolr+AND+%28%28version%3A%3E%3D7.4.0+AND+version%3A%3C7.7.3%29+OR+%28version%3A%3E%3D8.0.0+AND+version%3A%3C8.11.0%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="vendor:=Apache AND product:Solr AND ((version:&gt;=7.4.0 AND version:&lt;7.7.3) OR (version:&gt;=8.0.0 AND version:&lt;8.11.0))"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="apache tomcat 10.1.0-m1 &lt; 10.1.34 multiple vulnerabilities product:tomcat and (version:&gt;10.1.0-m1 and version:&lt;10.1.34) software vulnerability" data-ql-sev="critical">
      <div class="ql-card-header">
        <div class="ql-title">Apache Tomcat 10.1.0-M1 &lt; 10.1.34 Multiple Vulnerabilities</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><span class="ql-type-badge">software</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>product:Tomcat AND (version:&gt;10.1.0-M1 AND version:&lt;10.1.34)</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="product:Tomcat AND (version:&gt;10.1.0-M1 AND version:&lt;10.1.34)" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/software?search=product%3ATomcat+AND+%28version%3A%3E10.1.0-M1+AND+version%3A%3C10.1.34%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/software?search=product%3ATomcat+AND+%28version%3A%3E10.1.0-M1+AND+version%3A%3C10.1.34%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="product:Tomcat AND (version:&gt;10.1.0-M1 AND version:&lt;10.1.34)"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="apache tomcat 11.0.0-m1 &lt; 11.0.2 multiple vulnerabilities product:tomcat and (version:&gt;11.0.0-m1 and version:&lt;11.0.2) software vulnerability" data-ql-sev="critical">
      <div class="ql-card-header">
        <div class="ql-title">Apache Tomcat 11.0.0-M1 &lt; 11.0.2 Multiple Vulnerabilities</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><span class="ql-type-badge">software</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>product:Tomcat AND (version:&gt;11.0.0-M1 AND version:&lt;11.0.2)</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="product:Tomcat AND (version:&gt;11.0.0-M1 AND version:&lt;11.0.2)" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/software?search=product%3ATomcat+AND+%28version%3A%3E11.0.0-M1+AND+version%3A%3C11.0.2%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/software?search=product%3ATomcat+AND+%28version%3A%3E11.0.0-M1+AND+version%3A%3C11.0.2%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="product:Tomcat AND (version:&gt;11.0.0-M1 AND version:&lt;11.0.2)"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="apache tomcat 9.0.0-m1 &lt; 9.0.98 multiple vulnerabilities product:tomcat and (version:&gt;9.0.0-m1 and version:&lt;9.0.98) software vulnerability" data-ql-sev="critical">
      <div class="ql-card-header">
        <div class="ql-title">Apache Tomcat 9.0.0-M1 &lt; 9.0.98 Multiple Vulnerabilities</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><span class="ql-type-badge">software</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>product:Tomcat AND (version:&gt;9.0.0-M1 AND version:&lt;9.0.98)</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="product:Tomcat AND (version:&gt;9.0.0-M1 AND version:&lt;9.0.98)" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/software?search=product%3ATomcat+AND+%28version%3A%3E9.0.0-M1+AND+version%3A%3C9.0.98%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/software?search=product%3ATomcat+AND+%28version%3A%3E9.0.0-M1+AND+version%3A%3C9.0.98%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="product:Tomcat AND (version:&gt;9.0.0-M1 AND version:&lt;9.0.98)"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="apple tvos &lt; 16.2 multiple vulnerabilities os:&#34;apple tvos&#34; and osversion:&gt;0 and osversion:&lt;16.2 assets vulnerability" data-ql-sev="critical">
      <div class="ql-card-header">
        <div class="ql-title">Apple tvOS &lt; 16.2 Multiple Vulnerabilities</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><span class="ql-type-badge">assets</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>os:&#34;Apple tvOS&#34; AND osversion:&gt;0 AND osversion:&lt;16.2</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="os:&#34;Apple tvOS&#34; AND osversion:&gt;0 AND osversion:&lt;16.2" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/?search=os%3A%22Apple+tvOS%22+AND+osversion%3A%3E0+AND+osversion%3A%3C16.2" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/?search=os%3A%22Apple+tvOS%22+AND+osversion%3A%3E0+AND+osversion%3A%3C16.2" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="os:&#34;Apple tvOS&#34; AND osversion:&gt;0 AND osversion:&lt;16.2"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="apple tvos &lt; 18.6 multiple vulnerabilities os:&#34;apple tvos&#34; and osversion:&gt;0 and osversion:&lt;18.6 assets vulnerability" data-ql-sev="critical">
      <div class="ql-card-header">
        <div class="ql-title">Apple tvOS &lt; 18.6 Multiple Vulnerabilities</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><span class="ql-type-badge">assets</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>os:&#34;Apple tvOS&#34; AND osversion:&gt;0 AND osversion:&lt;18.6</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="os:&#34;Apple tvOS&#34; AND osversion:&gt;0 AND osversion:&lt;18.6" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/?search=os%3A%22Apple+tvOS%22+AND+osversion%3A%3E0+AND+osversion%3A%3C18.6" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/?search=os%3A%22Apple+tvOS%22+AND+osversion%3A%3E0+AND+osversion%3A%3C18.6" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="os:&#34;Apple tvOS&#34; AND osversion:&gt;0 AND osversion:&lt;18.6"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="apple tvos &lt; 26 multiple vulnerabilities os:&#34;apple tvos&#34; and osversion:&gt;0 and osversion:&lt;26 assets vulnerability" data-ql-sev="critical">
      <div class="ql-card-header">
        <div class="ql-title">Apple tvOS &lt; 26 Multiple Vulnerabilities</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><span class="ql-type-badge">assets</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>os:&#34;Apple tvOS&#34; AND osversion:&gt;0 AND osversion:&lt;26</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="os:&#34;Apple tvOS&#34; AND osversion:&gt;0 AND osversion:&lt;26" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/?search=os%3A%22Apple+tvOS%22+AND+osversion%3A%3E0+AND+osversion%3A%3C26" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/?search=os%3A%22Apple+tvOS%22+AND+osversion%3A%3E0+AND+osversion%3A%3C26" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="os:&#34;Apple tvOS&#34; AND osversion:&gt;0 AND osversion:&lt;26"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="atlassian confluence 8.0 &lt; 8.5.4 remote code execution vendor:=atlassian and product:confluence and (version:&gt;=8.0 and version:&lt;8.5.4) software vulnerability" data-ql-sev="critical">
      <div class="ql-card-header">
        <div class="ql-title">Atlassian Confluence 8.0 &lt; 8.5.4 Remote Code Execution</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><span class="ql-type-badge">software</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>vendor:=Atlassian AND product:Confluence AND (version:&gt;=8.0 AND version:&lt;8.5.4)</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="vendor:=Atlassian AND product:Confluence AND (version:&gt;=8.0 AND version:&lt;8.5.4)" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/software?search=vendor%3A%3DAtlassian+AND+product%3AConfluence+AND+%28version%3A%3E%3D8.0+AND+version%3A%3C8.5.4%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/software?search=vendor%3A%3DAtlassian+AND+product%3AConfluence+AND+%28version%3A%3E%3D8.0+AND+version%3A%3C8.5.4%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="vendor:=Atlassian AND product:Confluence AND (version:&gt;=8.0 AND version:&lt;8.5.4)"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="atlassian confluence cross-site scripting (cve-2024-4367) vendor:=atlassian and product:confluence and ( (version:&gt;0 and version:&lt;7.19.25) or (version:&gt;=7.20.0 and version:&lt;8.5.11) or  (version:&gt;=8.6.0 and version:&lt;8.9.3))  software vulnerability" data-ql-sev="critical">
      <div class="ql-card-header">
        <div class="ql-title">Atlassian Confluence Cross-Site Scripting (CVE-2024-4367)</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><span class="ql-type-badge">software</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>vendor:=Atlassian AND product:Confluence AND ( (version:&gt;0 AND version:&lt;7.19.25) OR (version:&gt;=7.20.0 AND version:&lt;8.5.11) OR  (version:&gt;=8.6.0 AND version:&lt;8.9.3)) </code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="vendor:=Atlassian AND product:Confluence AND ( (version:&gt;0 AND version:&lt;7.19.25) OR (version:&gt;=7.20.0 AND version:&lt;8.5.11) OR  (version:&gt;=8.6.0 AND version:&lt;8.9.3)) " title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/software?search=vendor%3A%3DAtlassian+AND+product%3AConfluence+AND+%28+%28version%3A%3E0+AND+version%3A%3C7.19.25%29+OR+%28version%3A%3E%3D7.20.0+AND+version%3A%3C8.5.11%29+OR++%28version%3A%3E%3D8.6.0+AND+version%3A%3C8.9.3%29%29+" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/software?search=vendor%3A%3DAtlassian+AND+product%3AConfluence+AND+%28+%28version%3A%3E0+AND+version%3A%3C7.19.25%29+OR+%28version%3A%3E%3D7.20.0+AND+version%3A%3C8.5.11%29+OR++%28version%3A%3E%3D8.6.0+AND+version%3A%3C8.9.3%29%29+" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="vendor:=Atlassian AND product:Confluence AND ( (version:&gt;0 AND version:&lt;7.19.25) OR (version:&gt;=7.20.0 AND version:&lt;8.5.11) OR  (version:&gt;=8.6.0 AND version:&lt;8.9.3)) "><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="atlassian confluence path traversal (cve-2019-3396) vendor:=atlassian and product:confluence and not type:=mobile and ( (version:&gt;0 and version:&lt;6.6.12) or (version:&gt;=6.7.0 and version:&lt;6.12.3) or (version:&gt;=6.13.0 and version:&lt;6.13.3) or (version:&gt;=6.14.0 and version:&lt;6.14.2)) software vulnerability" data-ql-sev="critical">
      <div class="ql-card-header">
        <div class="ql-title">Atlassian Confluence Path Traversal (CVE-2019-3396)</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><span class="ql-type-badge">software</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>vendor:=Atlassian AND product:Confluence AND NOT type:=Mobile AND ( (version:&gt;0 AND version:&lt;6.6.12) OR (version:&gt;=6.7.0 AND version:&lt;6.12.3) OR (version:&gt;=6.13.0 AND version:&lt;6.13.3) OR (version:&gt;=6.14.0 AND version:&lt;6.14.2))</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="vendor:=Atlassian AND product:Confluence AND NOT type:=Mobile AND ( (version:&gt;0 AND version:&lt;6.6.12) OR (version:&gt;=6.7.0 AND version:&lt;6.12.3) OR (version:&gt;=6.13.0 AND version:&lt;6.13.3) OR (version:&gt;=6.14.0 AND version:&lt;6.14.2))" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/software?search=vendor%3A%3DAtlassian+AND+product%3AConfluence+AND+NOT+type%3A%3DMobile+AND+%28+%28version%3A%3E0+AND+version%3A%3C6.6.12%29+OR+%28version%3A%3E%3D6.7.0+AND+version%3A%3C6.12.3%29+OR+%28version%3A%3E%3D6.13.0+AND+version%3A%3C6.13.3%29+OR+%28version%3A%3E%3D6.14.0+AND+version%3A%3C6.14.2%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/software?search=vendor%3A%3DAtlassian+AND+product%3AConfluence+AND+NOT+type%3A%3DMobile+AND+%28+%28version%3A%3E0+AND+version%3A%3C6.6.12%29+OR+%28version%3A%3E%3D6.7.0+AND+version%3A%3C6.12.3%29+OR+%28version%3A%3E%3D6.13.0+AND+version%3A%3C6.13.3%29+OR+%28version%3A%3E%3D6.14.0+AND+version%3A%3C6.14.2%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="vendor:=Atlassian AND product:Confluence AND NOT type:=Mobile AND ( (version:&gt;0 AND version:&lt;6.6.12) OR (version:&gt;=6.7.0 AND version:&lt;6.12.3) OR (version:&gt;=6.13.0 AND version:&lt;6.13.3) OR (version:&gt;=6.14.0 AND version:&lt;6.14.2))"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="atlassian confluence privilege escalation (cve-2023-22515) vendor:=atlassian and product:confluence and ( (version:&gt;=8.0 and version:&lt;8.3.3) or (version:&gt;=8.4.0 and version:&lt;8.4.3) or (version:&gt;=8.5.0 and version:&lt;8.5.2)) software vulnerability" data-ql-sev="critical">
      <div class="ql-card-header">
        <div class="ql-title">Atlassian Confluence Privilege Escalation (CVE-2023-22515)</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><span class="ql-type-badge">software</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>vendor:=Atlassian AND product:Confluence AND ( (version:&gt;=8.0 AND version:&lt;8.3.3) OR (version:&gt;=8.4.0 AND version:&lt;8.4.3) OR (version:&gt;=8.5.0 AND version:&lt;8.5.2))</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="vendor:=Atlassian AND product:Confluence AND ( (version:&gt;=8.0 AND version:&lt;8.3.3) OR (version:&gt;=8.4.0 AND version:&lt;8.4.3) OR (version:&gt;=8.5.0 AND version:&lt;8.5.2))" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/software?search=vendor%3A%3DAtlassian+AND+product%3AConfluence+AND+%28+%28version%3A%3E%3D8.0+AND+version%3A%3C8.3.3%29+OR+%28version%3A%3E%3D8.4.0+AND+version%3A%3C8.4.3%29+OR+%28version%3A%3E%3D8.5.0+AND+version%3A%3C8.5.2%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/software?search=vendor%3A%3DAtlassian+AND+product%3AConfluence+AND+%28+%28version%3A%3E%3D8.0+AND+version%3A%3C8.3.3%29+OR+%28version%3A%3E%3D8.4.0+AND+version%3A%3C8.4.3%29+OR+%28version%3A%3E%3D8.5.0+AND+version%3A%3C8.5.2%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="vendor:=Atlassian AND product:Confluence AND ( (version:&gt;=8.0 AND version:&lt;8.3.3) OR (version:&gt;=8.4.0 AND version:&lt;8.4.3) OR (version:&gt;=8.5.0 AND version:&lt;8.5.2))"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="atlassian confluence remote code execution (cve-2021-26084) vendor:=atlassian and product:confluence and ( (version:&gt;0 and version:&lt;6.13.23) or  (version:&gt;=6.14.0 and version:&lt;7.4.11) or  (version:&gt;=7.5.0 and version:&lt;7.11.6) or (version:&gt;=7.12.0 and version:&lt;7.12.5))  software vulnerability" data-ql-sev="critical">
      <div class="ql-card-header">
        <div class="ql-title">Atlassian Confluence Remote Code Execution (CVE-2021-26084)</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><span class="ql-type-badge">software</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>vendor:=Atlassian AND product:Confluence AND ( (version:&gt;0 AND version:&lt;6.13.23) OR  (version:&gt;=6.14.0 AND version:&lt;7.4.11) OR  (version:&gt;=7.5.0 AND version:&lt;7.11.6) OR (version:&gt;=7.12.0 AND version:&lt;7.12.5)) </code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="vendor:=Atlassian AND product:Confluence AND ( (version:&gt;0 AND version:&lt;6.13.23) OR  (version:&gt;=6.14.0 AND version:&lt;7.4.11) OR  (version:&gt;=7.5.0 AND version:&lt;7.11.6) OR (version:&gt;=7.12.0 AND version:&lt;7.12.5)) " title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/software?search=vendor%3A%3DAtlassian+AND+product%3AConfluence+AND+%28+%28version%3A%3E0+AND+version%3A%3C6.13.23%29+OR++%28version%3A%3E%3D6.14.0+AND+version%3A%3C7.4.11%29+OR++%28version%3A%3E%3D7.5.0+AND+version%3A%3C7.11.6%29+OR+%28version%3A%3E%3D7.12.0+AND+version%3A%3C7.12.5%29%29+" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/software?search=vendor%3A%3DAtlassian+AND+product%3AConfluence+AND+%28+%28version%3A%3E0+AND+version%3A%3C6.13.23%29+OR++%28version%3A%3E%3D6.14.0+AND+version%3A%3C7.4.11%29+OR++%28version%3A%3E%3D7.5.0+AND+version%3A%3C7.11.6%29+OR+%28version%3A%3E%3D7.12.0+AND+version%3A%3C7.12.5%29%29+" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="vendor:=Atlassian AND product:Confluence AND ( (version:&gt;0 AND version:&lt;6.13.23) OR  (version:&gt;=6.14.0 AND version:&lt;7.4.11) OR  (version:&gt;=7.5.0 AND version:&lt;7.11.6) OR (version:&gt;=7.12.0 AND version:&lt;7.12.5)) "><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="atlassian confluence remote code execution (cve-2022-26134) vendor:=atlassian and product:confluence and ( (version:&gt;=1.3.0 and version:&lt;7.4.17) or (version:&gt;=7.13.0 and version:&lt;7.13.7) or (version:&gt;=7.14.0 and version:&lt;7.14.3) or (version:&gt;=7.15.0 and version:&lt;7.15.2) or (version:&gt;=7.16.0 and version:&lt;7.16.4) or (version:&gt;=7.17.0 and version:&lt;7.17.4) or (version:&gt;=7.18.0 and version:&lt;7.18.1) or ) software vulnerability" data-ql-sev="critical">
      <div class="ql-card-header">
        <div class="ql-title">Atlassian Confluence Remote Code Execution (CVE-2022-26134)</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><span class="ql-type-badge">software</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>vendor:=Atlassian AND product:Confluence AND ( (version:&gt;=1.3.0 AND version:&lt;7.4.17) OR (version:&gt;=7.13.0 AND version:&lt;7.13.7) OR (version:&gt;=7.14.0 AND version:&lt;7.14.3) OR (version:&gt;=7.15.0 AND version:&lt;7.15.2) OR (version:&gt;=7.16.0 AND version:&lt;7.16.4) OR (version:&gt;=7.17.0 AND version:&lt;7.17.4) OR (version:&gt;=7.18.0 AND version:&lt;7.18.1) OR )</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="vendor:=Atlassian AND product:Confluence AND ( (version:&gt;=1.3.0 AND version:&lt;7.4.17) OR (version:&gt;=7.13.0 AND version:&lt;7.13.7) OR (version:&gt;=7.14.0 AND version:&lt;7.14.3) OR (version:&gt;=7.15.0 AND version:&lt;7.15.2) OR (version:&gt;=7.16.0 AND version:&lt;7.16.4) OR (version:&gt;=7.17.0 AND version:&lt;7.17.4) OR (version:&gt;=7.18.0 AND version:&lt;7.18.1) OR )" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/software?search=vendor%3A%3DAtlassian+AND+product%3AConfluence+AND+%28+%28version%3A%3E%3D1.3.0+AND+version%3A%3C7.4.17%29+OR+%28version%3A%3E%3D7.13.0+AND+version%3A%3C7.13.7%29+OR+%28version%3A%3E%3D7.14.0+AND+version%3A%3C7.14.3%29+OR+%28version%3A%3E%3D7.15.0+AND+version%3A%3C7.15.2%29+OR+%28version%3A%3E%3D7.16.0+AND+version%3A%3C7.16.4%29+OR+%28version%3A%3E%3D7.17.0+AND+version%3A%3C7.17.4%29+OR+%28version%3A%3E%3D7.18.0+AND+version%3A%3C7.18.1%29+OR+%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/software?search=vendor%3A%3DAtlassian+AND+product%3AConfluence+AND+%28+%28version%3A%3E%3D1.3.0+AND+version%3A%3C7.4.17%29+OR+%28version%3A%3E%3D7.13.0+AND+version%3A%3C7.13.7%29+OR+%28version%3A%3E%3D7.14.0+AND+version%3A%3C7.14.3%29+OR+%28version%3A%3E%3D7.15.0+AND+version%3A%3C7.15.2%29+OR+%28version%3A%3E%3D7.16.0+AND+version%3A%3C7.16.4%29+OR+%28version%3A%3E%3D7.17.0+AND+version%3A%3C7.17.4%29+OR+%28version%3A%3E%3D7.18.0+AND+version%3A%3C7.18.1%29+OR+%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="vendor:=Atlassian AND product:Confluence AND ( (version:&gt;=1.3.0 AND version:&lt;7.4.17) OR (version:&gt;=7.13.0 AND version:&lt;7.13.7) OR (version:&gt;=7.14.0 AND version:&lt;7.14.3) OR (version:&gt;=7.15.0 AND version:&lt;7.15.2) OR (version:&gt;=7.16.0 AND version:&lt;7.16.4) OR (version:&gt;=7.17.0 AND version:&lt;7.17.4) OR (version:&gt;=7.18.0 AND version:&lt;7.18.1) OR )"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="atlassian confluence server-side request forgery (cve-2019-3395) vendor:=atlassian and product:confluence and ( (version:&gt;0 and version:&lt;6.6.7) or (version:&gt;=6.7.0 and version:&lt;6.8.5) or (version:&gt;=6.9.0 and version:&lt;6.9.3)) software vulnerability" data-ql-sev="critical">
      <div class="ql-card-header">
        <div class="ql-title">Atlassian Confluence Server-Side Request Forgery (CVE-2019-3395)</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><span class="ql-type-badge">software</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>vendor:=Atlassian AND product:Confluence AND ( (version:&gt;0 AND version:&lt;6.6.7) OR (version:&gt;=6.7.0 AND version:&lt;6.8.5) OR (version:&gt;=6.9.0 AND version:&lt;6.9.3))</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="vendor:=Atlassian AND product:Confluence AND ( (version:&gt;0 AND version:&lt;6.6.7) OR (version:&gt;=6.7.0 AND version:&lt;6.8.5) OR (version:&gt;=6.9.0 AND version:&lt;6.9.3))" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/software?search=vendor%3A%3DAtlassian+AND+product%3AConfluence+AND+%28+%28version%3A%3E0+AND+version%3A%3C6.6.7%29+OR+%28version%3A%3E%3D6.7.0+AND+version%3A%3C6.8.5%29+OR+%28version%3A%3E%3D6.9.0+AND+version%3A%3C6.9.3%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/software?search=vendor%3A%3DAtlassian+AND+product%3AConfluence+AND+%28+%28version%3A%3E0+AND+version%3A%3C6.6.7%29+OR+%28version%3A%3E%3D6.7.0+AND+version%3A%3C6.8.5%29+OR+%28version%3A%3E%3D6.9.0+AND+version%3A%3C6.9.3%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="vendor:=Atlassian AND product:Confluence AND ( (version:&gt;0 AND version:&lt;6.6.7) OR (version:&gt;=6.7.0 AND version:&lt;6.8.5) OR (version:&gt;=6.9.0 AND version:&lt;6.9.3))"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="broadcom vmware esxi guest escape os:&#34;vmware esxi&#34; and ((os_version:&gt;0 and os_version:&lt;6) or (os_version:&gt;6 and os_version:&lt;&#34;6.7.0 build-24514018&#34;)   or (os_version:&gt;7 and os_version:&lt;&#34;7.0.3 build-24585291&#34;) or (os_version:&gt;8 and os_version:&lt;&#34;8.0.2&#34;) or (os_version:&gt;&#34;8.0.2&#34; and os_version:&lt;&#34;8.0.2 build-24585300&#34;) or (os_version:&gt;&#34;8.0.3&#34; and os_version:&lt;&#34;8.0.3 build-24585383&#34;)) assets vulnerability" data-ql-sev="critical">
      <div class="ql-card-header">
        <div class="ql-title">Broadcom VMware ESXi Guest Escape</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><span class="ql-type-badge">assets</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>os:&#34;vmware esxi&#34; AND ((os_version:&gt;0 AND os_version:&lt;6) OR (os_version:&gt;6 AND os_version:&lt;&#34;6.7.0 build-24514018&#34;)   OR (os_version:&gt;7 AND os_version:&lt;&#34;7.0.3 build-24585291&#34;) OR (os_version:&gt;8 AND os_version:&lt;&#34;8.0.2&#34;) OR (os_version:&gt;&#34;8.0.2&#34; AND os_version:&lt;&#34;8.0.2 build-24585300&#34;) OR (os_version:&gt;&#34;8.0.3&#34; AND os_version:&lt;&#34;8.0.3 build-24585383&#34;))</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="os:&#34;vmware esxi&#34; AND ((os_version:&gt;0 AND os_version:&lt;6) OR (os_version:&gt;6 AND os_version:&lt;&#34;6.7.0 build-24514018&#34;)   OR (os_version:&gt;7 AND os_version:&lt;&#34;7.0.3 build-24585291&#34;) OR (os_version:&gt;8 AND os_version:&lt;&#34;8.0.2&#34;) OR (os_version:&gt;&#34;8.0.2&#34; AND os_version:&lt;&#34;8.0.2 build-24585300&#34;) OR (os_version:&gt;&#34;8.0.3&#34; AND os_version:&lt;&#34;8.0.3 build-24585383&#34;))" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/?search=os%3A%22vmware+esxi%22+AND+%28%28os_version%3A%3E0+AND+os_version%3A%3C6%29+OR+%28os_version%3A%3E6+AND+os_version%3A%3C%226.7.0+build-24514018%22%29+++OR+%28os_version%3A%3E7+AND+os_version%3A%3C%227.0.3+build-24585291%22%29+OR+%28os_version%3A%3E8+AND+os_version%3A%3C%228.0.2%22%29+OR+%28os_version%3A%3E%228.0.2%22+AND+os_version%3A%3C%228.0.2+build-24585300%22%29+OR+%28os_version%3A%3E%228.0.3%22+AND+os_version%3A%3C%228.0.3+build-24585383%22%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/?search=os%3A%22vmware+esxi%22+AND+%28%28os_version%3A%3E0+AND+os_version%3A%3C6%29+OR+%28os_version%3A%3E6+AND+os_version%3A%3C%226.7.0+build-24514018%22%29+++OR+%28os_version%3A%3E7+AND+os_version%3A%3C%227.0.3+build-24585291%22%29+OR+%28os_version%3A%3E8+AND+os_version%3A%3C%228.0.2%22%29+OR+%28os_version%3A%3E%228.0.2%22+AND+os_version%3A%3C%228.0.2+build-24585300%22%29+OR+%28os_version%3A%3E%228.0.3%22+AND+os_version%3A%3C%228.0.3+build-24585383%22%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="os:&#34;vmware esxi&#34; AND ((os_version:&gt;0 AND os_version:&lt;6) OR (os_version:&gt;6 AND os_version:&lt;&#34;6.7.0 build-24514018&#34;)   OR (os_version:&gt;7 AND os_version:&lt;&#34;7.0.3 build-24585291&#34;) OR (os_version:&gt;8 AND os_version:&lt;&#34;8.0.2&#34;) OR (os_version:&gt;&#34;8.0.2&#34; AND os_version:&lt;&#34;8.0.2 build-24585300&#34;) OR (os_version:&gt;&#34;8.0.3&#34; AND os_version:&lt;&#34;8.0.3 build-24585383&#34;))"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="broadcom vmware esxi vm escape os:&#34;vmware esxi&#34; and ((os_version:&gt;7 and os_version:&lt;&#34;7.0.3 build-24784741&#34;) or (os_version:&gt;8 and (os_version:&lt;&#34;8.0.2 build-24789317&#34; or os_version:&lt;&#34;8.0.3 build-24784735&#34;))) assets vulnerability" data-ql-sev="critical">
      <div class="ql-card-header">
        <div class="ql-title">Broadcom VMware ESXi VM Escape</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><span class="ql-type-badge">assets</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>os:&#34;vmware esxi&#34; AND ((os_version:&gt;7 AND os_version:&lt;&#34;7.0.3 build-24784741&#34;) OR (os_version:&gt;8 AND (os_version:&lt;&#34;8.0.2 build-24789317&#34; OR os_version:&lt;&#34;8.0.3 build-24784735&#34;)))</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="os:&#34;vmware esxi&#34; AND ((os_version:&gt;7 AND os_version:&lt;&#34;7.0.3 build-24784741&#34;) OR (os_version:&gt;8 AND (os_version:&lt;&#34;8.0.2 build-24789317&#34; OR os_version:&lt;&#34;8.0.3 build-24784735&#34;)))" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/?search=os%3A%22vmware+esxi%22+AND+%28%28os_version%3A%3E7+AND+os_version%3A%3C%227.0.3+build-24784741%22%29+OR+%28os_version%3A%3E8+AND+%28os_version%3A%3C%228.0.2+build-24789317%22+OR+os_version%3A%3C%228.0.3+build-24784735%22%29%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/?search=os%3A%22vmware+esxi%22+AND+%28%28os_version%3A%3E7+AND+os_version%3A%3C%227.0.3+build-24784741%22%29+OR+%28os_version%3A%3E8+AND+%28os_version%3A%3C%228.0.2+build-24789317%22+OR+os_version%3A%3C%228.0.3+build-24784735%22%29%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="os:&#34;vmware esxi&#34; AND ((os_version:&gt;7 AND os_version:&lt;&#34;7.0.3 build-24784741&#34;) OR (os_version:&gt;8 AND (os_version:&lt;&#34;8.0.2 build-24789317&#34; OR os_version:&lt;&#34;8.0.3 build-24784735&#34;)))"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="cacti &lt; 1.2.23 remote code execution _asset.products:cacti and vendor:=cacti and product:cacti and (version:&gt;0 and version:&lt;1.2.23) software vulnerability" data-ql-sev="critical">
      <div class="ql-card-header">
        <div class="ql-title">Cacti &lt; 1.2.23 Remote Code Execution</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><span class="ql-type-badge">software</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>_asset.products:Cacti AND vendor:=Cacti AND product:Cacti AND (version:&gt;0 AND version:&lt;1.2.23)</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="_asset.products:Cacti AND vendor:=Cacti AND product:Cacti AND (version:&gt;0 AND version:&lt;1.2.23)" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/software?search=_asset.products%3ACacti+AND+vendor%3A%3DCacti+AND+product%3ACacti+AND+%28version%3A%3E0+AND+version%3A%3C1.2.23%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/software?search=_asset.products%3ACacti+AND+vendor%3A%3DCacti+AND+product%3ACacti+AND+%28version%3A%3E0+AND+version%3A%3C1.2.23%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="_asset.products:Cacti AND vendor:=Cacti AND product:Cacti AND (version:&gt;0 AND version:&lt;1.2.23)"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="cisco secure firewall management center multiple vulnerabilities (2026-03) os:=&#34;cisco fmc%&#34; and os_version:&gt;0 and ((os_version:&gt;=&#34;6.4.0.13&#34; and os_version:&lt;=&#34;6.4.0.18&#34;) or (os_version:&gt;=&#34;7.0.0&#34; and os_version:&lt;&#34;7.0.9&#34;) or (os_version:&gt;=&#34;7.1.0&#34; and os_version:&lt;&#34;7.2.11&#34;) or (os_version:&gt;=&#34;7.3.0&#34; and os_version:&lt;&#34;7.4.6&#34;) or (os_version:&gt;=&#34;7.6.0&#34; and os_version:&lt;&#34;7.6.5&#34;) or (os_version:&gt;=&#34;7.7.0&#34; and os_version:&lt;&#34;7.7.12&#34;) or (os_version:=&#34;10.0.0&#34;)) assets vulnerability" data-ql-sev="critical">
      <div class="ql-card-header">
        <div class="ql-title">Cisco Secure Firewall Management Center Multiple Vulnerabilities (2026-03)</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><span class="ql-type-badge">assets</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>os:=&#34;Cisco FMC%&#34; AND os_version:&gt;0 AND ((os_version:&gt;=&#34;6.4.0.13&#34; AND os_version:&lt;=&#34;6.4.0.18&#34;) OR (os_version:&gt;=&#34;7.0.0&#34; AND os_version:&lt;&#34;7.0.9&#34;) OR (os_version:&gt;=&#34;7.1.0&#34; AND os_version:&lt;&#34;7.2.11&#34;) OR (os_version:&gt;=&#34;7.3.0&#34; AND os_version:&lt;&#34;7.4.6&#34;) OR (os_version:&gt;=&#34;7.6.0&#34; AND os_version:&lt;&#34;7.6.5&#34;) OR (os_version:&gt;=&#34;7.7.0&#34; AND os_version:&lt;&#34;7.7.12&#34;) OR (os_version:=&#34;10.0.0&#34;))</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="os:=&#34;Cisco FMC%&#34; AND os_version:&gt;0 AND ((os_version:&gt;=&#34;6.4.0.13&#34; AND os_version:&lt;=&#34;6.4.0.18&#34;) OR (os_version:&gt;=&#34;7.0.0&#34; AND os_version:&lt;&#34;7.0.9&#34;) OR (os_version:&gt;=&#34;7.1.0&#34; AND os_version:&lt;&#34;7.2.11&#34;) OR (os_version:&gt;=&#34;7.3.0&#34; AND os_version:&lt;&#34;7.4.6&#34;) OR (os_version:&gt;=&#34;7.6.0&#34; AND os_version:&lt;&#34;7.6.5&#34;) OR (os_version:&gt;=&#34;7.7.0&#34; AND os_version:&lt;&#34;7.7.12&#34;) OR (os_version:=&#34;10.0.0&#34;))" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/?search=os%3A%3D%22Cisco+FMC%25%22+AND+os_version%3A%3E0+AND+%28%28os_version%3A%3E%3D%226.4.0.13%22+AND+os_version%3A%3C%3D%226.4.0.18%22%29+OR+%28os_version%3A%3E%3D%227.0.0%22+AND+os_version%3A%3C%227.0.9%22%29+OR+%28os_version%3A%3E%3D%227.1.0%22+AND+os_version%3A%3C%227.2.11%22%29+OR+%28os_version%3A%3E%3D%227.3.0%22+AND+os_version%3A%3C%227.4.6%22%29+OR+%28os_version%3A%3E%3D%227.6.0%22+AND+os_version%3A%3C%227.6.5%22%29+OR+%28os_version%3A%3E%3D%227.7.0%22+AND+os_version%3A%3C%227.7.12%22%29+OR+%28os_version%3A%3D%2210.0.0%22%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/?search=os%3A%3D%22Cisco+FMC%25%22+AND+os_version%3A%3E0+AND+%28%28os_version%3A%3E%3D%226.4.0.13%22+AND+os_version%3A%3C%3D%226.4.0.18%22%29+OR+%28os_version%3A%3E%3D%227.0.0%22+AND+os_version%3A%3C%227.0.9%22%29+OR+%28os_version%3A%3E%3D%227.1.0%22+AND+os_version%3A%3C%227.2.11%22%29+OR+%28os_version%3A%3E%3D%227.3.0%22+AND+os_version%3A%3C%227.4.6%22%29+OR+%28os_version%3A%3E%3D%227.6.0%22+AND+os_version%3A%3C%227.6.5%22%29+OR+%28os_version%3A%3E%3D%227.7.0%22+AND+os_version%3A%3C%227.7.12%22%29+OR+%28os_version%3A%3D%2210.0.0%22%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="os:=&#34;Cisco FMC%&#34; AND os_version:&gt;0 AND ((os_version:&gt;=&#34;6.4.0.13&#34; AND os_version:&lt;=&#34;6.4.0.18&#34;) OR (os_version:&gt;=&#34;7.0.0&#34; AND os_version:&lt;&#34;7.0.9&#34;) OR (os_version:&gt;=&#34;7.1.0&#34; AND os_version:&lt;&#34;7.2.11&#34;) OR (os_version:&gt;=&#34;7.3.0&#34; AND os_version:&lt;&#34;7.4.6&#34;) OR (os_version:&gt;=&#34;7.6.0&#34; AND os_version:&lt;&#34;7.6.5&#34;) OR (os_version:&gt;=&#34;7.7.0&#34; AND os_version:&lt;&#34;7.7.12&#34;) OR (os_version:=&#34;10.0.0&#34;))"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="cisco small business rv series routers stack-based buffer overflow vulnerability (cve-2022-20700) ((hw:=&#34;cisco rv160%&#34; or hw:=&#34;cisco rv260%&#34;) and (os_version:&gt;0 and os_version:&lt;=&#34;1.0.01.05&#34;)) or  ((hw:=&#34;cisco rv340%&#34; or hw:=&#34;cisco rv345%&#34;) and (os_version:&gt;0 and os_version:&lt;=&#34;1.0.03.24&#34;)) assets vulnerability" data-ql-sev="critical">
      <div class="ql-card-header">
        <div class="ql-title">Cisco Small Business RV Series Routers Stack-Based Buffer Overflow Vulnerability (CVE-2022-20700)</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><span class="ql-type-badge">assets</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>((hw:=&#34;Cisco RV160%&#34; OR hw:=&#34;Cisco RV260%&#34;) AND (os_version:&gt;0 AND os_version:&lt;=&#34;1.0.01.05&#34;)) OR  ((hw:=&#34;Cisco RV340%&#34; OR hw:=&#34;Cisco RV345%&#34;) AND (os_version:&gt;0 AND os_version:&lt;=&#34;1.0.03.24&#34;))</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="((hw:=&#34;Cisco RV160%&#34; OR hw:=&#34;Cisco RV260%&#34;) AND (os_version:&gt;0 AND os_version:&lt;=&#34;1.0.01.05&#34;)) OR  ((hw:=&#34;Cisco RV340%&#34; OR hw:=&#34;Cisco RV345%&#34;) AND (os_version:&gt;0 AND os_version:&lt;=&#34;1.0.03.24&#34;))" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/?search=%28%28hw%3A%3D%22Cisco+RV160%25%22+OR+hw%3A%3D%22Cisco+RV260%25%22%29+AND+%28os_version%3A%3E0+AND+os_version%3A%3C%3D%221.0.01.05%22%29%29+OR++%28%28hw%3A%3D%22Cisco+RV340%25%22+OR+hw%3A%3D%22Cisco+RV345%25%22%29+AND+%28os_version%3A%3E0+AND+os_version%3A%3C%3D%221.0.03.24%22%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/?search=%28%28hw%3A%3D%22Cisco+RV160%25%22+OR+hw%3A%3D%22Cisco+RV260%25%22%29+AND+%28os_version%3A%3E0+AND+os_version%3A%3C%3D%221.0.01.05%22%29%29+OR++%28%28hw%3A%3D%22Cisco+RV340%25%22+OR+hw%3A%3D%22Cisco+RV345%25%22%29+AND+%28os_version%3A%3E0+AND+os_version%3A%3C%3D%221.0.03.24%22%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="((hw:=&#34;Cisco RV160%&#34; OR hw:=&#34;Cisco RV260%&#34;) AND (os_version:&gt;0 AND os_version:&lt;=&#34;1.0.01.05&#34;)) OR  ((hw:=&#34;Cisco RV340%&#34; OR hw:=&#34;Cisco RV345%&#34;) AND (os_version:&gt;0 AND os_version:&lt;=&#34;1.0.03.24&#34;))"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="cisco small business rv series vpn routers remote code execution vulnerability (cve-2022-20699) (hw:=&#34;cisco rv340%&#34; or hw:=&#34;cisco rv345%&#34;) and (os_version:&gt;0 and os_version:&lt;=&#34;1.0.03.24&#34;) assets vulnerability" data-ql-sev="critical">
      <div class="ql-card-header">
        <div class="ql-title">Cisco Small Business RV Series VPN Routers Remote Code Execution Vulnerability (CVE-2022-20699)</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><span class="ql-type-badge">assets</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>(hw:=&#34;Cisco RV340%&#34; OR hw:=&#34;Cisco RV345%&#34;) AND (os_version:&gt;0 AND os_version:&lt;=&#34;1.0.03.24&#34;)</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="(hw:=&#34;Cisco RV340%&#34; OR hw:=&#34;Cisco RV345%&#34;) AND (os_version:&gt;0 AND os_version:&lt;=&#34;1.0.03.24&#34;)" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/?search=%28hw%3A%3D%22Cisco+RV340%25%22+OR+hw%3A%3D%22Cisco+RV345%25%22%29+AND+%28os_version%3A%3E0+AND+os_version%3A%3C%3D%221.0.03.24%22%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/?search=%28hw%3A%3D%22Cisco+RV340%25%22+OR+hw%3A%3D%22Cisco+RV345%25%22%29+AND+%28os_version%3A%3E0+AND+os_version%3A%3C%3D%221.0.03.24%22%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="(hw:=&#34;Cisco RV340%&#34; OR hw:=&#34;Cisco RV345%&#34;) AND (os_version:&gt;0 AND os_version:&lt;=&#34;1.0.03.24&#34;)"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="cleo harmony &lt; 5.8.0.21 unrestricted file upload/download vendor:=cleo and product:harmony and (version:&gt;0 and version:&lt;5.8.0.21) software vulnerability" data-ql-sev="critical">
      <div class="ql-card-header">
        <div class="ql-title">Cleo Harmony &lt; 5.8.0.21 Unrestricted File Upload/Download</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><span class="ql-type-badge">software</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>vendor:=Cleo AND product:harmony AND (version:&gt;0 AND version:&lt;5.8.0.21)</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="vendor:=Cleo AND product:harmony AND (version:&gt;0 AND version:&lt;5.8.0.21)" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/software?search=vendor%3A%3DCleo+AND+product%3Aharmony+AND+%28version%3A%3E0+AND+version%3A%3C5.8.0.21%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/software?search=vendor%3A%3DCleo+AND+product%3Aharmony+AND+%28version%3A%3E0+AND+version%3A%3C5.8.0.21%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="vendor:=Cleo AND product:harmony AND (version:&gt;0 AND version:&lt;5.8.0.21)"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="cleo lexicom &lt; 5.8.0.21 unrestricted file upload/download vendor:=cleo and product:lexicom and (version:&gt;0 and version:&lt;5.8.0.21) software vulnerability" data-ql-sev="critical">
      <div class="ql-card-header">
        <div class="ql-title">Cleo Lexicom &lt; 5.8.0.21 Unrestricted File Upload/Download</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><span class="ql-type-badge">software</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>vendor:=Cleo AND product:lexicom AND (version:&gt;0 AND version:&lt;5.8.0.21)</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="vendor:=Cleo AND product:lexicom AND (version:&gt;0 AND version:&lt;5.8.0.21)" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/software?search=vendor%3A%3DCleo+AND+product%3Alexicom+AND+%28version%3A%3E0+AND+version%3A%3C5.8.0.21%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/software?search=vendor%3A%3DCleo+AND+product%3Alexicom+AND+%28version%3A%3E0+AND+version%3A%3C5.8.0.21%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="vendor:=Cleo AND product:lexicom AND (version:&gt;0 AND version:&lt;5.8.0.21)"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="cleo vltrader &lt; 5.8.0.21 unrestricted file upload/download vendor:=cleo and product:vltrader and (version:&gt;0 and version:&lt;5.8.0.21) software vulnerability" data-ql-sev="critical">
      <div class="ql-card-header">
        <div class="ql-title">Cleo VLTrader &lt; 5.8.0.21 Unrestricted File Upload/Download</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><span class="ql-type-badge">software</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>vendor:=Cleo AND product:vltrader AND (version:&gt;0 AND version:&lt;5.8.0.21)</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="vendor:=Cleo AND product:vltrader AND (version:&gt;0 AND version:&lt;5.8.0.21)" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/software?search=vendor%3A%3DCleo+AND+product%3Avltrader+AND+%28version%3A%3E0+AND+version%3A%3C5.8.0.21%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/software?search=vendor%3A%3DCleo+AND+product%3Avltrader+AND+%28version%3A%3E0+AND+version%3A%3C5.8.0.21%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="vendor:=Cleo AND product:vltrader AND (version:&gt;0 AND version:&lt;5.8.0.21)"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="connectwise screenconnect &lt; 23.9.8 remote code execution vendor:=connectwise and product:screenconnect and (version:&gt;0 and version:&lt;23.9.8) software vulnerability" data-ql-sev="critical">
      <div class="ql-card-header">
        <div class="ql-title">ConnectWise ScreenConnect &lt; 23.9.8 Remote Code Execution</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><span class="ql-type-badge">software</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>vendor:=ConnectWise AND product:ScreenConnect AND (version:&gt;0 AND version:&lt;23.9.8)</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="vendor:=ConnectWise AND product:ScreenConnect AND (version:&gt;0 AND version:&lt;23.9.8)" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/software?search=vendor%3A%3DConnectWise+AND+product%3AScreenConnect+AND+%28version%3A%3E0+AND+version%3A%3C23.9.8%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/software?search=vendor%3A%3DConnectWise+AND+product%3AScreenConnect+AND+%28version%3A%3E0+AND+version%3A%3C23.9.8%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="vendor:=ConnectWise AND product:ScreenConnect AND (version:&gt;0 AND version:&lt;23.9.8)"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="elastic kibana 8.15.0 &lt; 8.17.3 remote code execution vendor:=elastic and product:kibana and (version:&gt;8.14 and version:&lt;8.17.3) software vulnerability" data-ql-sev="critical">
      <div class="ql-card-header">
        <div class="ql-title">Elastic Kibana 8.15.0 &lt; 8.17.3 Remote Code Execution</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><span class="ql-type-badge">software</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>vendor:=Elastic AND product:kibana AND (version:&gt;8.14 AND version:&lt;8.17.3)</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="vendor:=Elastic AND product:kibana AND (version:&gt;8.14 AND version:&lt;8.17.3)" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/software?search=vendor%3A%3DElastic+AND+product%3Akibana+AND+%28version%3A%3E8.14+AND+version%3A%3C8.17.3%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/software?search=vendor%3A%3DElastic+AND+product%3Akibana+AND+%28version%3A%3E8.14+AND+version%3A%3C8.17.3%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="vendor:=Elastic AND product:kibana AND (version:&gt;8.14 AND version:&lt;8.17.3)"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="elasticsearch &lt; 1.2 remote code execution vendor:=elastic and (product:=search or product:=elasticsearch) and ( (version:&gt;0 and version:&lt;1.2 and not version:&#34;0:%&#34;) or (version:&#34;0:%&#34; and version:&gt;&#34;0:0&#34; and version:&lt;&#34;0:1.2&#34;)) software vulnerability" data-ql-sev="critical">
      <div class="ql-card-header">
        <div class="ql-title">Elasticsearch &lt; 1.2 Remote Code Execution</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><span class="ql-type-badge">software</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>vendor:=Elastic AND (product:=Search OR product:=Elasticsearch) AND ( (version:&gt;0 AND version:&lt;1.2 AND NOT version:&#34;0:%&#34;) OR (version:&#34;0:%&#34; AND version:&gt;&#34;0:0&#34; AND version:&lt;&#34;0:1.2&#34;))</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="vendor:=Elastic AND (product:=Search OR product:=Elasticsearch) AND ( (version:&gt;0 AND version:&lt;1.2 AND NOT version:&#34;0:%&#34;) OR (version:&#34;0:%&#34; AND version:&gt;&#34;0:0&#34; AND version:&lt;&#34;0:1.2&#34;))" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/software?search=vendor%3A%3DElastic+AND+%28product%3A%3DSearch+OR+product%3A%3DElasticsearch%29+AND+%28+%28version%3A%3E0+AND+version%3A%3C1.2+AND+NOT+version%3A%220%3A%25%22%29+OR+%28version%3A%220%3A%25%22+AND+version%3A%3E%220%3A0%22+AND+version%3A%3C%220%3A1.2%22%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/software?search=vendor%3A%3DElastic+AND+%28product%3A%3DSearch+OR+product%3A%3DElasticsearch%29+AND+%28+%28version%3A%3E0+AND+version%3A%3C1.2+AND+NOT+version%3A%220%3A%25%22%29+OR+%28version%3A%220%3A%25%22+AND+version%3A%3E%220%3A0%22+AND+version%3A%3C%220%3A1.2%22%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="vendor:=Elastic AND (product:=Search OR product:=Elasticsearch) AND ( (version:&gt;0 AND version:&lt;1.2 AND NOT version:&#34;0:%&#34;) OR (version:&#34;0:%&#34; AND version:&gt;&#34;0:0&#34; AND version:&lt;&#34;0:1.2&#34;))"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="f5 big-ip remote code execution (cve-2021-22986) os:=&#34;f5 networks big-ip&#34; and ( (osversion:&gt;&#34;12.1&#34; and osversion:&lt;&#34;12.1.5.3&#34;) or (osversion:&gt;&#34;13.1&#34; and osversion:&lt;&#34;13.1.3.6&#34;) or (osversion:&gt;&#34;14.1&#34; and osversion:&lt;&#34;14.1.4&#34;) or (osversion:&gt;&#34;15.1&#34; and osversion:&lt;&#34;15.1.2.1&#34;) or (osversion:&gt;&#34;16.0&#34; and osversion:&lt;&#34;16.0.1.1&#34;) ) assets vulnerability" data-ql-sev="critical">
      <div class="ql-card-header">
        <div class="ql-title">F5 Big-IP Remote Code Execution (CVE-2021-22986)</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><span class="ql-type-badge">assets</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>os:=&#34;F5 Networks BIG-IP&#34; AND ( (osversion:&gt;&#34;12.1&#34; AND osversion:&lt;&#34;12.1.5.3&#34;) OR (osversion:&gt;&#34;13.1&#34; AND osversion:&lt;&#34;13.1.3.6&#34;) OR (osversion:&gt;&#34;14.1&#34; AND osversion:&lt;&#34;14.1.4&#34;) OR (osversion:&gt;&#34;15.1&#34; AND osversion:&lt;&#34;15.1.2.1&#34;) OR (osversion:&gt;&#34;16.0&#34; AND osversion:&lt;&#34;16.0.1.1&#34;) )</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="os:=&#34;F5 Networks BIG-IP&#34; AND ( (osversion:&gt;&#34;12.1&#34; AND osversion:&lt;&#34;12.1.5.3&#34;) OR (osversion:&gt;&#34;13.1&#34; AND osversion:&lt;&#34;13.1.3.6&#34;) OR (osversion:&gt;&#34;14.1&#34; AND osversion:&lt;&#34;14.1.4&#34;) OR (osversion:&gt;&#34;15.1&#34; AND osversion:&lt;&#34;15.1.2.1&#34;) OR (osversion:&gt;&#34;16.0&#34; AND osversion:&lt;&#34;16.0.1.1&#34;) )" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/?search=os%3A%3D%22F5+Networks+BIG-IP%22+AND+%28+%28osversion%3A%3E%2212.1%22+AND+osversion%3A%3C%2212.1.5.3%22%29+OR+%28osversion%3A%3E%2213.1%22+AND+osversion%3A%3C%2213.1.3.6%22%29+OR+%28osversion%3A%3E%2214.1%22+AND+osversion%3A%3C%2214.1.4%22%29+OR+%28osversion%3A%3E%2215.1%22+AND+osversion%3A%3C%2215.1.2.1%22%29+OR+%28osversion%3A%3E%2216.0%22+AND+osversion%3A%3C%2216.0.1.1%22%29+%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/?search=os%3A%3D%22F5+Networks+BIG-IP%22+AND+%28+%28osversion%3A%3E%2212.1%22+AND+osversion%3A%3C%2212.1.5.3%22%29+OR+%28osversion%3A%3E%2213.1%22+AND+osversion%3A%3C%2213.1.3.6%22%29+OR+%28osversion%3A%3E%2214.1%22+AND+osversion%3A%3C%2214.1.4%22%29+OR+%28osversion%3A%3E%2215.1%22+AND+osversion%3A%3C%2215.1.2.1%22%29+OR+%28osversion%3A%3E%2216.0%22+AND+osversion%3A%3C%2216.0.1.1%22%29+%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="os:=&#34;F5 Networks BIG-IP&#34; AND ( (osversion:&gt;&#34;12.1&#34; AND osversion:&lt;&#34;12.1.5.3&#34;) OR (osversion:&gt;&#34;13.1&#34; AND osversion:&lt;&#34;13.1.3.6&#34;) OR (osversion:&gt;&#34;14.1&#34; AND osversion:&lt;&#34;14.1.4&#34;) OR (osversion:&gt;&#34;15.1&#34; AND osversion:&lt;&#34;15.1.2.1&#34;) OR (osversion:&gt;&#34;16.0&#34; AND osversion:&lt;&#34;16.0.1.1&#34;) )"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="fortinet fortios out-of-bound write vulnerability (cve-2024-21762) os:=&#34;fortinet fortios&#34; and ((os_version:&gt;=&#34;7.4.0&#34; and os_version:&lt;&#34;7.4.3&#34;) or (os_version:&gt;=&#34;7.2.0&#34; and os_version:&lt;&#34;7.2.7&#34;) or (os_version:&gt;=&#34;7.0.0&#34; and os_version:&lt;&#34;7.0.14&#34;) or (os_version:&gt;=&#34;2.0.0&#34; and os_version:&lt;&#34;2.0.14&#34;) or (os_version:&gt;=&#34;1.2.0&#34; and os_version:&lt;&#34;1.2.14&#34;) or (os_version:&gt;=&#34;1.1.0&#34; and os_version:&lt;&#34;1.1.7&#34;) or (os_version:&gt;=&#34;1.0.0&#34; and os_version:&lt;&#34;1.0.8&#34;)) assets vulnerability" data-ql-sev="critical">
      <div class="ql-card-header">
        <div class="ql-title">Fortinet FortiOS Out-Of-Bound Write Vulnerability (CVE-2024-21762)</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><span class="ql-type-badge">assets</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>os:=&#34;Fortinet FortiOS&#34; AND ((os_version:&gt;=&#34;7.4.0&#34; AND os_version:&lt;&#34;7.4.3&#34;) OR (os_version:&gt;=&#34;7.2.0&#34; AND os_version:&lt;&#34;7.2.7&#34;) OR (os_version:&gt;=&#34;7.0.0&#34; AND os_version:&lt;&#34;7.0.14&#34;) OR (os_version:&gt;=&#34;2.0.0&#34; AND os_version:&lt;&#34;2.0.14&#34;) OR (os_version:&gt;=&#34;1.2.0&#34; AND os_version:&lt;&#34;1.2.14&#34;) OR (os_version:&gt;=&#34;1.1.0&#34; AND os_version:&lt;&#34;1.1.7&#34;) OR (os_version:&gt;=&#34;1.0.0&#34; AND os_version:&lt;&#34;1.0.8&#34;))</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="os:=&#34;Fortinet FortiOS&#34; AND ((os_version:&gt;=&#34;7.4.0&#34; AND os_version:&lt;&#34;7.4.3&#34;) OR (os_version:&gt;=&#34;7.2.0&#34; AND os_version:&lt;&#34;7.2.7&#34;) OR (os_version:&gt;=&#34;7.0.0&#34; AND os_version:&lt;&#34;7.0.14&#34;) OR (os_version:&gt;=&#34;2.0.0&#34; AND os_version:&lt;&#34;2.0.14&#34;) OR (os_version:&gt;=&#34;1.2.0&#34; AND os_version:&lt;&#34;1.2.14&#34;) OR (os_version:&gt;=&#34;1.1.0&#34; AND os_version:&lt;&#34;1.1.7&#34;) OR (os_version:&gt;=&#34;1.0.0&#34; AND os_version:&lt;&#34;1.0.8&#34;))" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/?search=os%3A%3D%22Fortinet+FortiOS%22+AND+%28%28os_version%3A%3E%3D%227.4.0%22+AND+os_version%3A%3C%227.4.3%22%29+OR+%28os_version%3A%3E%3D%227.2.0%22+AND+os_version%3A%3C%227.2.7%22%29+OR+%28os_version%3A%3E%3D%227.0.0%22+AND+os_version%3A%3C%227.0.14%22%29+OR+%28os_version%3A%3E%3D%222.0.0%22+AND+os_version%3A%3C%222.0.14%22%29+OR+%28os_version%3A%3E%3D%221.2.0%22+AND+os_version%3A%3C%221.2.14%22%29+OR+%28os_version%3A%3E%3D%221.1.0%22+AND+os_version%3A%3C%221.1.7%22%29+OR+%28os_version%3A%3E%3D%221.0.0%22+AND+os_version%3A%3C%221.0.8%22%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/?search=os%3A%3D%22Fortinet+FortiOS%22+AND+%28%28os_version%3A%3E%3D%227.4.0%22+AND+os_version%3A%3C%227.4.3%22%29+OR+%28os_version%3A%3E%3D%227.2.0%22+AND+os_version%3A%3C%227.2.7%22%29+OR+%28os_version%3A%3E%3D%227.0.0%22+AND+os_version%3A%3C%227.0.14%22%29+OR+%28os_version%3A%3E%3D%222.0.0%22+AND+os_version%3A%3C%222.0.14%22%29+OR+%28os_version%3A%3E%3D%221.2.0%22+AND+os_version%3A%3C%221.2.14%22%29+OR+%28os_version%3A%3E%3D%221.1.0%22+AND+os_version%3A%3C%221.1.7%22%29+OR+%28os_version%3A%3E%3D%221.0.0%22+AND+os_version%3A%3C%221.0.8%22%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="os:=&#34;Fortinet FortiOS&#34; AND ((os_version:&gt;=&#34;7.4.0&#34; AND os_version:&lt;&#34;7.4.3&#34;) OR (os_version:&gt;=&#34;7.2.0&#34; AND os_version:&lt;&#34;7.2.7&#34;) OR (os_version:&gt;=&#34;7.0.0&#34; AND os_version:&lt;&#34;7.0.14&#34;) OR (os_version:&gt;=&#34;2.0.0&#34; AND os_version:&lt;&#34;2.0.14&#34;) OR (os_version:&gt;=&#34;1.2.0&#34; AND os_version:&lt;&#34;1.2.14&#34;) OR (os_version:&gt;=&#34;1.1.0&#34; AND os_version:&lt;&#34;1.1.7&#34;) OR (os_version:&gt;=&#34;1.0.0&#34; AND os_version:&lt;&#34;1.0.8&#34;))"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="fortinet multiple products format string vulnerability (cve-2024-23113) (os:=&#34;fortinet fortios&#34; and ((os_version:&gt;=&#34;7.4.0&#34; and os_version:&lt;&#34;7.4.3&#34;) or (os_version:&gt;=&#34;7.2.0&#34; and os_version:&lt;&#34;7.2.7&#34;) or (os_version:&gt;=&#34;7.0.0&#34; and os_version:&lt;&#34;7.0.15&#34;))) or (os:=&#34;fortinet fortipam&#34; and ((os_version:&gt;=&#34;1.0.0&#34; and os_version:&lt;&#34;1.0.4&#34;) or (os_version:&gt;=&#34;1.1.0&#34; and os_version:&lt;&#34;1.1.3&#34;) or (os_version:=&#34;1.2.0&#34;))) assets vulnerability" data-ql-sev="critical">
      <div class="ql-card-header">
        <div class="ql-title">Fortinet Multiple Products Format String Vulnerability (CVE-2024-23113)</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><span class="ql-type-badge">assets</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>(os:=&#34;Fortinet FortiOS&#34; AND ((os_version:&gt;=&#34;7.4.0&#34; AND os_version:&lt;&#34;7.4.3&#34;) OR (os_version:&gt;=&#34;7.2.0&#34; AND os_version:&lt;&#34;7.2.7&#34;) OR (os_version:&gt;=&#34;7.0.0&#34; AND os_version:&lt;&#34;7.0.15&#34;))) OR (os:=&#34;Fortinet FortiPAM&#34; AND ((os_version:&gt;=&#34;1.0.0&#34; AND os_version:&lt;&#34;1.0.4&#34;) OR (os_version:&gt;=&#34;1.1.0&#34; AND os_version:&lt;&#34;1.1.3&#34;) OR (os_version:=&#34;1.2.0&#34;)))</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="(os:=&#34;Fortinet FortiOS&#34; AND ((os_version:&gt;=&#34;7.4.0&#34; AND os_version:&lt;&#34;7.4.3&#34;) OR (os_version:&gt;=&#34;7.2.0&#34; AND os_version:&lt;&#34;7.2.7&#34;) OR (os_version:&gt;=&#34;7.0.0&#34; AND os_version:&lt;&#34;7.0.15&#34;))) OR (os:=&#34;Fortinet FortiPAM&#34; AND ((os_version:&gt;=&#34;1.0.0&#34; AND os_version:&lt;&#34;1.0.4&#34;) OR (os_version:&gt;=&#34;1.1.0&#34; AND os_version:&lt;&#34;1.1.3&#34;) OR (os_version:=&#34;1.2.0&#34;)))" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/?search=%28os%3A%3D%22Fortinet+FortiOS%22+AND+%28%28os_version%3A%3E%3D%227.4.0%22+AND+os_version%3A%3C%227.4.3%22%29+OR+%28os_version%3A%3E%3D%227.2.0%22+AND+os_version%3A%3C%227.2.7%22%29+OR+%28os_version%3A%3E%3D%227.0.0%22+AND+os_version%3A%3C%227.0.15%22%29%29%29+OR+%28os%3A%3D%22Fortinet+FortiPAM%22+AND+%28%28os_version%3A%3E%3D%221.0.0%22+AND+os_version%3A%3C%221.0.4%22%29+OR+%28os_version%3A%3E%3D%221.1.0%22+AND+os_version%3A%3C%221.1.3%22%29+OR+%28os_version%3A%3D%221.2.0%22%29%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/?search=%28os%3A%3D%22Fortinet+FortiOS%22+AND+%28%28os_version%3A%3E%3D%227.4.0%22+AND+os_version%3A%3C%227.4.3%22%29+OR+%28os_version%3A%3E%3D%227.2.0%22+AND+os_version%3A%3C%227.2.7%22%29+OR+%28os_version%3A%3E%3D%227.0.0%22+AND+os_version%3A%3C%227.0.15%22%29%29%29+OR+%28os%3A%3D%22Fortinet+FortiPAM%22+AND+%28%28os_version%3A%3E%3D%221.0.0%22+AND+os_version%3A%3C%221.0.4%22%29+OR+%28os_version%3A%3E%3D%221.1.0%22+AND+os_version%3A%3C%221.1.3%22%29+OR+%28os_version%3A%3D%221.2.0%22%29%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="(os:=&#34;Fortinet FortiOS&#34; AND ((os_version:&gt;=&#34;7.4.0&#34; AND os_version:&lt;&#34;7.4.3&#34;) OR (os_version:&gt;=&#34;7.2.0&#34; AND os_version:&lt;&#34;7.2.7&#34;) OR (os_version:&gt;=&#34;7.0.0&#34; AND os_version:&lt;&#34;7.0.15&#34;))) OR (os:=&#34;Fortinet FortiPAM&#34; AND ((os_version:&gt;=&#34;1.0.0&#34; AND os_version:&lt;&#34;1.0.4&#34;) OR (os_version:&gt;=&#34;1.1.0&#34; AND os_version:&lt;&#34;1.1.3&#34;) OR (os_version:=&#34;1.2.0&#34;)))"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="fortra goanywhere mft license servlet deserialization vulnerability (cve-2025-10035) vendor:=fortra and product:=&#34;goanywhere managed file transfer&#34; and (version:&gt;0 and version:&lt;7.8.4 and not version:=7.6.3) software vulnerability" data-ql-sev="critical">
      <div class="ql-card-header">
        <div class="ql-title">Fortra GoAnywhere MFT License Servlet Deserialization Vulnerability (CVE-2025-10035)</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><span class="ql-type-badge">software</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>vendor:=Fortra AND product:=&#34;GoAnywhere Managed File Transfer&#34; AND (version:&gt;0 AND version:&lt;7.8.4 AND NOT version:=7.6.3)</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="vendor:=Fortra AND product:=&#34;GoAnywhere Managed File Transfer&#34; AND (version:&gt;0 AND version:&lt;7.8.4 AND NOT version:=7.6.3)" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/software?search=vendor%3A%3DFortra+AND+product%3A%3D%22GoAnywhere+Managed+File+Transfer%22+AND+%28version%3A%3E0+AND+version%3A%3C7.8.4+AND+NOT+version%3A%3D7.6.3%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/software?search=vendor%3A%3DFortra+AND+product%3A%3D%22GoAnywhere+Managed+File+Transfer%22+AND+%28version%3A%3E0+AND+version%3A%3C7.8.4+AND+NOT+version%3A%3D7.6.3%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="vendor:=Fortra AND product:=&#34;GoAnywhere Managed File Transfer&#34; AND (version:&gt;0 AND version:&lt;7.8.4 AND NOT version:=7.6.3)"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="gitlab remote code execution (cve-2021-22205) vendor:=gitlab and product:gitlab and ((version:&gt;11.9 and version:&lt;13.8.7) or (version:&gt;13.9 and version:&lt;13.9.5) or (version:&gt;13.10 and version:&lt;13.10.2)) software vulnerability" data-ql-sev="critical">
      <div class="ql-card-header">
        <div class="ql-title">GitLab Remote Code Execution (CVE-2021-22205)</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><span class="ql-type-badge">software</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>vendor:=GitLab AND product:gitlab AND ((version:&gt;11.9 AND version:&lt;13.8.7) OR (version:&gt;13.9 AND version:&lt;13.9.5) OR (version:&gt;13.10 AND version:&lt;13.10.2))</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="vendor:=GitLab AND product:gitlab AND ((version:&gt;11.9 AND version:&lt;13.8.7) OR (version:&gt;13.9 AND version:&lt;13.9.5) OR (version:&gt;13.10 AND version:&lt;13.10.2))" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/software?search=vendor%3A%3DGitLab+AND+product%3Agitlab+AND+%28%28version%3A%3E11.9+AND+version%3A%3C13.8.7%29+OR+%28version%3A%3E13.9+AND+version%3A%3C13.9.5%29+OR+%28version%3A%3E13.10+AND+version%3A%3C13.10.2%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/software?search=vendor%3A%3DGitLab+AND+product%3Agitlab+AND+%28%28version%3A%3E11.9+AND+version%3A%3C13.8.7%29+OR+%28version%3A%3E13.9+AND+version%3A%3C13.9.5%29+OR+%28version%3A%3E13.10+AND+version%3A%3C13.10.2%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="vendor:=GitLab AND product:gitlab AND ((version:&gt;11.9 AND version:&lt;13.8.7) OR (version:&gt;13.9 AND version:&lt;13.9.5) OR (version:&gt;13.10 AND version:&lt;13.10.2))"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="grandstream gxp1600 series voip phone rce (cve-2026-2329) hw:=&#34;grandstream gxp16__&#34; and (os_version:&gt;0 and os_version:&lt;&#34;1.0.7.81&#34;) assets vulnerability" data-ql-sev="critical">
      <div class="ql-card-header">
        <div class="ql-title">Grandstream GXP1600 Series VoIP Phone RCE (CVE-2026-2329)</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><span class="ql-type-badge">assets</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>hw:=&#34;Grandstream GXP16__&#34; AND (os_version:&gt;0 AND os_version:&lt;&#34;1.0.7.81&#34;)</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="hw:=&#34;Grandstream GXP16__&#34; AND (os_version:&gt;0 AND os_version:&lt;&#34;1.0.7.81&#34;)" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/?search=hw%3A%3D%22Grandstream+GXP16__%22+AND+%28os_version%3A%3E0+AND+os_version%3A%3C%221.0.7.81%22%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/?search=hw%3A%3D%22Grandstream+GXP16__%22+AND+%28os_version%3A%3E0+AND+os_version%3A%3C%221.0.7.81%22%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="hw:=&#34;Grandstream GXP16__&#34; AND (os_version:&gt;0 AND os_version:&lt;&#34;1.0.7.81&#34;)"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="hpe oneview remote code execution (cve-2025-37164) vendor:=&#34;hpe&#34; and product:=&#34;oneview&#34; and version:&gt;0 and version:&lt;=10.20 software vulnerability" data-ql-sev="critical">
      <div class="ql-card-header">
        <div class="ql-title">HPE OneView Remote Code Execution (CVE-2025-37164)</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><span class="ql-type-badge">software</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>vendor:=&#34;HPE&#34; AND product:=&#34;OneView&#34; AND version:&gt;0 AND version:&lt;=10.20</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="vendor:=&#34;HPE&#34; AND product:=&#34;OneView&#34; AND version:&gt;0 AND version:&lt;=10.20" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/software?search=vendor%3A%3D%22HPE%22+AND+product%3A%3D%22OneView%22+AND+version%3A%3E0+AND+version%3A%3C%3D10.20" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/software?search=vendor%3A%3D%22HPE%22+AND+product%3A%3D%22OneView%22+AND+version%3A%3E0+AND+version%3A%3C%3D10.20" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="vendor:=&#34;HPE&#34; AND product:=&#34;OneView&#34; AND version:&gt;0 AND version:&lt;=10.20"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="hpe ilo 4 authentication bypass os:&#34;ilo 4&#34; and os_version:&gt;0 and os_version:&lt;2.53 assets vulnerability" data-ql-sev="critical">
      <div class="ql-card-header">
        <div class="ql-title">HPE iLO 4 Authentication Bypass</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><span class="ql-type-badge">assets</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>os:&#34;iLO 4&#34; and os_version:&gt;0 AND os_version:&lt;2.53</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="os:&#34;iLO 4&#34; and os_version:&gt;0 AND os_version:&lt;2.53" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/?search=os%3A%22iLO+4%22+and+os_version%3A%3E0+AND+os_version%3A%3C2.53" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/?search=os%3A%22iLO+4%22+and+os_version%3A%3E0+AND+os_version%3A%3C2.53" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="os:&#34;iLO 4&#34; and os_version:&gt;0 AND os_version:&lt;2.53"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="hashicorp vault multiple vulnerabilities - hcsec-2025-22 vendor:=&#34;hashicorp&#34; and product:&#34;vault&#34; and ( (version:&gt;=1.20.0 and version:&lt;1.20.2) or (version:&gt;=1.19.0 and version:&lt;1.19.8) or (version:&gt;=1.18.0 and version:&lt;1.18.13) or (version:&gt;0 and version:&lt;1.16.24)) software vulnerability" data-ql-sev="critical">
      <div class="ql-card-header">
        <div class="ql-title">HashiCorp Vault Multiple Vulnerabilities - HCSEC-2025-22</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><span class="ql-type-badge">software</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>vendor:=&#34;HashiCorp&#34; AND product:&#34;Vault&#34; AND ( (version:&gt;=1.20.0 AND version:&lt;1.20.2) OR (version:&gt;=1.19.0 AND version:&lt;1.19.8) OR (version:&gt;=1.18.0 AND version:&lt;1.18.13) OR (version:&gt;0 AND version:&lt;1.16.24))</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="vendor:=&#34;HashiCorp&#34; AND product:&#34;Vault&#34; AND ( (version:&gt;=1.20.0 AND version:&lt;1.20.2) OR (version:&gt;=1.19.0 AND version:&lt;1.19.8) OR (version:&gt;=1.18.0 AND version:&lt;1.18.13) OR (version:&gt;0 AND version:&lt;1.16.24))" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/software?search=vendor%3A%3D%22HashiCorp%22+AND+product%3A%22Vault%22+AND+%28+%28version%3A%3E%3D1.20.0+AND+version%3A%3C1.20.2%29+OR+%28version%3A%3E%3D1.19.0+AND+version%3A%3C1.19.8%29+OR+%28version%3A%3E%3D1.18.0+AND+version%3A%3C1.18.13%29+OR+%28version%3A%3E0+AND+version%3A%3C1.16.24%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/software?search=vendor%3A%3D%22HashiCorp%22+AND+product%3A%22Vault%22+AND+%28+%28version%3A%3E%3D1.20.0+AND+version%3A%3C1.20.2%29+OR+%28version%3A%3E%3D1.19.0+AND+version%3A%3C1.19.8%29+OR+%28version%3A%3E%3D1.18.0+AND+version%3A%3C1.18.13%29+OR+%28version%3A%3E0+AND+version%3A%3C1.16.24%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="vendor:=&#34;HashiCorp&#34; AND product:&#34;Vault&#34; AND ( (version:&gt;=1.20.0 AND version:&lt;1.20.2) OR (version:&gt;=1.19.0 AND version:&lt;1.19.8) OR (version:&gt;=1.18.0 AND version:&lt;1.18.13) OR (version:&gt;0 AND version:&lt;1.16.24))"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="ipmi 1.5 legacy null authentication _asset.protocols:ipmi and ipmi.passauth:none services vulnerability" data-ql-sev="critical">
      <div class="ql-card-header">
        <div class="ql-title">IPMI 1.5 Legacy Null Authentication</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><span class="ql-type-badge">services</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>_asset.protocols:ipmi AND ipmi.passAuth:none</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="_asset.protocols:ipmi AND ipmi.passAuth:none" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/services?search=_asset.protocols%3Aipmi+AND+ipmi.passAuth%3Anone" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/services?search=_asset.protocols%3Aipmi+AND+ipmi.passAuth%3Anone" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="_asset.protocols:ipmi AND ipmi.passAuth:none"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="ipmi cipher zero authentication bypass (cve-2013-4782) _asset.protocols:ipmi and has:ipmi.cipherzero services vulnerability" data-ql-sev="critical">
      <div class="ql-card-header">
        <div class="ql-title">IPMI Cipher Zero Authentication Bypass (CVE-2013-4782)</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><span class="ql-type-badge">services</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>_asset.protocols:ipmi AND has:ipmi.cipherZero</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="_asset.protocols:ipmi AND has:ipmi.cipherZero" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/services?search=_asset.protocols%3Aipmi+AND+has%3Aipmi.cipherZero" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/services?search=_asset.protocols%3Aipmi+AND+has%3Aipmi.cipherZero" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="_asset.protocols:ipmi AND has:ipmi.cipherZero"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="ipmi rakp+ weak or default passwords (cve-2013-4786) _asset.protocols:ipmi and has:ipmi.rakp.cracked services vulnerability" data-ql-sev="critical">
      <div class="ql-card-header">
        <div class="ql-title">IPMI RAKP+ Weak Or Default Passwords (CVE-2013-4786)</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><span class="ql-type-badge">services</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>_asset.protocols:ipmi AND has:ipmi.rakp.cracked</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="_asset.protocols:ipmi AND has:ipmi.rakp.cracked" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/services?search=_asset.protocols%3Aipmi+AND+has%3Aipmi.rakp.cracked" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/services?search=_asset.protocols%3Aipmi+AND+has%3Aipmi.rakp.cracked" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="_asset.protocols:ipmi AND has:ipmi.rakp.cracked"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="langflow rce (cve-2026-33017) vendor:=langflow and product:=langflow and (version:&gt;0 and version:&lt;1.8.2) software vulnerability" data-ql-sev="critical">
      <div class="ql-card-header">
        <div class="ql-title">Langflow RCE (CVE-2026-33017)</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><span class="ql-type-badge">software</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>vendor:=Langflow AND product:=Langflow AND (version:&gt;0 AND version:&lt;1.8.2)</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="vendor:=Langflow AND product:=Langflow AND (version:&gt;0 AND version:&lt;1.8.2)" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/software?search=vendor%3A%3DLangflow+AND+product%3A%3DLangflow+AND+%28version%3A%3E0+AND+version%3A%3C1.8.2%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/software?search=vendor%3A%3DLangflow+AND+product%3A%3DLangflow+AND+%28version%3A%3E0+AND+version%3A%3C1.8.2%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="vendor:=Langflow AND product:=Langflow AND (version:&gt;0 AND version:&lt;1.8.2)"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="microsoft omi wsman authentication bypass _asset.protocol:wsman and wsman.productvendor:=&#34;open management infrastructure&#34; and (wsman.productversion:=0.% or wsman.productversion:=1.0.% or  wsman.productversion:=1.1.% or wsman.productversion:1.2.% or  wsman.productversion:=1.3.% or wsman.productversion:=1.4.% or  wsman.productversion:=1.5.% or wsman.productversion:=1.6.0-% or  wsman.productversion:=1.6.1-% or wsman.productversion:=1.6.2-% or  wsman.productversion:=1.6.3-% or wsman.productversion:=1.6.4-% or  wsman.productversion:=1.6.5-% or wsman.productversion:=1.6.6-% or  wsman.productversion:=1.6.7-% or wsman.productversion:=1.6.8-0) services vulnerability" data-ql-sev="critical">
      <div class="ql-card-header">
        <div class="ql-title">Microsoft OMI WSMAN Authentication Bypass</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><span class="ql-type-badge">services</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>_asset.protocol:wsman AND wsman.productVendor:=&#34;Open Management Infrastructure&#34; AND (wsman.productVersion:=0.% or wsman.productVersion:=1.0.% or  wsman.productVersion:=1.1.% or wsman.productVersion:1.2.% or  wsman.productVersion:=1.3.% or wsman.productVersion:=1.4.% or  wsman.productVersion:=1.5.% or wsman.productVersion:=1.6.0-% or  wsman.productVersion:=1.6.1-% or wsman.productVersion:=1.6.2-% or  wsman.productVersion:=1.6.3-% or wsman.productVersion:=1.6.4-% or  wsman.productVersion:=1.6.5-% or wsman.productVersion:=1.6.6-% or  wsman.productVersion:=1.6.7-% or wsman.productVersion:=1.6.8-0)</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="_asset.protocol:wsman AND wsman.productVendor:=&#34;Open Management Infrastructure&#34; AND (wsman.productVersion:=0.% or wsman.productVersion:=1.0.% or  wsman.productVersion:=1.1.% or wsman.productVersion:1.2.% or  wsman.productVersion:=1.3.% or wsman.productVersion:=1.4.% or  wsman.productVersion:=1.5.% or wsman.productVersion:=1.6.0-% or  wsman.productVersion:=1.6.1-% or wsman.productVersion:=1.6.2-% or  wsman.productVersion:=1.6.3-% or wsman.productVersion:=1.6.4-% or  wsman.productVersion:=1.6.5-% or wsman.productVersion:=1.6.6-% or  wsman.productVersion:=1.6.7-% or wsman.productVersion:=1.6.8-0)" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/services?search=_asset.protocol%3Awsman+AND+wsman.productVendor%3A%3D%22Open+Management+Infrastructure%22+AND+%28wsman.productVersion%3A%3D0.%25+or+wsman.productVersion%3A%3D1.0.%25+or++wsman.productVersion%3A%3D1.1.%25+or+wsman.productVersion%3A1.2.%25+or++wsman.productVersion%3A%3D1.3.%25+or+wsman.productVersion%3A%3D1.4.%25+or++wsman.productVersion%3A%3D1.5.%25+or+wsman.productVersion%3A%3D1.6.0-%25+or++wsman.productVersion%3A%3D1.6.1-%25+or+wsman.productVersion%3A%3D1.6.2-%25+or++wsman.productVersion%3A%3D1.6.3-%25+or+wsman.productVersion%3A%3D1.6.4-%25+or++wsman.productVersion%3A%3D1.6.5-%25+or+wsman.productVersion%3A%3D1.6.6-%25+or++wsman.productVersion%3A%3D1.6.7-%25+or+wsman.productVersion%3A%3D1.6.8-0%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/services?search=_asset.protocol%3Awsman+AND+wsman.productVendor%3A%3D%22Open+Management+Infrastructure%22+AND+%28wsman.productVersion%3A%3D0.%25+or+wsman.productVersion%3A%3D1.0.%25+or++wsman.productVersion%3A%3D1.1.%25+or+wsman.productVersion%3A1.2.%25+or++wsman.productVersion%3A%3D1.3.%25+or+wsman.productVersion%3A%3D1.4.%25+or++wsman.productVersion%3A%3D1.5.%25+or+wsman.productVersion%3A%3D1.6.0-%25+or++wsman.productVersion%3A%3D1.6.1-%25+or+wsman.productVersion%3A%3D1.6.2-%25+or++wsman.productVersion%3A%3D1.6.3-%25+or+wsman.productVersion%3A%3D1.6.4-%25+or++wsman.productVersion%3A%3D1.6.5-%25+or+wsman.productVersion%3A%3D1.6.6-%25+or++wsman.productVersion%3A%3D1.6.7-%25+or+wsman.productVersion%3A%3D1.6.8-0%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="_asset.protocol:wsman AND wsman.productVendor:=&#34;Open Management Infrastructure&#34; AND (wsman.productVersion:=0.% or wsman.productVersion:=1.0.% or  wsman.productVersion:=1.1.% or wsman.productVersion:1.2.% or  wsman.productVersion:=1.3.% or wsman.productVersion:=1.4.% or  wsman.productVersion:=1.5.% or wsman.productVersion:=1.6.0-% or  wsman.productVersion:=1.6.1-% or wsman.productVersion:=1.6.2-% or  wsman.productVersion:=1.6.3-% or wsman.productVersion:=1.6.4-% or  wsman.productVersion:=1.6.5-% or wsman.productVersion:=1.6.6-% or  wsman.productVersion:=1.6.7-% or wsman.productVersion:=1.6.8-0)"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="microsoft sharepoint remote code execution vulnerability (cve-2026-20963) vendor:=microsoft and ( (product:=&#34;sharepoint server 2016&#34; and (version:&gt;=16.0.4107.1002 and version:&lt;16.0.5535.1001)) or (product:=&#34;sharepoint server 2019&#34; and (version:&gt;=16.0.10711.37301 and version:&lt;16.0.10417.20083)) or (product:=&#34;sharepoint server subscription edition&#34; and (version:&gt;=16.0.0.1 and version:&lt;16.0.19127.20442)) ) software vulnerability" data-ql-sev="critical">
      <div class="ql-card-header">
        <div class="ql-title">Microsoft SharePoint Remote Code Execution Vulnerability (CVE-2026-20963)</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><span class="ql-type-badge">software</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>vendor:=Microsoft AND ( (product:=&#34;SharePoint Server 2016&#34; AND (version:&gt;=16.0.4107.1002 AND version:&lt;16.0.5535.1001)) OR (product:=&#34;SharePoint Server 2019&#34; AND (version:&gt;=16.0.10711.37301 AND version:&lt;16.0.10417.20083)) OR (product:=&#34;SharePoint Server Subscription Edition&#34; AND (version:&gt;=16.0.0.1 AND version:&lt;16.0.19127.20442)) )</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="vendor:=Microsoft AND ( (product:=&#34;SharePoint Server 2016&#34; AND (version:&gt;=16.0.4107.1002 AND version:&lt;16.0.5535.1001)) OR (product:=&#34;SharePoint Server 2019&#34; AND (version:&gt;=16.0.10711.37301 AND version:&lt;16.0.10417.20083)) OR (product:=&#34;SharePoint Server Subscription Edition&#34; AND (version:&gt;=16.0.0.1 AND version:&lt;16.0.19127.20442)) )" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/software?search=vendor%3A%3DMicrosoft+AND+%28+%28product%3A%3D%22SharePoint+Server+2016%22+AND+%28version%3A%3E%3D16.0.4107.1002+AND+version%3A%3C16.0.5535.1001%29%29+OR+%28product%3A%3D%22SharePoint+Server+2019%22+AND+%28version%3A%3E%3D16.0.10711.37301+AND+version%3A%3C16.0.10417.20083%29%29+OR+%28product%3A%3D%22SharePoint+Server+Subscription+Edition%22+AND+%28version%3A%3E%3D16.0.0.1+AND+version%3A%3C16.0.19127.20442%29%29+%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/software?search=vendor%3A%3DMicrosoft+AND+%28+%28product%3A%3D%22SharePoint+Server+2016%22+AND+%28version%3A%3E%3D16.0.4107.1002+AND+version%3A%3C16.0.5535.1001%29%29+OR+%28product%3A%3D%22SharePoint+Server+2019%22+AND+%28version%3A%3E%3D16.0.10711.37301+AND+version%3A%3C16.0.10417.20083%29%29+OR+%28product%3A%3D%22SharePoint+Server+Subscription+Edition%22+AND+%28version%3A%3E%3D16.0.0.1+AND+version%3A%3C16.0.19127.20442%29%29+%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="vendor:=Microsoft AND ( (product:=&#34;SharePoint Server 2016&#34; AND (version:&gt;=16.0.4107.1002 AND version:&lt;16.0.5535.1001)) OR (product:=&#34;SharePoint Server 2019&#34; AND (version:&gt;=16.0.10711.37301 AND version:&lt;16.0.10417.20083)) OR (product:=&#34;SharePoint Server Subscription Edition&#34; AND (version:&gt;=16.0.0.1 AND version:&lt;16.0.19127.20442)) )"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="mikrotik router os directory traversal vulnerability (cve-2018-14847) os:=&#34;mikrotik routeros&#34; and (os_version:&gt;&#34;0&#34; and os_version:&lt;=&#34;6.42&#34;) assets vulnerability" data-ql-sev="critical">
      <div class="ql-card-header">
        <div class="ql-title">MikroTik Router OS Directory Traversal Vulnerability (CVE-2018-14847)</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><span class="ql-type-badge">assets</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>os:=&#34;MikroTik RouterOS&#34; AND (os_version:&gt;&#34;0&#34; AND os_version:&lt;=&#34;6.42&#34;)</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="os:=&#34;MikroTik RouterOS&#34; AND (os_version:&gt;&#34;0&#34; AND os_version:&lt;=&#34;6.42&#34;)" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/?search=os%3A%3D%22MikroTik+RouterOS%22+AND+%28os_version%3A%3E%220%22+AND+os_version%3A%3C%3D%226.42%22%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/?search=os%3A%3D%22MikroTik+RouterOS%22+AND+%28os_version%3A%3E%220%22+AND+os_version%3A%3C%3D%226.42%22%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="os:=&#34;MikroTik RouterOS&#34; AND (os_version:&gt;&#34;0&#34; AND os_version:&lt;=&#34;6.42&#34;)"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="monsta ftp rce (cve-2025-34299) vendor:=&#34;monsta limited&#34; and product:=&#34;monsta ftp&#34; and version:&gt;0 and version:&lt;2.11.3 software vulnerability" data-ql-sev="critical">
      <div class="ql-card-header">
        <div class="ql-title">Monsta FTP RCE (CVE-2025-34299)</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><span class="ql-type-badge">software</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>vendor:=&#34;Monsta Limited&#34; AND product:=&#34;Monsta FTP&#34; AND version:&gt;0 AND version:&lt;2.11.3</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="vendor:=&#34;Monsta Limited&#34; AND product:=&#34;Monsta FTP&#34; AND version:&gt;0 AND version:&lt;2.11.3" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/software?search=vendor%3A%3D%22Monsta+Limited%22+AND+product%3A%3D%22Monsta+FTP%22+AND+version%3A%3E0+AND+version%3A%3C2.11.3" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/software?search=vendor%3A%3D%22Monsta+Limited%22+AND+product%3A%3D%22Monsta+FTP%22+AND+version%3A%3E0+AND+version%3A%3C2.11.3" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="vendor:=&#34;Monsta Limited&#34; AND product:=&#34;Monsta FTP&#34; AND version:&gt;0 AND version:&lt;2.11.3"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="multiple fortinet products authentication bypass (cve-2025-59718 and cve-2025-59719) os:=&#34;fortinet fortios&#34; and os_version:&gt;0 and ((os_version:&gt;=&#34;7.6.0&#34; and os_version:&lt;=&#34;7.6.3&#34;) or (os_version:&gt;=&#34;7.4.0&#34; and os_version:&lt;=&#34;7.4.8&#34;) or (os_version:&gt;=&#34;7.2.0&#34; and os_version:&lt;=&#34;7.2.11&#34;) or (os_version:&gt;=&#34;7.0.0&#34; and os_version:&lt;=&#34;7.0.17&#34;)) assets vulnerability" data-ql-sev="critical">
      <div class="ql-card-header">
        <div class="ql-title">Multiple Fortinet Products Authentication Bypass (CVE-2025-59718 and CVE-2025-59719)</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><span class="ql-type-badge">assets</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>os:=&#34;Fortinet FortiOS&#34; AND os_version:&gt;0 AND ((os_version:&gt;=&#34;7.6.0&#34; AND os_version:&lt;=&#34;7.6.3&#34;) OR (os_version:&gt;=&#34;7.4.0&#34; AND os_version:&lt;=&#34;7.4.8&#34;) OR (os_version:&gt;=&#34;7.2.0&#34; AND os_version:&lt;=&#34;7.2.11&#34;) OR (os_version:&gt;=&#34;7.0.0&#34; AND os_version:&lt;=&#34;7.0.17&#34;))</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="os:=&#34;Fortinet FortiOS&#34; AND os_version:&gt;0 AND ((os_version:&gt;=&#34;7.6.0&#34; AND os_version:&lt;=&#34;7.6.3&#34;) OR (os_version:&gt;=&#34;7.4.0&#34; AND os_version:&lt;=&#34;7.4.8&#34;) OR (os_version:&gt;=&#34;7.2.0&#34; AND os_version:&lt;=&#34;7.2.11&#34;) OR (os_version:&gt;=&#34;7.0.0&#34; AND os_version:&lt;=&#34;7.0.17&#34;))" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/?search=os%3A%3D%22Fortinet+FortiOS%22+AND+os_version%3A%3E0+AND+%28%28os_version%3A%3E%3D%227.6.0%22+AND+os_version%3A%3C%3D%227.6.3%22%29+OR+%28os_version%3A%3E%3D%227.4.0%22+AND+os_version%3A%3C%3D%227.4.8%22%29+OR+%28os_version%3A%3E%3D%227.2.0%22+AND+os_version%3A%3C%3D%227.2.11%22%29+OR+%28os_version%3A%3E%3D%227.0.0%22+AND+os_version%3A%3C%3D%227.0.17%22%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/?search=os%3A%3D%22Fortinet+FortiOS%22+AND+os_version%3A%3E0+AND+%28%28os_version%3A%3E%3D%227.6.0%22+AND+os_version%3A%3C%3D%227.6.3%22%29+OR+%28os_version%3A%3E%3D%227.4.0%22+AND+os_version%3A%3C%3D%227.4.8%22%29+OR+%28os_version%3A%3E%3D%227.2.0%22+AND+os_version%3A%3C%3D%227.2.11%22%29+OR+%28os_version%3A%3E%3D%227.0.0%22+AND+os_version%3A%3C%3D%227.0.17%22%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="os:=&#34;Fortinet FortiOS&#34; AND os_version:&gt;0 AND ((os_version:&gt;=&#34;7.6.0&#34; AND os_version:&lt;=&#34;7.6.3&#34;) OR (os_version:&gt;=&#34;7.4.0&#34; AND os_version:&lt;=&#34;7.4.8&#34;) OR (os_version:&gt;=&#34;7.2.0&#34; AND os_version:&lt;=&#34;7.2.11&#34;) OR (os_version:&gt;=&#34;7.0.0&#34; AND os_version:&lt;=&#34;7.0.17&#34;))"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="multiple fortinet products buffer overflow hw:=&#34;fortinet%&#34; and type:=&#34;sip gateway&#34; and ((osversion:=&#34;7.2.0&#34;) or (osversion:&gt;&#34;7.0.0&#34; and osversion:&lt;&#34;7.0.7&#34;) or (osversion:&gt;=&#34;6.4.0&#34; and osversion:&lt;&#34;6.4.11&#34;)) assets vulnerability" data-ql-sev="critical">
      <div class="ql-card-header">
        <div class="ql-title">Multiple Fortinet Products Buffer Overflow</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><span class="ql-type-badge">assets</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>hw:=&#34;Fortinet%&#34; AND type:=&#34;SIP Gateway&#34; AND ((osversion:=&#34;7.2.0&#34;) OR (osversion:&gt;&#34;7.0.0&#34; AND osversion:&lt;&#34;7.0.7&#34;) OR (osversion:&gt;=&#34;6.4.0&#34; AND osversion:&lt;&#34;6.4.11&#34;))</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="hw:=&#34;Fortinet%&#34; AND type:=&#34;SIP Gateway&#34; AND ((osversion:=&#34;7.2.0&#34;) OR (osversion:&gt;&#34;7.0.0&#34; AND osversion:&lt;&#34;7.0.7&#34;) OR (osversion:&gt;=&#34;6.4.0&#34; AND osversion:&lt;&#34;6.4.11&#34;))" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/?search=hw%3A%3D%22Fortinet%25%22+AND+type%3A%3D%22SIP+Gateway%22+AND+%28%28osversion%3A%3D%227.2.0%22%29+OR+%28osversion%3A%3E%227.0.0%22+AND+osversion%3A%3C%227.0.7%22%29+OR+%28osversion%3A%3E%3D%226.4.0%22+AND+osversion%3A%3C%226.4.11%22%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/?search=hw%3A%3D%22Fortinet%25%22+AND+type%3A%3D%22SIP+Gateway%22+AND+%28%28osversion%3A%3D%227.2.0%22%29+OR+%28osversion%3A%3E%227.0.0%22+AND+osversion%3A%3C%227.0.7%22%29+OR+%28osversion%3A%3E%3D%226.4.0%22+AND+osversion%3A%3C%226.4.11%22%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="hw:=&#34;Fortinet%&#34; AND type:=&#34;SIP Gateway&#34; AND ((osversion:=&#34;7.2.0&#34;) OR (osversion:&gt;&#34;7.0.0&#34; AND osversion:&lt;&#34;7.0.7&#34;) OR (osversion:&gt;=&#34;6.4.0&#34; AND osversion:&lt;&#34;6.4.11&#34;))"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="novi survey insecure deserialization vulnerability vendor:=&#34;3rd millennium&#34; and product:=&#34;novi survey&#34; and (version:&gt;&#34;0&#34; and version:&lt;&#34;8.9.43676&#34;)  software vulnerability" data-ql-sev="critical">
      <div class="ql-card-header">
        <div class="ql-title">Novi Survey Insecure Deserialization Vulnerability</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><span class="ql-type-badge">software</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>vendor:=&#34;3rd Millennium&#34; AND product:=&#34;Novi Survey&#34; AND (version:&gt;&#34;0&#34; AND version:&lt;&#34;8.9.43676&#34;) </code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="vendor:=&#34;3rd Millennium&#34; AND product:=&#34;Novi Survey&#34; AND (version:&gt;&#34;0&#34; AND version:&lt;&#34;8.9.43676&#34;) " title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/software?search=vendor%3A%3D%223rd+Millennium%22+AND+product%3A%3D%22Novi+Survey%22+AND+%28version%3A%3E%220%22+AND+version%3A%3C%228.9.43676%22%29+" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/software?search=vendor%3A%3D%223rd+Millennium%22+AND+product%3A%3D%22Novi+Survey%22+AND+%28version%3A%3E%220%22+AND+version%3A%3C%228.9.43676%22%29+" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="vendor:=&#34;3rd Millennium&#34; AND product:=&#34;Novi Survey&#34; AND (version:&gt;&#34;0&#34; AND version:&lt;&#34;8.9.43676&#34;) "><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="php 8.1.0 &lt; 8.1.29 multiple vulnerabilities os:&#34;windows&#34; and _asset.products:apache and product:php and (version:&gt;8.1 and version:&lt;8.1.29) software vulnerability" data-ql-sev="critical">
      <div class="ql-card-header">
        <div class="ql-title">PHP 8.1.0 &lt; 8.1.29 Multiple Vulnerabilities</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><span class="ql-type-badge">software</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>os:&#34;Windows&#34; AND _asset.products:apache AND product:PHP AND (version:&gt;8.1 AND version:&lt;8.1.29)</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="os:&#34;Windows&#34; AND _asset.products:apache AND product:PHP AND (version:&gt;8.1 AND version:&lt;8.1.29)" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/software?search=os%3A%22Windows%22+AND+_asset.products%3Aapache+AND+product%3APHP+AND+%28version%3A%3E8.1+AND+version%3A%3C8.1.29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/software?search=os%3A%22Windows%22+AND+_asset.products%3Aapache+AND+product%3APHP+AND+%28version%3A%3E8.1+AND+version%3A%3C8.1.29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="os:&#34;Windows&#34; AND _asset.products:apache AND product:PHP AND (version:&gt;8.1 AND version:&lt;8.1.29)"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="php 8.2.0 &lt; 8.2.20 multiple vulnerabilities os:&#34;windows&#34; and _asset.products:apache and product:php and (version:&gt;8.2 and version:&lt;8.2.20) software vulnerability" data-ql-sev="critical">
      <div class="ql-card-header">
        <div class="ql-title">PHP 8.2.0 &lt; 8.2.20 Multiple Vulnerabilities</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><span class="ql-type-badge">software</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>os:&#34;Windows&#34; AND _asset.products:apache AND product:PHP AND (version:&gt;8.2 AND version:&lt;8.2.20)</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="os:&#34;Windows&#34; AND _asset.products:apache AND product:PHP AND (version:&gt;8.2 AND version:&lt;8.2.20)" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/software?search=os%3A%22Windows%22+AND+_asset.products%3Aapache+AND+product%3APHP+AND+%28version%3A%3E8.2+AND+version%3A%3C8.2.20%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/software?search=os%3A%22Windows%22+AND+_asset.products%3Aapache+AND+product%3APHP+AND+%28version%3A%3E8.2+AND+version%3A%3C8.2.20%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="os:&#34;Windows&#34; AND _asset.products:apache AND product:PHP AND (version:&gt;8.2 AND version:&lt;8.2.20)"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="php 8.3.0 &lt; 8.3.8 multiple vulnerabilities os:&#34;windows&#34; and _asset.products:apache and product:php and (version:&gt;8.3 and version:&lt;8.3.8) software vulnerability" data-ql-sev="critical">
      <div class="ql-card-header">
        <div class="ql-title">PHP 8.3.0 &lt; 8.3.8 Multiple Vulnerabilities</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><span class="ql-type-badge">software</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>os:&#34;Windows&#34; AND _asset.products:apache AND product:PHP AND (version:&gt;8.3 AND version:&lt;8.3.8)</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="os:&#34;Windows&#34; AND _asset.products:apache AND product:PHP AND (version:&gt;8.3 AND version:&lt;8.3.8)" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/software?search=os%3A%22Windows%22+AND+_asset.products%3Aapache+AND+product%3APHP+AND+%28version%3A%3E8.3+AND+version%3A%3C8.3.8%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/software?search=os%3A%22Windows%22+AND+_asset.products%3Aapache+AND+product%3APHP+AND+%28version%3A%3E8.3+AND+version%3A%3C8.3.8%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="os:&#34;Windows&#34; AND _asset.products:apache AND product:PHP AND (version:&gt;8.3 AND version:&lt;8.3.8)"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="palo alto networks pan-os authentication bypass os:=&#34;palo alto networks pan-os&#34; and (osversion:&gt;&#34;11.1.6-h1&#34; and osversion:&lt;11.2.4-h4) and (osversion:&gt;&#34;10.2.13-h3&#34; and osversion:&lt;11.1.6-h1) and (osversion:&gt;&#34;10.1.14-h9&#34; and osversion:&lt;&#34;10.2.13-h3&#34;) and (osversion:&gt;&#34;10.1.0&#34; and osversion:&lt;&#34;10.1.14-h9&#34;) assets vulnerability" data-ql-sev="critical">
      <div class="ql-card-header">
        <div class="ql-title">Palo Alto Networks PAN-OS Authentication Bypass</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><span class="ql-type-badge">assets</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>os:=&#34;Palo Alto Networks PAN-OS&#34; AND (osversion:&gt;&#34;11.1.6-h1&#34; AND osversion:&lt;11.2.4-h4) AND (osversion:&gt;&#34;10.2.13-h3&#34; AND osversion:&lt;11.1.6-h1) AND (osversion:&gt;&#34;10.1.14-h9&#34; AND osversion:&lt;&#34;10.2.13-h3&#34;) AND (osversion:&gt;&#34;10.1.0&#34; AND osversion:&lt;&#34;10.1.14-h9&#34;)</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="os:=&#34;Palo Alto Networks PAN-OS&#34; AND (osversion:&gt;&#34;11.1.6-h1&#34; AND osversion:&lt;11.2.4-h4) AND (osversion:&gt;&#34;10.2.13-h3&#34; AND osversion:&lt;11.1.6-h1) AND (osversion:&gt;&#34;10.1.14-h9&#34; AND osversion:&lt;&#34;10.2.13-h3&#34;) AND (osversion:&gt;&#34;10.1.0&#34; AND osversion:&lt;&#34;10.1.14-h9&#34;)" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/?search=os%3A%3D%22Palo+Alto+Networks+PAN-OS%22+AND+%28osversion%3A%3E%2211.1.6-h1%22+AND+osversion%3A%3C11.2.4-h4%29+AND+%28osversion%3A%3E%2210.2.13-h3%22+AND+osversion%3A%3C11.1.6-h1%29+AND+%28osversion%3A%3E%2210.1.14-h9%22+AND+osversion%3A%3C%2210.2.13-h3%22%29+AND+%28osversion%3A%3E%2210.1.0%22+AND+osversion%3A%3C%2210.1.14-h9%22%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/?search=os%3A%3D%22Palo+Alto+Networks+PAN-OS%22+AND+%28osversion%3A%3E%2211.1.6-h1%22+AND+osversion%3A%3C11.2.4-h4%29+AND+%28osversion%3A%3E%2210.2.13-h3%22+AND+osversion%3A%3C11.1.6-h1%29+AND+%28osversion%3A%3E%2210.1.14-h9%22+AND+osversion%3A%3C%2210.2.13-h3%22%29+AND+%28osversion%3A%3E%2210.1.0%22+AND+osversion%3A%3C%2210.1.14-h9%22%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="os:=&#34;Palo Alto Networks PAN-OS&#34; AND (osversion:&gt;&#34;11.1.6-h1&#34; AND osversion:&lt;11.2.4-h4) AND (osversion:&gt;&#34;10.2.13-h3&#34; AND osversion:&lt;11.1.6-h1) AND (osversion:&gt;&#34;10.1.14-h9&#34; AND osversion:&lt;&#34;10.2.13-h3&#34;) AND (osversion:&gt;&#34;10.1.0&#34; AND osversion:&lt;&#34;10.1.14-h9&#34;)"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="plesk panel 9.0.x &lt; 9.2.3 remote code execution not os:windows and vendor:=parallels and product:=plesk and (version:&gt;9.0.0 and version:&lt;9.5.4) software vulnerability" data-ql-sev="critical">
      <div class="ql-card-header">
        <div class="ql-title">Plesk Panel 9.0.X &lt; 9.2.3 Remote Code Execution</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><span class="ql-type-badge">software</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>not os:Windows AND vendor:=parallels AND product:=plesk AND (version:&gt;9.0.0 AND version:&lt;9.5.4)</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="not os:Windows AND vendor:=parallels AND product:=plesk AND (version:&gt;9.0.0 AND version:&lt;9.5.4)" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/software?search=not+os%3AWindows+AND+vendor%3A%3Dparallels+AND+product%3A%3Dplesk+AND+%28version%3A%3E9.0.0+AND+version%3A%3C9.5.4%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/software?search=not+os%3AWindows+AND+vendor%3A%3Dparallels+AND+product%3A%3Dplesk+AND+%28version%3A%3E9.0.0+AND+version%3A%3C9.5.4%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="not os:Windows AND vendor:=parallels AND product:=plesk AND (version:&gt;9.0.0 AND version:&lt;9.5.4)"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="redis multiple vulnerabilities (2025-10) vendor:=redis and product:=redis and (version:&gt;0 and ( (version:&gt;=6.2 and version:&lt;6.2.20) or (version:&gt;=7.2 and version:&lt;7.2.11) or (version:&gt;=7.4 and version:&lt;7.4.6) or (version:&gt;=8.0 and version:&lt;8.0.4) or (version:&gt;=8.2 and version:&lt;8.2.2))) software vulnerability" data-ql-sev="critical">
      <div class="ql-card-header">
        <div class="ql-title">Redis Multiple Vulnerabilities (2025-10)</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><span class="ql-type-badge">software</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>vendor:=Redis AND product:=Redis AND (version:&gt;0 AND ( (version:&gt;=6.2 AND version:&lt;6.2.20) OR (version:&gt;=7.2 AND version:&lt;7.2.11) OR (version:&gt;=7.4 AND version:&lt;7.4.6) OR (version:&gt;=8.0 AND version:&lt;8.0.4) OR (version:&gt;=8.2 AND version:&lt;8.2.2)))</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="vendor:=Redis AND product:=Redis AND (version:&gt;0 AND ( (version:&gt;=6.2 AND version:&lt;6.2.20) OR (version:&gt;=7.2 AND version:&lt;7.2.11) OR (version:&gt;=7.4 AND version:&lt;7.4.6) OR (version:&gt;=8.0 AND version:&lt;8.0.4) OR (version:&gt;=8.2 AND version:&lt;8.2.2)))" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/software?search=vendor%3A%3DRedis+AND+product%3A%3DRedis+AND+%28version%3A%3E0+AND+%28+%28version%3A%3E%3D6.2+AND+version%3A%3C6.2.20%29+OR+%28version%3A%3E%3D7.2+AND+version%3A%3C7.2.11%29+OR+%28version%3A%3E%3D7.4+AND+version%3A%3C7.4.6%29+OR+%28version%3A%3E%3D8.0+AND+version%3A%3C8.0.4%29+OR+%28version%3A%3E%3D8.2+AND+version%3A%3C8.2.2%29%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/software?search=vendor%3A%3DRedis+AND+product%3A%3DRedis+AND+%28version%3A%3E0+AND+%28+%28version%3A%3E%3D6.2+AND+version%3A%3C6.2.20%29+OR+%28version%3A%3E%3D7.2+AND+version%3A%3C7.2.11%29+OR+%28version%3A%3E%3D7.4+AND+version%3A%3C7.4.6%29+OR+%28version%3A%3E%3D8.0+AND+version%3A%3C8.0.4%29+OR+%28version%3A%3E%3D8.2+AND+version%3A%3C8.2.2%29%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="vendor:=Redis AND product:=Redis AND (version:&gt;0 AND ( (version:&gt;=6.2 AND version:&lt;6.2.20) OR (version:&gt;=7.2 AND version:&lt;7.2.11) OR (version:&gt;=7.4 AND version:&lt;7.4.6) OR (version:&gt;=8.0 AND version:&lt;8.0.4) OR (version:&gt;=8.2 AND version:&lt;8.2.2)))"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="rejetto http file server 2 remote code execution vendor:=rejetto and product:&#34;http file server&#34; and version:&gt;0 and version:&lt;3 software vulnerability" data-ql-sev="critical">
      <div class="ql-card-header">
        <div class="ql-title">Rejetto HTTP File Server 2 Remote Code Execution</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><span class="ql-type-badge">software</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>vendor:=Rejetto AND product:&#34;HTTP File Server&#34; AND version:&gt;0 AND version:&lt;3</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="vendor:=Rejetto AND product:&#34;HTTP File Server&#34; AND version:&gt;0 AND version:&lt;3" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/software?search=vendor%3A%3DRejetto+AND+product%3A%22HTTP+File+Server%22+AND+version%3A%3E0+AND+version%3A%3C3" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/software?search=vendor%3A%3DRejetto+AND+product%3A%22HTTP+File+Server%22+AND+version%3A%3E0+AND+version%3A%3C3" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="vendor:=Rejetto AND product:&#34;HTTP File Server&#34; AND version:&gt;0 AND version:&lt;3"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="rejetto http file server 2.0 &lt; 2.3m remote code execution os:windows and vendor:=rejetto and product:&#34;http file server&#34; and version:&gt;=2.0 and version:&lt;&#34;2.3m&#34;   software vulnerability" data-ql-sev="critical">
      <div class="ql-card-header">
        <div class="ql-title">Rejetto HTTP File Server 2.0 &lt; 2.3M Remote Code Execution</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><span class="ql-type-badge">software</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>os:Windows AND vendor:=Rejetto AND product:&#34;HTTP File Server&#34; AND version:&gt;=2.0 AND version:&lt;&#34;2.3m&#34;  </code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="os:Windows AND vendor:=Rejetto AND product:&#34;HTTP File Server&#34; AND version:&gt;=2.0 AND version:&lt;&#34;2.3m&#34;  " title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/software?search=os%3AWindows+AND+vendor%3A%3DRejetto+AND+product%3A%22HTTP+File+Server%22+AND+version%3A%3E%3D2.0+AND+version%3A%3C%222.3m%22++" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/software?search=os%3AWindows+AND+vendor%3A%3DRejetto+AND+product%3A%22HTTP+File+Server%22+AND+version%3A%3E%3D2.0+AND+version%3A%3C%222.3m%22++" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="os:Windows AND vendor:=Rejetto AND product:&#34;HTTP File Server&#34; AND version:&gt;=2.0 AND version:&lt;&#34;2.3m&#34;  "><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="rockwell automation controllogix ethernet rce (cve-2025-7353) ((_asset.protocol:=&#34;cip&#34; or asset.protocol:=&#34;cip-udp&#34;) and protocol:&#34;cip&#34; and (cip.product:=&#34;1756-en2t/d&#34; or cip.product:=&#34;1756-en2f/c&#34; or cip.product:=&#34;1756-en2tr/c&#34; or cip.product:=&#34;1756-en3tr/b&#34; or cip.product:=&#34;1756-en2tp/a&#34;) and (cip.revision:&gt;&#34;0&#34; and (cip.revision:&lt;&#34;12&#34; or cip.revision:&#34;12.0%&#34;))) or ((_asset.protocol:=&#34;ethernetip&#34; or asset.protocol:=&#34;ethernetip-udp&#34;) and protocol:&#34;ethernetip&#34; and (ethernetip.product:=&#34;1756-en2t/d&#34; or ethernetip.product:=&#34;1756-en2f/c&#34; or ethernetip.product:=&#34;1756-en2tr/c&#34; or ethernetip.product:=&#34;1756-en3tr/b&#34; or ethernetip.product:=&#34;1756-en2tp/a&#34;) and (ethernetip.revision:&gt;&#34;0&#34; and (ethernetip.revision:&lt;&#34;12&#34; or ethernetip.revision:&#34;12.0%&#34;))) services vulnerability" data-ql-sev="critical">
      <div class="ql-card-header">
        <div class="ql-title">Rockwell Automation ControlLogix Ethernet RCE (CVE-2025-7353)</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><span class="ql-type-badge">services</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>((_asset.protocol:=&#34;cip&#34; OR asset.protocol:=&#34;cip-udp&#34;) AND protocol:&#34;cip&#34; AND (cip.product:=&#34;1756-EN2T/D&#34; OR cip.product:=&#34;1756-EN2F/C&#34; OR cip.product:=&#34;1756-EN2TR/C&#34; OR cip.product:=&#34;1756-EN3TR/B&#34; OR cip.product:=&#34;1756-EN2TP/A&#34;) AND (cip.revision:&gt;&#34;0&#34; AND (cip.revision:&lt;&#34;12&#34; OR cip.revision:&#34;12.0%&#34;))) OR ((_asset.protocol:=&#34;ethernetip&#34; OR asset.protocol:=&#34;ethernetip-udp&#34;) AND protocol:&#34;ethernetip&#34; AND (ethernetip.product:=&#34;1756-EN2T/D&#34; OR ethernetip.product:=&#34;1756-EN2F/C&#34; OR ethernetip.product:=&#34;1756-EN2TR/C&#34; OR ethernetip.product:=&#34;1756-EN3TR/B&#34; OR ethernetip.product:=&#34;1756-EN2TP/A&#34;) AND (ethernetip.revision:&gt;&#34;0&#34; AND (ethernetip.revision:&lt;&#34;12&#34; OR ethernetip.revision:&#34;12.0%&#34;)))</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="((_asset.protocol:=&#34;cip&#34; OR asset.protocol:=&#34;cip-udp&#34;) AND protocol:&#34;cip&#34; AND (cip.product:=&#34;1756-EN2T/D&#34; OR cip.product:=&#34;1756-EN2F/C&#34; OR cip.product:=&#34;1756-EN2TR/C&#34; OR cip.product:=&#34;1756-EN3TR/B&#34; OR cip.product:=&#34;1756-EN2TP/A&#34;) AND (cip.revision:&gt;&#34;0&#34; AND (cip.revision:&lt;&#34;12&#34; OR cip.revision:&#34;12.0%&#34;))) OR ((_asset.protocol:=&#34;ethernetip&#34; OR asset.protocol:=&#34;ethernetip-udp&#34;) AND protocol:&#34;ethernetip&#34; AND (ethernetip.product:=&#34;1756-EN2T/D&#34; OR ethernetip.product:=&#34;1756-EN2F/C&#34; OR ethernetip.product:=&#34;1756-EN2TR/C&#34; OR ethernetip.product:=&#34;1756-EN3TR/B&#34; OR ethernetip.product:=&#34;1756-EN2TP/A&#34;) AND (ethernetip.revision:&gt;&#34;0&#34; AND (ethernetip.revision:&lt;&#34;12&#34; OR ethernetip.revision:&#34;12.0%&#34;)))" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/services?search=%28%28_asset.protocol%3A%3D%22cip%22+OR+asset.protocol%3A%3D%22cip-udp%22%29+AND+protocol%3A%22cip%22+AND+%28cip.product%3A%3D%221756-EN2T%2FD%22+OR+cip.product%3A%3D%221756-EN2F%2FC%22+OR+cip.product%3A%3D%221756-EN2TR%2FC%22+OR+cip.product%3A%3D%221756-EN3TR%2FB%22+OR+cip.product%3A%3D%221756-EN2TP%2FA%22%29+AND+%28cip.revision%3A%3E%220%22+AND+%28cip.revision%3A%3C%2212%22+OR+cip.revision%3A%2212.0%25%22%29%29%29+OR+%28%28_asset.protocol%3A%3D%22ethernetip%22+OR+asset.protocol%3A%3D%22ethernetip-udp%22%29+AND+protocol%3A%22ethernetip%22+AND+%28ethernetip.product%3A%3D%221756-EN2T%2FD%22+OR+ethernetip.product%3A%3D%221756-EN2F%2FC%22+OR+ethernetip.product%3A%3D%221756-EN2TR%2FC%22+OR+ethernetip.product%3A%3D%221756-EN3TR%2FB%22+OR+ethernetip.product%3A%3D%221756-EN2TP%2FA%22%29+AND+%28ethernetip.revision%3A%3E%220%22+AND+%28ethernetip.revision%3A%3C%2212%22+OR+ethernetip.revision%3A%2212.0%25%22%29%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/services?search=%28%28_asset.protocol%3A%3D%22cip%22+OR+asset.protocol%3A%3D%22cip-udp%22%29+AND+protocol%3A%22cip%22+AND+%28cip.product%3A%3D%221756-EN2T%2FD%22+OR+cip.product%3A%3D%221756-EN2F%2FC%22+OR+cip.product%3A%3D%221756-EN2TR%2FC%22+OR+cip.product%3A%3D%221756-EN3TR%2FB%22+OR+cip.product%3A%3D%221756-EN2TP%2FA%22%29+AND+%28cip.revision%3A%3E%220%22+AND+%28cip.revision%3A%3C%2212%22+OR+cip.revision%3A%2212.0%25%22%29%29%29+OR+%28%28_asset.protocol%3A%3D%22ethernetip%22+OR+asset.protocol%3A%3D%22ethernetip-udp%22%29+AND+protocol%3A%22ethernetip%22+AND+%28ethernetip.product%3A%3D%221756-EN2T%2FD%22+OR+ethernetip.product%3A%3D%221756-EN2F%2FC%22+OR+ethernetip.product%3A%3D%221756-EN2TR%2FC%22+OR+ethernetip.product%3A%3D%221756-EN3TR%2FB%22+OR+ethernetip.product%3A%3D%221756-EN2TP%2FA%22%29+AND+%28ethernetip.revision%3A%3E%220%22+AND+%28ethernetip.revision%3A%3C%2212%22+OR+ethernetip.revision%3A%2212.0%25%22%29%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="((_asset.protocol:=&#34;cip&#34; OR asset.protocol:=&#34;cip-udp&#34;) AND protocol:&#34;cip&#34; AND (cip.product:=&#34;1756-EN2T/D&#34; OR cip.product:=&#34;1756-EN2F/C&#34; OR cip.product:=&#34;1756-EN2TR/C&#34; OR cip.product:=&#34;1756-EN3TR/B&#34; OR cip.product:=&#34;1756-EN2TP/A&#34;) AND (cip.revision:&gt;&#34;0&#34; AND (cip.revision:&lt;&#34;12&#34; OR cip.revision:&#34;12.0%&#34;))) OR ((_asset.protocol:=&#34;ethernetip&#34; OR asset.protocol:=&#34;ethernetip-udp&#34;) AND protocol:&#34;ethernetip&#34; AND (ethernetip.product:=&#34;1756-EN2T/D&#34; OR ethernetip.product:=&#34;1756-EN2F/C&#34; OR ethernetip.product:=&#34;1756-EN2TR/C&#34; OR ethernetip.product:=&#34;1756-EN3TR/B&#34; OR ethernetip.product:=&#34;1756-EN2TP/A&#34;) AND (ethernetip.revision:&gt;&#34;0&#34; AND (ethernetip.revision:&lt;&#34;12&#34; OR ethernetip.revision:&#34;12.0%&#34;)))"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="roundcube webmail remote code execution vendor:=roundcube and product:=webmail and ((version:&gt;=1.5 and version:&lt;1.5.10) or (version:&gt;=1.6 and version:&lt;1.6.11)) software vulnerability" data-ql-sev="critical">
      <div class="ql-card-header">
        <div class="ql-title">Roundcube Webmail Remote Code Execution</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><span class="ql-type-badge">software</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>vendor:=Roundcube AND product:=Webmail AND ((version:&gt;=1.5 AND version:&lt;1.5.10) OR (version:&gt;=1.6 AND version:&lt;1.6.11))</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="vendor:=Roundcube AND product:=Webmail AND ((version:&gt;=1.5 AND version:&lt;1.5.10) OR (version:&gt;=1.6 AND version:&lt;1.6.11))" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/software?search=vendor%3A%3DRoundcube+AND+product%3A%3DWebmail+AND+%28%28version%3A%3E%3D1.5+AND+version%3A%3C1.5.10%29+OR+%28version%3A%3E%3D1.6+AND+version%3A%3C1.6.11%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/software?search=vendor%3A%3DRoundcube+AND+product%3A%3DWebmail+AND+%28%28version%3A%3E%3D1.5+AND+version%3A%3C1.5.10%29+OR+%28version%3A%3E%3D1.6+AND+version%3A%3C1.6.11%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="vendor:=Roundcube AND product:=Webmail AND ((version:&gt;=1.5 AND version:&lt;1.5.10) OR (version:&gt;=1.6 AND version:&lt;1.6.11))"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="sap netweaver (rmi-p4) insecure deserialization (cve-2025-42944) vendor:=sap and product:&#34;netweaver&#34; and (version:&gt;0 and version:&lt;=7.50) software vulnerability" data-ql-sev="critical">
      <div class="ql-card-header">
        <div class="ql-title">SAP NetWeaver (RMI-P4) Insecure Deserialization (CVE-2025-42944)</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><span class="ql-type-badge">software</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>vendor:=SAP AND product:&#34;NetWeaver&#34; AND (version:&gt;0 AND version:&lt;=7.50)</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="vendor:=SAP AND product:&#34;NetWeaver&#34; AND (version:&gt;0 AND version:&lt;=7.50)" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/software?search=vendor%3A%3DSAP+AND+product%3A%22NetWeaver%22+AND+%28version%3A%3E0+AND+version%3A%3C%3D7.50%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/software?search=vendor%3A%3DSAP+AND+product%3A%22NetWeaver%22+AND+%28version%3A%3E0+AND+version%3A%3C%3D7.50%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="vendor:=SAP AND product:&#34;NetWeaver&#34; AND (version:&gt;0 AND version:&lt;=7.50)"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="sangoma freepbx rce (cve-2025-57819) ((vendor:=freepbx and product:=pbx) or (vendor:=sangoma and product:=freepbx)) and (version:&gt;0 and (version:&lt;&#34;15.0.66(%)&#34; or version:&lt;&#34;16.0.89(%)&#34; or version:&lt;&#34;17.0.3(%)&#34;)) software vulnerability" data-ql-sev="critical">
      <div class="ql-card-header">
        <div class="ql-title">Sangoma FreePBX RCE (CVE-2025-57819)</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><span class="ql-type-badge">software</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>((vendor:=FreePBX AND product:=PBX) OR (vendor:=Sangoma AND product:=FreePBX)) AND (version:&gt;0 AND (version:&lt;&#34;15.0.66(%)&#34; OR version:&lt;&#34;16.0.89(%)&#34; OR version:&lt;&#34;17.0.3(%)&#34;))</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="((vendor:=FreePBX AND product:=PBX) OR (vendor:=Sangoma AND product:=FreePBX)) AND (version:&gt;0 AND (version:&lt;&#34;15.0.66(%)&#34; OR version:&lt;&#34;16.0.89(%)&#34; OR version:&lt;&#34;17.0.3(%)&#34;))" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/software?search=%28%28vendor%3A%3DFreePBX+AND+product%3A%3DPBX%29+OR+%28vendor%3A%3DSangoma+AND+product%3A%3DFreePBX%29%29+AND+%28version%3A%3E0+AND+%28version%3A%3C%2215.0.66%28%25%29%22+OR+version%3A%3C%2216.0.89%28%25%29%22+OR+version%3A%3C%2217.0.3%28%25%29%22%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/software?search=%28%28vendor%3A%3DFreePBX+AND+product%3A%3DPBX%29+OR+%28vendor%3A%3DSangoma+AND+product%3A%3DFreePBX%29%29+AND+%28version%3A%3E0+AND+%28version%3A%3C%2215.0.66%28%25%29%22+OR+version%3A%3C%2216.0.89%28%25%29%22+OR+version%3A%3C%2217.0.3%28%25%29%22%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="((vendor:=FreePBX AND product:=PBX) OR (vendor:=Sangoma AND product:=FreePBX)) AND (version:&gt;0 AND (version:&lt;&#34;15.0.66(%)&#34; OR version:&lt;&#34;16.0.89(%)&#34; OR version:&lt;&#34;17.0.3(%)&#34;))"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="solarwinds web help desk multiple vulnerabilities (2026-01) vendor:=solarwinds and product:=&#34;web help desk&#34; and (version:&gt;0 and version:&lt;12.8.8.2585) software vulnerability" data-ql-sev="critical">
      <div class="ql-card-header">
        <div class="ql-title">SolarWinds Web Help Desk Multiple Vulnerabilities (2026-01)</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><span class="ql-type-badge">software</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>vendor:=SolarWinds AND product:=&#34;Web Help Desk&#34; AND (version:&gt;0 AND version:&lt;12.8.8.2585)</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="vendor:=SolarWinds AND product:=&#34;Web Help Desk&#34; AND (version:&gt;0 AND version:&lt;12.8.8.2585)" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/software?search=vendor%3A%3DSolarWinds+AND+product%3A%3D%22Web+Help+Desk%22+AND+%28version%3A%3E0+AND+version%3A%3C12.8.8.2585%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/software?search=vendor%3A%3DSolarWinds+AND+product%3A%3D%22Web+Help+Desk%22+AND+%28version%3A%3E0+AND+version%3A%3C12.8.8.2585%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="vendor:=SolarWinds AND product:=&#34;Web Help Desk&#34; AND (version:&gt;0 AND version:&lt;12.8.8.2585)"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="solarwinds web help desk rce (cve-2025-26399) vendor:=solarwinds and product:=&#34;web help desk&#34; and (version:&gt;0 and version:&lt;12.8.7.2174) software vulnerability" data-ql-sev="critical">
      <div class="ql-card-header">
        <div class="ql-title">SolarWinds Web Help Desk RCE (CVE-2025-26399)</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><span class="ql-type-badge">software</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>vendor:=SolarWinds AND product:=&#34;Web Help Desk&#34; AND (version:&gt;0 AND version:&lt;12.8.7.2174)</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="vendor:=SolarWinds AND product:=&#34;Web Help Desk&#34; AND (version:&gt;0 AND version:&lt;12.8.7.2174)" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/software?search=vendor%3A%3DSolarWinds+AND+product%3A%3D%22Web+Help+Desk%22+AND+%28version%3A%3E0+AND+version%3A%3C12.8.7.2174%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/software?search=vendor%3A%3DSolarWinds+AND+product%3A%3D%22Web+Help+Desk%22+AND+%28version%3A%3E0+AND+version%3A%3C12.8.7.2174%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="vendor:=SolarWinds AND product:=&#34;Web Help Desk&#34; AND (version:&gt;0 AND version:&lt;12.8.7.2174)"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="sonicwall sma1000 &lt; 12.4.3 remote code execution hw:=&#34;sonicwall sma1000&#34; and (osversion:&gt;0 and osversion:&lt;12.4.3) assets vulnerability" data-ql-sev="critical">
      <div class="ql-card-header">
        <div class="ql-title">SonicWall SMA1000 &lt; 12.4.3 Remote Code Execution</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><span class="ql-type-badge">assets</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>hw:=&#34;SonicWall SMA1000&#34; AND (osversion:&gt;0 AND osversion:&lt;12.4.3)</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="hw:=&#34;SonicWall SMA1000&#34; AND (osversion:&gt;0 AND osversion:&lt;12.4.3)" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/?search=hw%3A%3D%22SonicWall+SMA1000%22+AND+%28osversion%3A%3E0+AND+osversion%3A%3C12.4.3%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/?search=hw%3A%3D%22SonicWall+SMA1000%22+AND+%28osversion%3A%3E0+AND+osversion%3A%3C12.4.3%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="hw:=&#34;SonicWall SMA1000&#34; AND (osversion:&gt;0 AND osversion:&lt;12.4.3)"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="sonicwall sslvpn authentication bypass (cve-2024-53704) os:sonicos and ( (osversion:&gt;&#34;6.0&#34; and osversion:&lt;&#34;6.5.5.1-6n&#34;) or (osversion:&gt;&#34;7.0&#34; and osversion:&lt;&#34;7.0.1-5165&#34;) or (osversion:&gt;&#34;7.1&#34; and osversion:&lt;&#34;7.1.3-7015&#34;) or (hw:tz80 and osversion:&gt;&#34;8.0&#34; and osversion:&lt;&#34;8.0.0-8037&#34;)) assets vulnerability" data-ql-sev="critical">
      <div class="ql-card-header">
        <div class="ql-title">SonicWall SSLVPN Authentication Bypass (CVE-2024-53704)</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><span class="ql-type-badge">assets</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>os:SonicOS AND ( (osversion:&gt;&#34;6.0&#34; AND osversion:&lt;&#34;6.5.5.1-6n&#34;) OR (osversion:&gt;&#34;7.0&#34; AND osversion:&lt;&#34;7.0.1-5165&#34;) OR (osversion:&gt;&#34;7.1&#34; AND osversion:&lt;&#34;7.1.3-7015&#34;) OR (hw:TZ80 AND osversion:&gt;&#34;8.0&#34; AND osversion:&lt;&#34;8.0.0-8037&#34;))</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="os:SonicOS AND ( (osversion:&gt;&#34;6.0&#34; AND osversion:&lt;&#34;6.5.5.1-6n&#34;) OR (osversion:&gt;&#34;7.0&#34; AND osversion:&lt;&#34;7.0.1-5165&#34;) OR (osversion:&gt;&#34;7.1&#34; AND osversion:&lt;&#34;7.1.3-7015&#34;) OR (hw:TZ80 AND osversion:&gt;&#34;8.0&#34; AND osversion:&lt;&#34;8.0.0-8037&#34;))" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/?search=os%3ASonicOS+AND+%28+%28osversion%3A%3E%226.0%22+AND+osversion%3A%3C%226.5.5.1-6n%22%29+OR+%28osversion%3A%3E%227.0%22+AND+osversion%3A%3C%227.0.1-5165%22%29+OR+%28osversion%3A%3E%227.1%22+AND+osversion%3A%3C%227.1.3-7015%22%29+OR+%28hw%3ATZ80+AND+osversion%3A%3E%228.0%22+AND+osversion%3A%3C%228.0.0-8037%22%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/?search=os%3ASonicOS+AND+%28+%28osversion%3A%3E%226.0%22+AND+osversion%3A%3C%226.5.5.1-6n%22%29+OR+%28osversion%3A%3E%227.0%22+AND+osversion%3A%3C%227.0.1-5165%22%29+OR+%28osversion%3A%3E%227.1%22+AND+osversion%3A%3C%227.1.3-7015%22%29+OR+%28hw%3ATZ80+AND+osversion%3A%3E%228.0%22+AND+osversion%3A%3C%228.0.0-8037%22%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="os:SonicOS AND ( (osversion:&gt;&#34;6.0&#34; AND osversion:&lt;&#34;6.5.5.1-6n&#34;) OR (osversion:&gt;&#34;7.0&#34; AND osversion:&lt;&#34;7.0.1-5165&#34;) OR (osversion:&gt;&#34;7.1&#34; AND osversion:&lt;&#34;7.1.3-7015&#34;) OR (hw:TZ80 AND osversion:&gt;&#34;8.0&#34; AND osversion:&lt;&#34;8.0.0-8037&#34;))"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="sonicwall sonicos buffer overflow vulnerability (cve-2020-5135) os:=&#34;sonicwall sonicos&#34; and  (os_version:=&#34;7.0.0.0&#34; or os_version:=&#34;6.5.4.7&#34; or os_version:=&#34;6.5.1.12&#34; or os_version:=&#34;6.0.5.3&#34; or os_version:=&#34;6.5.4.v&#34;) assets vulnerability" data-ql-sev="critical">
      <div class="ql-card-header">
        <div class="ql-title">SonicWall SonicOS Buffer Overflow Vulnerability (CVE-2020-5135)</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><span class="ql-type-badge">assets</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>os:=&#34;SonicWall SonicOS&#34; AND  (os_version:=&#34;7.0.0.0&#34; OR os_version:=&#34;6.5.4.7&#34; OR os_version:=&#34;6.5.1.12&#34; OR os_version:=&#34;6.0.5.3&#34; OR os_version:=&#34;6.5.4.v&#34;)</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="os:=&#34;SonicWall SonicOS&#34; AND  (os_version:=&#34;7.0.0.0&#34; OR os_version:=&#34;6.5.4.7&#34; OR os_version:=&#34;6.5.1.12&#34; OR os_version:=&#34;6.0.5.3&#34; OR os_version:=&#34;6.5.4.v&#34;)" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/?search=os%3A%3D%22SonicWall+SonicOS%22+AND++%28os_version%3A%3D%227.0.0.0%22+OR+os_version%3A%3D%226.5.4.7%22+OR+os_version%3A%3D%226.5.1.12%22+OR+os_version%3A%3D%226.0.5.3%22+OR+os_version%3A%3D%226.5.4.v%22%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/?search=os%3A%3D%22SonicWall+SonicOS%22+AND++%28os_version%3A%3D%227.0.0.0%22+OR+os_version%3A%3D%226.5.4.7%22+OR+os_version%3A%3D%226.5.1.12%22+OR+os_version%3A%3D%226.0.5.3%22+OR+os_version%3A%3D%226.5.4.v%22%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="os:=&#34;SonicWall SonicOS&#34; AND  (os_version:=&#34;7.0.0.0&#34; OR os_version:=&#34;6.5.4.7&#34; OR os_version:=&#34;6.5.1.12&#34; OR os_version:=&#34;6.0.5.3&#34; OR os_version:=&#34;6.5.4.v&#34;)"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="sonicwall sonicos improper access control vulnerability (cve-2024-40766) hw:=&#34;sonicwall%&#34; and ((os_version:&gt;0 and os_version:&lt;&#34;5.9.2.14-13o&#34;) or (os_version:&gt;&#34;6.0&#34; and os_version:&lt;&#34;6.5.4.15.116n&#34;) or (os_version:&gt;&#34;7.0&#34; and os_version:&lt;&#34;7.0.1-5035&#34;) or (os_version:&gt;&#34;6.0&#34; and os_version:&lt;&#34;6.5.2.8-2n&#34; and  (hw:&#34;sm9800&#34; or hw:&#34;nssp 12400&#34; or hw:&#34;nssp 12800&#34;))) assets vulnerability" data-ql-sev="critical">
      <div class="ql-card-header">
        <div class="ql-title">SonicWall SonicOS Improper Access Control Vulnerability (CVE-2024-40766)</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><span class="ql-type-badge">assets</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>hw:=&#34;SonicWall%&#34; AND ((os_version:&gt;0 AND os_version:&lt;&#34;5.9.2.14-13o&#34;) OR (os_version:&gt;&#34;6.0&#34; AND os_version:&lt;&#34;6.5.4.15.116n&#34;) OR (os_version:&gt;&#34;7.0&#34; AND os_version:&lt;&#34;7.0.1-5035&#34;) OR (os_version:&gt;&#34;6.0&#34; AND os_version:&lt;&#34;6.5.2.8-2n&#34; AND  (hw:&#34;SM9800&#34; OR hw:&#34;NSsp 12400&#34; OR hw:&#34;NSsp 12800&#34;)))</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="hw:=&#34;SonicWall%&#34; AND ((os_version:&gt;0 AND os_version:&lt;&#34;5.9.2.14-13o&#34;) OR (os_version:&gt;&#34;6.0&#34; AND os_version:&lt;&#34;6.5.4.15.116n&#34;) OR (os_version:&gt;&#34;7.0&#34; AND os_version:&lt;&#34;7.0.1-5035&#34;) OR (os_version:&gt;&#34;6.0&#34; AND os_version:&lt;&#34;6.5.2.8-2n&#34; AND  (hw:&#34;SM9800&#34; OR hw:&#34;NSsp 12400&#34; OR hw:&#34;NSsp 12800&#34;)))" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/?search=hw%3A%3D%22SonicWall%25%22+AND+%28%28os_version%3A%3E0+AND+os_version%3A%3C%225.9.2.14-13o%22%29+OR+%28os_version%3A%3E%226.0%22+AND+os_version%3A%3C%226.5.4.15.116n%22%29+OR+%28os_version%3A%3E%227.0%22+AND+os_version%3A%3C%227.0.1-5035%22%29+OR+%28os_version%3A%3E%226.0%22+AND+os_version%3A%3C%226.5.2.8-2n%22+AND++%28hw%3A%22SM9800%22+OR+hw%3A%22NSsp+12400%22+OR+hw%3A%22NSsp+12800%22%29%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/?search=hw%3A%3D%22SonicWall%25%22+AND+%28%28os_version%3A%3E0+AND+os_version%3A%3C%225.9.2.14-13o%22%29+OR+%28os_version%3A%3E%226.0%22+AND+os_version%3A%3C%226.5.4.15.116n%22%29+OR+%28os_version%3A%3E%227.0%22+AND+os_version%3A%3C%227.0.1-5035%22%29+OR+%28os_version%3A%3E%226.0%22+AND+os_version%3A%3C%226.5.2.8-2n%22+AND++%28hw%3A%22SM9800%22+OR+hw%3A%22NSsp+12400%22+OR+hw%3A%22NSsp+12800%22%29%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="hw:=&#34;SonicWall%&#34; AND ((os_version:&gt;0 AND os_version:&lt;&#34;5.9.2.14-13o&#34;) OR (os_version:&gt;&#34;6.0&#34; AND os_version:&lt;&#34;6.5.4.15.116n&#34;) OR (os_version:&gt;&#34;7.0&#34; AND os_version:&lt;&#34;7.0.1-5035&#34;) OR (os_version:&gt;&#34;6.0&#34; AND os_version:&lt;&#34;6.5.2.8-2n&#34; AND  (hw:&#34;SM9800&#34; OR hw:&#34;NSsp 12400&#34; OR hw:&#34;NSsp 12800&#34;)))"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="squid information disclosure (cve-2025-62168) vendor:=&#34;squid cache&#34; and product:=squid and (version:&gt;0 and version:&lt;7.2) software vulnerability" data-ql-sev="critical">
      <div class="ql-card-header">
        <div class="ql-title">Squid Information Disclosure (CVE-2025-62168)</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><span class="ql-type-badge">software</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>vendor:=&#34;Squid Cache&#34; AND product:=Squid AND (version:&gt;0 AND version:&lt;7.2)</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="vendor:=&#34;Squid Cache&#34; AND product:=Squid AND (version:&gt;0 AND version:&lt;7.2)" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/software?search=vendor%3A%3D%22Squid+Cache%22+AND+product%3A%3DSquid+AND+%28version%3A%3E0+AND+version%3A%3C7.2%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/software?search=vendor%3A%3D%22Squid+Cache%22+AND+product%3A%3DSquid+AND+%28version%3A%3E0+AND+version%3A%3C7.2%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="vendor:=&#34;Squid Cache&#34; AND product:=Squid AND (version:&gt;0 AND version:&lt;7.2)"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="squid urn handling buffer overflow (cve-2025-54574) vendor:=&#34;squid cache&#34; and product:=squid and (version:&gt;0 and version:&lt;6.4) software vulnerability" data-ql-sev="critical">
      <div class="ql-card-header">
        <div class="ql-title">Squid URN Handling Buffer Overflow (CVE-2025-54574)</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><span class="ql-type-badge">software</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>vendor:=&#34;Squid Cache&#34; AND product:=Squid AND (version:&gt;0 AND version:&lt;6.4)</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="vendor:=&#34;Squid Cache&#34; AND product:=Squid AND (version:&gt;0 AND version:&lt;6.4)" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/software?search=vendor%3A%3D%22Squid+Cache%22+AND+product%3A%3DSquid+AND+%28version%3A%3E0+AND+version%3A%3C6.4%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/software?search=vendor%3A%3D%22Squid+Cache%22+AND+product%3A%3DSquid+AND+%28version%3A%3E0+AND+version%3A%3C6.4%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="vendor:=&#34;Squid Cache&#34; AND product:=Squid AND (version:&gt;0 AND version:&lt;6.4)"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="unifi network application multiple vulnerabilities (2026-03) vendor:=ubiquiti and product:=&#34;unifi network&#34; and version:&gt;0 and (version:&lt;9.0.118 or (version:&gt;=10.1.0 and version:&lt;10.1.89) or (version:&gt;=10.2.0 and version:&lt;10.2.97)) software vulnerability" data-ql-sev="critical">
      <div class="ql-card-header">
        <div class="ql-title">UniFi Network Application Multiple Vulnerabilities (2026-03)</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><span class="ql-type-badge">software</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>vendor:=Ubiquiti AND product:=&#34;UniFi Network&#34; AND version:&gt;0 AND (version:&lt;9.0.118 OR (version:&gt;=10.1.0 AND version:&lt;10.1.89) OR (version:&gt;=10.2.0 AND version:&lt;10.2.97))</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="vendor:=Ubiquiti AND product:=&#34;UniFi Network&#34; AND version:&gt;0 AND (version:&lt;9.0.118 OR (version:&gt;=10.1.0 AND version:&lt;10.1.89) OR (version:&gt;=10.2.0 AND version:&lt;10.2.97))" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/software?search=vendor%3A%3DUbiquiti+AND+product%3A%3D%22UniFi+Network%22+AND+version%3A%3E0+AND+%28version%3A%3C9.0.118+OR+%28version%3A%3E%3D10.1.0+AND+version%3A%3C10.1.89%29+OR+%28version%3A%3E%3D10.2.0+AND+version%3A%3C10.2.97%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/software?search=vendor%3A%3DUbiquiti+AND+product%3A%3D%22UniFi+Network%22+AND+version%3A%3E0+AND+%28version%3A%3C9.0.118+OR+%28version%3A%3E%3D10.1.0+AND+version%3A%3C10.1.89%29+OR+%28version%3A%3E%3D10.2.0+AND+version%3A%3C10.2.97%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="vendor:=Ubiquiti AND product:=&#34;UniFi Network&#34; AND version:&gt;0 AND (version:&lt;9.0.118 OR (version:&gt;=10.1.0 AND version:&lt;10.1.89) OR (version:&gt;=10.2.0 AND version:&lt;10.2.97))"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="vmware vcenter server 7.0 &lt; 7.0 u3t / 8.0 &lt; 8.0 u3d multiple vulnerabilities vendor:=vmware and (product:&#34;vcenter server&#34; or product:&#34;cloud foundation&#34;) and ((version:&gt;7.0 and version:&lt;&#34;7.0.3 build-24322018&#34;) or (version:&gt;8.0 and version:&lt;&#34;8.0.3 build-24322831&#34;)) software vulnerability" data-ql-sev="critical">
      <div class="ql-card-header">
        <div class="ql-title">VMware vCenter Server 7.0 &lt; 7.0 U3t / 8.0 &lt; 8.0 U3d Multiple Vulnerabilities</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><span class="ql-type-badge">software</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>vendor:=VMware AND (product:&#34;vcenter server&#34; OR product:&#34;cloud foundation&#34;) AND ((version:&gt;7.0 AND version:&lt;&#34;7.0.3 build-24322018&#34;) OR (version:&gt;8.0 AND version:&lt;&#34;8.0.3 build-24322831&#34;))</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="vendor:=VMware AND (product:&#34;vcenter server&#34; OR product:&#34;cloud foundation&#34;) AND ((version:&gt;7.0 AND version:&lt;&#34;7.0.3 build-24322018&#34;) OR (version:&gt;8.0 AND version:&lt;&#34;8.0.3 build-24322831&#34;))" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/software?search=vendor%3A%3DVMware+AND+%28product%3A%22vcenter+server%22+OR+product%3A%22cloud+foundation%22%29+AND+%28%28version%3A%3E7.0+AND+version%3A%3C%227.0.3+build-24322018%22%29+OR+%28version%3A%3E8.0+AND+version%3A%3C%228.0.3+build-24322831%22%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/software?search=vendor%3A%3DVMware+AND+%28product%3A%22vcenter+server%22+OR+product%3A%22cloud+foundation%22%29+AND+%28%28version%3A%3E7.0+AND+version%3A%3C%227.0.3+build-24322018%22%29+OR+%28version%3A%3E8.0+AND+version%3A%3C%228.0.3+build-24322831%22%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="vendor:=VMware AND (product:&#34;vcenter server&#34; OR product:&#34;cloud foundation&#34;) AND ((version:&gt;7.0 AND version:&lt;&#34;7.0.3 build-24322018&#34;) OR (version:&gt;8.0 AND version:&lt;&#34;8.0.3 build-24322831&#34;))"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="valkey multiple vulnerabilities (2025-10) (vendor:=valkey or vendor:=&#34;fedora project&#34;) and product:=valkey and (version:&gt;0 and ( (version:&gt;=7.2 and version:&lt;7.2.11) or (version:&gt;=8.0 and version:&lt;8.0.6) or (version:&gt;=8.1 and version:&lt;8.1.4))) software vulnerability" data-ql-sev="critical">
      <div class="ql-card-header">
        <div class="ql-title">Valkey Multiple Vulnerabilities (2025-10)</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><span class="ql-type-badge">software</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>(vendor:=valkey OR vendor:=&#34;Fedora Project&#34;) AND product:=valkey AND (version:&gt;0 AND ( (version:&gt;=7.2 AND version:&lt;7.2.11) OR (version:&gt;=8.0 AND version:&lt;8.0.6) OR (version:&gt;=8.1 AND version:&lt;8.1.4)))</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="(vendor:=valkey OR vendor:=&#34;Fedora Project&#34;) AND product:=valkey AND (version:&gt;0 AND ( (version:&gt;=7.2 AND version:&lt;7.2.11) OR (version:&gt;=8.0 AND version:&lt;8.0.6) OR (version:&gt;=8.1 AND version:&lt;8.1.4)))" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/software?search=%28vendor%3A%3Dvalkey+OR+vendor%3A%3D%22Fedora+Project%22%29+AND+product%3A%3Dvalkey+AND+%28version%3A%3E0+AND+%28+%28version%3A%3E%3D7.2+AND+version%3A%3C7.2.11%29+OR+%28version%3A%3E%3D8.0+AND+version%3A%3C8.0.6%29+OR+%28version%3A%3E%3D8.1+AND+version%3A%3C8.1.4%29%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/software?search=%28vendor%3A%3Dvalkey+OR+vendor%3A%3D%22Fedora+Project%22%29+AND+product%3A%3Dvalkey+AND+%28version%3A%3E0+AND+%28+%28version%3A%3E%3D7.2+AND+version%3A%3C7.2.11%29+OR+%28version%3A%3E%3D8.0+AND+version%3A%3C8.0.6%29+OR+%28version%3A%3E%3D8.1+AND+version%3A%3C8.1.4%29%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="(vendor:=valkey OR vendor:=&#34;Fedora Project&#34;) AND product:=valkey AND (version:&gt;0 AND ( (version:&gt;=7.2 AND version:&lt;7.2.11) OR (version:&gt;=8.0 AND version:&lt;8.0.6) OR (version:&gt;=8.1 AND version:&lt;8.1.4)))"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="veeam backup &amp; replication multiple vulnerabilities (2026-03) vendor:=veeam and (product:=&#34;backup &amp; replication&#34; or product:=&#34;veeam backup &amp; replication&#34;) and ((version:&gt;=12.3 and version:&lt;12.3.2.4465) or (version:&gt;=13.0 and version:&lt;13.0.1.2067)) software vulnerability" data-ql-sev="critical">
      <div class="ql-card-header">
        <div class="ql-title">Veeam Backup &amp; Replication Multiple Vulnerabilities (2026-03)</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><span class="ql-type-badge">software</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>vendor:=Veeam AND (product:=&#34;Backup &amp; Replication&#34; OR product:=&#34;Veeam Backup &amp; Replication&#34;) AND ((version:&gt;=12.3 AND version:&lt;12.3.2.4465) OR (version:&gt;=13.0 AND version:&lt;13.0.1.2067))</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="vendor:=Veeam AND (product:=&#34;Backup &amp; Replication&#34; OR product:=&#34;Veeam Backup &amp; Replication&#34;) AND ((version:&gt;=12.3 AND version:&lt;12.3.2.4465) OR (version:&gt;=13.0 AND version:&lt;13.0.1.2067))" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/software?search=vendor%3A%3DVeeam+AND+%28product%3A%3D%22Backup+%26+Replication%22+OR+product%3A%3D%22Veeam+Backup+%26+Replication%22%29+AND+%28%28version%3A%3E%3D12.3+AND+version%3A%3C12.3.2.4465%29+OR+%28version%3A%3E%3D13.0+AND+version%3A%3C13.0.1.2067%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/software?search=vendor%3A%3DVeeam+AND+%28product%3A%3D%22Backup+%26+Replication%22+OR+product%3A%3D%22Veeam+Backup+%26+Replication%22%29+AND+%28%28version%3A%3E%3D12.3+AND+version%3A%3C12.3.2.4465%29+OR+%28version%3A%3E%3D13.0+AND+version%3A%3C13.0.1.2067%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="vendor:=Veeam AND (product:=&#34;Backup &amp; Replication&#34; OR product:=&#34;Veeam Backup &amp; Replication&#34;) AND ((version:&gt;=12.3 AND version:&lt;12.3.2.4465) OR (version:&gt;=13.0 AND version:&lt;13.0.1.2067))"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="veeam backup &amp; replication rce multiple vulnerabilities (2025-10) vendor:=veeam and (product:=&#34;backup &amp; replication&#34; or product:=&#34;veeam backup &amp; replication&#34;) and (version:&gt;0 and version:&gt;=12 and version:&lt;12.3.2.4165) software vulnerability" data-ql-sev="critical">
      <div class="ql-card-header">
        <div class="ql-title">Veeam Backup &amp; Replication RCE Multiple Vulnerabilities (2025-10)</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><span class="ql-type-badge">software</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>vendor:=Veeam AND (product:=&#34;Backup &amp; Replication&#34; OR product:=&#34;Veeam Backup &amp; Replication&#34;) AND (version:&gt;0 AND version:&gt;=12 AND version:&lt;12.3.2.4165)</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="vendor:=Veeam AND (product:=&#34;Backup &amp; Replication&#34; OR product:=&#34;Veeam Backup &amp; Replication&#34;) AND (version:&gt;0 AND version:&gt;=12 AND version:&lt;12.3.2.4165)" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/software?search=vendor%3A%3DVeeam+AND+%28product%3A%3D%22Backup+%26+Replication%22+OR+product%3A%3D%22Veeam+Backup+%26+Replication%22%29+AND+%28version%3A%3E0+AND+version%3A%3E%3D12+AND+version%3A%3C12.3.2.4165%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/software?search=vendor%3A%3DVeeam+AND+%28product%3A%3D%22Backup+%26+Replication%22+OR+product%3A%3D%22Veeam+Backup+%26+Replication%22%29+AND+%28version%3A%3E0+AND+version%3A%3E%3D12+AND+version%3A%3C12.3.2.4165%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="vendor:=Veeam AND (product:=&#34;Backup &amp; Replication&#34; OR product:=&#34;Veeam Backup &amp; Replication&#34;) AND (version:&gt;0 AND version:&gt;=12 AND version:&lt;12.3.2.4165)"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="zyxel multiple firewalls buffer overflow vulnerability (cve-2023-33009) ((os:=&#34;zyxel atp%&#34; or os:=&#34;zyxel usg flex%&#34; or os:=&#34;zyxel usg20w-vpn&#34; or os:=&#34;zyxel usg20-vpn&#34; or os:=&#34;zyxel vpn%&#34;)  and (os_version:&gt;=&#34;4.60&#34; and os_version:&lt;=&#34;5.36&#34;)) or ((os:=&#34;zyxel usg40%&#34; or os:=&#34;zyxel usg60%&#34;) and (os_version:&gt;=&#34;4.60&#34; and os_version:&lt;=&#34;4.73&#34;)) assets vulnerability" data-ql-sev="critical">
      <div class="ql-card-header">
        <div class="ql-title">Zyxel Multiple Firewalls Buffer Overflow Vulnerability (CVE-2023-33009)</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><span class="ql-type-badge">assets</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>((os:=&#34;Zyxel ATP%&#34; OR os:=&#34;Zyxel USG Flex%&#34; OR os:=&#34;Zyxel USG20W-VPN&#34; OR os:=&#34;Zyxel USG20-VPN&#34; OR os:=&#34;Zyxel VPN%&#34;)  AND (os_version:&gt;=&#34;4.60&#34; AND os_version:&lt;=&#34;5.36&#34;)) OR ((os:=&#34;Zyxel USG40%&#34; OR os:=&#34;Zyxel USG60%&#34;) AND (os_version:&gt;=&#34;4.60&#34; AND os_version:&lt;=&#34;4.73&#34;))</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="((os:=&#34;Zyxel ATP%&#34; OR os:=&#34;Zyxel USG Flex%&#34; OR os:=&#34;Zyxel USG20W-VPN&#34; OR os:=&#34;Zyxel USG20-VPN&#34; OR os:=&#34;Zyxel VPN%&#34;)  AND (os_version:&gt;=&#34;4.60&#34; AND os_version:&lt;=&#34;5.36&#34;)) OR ((os:=&#34;Zyxel USG40%&#34; OR os:=&#34;Zyxel USG60%&#34;) AND (os_version:&gt;=&#34;4.60&#34; AND os_version:&lt;=&#34;4.73&#34;))" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/?search=%28%28os%3A%3D%22Zyxel+ATP%25%22+OR+os%3A%3D%22Zyxel+USG+Flex%25%22+OR+os%3A%3D%22Zyxel+USG20W-VPN%22+OR+os%3A%3D%22Zyxel+USG20-VPN%22+OR+os%3A%3D%22Zyxel+VPN%25%22%29++AND+%28os_version%3A%3E%3D%224.60%22+AND+os_version%3A%3C%3D%225.36%22%29%29+OR+%28%28os%3A%3D%22Zyxel+USG40%25%22+OR+os%3A%3D%22Zyxel+USG60%25%22%29+AND+%28os_version%3A%3E%3D%224.60%22+AND+os_version%3A%3C%3D%224.73%22%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/?search=%28%28os%3A%3D%22Zyxel+ATP%25%22+OR+os%3A%3D%22Zyxel+USG+Flex%25%22+OR+os%3A%3D%22Zyxel+USG20W-VPN%22+OR+os%3A%3D%22Zyxel+USG20-VPN%22+OR+os%3A%3D%22Zyxel+VPN%25%22%29++AND+%28os_version%3A%3E%3D%224.60%22+AND+os_version%3A%3C%3D%225.36%22%29%29+OR+%28%28os%3A%3D%22Zyxel+USG40%25%22+OR+os%3A%3D%22Zyxel+USG60%25%22%29+AND+%28os_version%3A%3E%3D%224.60%22+AND+os_version%3A%3C%3D%224.73%22%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="((os:=&#34;Zyxel ATP%&#34; OR os:=&#34;Zyxel USG Flex%&#34; OR os:=&#34;Zyxel USG20W-VPN&#34; OR os:=&#34;Zyxel USG20-VPN&#34; OR os:=&#34;Zyxel VPN%&#34;)  AND (os_version:&gt;=&#34;4.60&#34; AND os_version:&lt;=&#34;5.36&#34;)) OR ((os:=&#34;Zyxel USG40%&#34; OR os:=&#34;Zyxel USG60%&#34;) AND (os_version:&gt;=&#34;4.60&#34; AND os_version:&lt;=&#34;4.73&#34;))"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="zyxel multiple firewalls buffer overflow vulnerability (cve-2023-33010) (os:=&#34;zyxel atp%&#34; and (os_version:&gt;=&#34;4.32&#34; and os_version:&lt;=&#34;5.36&#34;)) or (os:=&#34;zyxel usg flex 50w&#34; and (os_version:&gt;=&#34;4.25&#34; and os_version:&lt;=&#34;5.36&#34;)) or (os:=&#34;zyxel usg20w-vpn&#34; and (os_version:&gt;=&#34;4.25&#34; and os_version:&lt;=&#34;5.36&#34;)) or ((os:=&#34;zyxel usg20%&#34; or os:=&#34;zyxel usg40%&#34; or os:=&#34;zyxel usg60%&#34;) and (os_version:&gt;=&#34;4.50&#34; and os_version:&lt;=&#34;5.36&#34;)) or (os:=&#34;zyxel usg flex%&#34; and (os_version:&gt;=&#34;4.25&#34; and os_version:&lt;=&#34;4.73&#34; and not os:=&#34;zyxel usg flex 50w&#34;)) or (os:=&#34;zyxel vpn%&#34; and (os_version:&gt;=&#34;4.30&#34; and os_version:&lt;=&#34;5.36&#34;)) assets vulnerability" data-ql-sev="critical">
      <div class="ql-card-header">
        <div class="ql-title">Zyxel Multiple Firewalls Buffer Overflow Vulnerability (CVE-2023-33010)</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><span class="ql-type-badge">assets</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>(os:=&#34;Zyxel ATP%&#34; AND (os_version:&gt;=&#34;4.32&#34; AND os_version:&lt;=&#34;5.36&#34;)) OR (os:=&#34;Zyxel USG Flex 50W&#34; AND (os_version:&gt;=&#34;4.25&#34; AND os_version:&lt;=&#34;5.36&#34;)) OR (os:=&#34;Zyxel USG20W-VPN&#34; AND (os_version:&gt;=&#34;4.25&#34; AND os_version:&lt;=&#34;5.36&#34;)) OR ((os:=&#34;Zyxel USG20%&#34; OR os:=&#34;Zyxel USG40%&#34; OR os:=&#34;Zyxel USG60%&#34;) AND (os_version:&gt;=&#34;4.50&#34; AND os_version:&lt;=&#34;5.36&#34;)) OR (os:=&#34;Zyxel USG Flex%&#34; AND (os_version:&gt;=&#34;4.25&#34; AND os_version:&lt;=&#34;4.73&#34; AND not os:=&#34;Zyxel USG Flex 50W&#34;)) OR (os:=&#34;Zyxel VPN%&#34; AND (os_version:&gt;=&#34;4.30&#34; AND os_version:&lt;=&#34;5.36&#34;))</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="(os:=&#34;Zyxel ATP%&#34; AND (os_version:&gt;=&#34;4.32&#34; AND os_version:&lt;=&#34;5.36&#34;)) OR (os:=&#34;Zyxel USG Flex 50W&#34; AND (os_version:&gt;=&#34;4.25&#34; AND os_version:&lt;=&#34;5.36&#34;)) OR (os:=&#34;Zyxel USG20W-VPN&#34; AND (os_version:&gt;=&#34;4.25&#34; AND os_version:&lt;=&#34;5.36&#34;)) OR ((os:=&#34;Zyxel USG20%&#34; OR os:=&#34;Zyxel USG40%&#34; OR os:=&#34;Zyxel USG60%&#34;) AND (os_version:&gt;=&#34;4.50&#34; AND os_version:&lt;=&#34;5.36&#34;)) OR (os:=&#34;Zyxel USG Flex%&#34; AND (os_version:&gt;=&#34;4.25&#34; AND os_version:&lt;=&#34;4.73&#34; AND not os:=&#34;Zyxel USG Flex 50W&#34;)) OR (os:=&#34;Zyxel VPN%&#34; AND (os_version:&gt;=&#34;4.30&#34; AND os_version:&lt;=&#34;5.36&#34;))" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/?search=%28os%3A%3D%22Zyxel+ATP%25%22+AND+%28os_version%3A%3E%3D%224.32%22+AND+os_version%3A%3C%3D%225.36%22%29%29+OR+%28os%3A%3D%22Zyxel+USG+Flex+50W%22+AND+%28os_version%3A%3E%3D%224.25%22+AND+os_version%3A%3C%3D%225.36%22%29%29+OR+%28os%3A%3D%22Zyxel+USG20W-VPN%22+AND+%28os_version%3A%3E%3D%224.25%22+AND+os_version%3A%3C%3D%225.36%22%29%29+OR+%28%28os%3A%3D%22Zyxel+USG20%25%22+OR+os%3A%3D%22Zyxel+USG40%25%22+OR+os%3A%3D%22Zyxel+USG60%25%22%29+AND+%28os_version%3A%3E%3D%224.50%22+AND+os_version%3A%3C%3D%225.36%22%29%29+OR+%28os%3A%3D%22Zyxel+USG+Flex%25%22+AND+%28os_version%3A%3E%3D%224.25%22+AND+os_version%3A%3C%3D%224.73%22+AND+not+os%3A%3D%22Zyxel+USG+Flex+50W%22%29%29+OR+%28os%3A%3D%22Zyxel+VPN%25%22+AND+%28os_version%3A%3E%3D%224.30%22+AND+os_version%3A%3C%3D%225.36%22%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/?search=%28os%3A%3D%22Zyxel+ATP%25%22+AND+%28os_version%3A%3E%3D%224.32%22+AND+os_version%3A%3C%3D%225.36%22%29%29+OR+%28os%3A%3D%22Zyxel+USG+Flex+50W%22+AND+%28os_version%3A%3E%3D%224.25%22+AND+os_version%3A%3C%3D%225.36%22%29%29+OR+%28os%3A%3D%22Zyxel+USG20W-VPN%22+AND+%28os_version%3A%3E%3D%224.25%22+AND+os_version%3A%3C%3D%225.36%22%29%29+OR+%28%28os%3A%3D%22Zyxel+USG20%25%22+OR+os%3A%3D%22Zyxel+USG40%25%22+OR+os%3A%3D%22Zyxel+USG60%25%22%29+AND+%28os_version%3A%3E%3D%224.50%22+AND+os_version%3A%3C%3D%225.36%22%29%29+OR+%28os%3A%3D%22Zyxel+USG+Flex%25%22+AND+%28os_version%3A%3E%3D%224.25%22+AND+os_version%3A%3C%3D%224.73%22+AND+not+os%3A%3D%22Zyxel+USG+Flex+50W%22%29%29+OR+%28os%3A%3D%22Zyxel+VPN%25%22+AND+%28os_version%3A%3E%3D%224.30%22+AND+os_version%3A%3C%3D%225.36%22%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="(os:=&#34;Zyxel ATP%&#34; AND (os_version:&gt;=&#34;4.32&#34; AND os_version:&lt;=&#34;5.36&#34;)) OR (os:=&#34;Zyxel USG Flex 50W&#34; AND (os_version:&gt;=&#34;4.25&#34; AND os_version:&lt;=&#34;5.36&#34;)) OR (os:=&#34;Zyxel USG20W-VPN&#34; AND (os_version:&gt;=&#34;4.25&#34; AND os_version:&lt;=&#34;5.36&#34;)) OR ((os:=&#34;Zyxel USG20%&#34; OR os:=&#34;Zyxel USG40%&#34; OR os:=&#34;Zyxel USG60%&#34;) AND (os_version:&gt;=&#34;4.50&#34; AND os_version:&lt;=&#34;5.36&#34;)) OR (os:=&#34;Zyxel USG Flex%&#34; AND (os_version:&gt;=&#34;4.25&#34; AND os_version:&lt;=&#34;4.73&#34; AND not os:=&#34;Zyxel USG Flex 50W&#34;)) OR (os:=&#34;Zyxel VPN%&#34; AND (os_version:&gt;=&#34;4.30&#34; AND os_version:&lt;=&#34;5.36&#34;))"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="zyxel multiple firewalls os command injection vulnerability (cve-2023-28771) ((os:=&#34;zyxel atp%&#34; or os:=&#34;zyxel usg flex%&#34; or os:=&#34;zyxel vpn%&#34;) and (os_version:&gt;=&#34;4.60&#34; and os_version:&lt;=&#34;5.35&#34;)) or ((os:=&#34;zyxel %usg100&#34; or os:=&#34;zyxel %usg300&#34;) and (os_version:&gt;=&#34;4.60&#34; and os_version:&lt;=&#34;4.73&#34;)) assets vulnerability" data-ql-sev="critical">
      <div class="ql-card-header">
        <div class="ql-title">Zyxel Multiple Firewalls OS Command Injection Vulnerability (CVE-2023-28771)</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><span class="ql-type-badge">assets</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>((os:=&#34;Zyxel ATP%&#34; OR os:=&#34;Zyxel USG Flex%&#34; OR os:=&#34;Zyxel VPN%&#34;) AND (os_version:&gt;=&#34;4.60&#34; AND os_version:&lt;=&#34;5.35&#34;)) OR ((os:=&#34;Zyxel %USG100&#34; OR os:=&#34;Zyxel %USG300&#34;) AND (os_version:&gt;=&#34;4.60&#34; AND os_version:&lt;=&#34;4.73&#34;))</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="((os:=&#34;Zyxel ATP%&#34; OR os:=&#34;Zyxel USG Flex%&#34; OR os:=&#34;Zyxel VPN%&#34;) AND (os_version:&gt;=&#34;4.60&#34; AND os_version:&lt;=&#34;5.35&#34;)) OR ((os:=&#34;Zyxel %USG100&#34; OR os:=&#34;Zyxel %USG300&#34;) AND (os_version:&gt;=&#34;4.60&#34; AND os_version:&lt;=&#34;4.73&#34;))" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/?search=%28%28os%3A%3D%22Zyxel+ATP%25%22+OR+os%3A%3D%22Zyxel+USG+Flex%25%22+OR+os%3A%3D%22Zyxel+VPN%25%22%29+AND+%28os_version%3A%3E%3D%224.60%22+AND+os_version%3A%3C%3D%225.35%22%29%29+OR+%28%28os%3A%3D%22Zyxel+%25USG100%22+OR+os%3A%3D%22Zyxel+%25USG300%22%29+AND+%28os_version%3A%3E%3D%224.60%22+AND+os_version%3A%3C%3D%224.73%22%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/?search=%28%28os%3A%3D%22Zyxel+ATP%25%22+OR+os%3A%3D%22Zyxel+USG+Flex%25%22+OR+os%3A%3D%22Zyxel+VPN%25%22%29+AND+%28os_version%3A%3E%3D%224.60%22+AND+os_version%3A%3C%3D%225.35%22%29%29+OR+%28%28os%3A%3D%22Zyxel+%25USG100%22+OR+os%3A%3D%22Zyxel+%25USG300%22%29+AND+%28os_version%3A%3E%3D%224.60%22+AND+os_version%3A%3C%3D%224.73%22%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="((os:=&#34;Zyxel ATP%&#34; OR os:=&#34;Zyxel USG Flex%&#34; OR os:=&#34;Zyxel VPN%&#34;) AND (os_version:&gt;=&#34;4.60&#34; AND os_version:&lt;=&#34;5.35&#34;)) OR ((os:=&#34;Zyxel %USG100&#34; OR os:=&#34;Zyxel %USG300&#34;) AND (os_version:&gt;=&#34;4.60&#34; AND os_version:&lt;=&#34;4.73&#34;))"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="zyxel multiple firewalls path traversal vulnerability (cve-2024-11667) (os:=&#34;zyxel atp%&#34; and (os_version:&gt;=&#34;5.00&#34; and os_version:&lt;&#34;5.39&#34;)) or (os:=&#34;zyxel usg20w-vpn&#34; and (os_version:&gt;=&#34;5.10&#34; and os_version:&lt;&#34;5.39&#34;)) or (os:=&#34;zyxel usg flex 50w&#34; and (os_version:&gt;=&#34;5.10&#34; and os_version:&lt;&#34;5.39&#34;)) or (os:=&#34;zyxel usg flex%&#34; and (os_version:&gt;=&#34;5.00&#34; and os_version:&lt;&#34;5.39&#34;)) assets vulnerability" data-ql-sev="critical">
      <div class="ql-card-header">
        <div class="ql-title">Zyxel Multiple Firewalls Path Traversal Vulnerability (CVE-2024-11667)</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><span class="ql-type-badge">assets</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>(os:=&#34;Zyxel ATP%&#34; AND (os_version:&gt;=&#34;5.00&#34; AND os_version:&lt;&#34;5.39&#34;)) OR (os:=&#34;Zyxel USG20W-VPN&#34; AND (os_version:&gt;=&#34;5.10&#34; AND os_version:&lt;&#34;5.39&#34;)) OR (os:=&#34;Zyxel USG Flex 50W&#34; AND (os_version:&gt;=&#34;5.10&#34; AND os_version:&lt;&#34;5.39&#34;)) OR (os:=&#34;Zyxel USG Flex%&#34; AND (os_version:&gt;=&#34;5.00&#34; AND os_version:&lt;&#34;5.39&#34;))</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="(os:=&#34;Zyxel ATP%&#34; AND (os_version:&gt;=&#34;5.00&#34; AND os_version:&lt;&#34;5.39&#34;)) OR (os:=&#34;Zyxel USG20W-VPN&#34; AND (os_version:&gt;=&#34;5.10&#34; AND os_version:&lt;&#34;5.39&#34;)) OR (os:=&#34;Zyxel USG Flex 50W&#34; AND (os_version:&gt;=&#34;5.10&#34; AND os_version:&lt;&#34;5.39&#34;)) OR (os:=&#34;Zyxel USG Flex%&#34; AND (os_version:&gt;=&#34;5.00&#34; AND os_version:&lt;&#34;5.39&#34;))" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/?search=%28os%3A%3D%22Zyxel+ATP%25%22+AND+%28os_version%3A%3E%3D%225.00%22+AND+os_version%3A%3C%225.39%22%29%29+OR+%28os%3A%3D%22Zyxel+USG20W-VPN%22+AND+%28os_version%3A%3E%3D%225.10%22+AND+os_version%3A%3C%225.39%22%29%29+OR+%28os%3A%3D%22Zyxel+USG+Flex+50W%22+AND+%28os_version%3A%3E%3D%225.10%22+AND+os_version%3A%3C%225.39%22%29%29+OR+%28os%3A%3D%22Zyxel+USG+Flex%25%22+AND+%28os_version%3A%3E%3D%225.00%22+AND+os_version%3A%3C%225.39%22%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/?search=%28os%3A%3D%22Zyxel+ATP%25%22+AND+%28os_version%3A%3E%3D%225.00%22+AND+os_version%3A%3C%225.39%22%29%29+OR+%28os%3A%3D%22Zyxel+USG20W-VPN%22+AND+%28os_version%3A%3E%3D%225.10%22+AND+os_version%3A%3C%225.39%22%29%29+OR+%28os%3A%3D%22Zyxel+USG+Flex+50W%22+AND+%28os_version%3A%3E%3D%225.10%22+AND+os_version%3A%3C%225.39%22%29%29+OR+%28os%3A%3D%22Zyxel+USG+Flex%25%22+AND+%28os_version%3A%3E%3D%225.00%22+AND+os_version%3A%3C%225.39%22%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="(os:=&#34;Zyxel ATP%&#34; AND (os_version:&gt;=&#34;5.00&#34; AND os_version:&lt;&#34;5.39&#34;)) OR (os:=&#34;Zyxel USG20W-VPN&#34; AND (os_version:&gt;=&#34;5.10&#34; AND os_version:&lt;&#34;5.39&#34;)) OR (os:=&#34;Zyxel USG Flex 50W&#34; AND (os_version:&gt;=&#34;5.10&#34; AND os_version:&lt;&#34;5.39&#34;)) OR (os:=&#34;Zyxel USG Flex%&#34; AND (os_version:&gt;=&#34;5.00&#34; AND os_version:&lt;&#34;5.39&#34;))"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="n8n unauthenticated file access (cve-2026-21858) vendor:=n8n and product:=n8n and version:&gt;0 and (version:&gt;=1.65.0 and version:&lt;1.121.0)  software vulnerability" data-ql-sev="critical">
      <div class="ql-card-header">
        <div class="ql-title">n8n Unauthenticated File Access (CVE-2026-21858)</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-critical fd-badge-sm">Critical</span><span class="ql-type-badge">software</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>vendor:=n8n AND product:=n8n AND version:&gt;0 AND (version:&gt;=1.65.0 AND version:&lt;1.121.0) </code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="vendor:=n8n AND product:=n8n AND version:&gt;0 AND (version:&gt;=1.65.0 AND version:&lt;1.121.0) " title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/software?search=vendor%3A%3Dn8n+AND+product%3A%3Dn8n+AND+version%3A%3E0+AND+%28version%3A%3E%3D1.65.0+AND+version%3A%3C1.121.0%29+" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/software?search=vendor%3A%3Dn8n+AND+product%3A%3Dn8n+AND+version%3A%3E0+AND+%28version%3A%3E%3D1.65.0+AND+version%3A%3C1.121.0%29+" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="vendor:=n8n AND product:=n8n AND version:&gt;0 AND (version:&gt;=1.65.0 AND version:&lt;1.121.0) "><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="apache http server http2 double free and possible rce (cve-2026-23918) vendor:=apache and product:=httpd and version:&gt;0 and version:=2.4.66 software vulnerability" data-ql-sev="high">
      <div class="ql-card-header">
        <div class="ql-title">Apache HTTP Server HTTP2 Double Free And Possible RCE (CVE-2026-23918)</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><span class="ql-type-badge">software</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>vendor:=Apache AND product:=HTTPD AND version:&gt;0 AND version:=2.4.66</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="vendor:=Apache AND product:=HTTPD AND version:&gt;0 AND version:=2.4.66" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/software?search=vendor%3A%3DApache+AND+product%3A%3DHTTPD+AND+version%3A%3E0+AND+version%3A%3D2.4.66" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/software?search=vendor%3A%3DApache+AND+product%3A%3DHTTPD+AND+version%3A%3E0+AND+version%3A%3D2.4.66" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="vendor:=Apache AND product:=HTTPD AND version:&gt;0 AND version:=2.4.66"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="apache tomcat 10.1.0-m1 &lt; 10.1.43 multiple vulnerabilities product:tomcat and (version:&gt;10.1.0-m1 and version:&lt;10.1.43) software vulnerability" data-ql-sev="high">
      <div class="ql-card-header">
        <div class="ql-title">Apache Tomcat 10.1.0-M1 &lt; 10.1.43 Multiple Vulnerabilities</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><span class="ql-type-badge">software</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>product:Tomcat AND (version:&gt;10.1.0-M1 AND version:&lt;10.1.43)</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="product:Tomcat AND (version:&gt;10.1.0-M1 AND version:&lt;10.1.43)" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/software?search=product%3ATomcat+AND+%28version%3A%3E10.1.0-M1+AND+version%3A%3C10.1.43%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/software?search=product%3ATomcat+AND+%28version%3A%3E10.1.0-M1+AND+version%3A%3C10.1.43%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="product:Tomcat AND (version:&gt;10.1.0-M1 AND version:&lt;10.1.43)"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="apache tomcat 10.1.0-m1 &lt; 10.1.44 http/2 madeyoureset dos product:tomcat and (version:&gt;10.1.0-m1 and version:&lt;10.1.44) software vulnerability" data-ql-sev="high">
      <div class="ql-card-header">
        <div class="ql-title">Apache Tomcat 10.1.0-M1 &lt; 10.1.44 HTTP/2 MadeYouReset DoS</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><span class="ql-type-badge">software</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>product:Tomcat AND (version:&gt;10.1.0-M1 AND version:&lt;10.1.44)</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="product:Tomcat AND (version:&gt;10.1.0-M1 AND version:&lt;10.1.44)" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/software?search=product%3ATomcat+AND+%28version%3A%3E10.1.0-M1+AND+version%3A%3C10.1.44%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/software?search=product%3ATomcat+AND+%28version%3A%3E10.1.0-M1+AND+version%3A%3C10.1.44%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="product:Tomcat AND (version:&gt;10.1.0-M1 AND version:&lt;10.1.44)"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="apache tomcat 11.0.0-m1 &lt; 11.0.10 multiple vulnerabilities product:tomcat and (version:&gt;11.0.0-m1 and version:&lt;11.0.10) software vulnerability" data-ql-sev="high">
      <div class="ql-card-header">
        <div class="ql-title">Apache Tomcat 11.0.0-M1 &lt; 11.0.10 Multiple Vulnerabilities</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><span class="ql-type-badge">software</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>product:Tomcat AND (version:&gt;11.0.0-M1 AND version:&lt;11.0.10)</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="product:Tomcat AND (version:&gt;11.0.0-M1 AND version:&lt;11.0.10)" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/software?search=product%3ATomcat+AND+%28version%3A%3E11.0.0-M1+AND+version%3A%3C11.0.10%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/software?search=product%3ATomcat+AND+%28version%3A%3E11.0.0-M1+AND+version%3A%3C11.0.10%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="product:Tomcat AND (version:&gt;11.0.0-M1 AND version:&lt;11.0.10)"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="apache tomcat 11.0.0-m1 &lt; 11.0.9 multiple vulnerabilities product:tomcat and (version:&gt;11.0.0-m1 and version:&lt;11.0.9) software vulnerability" data-ql-sev="high">
      <div class="ql-card-header">
        <div class="ql-title">Apache Tomcat 11.0.0-M1 &lt; 11.0.9 Multiple Vulnerabilities</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><span class="ql-type-badge">software</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>product:Tomcat AND (version:&gt;11.0.0-M1 AND version:&lt;11.0.9)</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="product:Tomcat AND (version:&gt;11.0.0-M1 AND version:&lt;11.0.9)" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/software?search=product%3ATomcat+AND+%28version%3A%3E11.0.0-M1+AND+version%3A%3C11.0.9%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/software?search=product%3ATomcat+AND+%28version%3A%3E11.0.0-M1+AND+version%3A%3C11.0.9%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="product:Tomcat AND (version:&gt;11.0.0-M1 AND version:&lt;11.0.9)"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="apache tomcat 9.0.0-m1 &lt; 9.0.107 multiple vulnerabilities product:tomcat and (version:&gt;9.0.0-m1 and version:&lt;9.0.107) software vulnerability" data-ql-sev="high">
      <div class="ql-card-header">
        <div class="ql-title">Apache Tomcat 9.0.0-M1 &lt; 9.0.107 Multiple Vulnerabilities</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><span class="ql-type-badge">software</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>product:Tomcat AND (version:&gt;9.0.0-M1 AND version:&lt;9.0.107)</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="product:Tomcat AND (version:&gt;9.0.0-M1 AND version:&lt;9.0.107)" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/software?search=product%3ATomcat+AND+%28version%3A%3E9.0.0-M1+AND+version%3A%3C9.0.107%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/software?search=product%3ATomcat+AND+%28version%3A%3E9.0.0-M1+AND+version%3A%3C9.0.107%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="product:Tomcat AND (version:&gt;9.0.0-M1 AND version:&lt;9.0.107)"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="apache tomcat 9.0.0-m1 &lt; 9.0.108 http/2 madeyoureset dos product:tomcat and (version:&gt;9.0.0-m1 and version:&lt;9.0.108) software vulnerability" data-ql-sev="high">
      <div class="ql-card-header">
        <div class="ql-title">Apache Tomcat 9.0.0-M1 &lt; 9.0.108 HTTP/2 MadeYouReset DoS</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><span class="ql-type-badge">software</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>product:Tomcat AND (version:&gt;9.0.0-M1 AND version:&lt;9.0.108)</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="product:Tomcat AND (version:&gt;9.0.0-M1 AND version:&lt;9.0.108)" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/software?search=product%3ATomcat+AND+%28version%3A%3E9.0.0-M1+AND+version%3A%3C9.0.108%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/software?search=product%3ATomcat+AND+%28version%3A%3E9.0.0-M1+AND+version%3A%3C9.0.108%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="product:Tomcat AND (version:&gt;9.0.0-M1 AND version:&lt;9.0.108)"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="apache tomcat partial put deserialization vulnerability _asset.products:&#34;tomcat&#34; and product:&#34;tomcat&#34; and ((version:&gt;=11.0.0 and version:&lt;11.0.3) or (version:&gt;=10.1.0 and version:&lt;10.1.35) or (version:&gt;=9.0.0 and version:&lt;9.0.99)) software vulnerability" data-ql-sev="high">
      <div class="ql-card-header">
        <div class="ql-title">Apache Tomcat Partial PUT Deserialization Vulnerability</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><span class="ql-type-badge">software</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>_asset.products:&#34;Tomcat&#34; AND product:&#34;Tomcat&#34; AND ((version:&gt;=11.0.0 AND version:&lt;11.0.3) OR (version:&gt;=10.1.0 AND version:&lt;10.1.35) OR (version:&gt;=9.0.0 AND version:&lt;9.0.99))</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="_asset.products:&#34;Tomcat&#34; AND product:&#34;Tomcat&#34; AND ((version:&gt;=11.0.0 AND version:&lt;11.0.3) OR (version:&gt;=10.1.0 AND version:&lt;10.1.35) OR (version:&gt;=9.0.0 AND version:&lt;9.0.99))" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/software?search=_asset.products%3A%22Tomcat%22+AND+product%3A%22Tomcat%22+AND+%28%28version%3A%3E%3D11.0.0+AND+version%3A%3C11.0.3%29+OR+%28version%3A%3E%3D10.1.0+AND+version%3A%3C10.1.35%29+OR+%28version%3A%3E%3D9.0.0+AND+version%3A%3C9.0.99%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/software?search=_asset.products%3A%22Tomcat%22+AND+product%3A%22Tomcat%22+AND+%28%28version%3A%3E%3D11.0.0+AND+version%3A%3C11.0.3%29+OR+%28version%3A%3E%3D10.1.0+AND+version%3A%3C10.1.35%29+OR+%28version%3A%3E%3D9.0.0+AND+version%3A%3C9.0.99%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="_asset.products:&#34;Tomcat&#34; AND product:&#34;Tomcat&#34; AND ((version:&gt;=11.0.0 AND version:&lt;11.0.3) OR (version:&gt;=10.1.0 AND version:&lt;10.1.35) OR (version:&gt;=9.0.0 AND version:&lt;9.0.99))"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="apple device ecosystem multiple vulnerabilities (coruna) (os:=&#34;apple ios&#34; or os:=&#34;apple ipados&#34; ) and ((osversion:&gt;=&#34;17.0&#34; and osversion:&lt;&#34;17.5&#34;) or (osversion:&gt;=&#34;16.0&#34; and osversion:&lt;&#34;16.7.8&#34;) or (osversion:&gt;=&#34;15.0&#34; and osversion:&lt;&#34;15.7.8&#34;) or (osversion:&gt;=&#34;13.0&#34; and osversion:&lt;&#34;14.7&#34;)) assets vulnerability" data-ql-sev="high">
      <div class="ql-card-header">
        <div class="ql-title">Apple Device Ecosystem Multiple Vulnerabilities (Coruna)</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><span class="ql-type-badge">assets</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>(os:=&#34;apple ios&#34; OR os:=&#34;apple ipados&#34; ) AND ((osversion:&gt;=&#34;17.0&#34; AND osversion:&lt;&#34;17.5&#34;) OR (osversion:&gt;=&#34;16.0&#34; AND osversion:&lt;&#34;16.7.8&#34;) OR (osversion:&gt;=&#34;15.0&#34; AND osversion:&lt;&#34;15.7.8&#34;) OR (osversion:&gt;=&#34;13.0&#34; AND osversion:&lt;&#34;14.7&#34;))</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="(os:=&#34;apple ios&#34; OR os:=&#34;apple ipados&#34; ) AND ((osversion:&gt;=&#34;17.0&#34; AND osversion:&lt;&#34;17.5&#34;) OR (osversion:&gt;=&#34;16.0&#34; AND osversion:&lt;&#34;16.7.8&#34;) OR (osversion:&gt;=&#34;15.0&#34; AND osversion:&lt;&#34;15.7.8&#34;) OR (osversion:&gt;=&#34;13.0&#34; AND osversion:&lt;&#34;14.7&#34;))" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/?search=%28os%3A%3D%22apple+ios%22+OR+os%3A%3D%22apple+ipados%22+%29+AND+%28%28osversion%3A%3E%3D%2217.0%22+AND+osversion%3A%3C%2217.5%22%29+OR+%28osversion%3A%3E%3D%2216.0%22+AND+osversion%3A%3C%2216.7.8%22%29+OR+%28osversion%3A%3E%3D%2215.0%22+AND+osversion%3A%3C%2215.7.8%22%29+OR+%28osversion%3A%3E%3D%2213.0%22+AND+osversion%3A%3C%2214.7%22%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/?search=%28os%3A%3D%22apple+ios%22+OR+os%3A%3D%22apple+ipados%22+%29+AND+%28%28osversion%3A%3E%3D%2217.0%22+AND+osversion%3A%3C%2217.5%22%29+OR+%28osversion%3A%3E%3D%2216.0%22+AND+osversion%3A%3C%2216.7.8%22%29+OR+%28osversion%3A%3E%3D%2215.0%22+AND+osversion%3A%3C%2215.7.8%22%29+OR+%28osversion%3A%3E%3D%2213.0%22+AND+osversion%3A%3C%2214.7%22%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="(os:=&#34;apple ios&#34; OR os:=&#34;apple ipados&#34; ) AND ((osversion:&gt;=&#34;17.0&#34; AND osversion:&lt;&#34;17.5&#34;) OR (osversion:&gt;=&#34;16.0&#34; AND osversion:&lt;&#34;16.7.8&#34;) OR (osversion:&gt;=&#34;15.0&#34; AND osversion:&lt;&#34;15.7.8&#34;) OR (osversion:&gt;=&#34;13.0&#34; AND osversion:&lt;&#34;14.7&#34;))"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="apple device ecosystem multiple vulnerabilities (darksword) (os:=&#34;apple ios&#34; or os:=&#34;apple ipados&#34; or os:=&#34;apple tvos&#34; or os:=&#34;apple macos&#34; or os:=&#34;apple watchos&#34; or os:=&#34;apple visionos&#34;) and osversion:&gt;0 and ( (osversion:&gt;=&#34;26.0&#34; and osversion:&lt;&#34;26.3&#34;) or (osversion:&gt;=&#34;18.0&#34; and osversion:&lt;&#34;18.7.3&#34;) ) assets vulnerability" data-ql-sev="high">
      <div class="ql-card-header">
        <div class="ql-title">Apple Device Ecosystem Multiple Vulnerabilities (DarkSword)</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><span class="ql-type-badge">assets</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>(os:=&#34;apple ios&#34; OR os:=&#34;apple ipados&#34; OR os:=&#34;apple tvos&#34; OR os:=&#34;apple macos&#34; OR os:=&#34;apple watchos&#34; OR os:=&#34;apple visionos&#34;) AND osversion:&gt;0 AND ( (osversion:&gt;=&#34;26.0&#34; AND osversion:&lt;&#34;26.3&#34;) OR (osversion:&gt;=&#34;18.0&#34; AND osversion:&lt;&#34;18.7.3&#34;) )</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="(os:=&#34;apple ios&#34; OR os:=&#34;apple ipados&#34; OR os:=&#34;apple tvos&#34; OR os:=&#34;apple macos&#34; OR os:=&#34;apple watchos&#34; OR os:=&#34;apple visionos&#34;) AND osversion:&gt;0 AND ( (osversion:&gt;=&#34;26.0&#34; AND osversion:&lt;&#34;26.3&#34;) OR (osversion:&gt;=&#34;18.0&#34; AND osversion:&lt;&#34;18.7.3&#34;) )" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/?search=%28os%3A%3D%22apple+ios%22+OR+os%3A%3D%22apple+ipados%22+OR+os%3A%3D%22apple+tvos%22+OR+os%3A%3D%22apple+macos%22+OR+os%3A%3D%22apple+watchos%22+OR+os%3A%3D%22apple+visionos%22%29+AND+osversion%3A%3E0+AND+%28+%28osversion%3A%3E%3D%2226.0%22+AND+osversion%3A%3C%2226.3%22%29+OR+%28osversion%3A%3E%3D%2218.0%22+AND+osversion%3A%3C%2218.7.3%22%29+%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/?search=%28os%3A%3D%22apple+ios%22+OR+os%3A%3D%22apple+ipados%22+OR+os%3A%3D%22apple+tvos%22+OR+os%3A%3D%22apple+macos%22+OR+os%3A%3D%22apple+watchos%22+OR+os%3A%3D%22apple+visionos%22%29+AND+osversion%3A%3E0+AND+%28+%28osversion%3A%3E%3D%2226.0%22+AND+osversion%3A%3C%2226.3%22%29+OR+%28osversion%3A%3E%3D%2218.0%22+AND+osversion%3A%3C%2218.7.3%22%29+%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="(os:=&#34;apple ios&#34; OR os:=&#34;apple ipados&#34; OR os:=&#34;apple tvos&#34; OR os:=&#34;apple macos&#34; OR os:=&#34;apple watchos&#34; OR os:=&#34;apple visionos&#34;) AND osversion:&gt;0 AND ( (osversion:&gt;=&#34;26.0&#34; AND osversion:&lt;&#34;26.3&#34;) OR (osversion:&gt;=&#34;18.0&#34; AND osversion:&lt;&#34;18.7.3&#34;) )"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="apple tvos &lt; 11.4 multiple vulnerabilities os:&#34;apple tvos&#34; and osversion:&gt;0 and osversion:&lt;11.4 assets vulnerability" data-ql-sev="high">
      <div class="ql-card-header">
        <div class="ql-title">Apple tvOS &lt; 11.4 Multiple Vulnerabilities</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><span class="ql-type-badge">assets</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>os:&#34;Apple tvOS&#34; AND osversion:&gt;0 AND osversion:&lt;11.4</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="os:&#34;Apple tvOS&#34; AND osversion:&gt;0 AND osversion:&lt;11.4" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/?search=os%3A%22Apple+tvOS%22+AND+osversion%3A%3E0+AND+osversion%3A%3C11.4" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/?search=os%3A%22Apple+tvOS%22+AND+osversion%3A%3E0+AND+osversion%3A%3C11.4" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="os:&#34;Apple tvOS&#34; AND osversion:&gt;0 AND osversion:&lt;11.4"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="apple tvos &lt; 13.3.1 multiple vulnerabilities os:&#34;apple tvos&#34; and osversion:&gt;0 and osversion:&lt;13.3.1 assets vulnerability" data-ql-sev="high">
      <div class="ql-card-header">
        <div class="ql-title">Apple tvOS &lt; 13.3.1 Multiple Vulnerabilities</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><span class="ql-type-badge">assets</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>os:&#34;Apple tvOS&#34; AND osversion:&gt;0 AND osversion:&lt;13.3.1</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="os:&#34;Apple tvOS&#34; AND osversion:&gt;0 AND osversion:&lt;13.3.1" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/?search=os%3A%22Apple+tvOS%22+AND+osversion%3A%3E0+AND+osversion%3A%3C13.3.1" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/?search=os%3A%22Apple+tvOS%22+AND+osversion%3A%3E0+AND+osversion%3A%3C13.3.1" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="os:&#34;Apple tvOS&#34; AND osversion:&gt;0 AND osversion:&lt;13.3.1"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="apple tvos &lt; 15.2 multiple vulnerabilities os:&#34;apple tvos&#34; and osversion:&gt;0 and osversion:&lt;15.2 assets vulnerability" data-ql-sev="high">
      <div class="ql-card-header">
        <div class="ql-title">Apple tvOS &lt; 15.2 Multiple Vulnerabilities</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><span class="ql-type-badge">assets</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>os:&#34;Apple tvOS&#34; AND osversion:&gt;0 AND osversion:&lt;15.2</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="os:&#34;Apple tvOS&#34; AND osversion:&gt;0 AND osversion:&lt;15.2" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/?search=os%3A%22Apple+tvOS%22+AND+osversion%3A%3E0+AND+osversion%3A%3C15.2" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/?search=os%3A%22Apple+tvOS%22+AND+osversion%3A%3E0+AND+osversion%3A%3C15.2" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="os:&#34;Apple tvOS&#34; AND osversion:&gt;0 AND osversion:&lt;15.2"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="arcserve unified data protection &lt; 10.2 heap overflow vulnerabilities vendor:=arcserve and product:=udp and version:&gt;0 and version:&lt;10.2 software vulnerability" data-ql-sev="high">
      <div class="ql-card-header">
        <div class="ql-title">Arcserve Unified Data Protection &lt; 10.2 Heap Overflow Vulnerabilities</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><span class="ql-type-badge">software</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>vendor:=Arcserve AND product:=UDP AND version:&gt;0 AND version:&lt;10.2</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="vendor:=Arcserve AND product:=UDP AND version:&gt;0 AND version:&lt;10.2" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/software?search=vendor%3A%3DArcserve+AND+product%3A%3DUDP+AND+version%3A%3E0+AND+version%3A%3C10.2" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/software?search=vendor%3A%3DArcserve+AND+product%3A%3DUDP+AND+version%3A%3E0+AND+version%3A%3C10.2" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="vendor:=Arcserve AND product:=UDP AND version:&gt;0 AND version:&lt;10.2"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="atlassian confluence 5.2 &lt; 7.19.22 remote code execution vendor:=atlassian and product:confluence and (version:&gt;=5.2 and version:&lt;7.19.22) software vulnerability" data-ql-sev="high">
      <div class="ql-card-header">
        <div class="ql-title">Atlassian Confluence 5.2 &lt; 7.19.22 Remote Code Execution</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><span class="ql-type-badge">software</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>vendor:=Atlassian AND product:Confluence AND (version:&gt;=5.2 AND version:&lt;7.19.22)</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="vendor:=Atlassian AND product:Confluence AND (version:&gt;=5.2 AND version:&lt;7.19.22)" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/software?search=vendor%3A%3DAtlassian+AND+product%3AConfluence+AND+%28version%3A%3E%3D5.2+AND+version%3A%3C7.19.22%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/software?search=vendor%3A%3DAtlassian+AND+product%3AConfluence+AND+%28version%3A%3E%3D5.2+AND+version%3A%3C7.19.22%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="vendor:=Atlassian AND product:Confluence AND (version:&gt;=5.2 AND version:&lt;7.19.22)"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="cisco confd ssh server remote code execution vendor:=&#34;cisco&#34; and product:=&#34;confd&#34; and ( (version:&gt;&#34;7.0.0.0&#34; and version:&lt;&#34;7.7.19.1&#34;) or (version:&gt;&#34;8.0.0.0&#34; and version:&lt;&#34;8.0.17.1&#34;) or (version:&gt;&#34;8.1.0.0&#34; and version:&lt;&#34;8.1.16.2&#34;) or (version:&gt;&#34;8.2.0.0&#34; and version:&lt;&#34;8.2.11.1&#34;) or (version:&gt;&#34;8.3.0.0&#34; and version:&lt;&#34;8.3.8.1&#34;) or (version:&gt;&#34;8.4.0.0&#34; and version:&lt;&#34;8.4.4.1&#34;)) software vulnerability" data-ql-sev="high">
      <div class="ql-card-header">
        <div class="ql-title">Cisco ConfD SSH Server Remote Code Execution</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><span class="ql-type-badge">software</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>vendor:=&#34;Cisco&#34; AND product:=&#34;ConfD&#34; AND ( (version:&gt;&#34;7.0.0.0&#34; AND version:&lt;&#34;7.7.19.1&#34;) OR (version:&gt;&#34;8.0.0.0&#34; AND version:&lt;&#34;8.0.17.1&#34;) OR (version:&gt;&#34;8.1.0.0&#34; AND version:&lt;&#34;8.1.16.2&#34;) OR (version:&gt;&#34;8.2.0.0&#34; AND version:&lt;&#34;8.2.11.1&#34;) OR (version:&gt;&#34;8.3.0.0&#34; AND version:&lt;&#34;8.3.8.1&#34;) OR (version:&gt;&#34;8.4.0.0&#34; AND version:&lt;&#34;8.4.4.1&#34;))</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="vendor:=&#34;Cisco&#34; AND product:=&#34;ConfD&#34; AND ( (version:&gt;&#34;7.0.0.0&#34; AND version:&lt;&#34;7.7.19.1&#34;) OR (version:&gt;&#34;8.0.0.0&#34; AND version:&lt;&#34;8.0.17.1&#34;) OR (version:&gt;&#34;8.1.0.0&#34; AND version:&lt;&#34;8.1.16.2&#34;) OR (version:&gt;&#34;8.2.0.0&#34; AND version:&lt;&#34;8.2.11.1&#34;) OR (version:&gt;&#34;8.3.0.0&#34; AND version:&lt;&#34;8.3.8.1&#34;) OR (version:&gt;&#34;8.4.0.0&#34; AND version:&lt;&#34;8.4.4.1&#34;))" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/software?search=vendor%3A%3D%22Cisco%22+AND+product%3A%3D%22ConfD%22+AND+%28+%28version%3A%3E%227.0.0.0%22+AND+version%3A%3C%227.7.19.1%22%29+OR+%28version%3A%3E%228.0.0.0%22+AND+version%3A%3C%228.0.17.1%22%29+OR+%28version%3A%3E%228.1.0.0%22+AND+version%3A%3C%228.1.16.2%22%29+OR+%28version%3A%3E%228.2.0.0%22+AND+version%3A%3C%228.2.11.1%22%29+OR+%28version%3A%3E%228.3.0.0%22+AND+version%3A%3C%228.3.8.1%22%29+OR+%28version%3A%3E%228.4.0.0%22+AND+version%3A%3C%228.4.4.1%22%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/software?search=vendor%3A%3D%22Cisco%22+AND+product%3A%3D%22ConfD%22+AND+%28+%28version%3A%3E%227.0.0.0%22+AND+version%3A%3C%227.7.19.1%22%29+OR+%28version%3A%3E%228.0.0.0%22+AND+version%3A%3C%228.0.17.1%22%29+OR+%28version%3A%3E%228.1.0.0%22+AND+version%3A%3C%228.1.16.2%22%29+OR+%28version%3A%3E%228.2.0.0%22+AND+version%3A%3C%228.2.11.1%22%29+OR+%28version%3A%3E%228.3.0.0%22+AND+version%3A%3C%228.3.8.1%22%29+OR+%28version%3A%3E%228.4.0.0%22+AND+version%3A%3C%228.4.4.1%22%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="vendor:=&#34;Cisco&#34; AND product:=&#34;ConfD&#34; AND ( (version:&gt;&#34;7.0.0.0&#34; AND version:&lt;&#34;7.7.19.1&#34;) OR (version:&gt;&#34;8.0.0.0&#34; AND version:&lt;&#34;8.0.17.1&#34;) OR (version:&gt;&#34;8.1.0.0&#34; AND version:&lt;&#34;8.1.16.2&#34;) OR (version:&gt;&#34;8.2.0.0&#34; AND version:&lt;&#34;8.2.11.1&#34;) OR (version:&gt;&#34;8.3.0.0&#34; AND version:&lt;&#34;8.3.8.1&#34;) OR (version:&gt;&#34;8.4.0.0&#34; AND version:&lt;&#34;8.4.4.1&#34;))"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="cisco ios xe arbitrary file upload os:=&#34;cisco ios xe&#34; and hw:&#34;catalyst&#34; and ( (osversion:&gt;=&#34;17.7.0&#34; and osversion:&lt;=&#34;17.7.1&#34;) or (osversion:&gt;=&#34;17.10.0&#34; and osversion:&lt;=&#34;17.10.1&#34;) or (osversion:&gt;=&#34;17.8.0&#34; and osversion:&lt;=&#34;17.8.1&#34;) or (osversion:&gt;=&#34;17.9.0&#34; and osversion:&lt;=&#34;17.9.5&#34;) or (osversion:&gt;=&#34;17.11.0&#34; and osversion:&lt;=&#34;17.11.1&#34;) or (osversion:&gt;=&#34;17.12.0&#34; and osversion:&lt;=&#34;17.2.3&#34;) or (osversion:&gt;=&#34;17.13.0&#34; and osversion:&lt;=&#34;17.13.1&#34;) or (osversion:&gt;=&#34;17.14.0&#34; and osversion:&lt;=&#34;17.14.1&#34;) or (osversion:&gt;=&#34;17.11.0&#34; and osversion:&lt;=&#34;17.11.99&#34;) ) assets vulnerability" data-ql-sev="high">
      <div class="ql-card-header">
        <div class="ql-title">Cisco IOS XE Arbitrary File Upload</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><span class="ql-type-badge">assets</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>os:=&#34;Cisco IOS XE&#34; AND hw:&#34;Catalyst&#34; AND ( (osversion:&gt;=&#34;17.7.0&#34; AND osversion:&lt;=&#34;17.7.1&#34;) OR (osversion:&gt;=&#34;17.10.0&#34; AND osversion:&lt;=&#34;17.10.1&#34;) OR (osversion:&gt;=&#34;17.8.0&#34; AND osversion:&lt;=&#34;17.8.1&#34;) OR (osversion:&gt;=&#34;17.9.0&#34; AND osversion:&lt;=&#34;17.9.5&#34;) OR (osversion:&gt;=&#34;17.11.0&#34; AND osversion:&lt;=&#34;17.11.1&#34;) OR (osversion:&gt;=&#34;17.12.0&#34; AND osversion:&lt;=&#34;17.2.3&#34;) OR (osversion:&gt;=&#34;17.13.0&#34; AND osversion:&lt;=&#34;17.13.1&#34;) OR (osversion:&gt;=&#34;17.14.0&#34; AND osversion:&lt;=&#34;17.14.1&#34;) OR (osversion:&gt;=&#34;17.11.0&#34; AND osversion:&lt;=&#34;17.11.99&#34;) )</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="os:=&#34;Cisco IOS XE&#34; AND hw:&#34;Catalyst&#34; AND ( (osversion:&gt;=&#34;17.7.0&#34; AND osversion:&lt;=&#34;17.7.1&#34;) OR (osversion:&gt;=&#34;17.10.0&#34; AND osversion:&lt;=&#34;17.10.1&#34;) OR (osversion:&gt;=&#34;17.8.0&#34; AND osversion:&lt;=&#34;17.8.1&#34;) OR (osversion:&gt;=&#34;17.9.0&#34; AND osversion:&lt;=&#34;17.9.5&#34;) OR (osversion:&gt;=&#34;17.11.0&#34; AND osversion:&lt;=&#34;17.11.1&#34;) OR (osversion:&gt;=&#34;17.12.0&#34; AND osversion:&lt;=&#34;17.2.3&#34;) OR (osversion:&gt;=&#34;17.13.0&#34; AND osversion:&lt;=&#34;17.13.1&#34;) OR (osversion:&gt;=&#34;17.14.0&#34; AND osversion:&lt;=&#34;17.14.1&#34;) OR (osversion:&gt;=&#34;17.11.0&#34; AND osversion:&lt;=&#34;17.11.99&#34;) )" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/?search=os%3A%3D%22Cisco+IOS+XE%22+AND+hw%3A%22Catalyst%22+AND+%28+%28osversion%3A%3E%3D%2217.7.0%22+AND+osversion%3A%3C%3D%2217.7.1%22%29+OR+%28osversion%3A%3E%3D%2217.10.0%22+AND+osversion%3A%3C%3D%2217.10.1%22%29+OR+%28osversion%3A%3E%3D%2217.8.0%22+AND+osversion%3A%3C%3D%2217.8.1%22%29+OR+%28osversion%3A%3E%3D%2217.9.0%22+AND+osversion%3A%3C%3D%2217.9.5%22%29+OR+%28osversion%3A%3E%3D%2217.11.0%22+AND+osversion%3A%3C%3D%2217.11.1%22%29+OR+%28osversion%3A%3E%3D%2217.12.0%22+AND+osversion%3A%3C%3D%2217.2.3%22%29+OR+%28osversion%3A%3E%3D%2217.13.0%22+AND+osversion%3A%3C%3D%2217.13.1%22%29+OR+%28osversion%3A%3E%3D%2217.14.0%22+AND+osversion%3A%3C%3D%2217.14.1%22%29+OR+%28osversion%3A%3E%3D%2217.11.0%22+AND+osversion%3A%3C%3D%2217.11.99%22%29+%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/?search=os%3A%3D%22Cisco+IOS+XE%22+AND+hw%3A%22Catalyst%22+AND+%28+%28osversion%3A%3E%3D%2217.7.0%22+AND+osversion%3A%3C%3D%2217.7.1%22%29+OR+%28osversion%3A%3E%3D%2217.10.0%22+AND+osversion%3A%3C%3D%2217.10.1%22%29+OR+%28osversion%3A%3E%3D%2217.8.0%22+AND+osversion%3A%3C%3D%2217.8.1%22%29+OR+%28osversion%3A%3E%3D%2217.9.0%22+AND+osversion%3A%3C%3D%2217.9.5%22%29+OR+%28osversion%3A%3E%3D%2217.11.0%22+AND+osversion%3A%3C%3D%2217.11.1%22%29+OR+%28osversion%3A%3E%3D%2217.12.0%22+AND+osversion%3A%3C%3D%2217.2.3%22%29+OR+%28osversion%3A%3E%3D%2217.13.0%22+AND+osversion%3A%3C%3D%2217.13.1%22%29+OR+%28osversion%3A%3E%3D%2217.14.0%22+AND+osversion%3A%3C%3D%2217.14.1%22%29+OR+%28osversion%3A%3E%3D%2217.11.0%22+AND+osversion%3A%3C%3D%2217.11.99%22%29+%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="os:=&#34;Cisco IOS XE&#34; AND hw:&#34;Catalyst&#34; AND ( (osversion:&gt;=&#34;17.7.0&#34; AND osversion:&lt;=&#34;17.7.1&#34;) OR (osversion:&gt;=&#34;17.10.0&#34; AND osversion:&lt;=&#34;17.10.1&#34;) OR (osversion:&gt;=&#34;17.8.0&#34; AND osversion:&lt;=&#34;17.8.1&#34;) OR (osversion:&gt;=&#34;17.9.0&#34; AND osversion:&lt;=&#34;17.9.5&#34;) OR (osversion:&gt;=&#34;17.11.0&#34; AND osversion:&lt;=&#34;17.11.1&#34;) OR (osversion:&gt;=&#34;17.12.0&#34; AND osversion:&lt;=&#34;17.2.3&#34;) OR (osversion:&gt;=&#34;17.13.0&#34; AND osversion:&lt;=&#34;17.13.1&#34;) OR (osversion:&gt;=&#34;17.14.0&#34; AND osversion:&lt;=&#34;17.14.1&#34;) OR (osversion:&gt;=&#34;17.11.0&#34; AND osversion:&lt;=&#34;17.11.99&#34;) )"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="commvault command center remote code execution vendor:=&#34;commvault&#34; and product:=&#34;command center&#34; and version:&gt;&#34;11.38.0&#34; and version:&lt;&#34;11.38.20&#34; software vulnerability" data-ql-sev="high">
      <div class="ql-card-header">
        <div class="ql-title">Commvault Command Center Remote Code Execution</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><span class="ql-type-badge">software</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>vendor:=&#34;Commvault&#34; AND product:=&#34;Command Center&#34; AND version:&gt;&#34;11.38.0&#34; AND version:&lt;&#34;11.38.20&#34;</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="vendor:=&#34;Commvault&#34; AND product:=&#34;Command Center&#34; AND version:&gt;&#34;11.38.0&#34; AND version:&lt;&#34;11.38.20&#34;" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/software?search=vendor%3A%3D%22Commvault%22+AND+product%3A%3D%22Command+Center%22+AND+version%3A%3E%2211.38.0%22+AND+version%3A%3C%2211.38.20%22" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/software?search=vendor%3A%3D%22Commvault%22+AND+product%3A%3D%22Command+Center%22+AND+version%3A%3E%2211.38.0%22+AND+version%3A%3C%2211.38.20%22" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="vendor:=&#34;Commvault&#34; AND product:=&#34;Command Center&#34; AND version:&gt;&#34;11.38.0&#34; AND version:&lt;&#34;11.38.20&#34;"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="connectwise screenconnect &lt; 25.2.4 viewstate code injection vendor:=connectwise and product:=screenconnect and (version:&gt;0 and version:&lt;25.2.4) software vulnerability" data-ql-sev="high">
      <div class="ql-card-header">
        <div class="ql-title">ConnectWise ScreenConnect &lt; 25.2.4 ViewState Code Injection</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><span class="ql-type-badge">software</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>vendor:=ConnectWise AND product:=ScreenConnect AND (version:&gt;0 AND version:&lt;25.2.4)</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="vendor:=ConnectWise AND product:=ScreenConnect AND (version:&gt;0 AND version:&lt;25.2.4)" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/software?search=vendor%3A%3DConnectWise+AND+product%3A%3DScreenConnect+AND+%28version%3A%3E0+AND+version%3A%3C25.2.4%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/software?search=vendor%3A%3DConnectWise+AND+product%3A%3DScreenConnect+AND+%28version%3A%3E0+AND+version%3A%3C25.2.4%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="vendor:=ConnectWise AND product:=ScreenConnect AND (version:&gt;0 AND version:&lt;25.2.4)"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="crowdstrike falcon logscale unauthenticated path traversal (cve-2026-40050) vendor:=&#34;crowdstrike&#34; and product:=&#34;logscale&#34; and version:&gt;0 and ((version:&gt;=1.224.0 and version:&lt;=1.234.0) and not ((version:&gt;=1.228.2 and version:&lt;1.229.0) or (version:&gt;=1.233.1 and version:&lt;1.234.0))) software vulnerability" data-ql-sev="high">
      <div class="ql-card-header">
        <div class="ql-title">CrowdStrike Falcon LogScale Unauthenticated Path Traversal (CVE-2026-40050)</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><span class="ql-type-badge">software</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>vendor:=&#34;CrowdStrike&#34; AND product:=&#34;LogScale&#34; AND version:&gt;0 AND ((version:&gt;=1.224.0 AND version:&lt;=1.234.0) AND NOT ((version:&gt;=1.228.2 AND version:&lt;1.229.0) OR (version:&gt;=1.233.1 AND version:&lt;1.234.0)))</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="vendor:=&#34;CrowdStrike&#34; AND product:=&#34;LogScale&#34; AND version:&gt;0 AND ((version:&gt;=1.224.0 AND version:&lt;=1.234.0) AND NOT ((version:&gt;=1.228.2 AND version:&lt;1.229.0) OR (version:&gt;=1.233.1 AND version:&lt;1.234.0)))" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/software?search=vendor%3A%3D%22CrowdStrike%22+AND+product%3A%3D%22LogScale%22+AND+version%3A%3E0+AND+%28%28version%3A%3E%3D1.224.0+AND+version%3A%3C%3D1.234.0%29+AND+NOT+%28%28version%3A%3E%3D1.228.2+AND+version%3A%3C1.229.0%29+OR+%28version%3A%3E%3D1.233.1+AND+version%3A%3C1.234.0%29%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/software?search=vendor%3A%3D%22CrowdStrike%22+AND+product%3A%3D%22LogScale%22+AND+version%3A%3E0+AND+%28%28version%3A%3E%3D1.224.0+AND+version%3A%3C%3D1.234.0%29+AND+NOT+%28%28version%3A%3E%3D1.228.2+AND+version%3A%3C1.229.0%29+OR+%28version%3A%3E%3D1.233.1+AND+version%3A%3C1.234.0%29%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="vendor:=&#34;CrowdStrike&#34; AND product:=&#34;LogScale&#34; AND version:&gt;0 AND ((version:&gt;=1.224.0 AND version:&lt;=1.234.0) AND NOT ((version:&gt;=1.228.2 AND version:&lt;1.229.0) OR (version:&gt;=1.233.1 AND version:&lt;1.234.0)))"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="dell emc unity, unityvsa, and unity xt os:&#34;emc unity&#34; and osversion:&gt;0 and osversion:&lt;5.5.0.0.0.5.259 assets vulnerability" data-ql-sev="high">
      <div class="ql-card-header">
        <div class="ql-title">Dell EMC Unity, UnityVSA, And Unity XT</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><span class="ql-type-badge">assets</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>os:&#34;EMC Unity&#34; AND osversion:&gt;0 AND osversion:&lt;5.5.0.0.0.5.259</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="os:&#34;EMC Unity&#34; AND osversion:&gt;0 AND osversion:&lt;5.5.0.0.0.5.259" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/?search=os%3A%22EMC+Unity%22+AND+osversion%3A%3E0+AND+osversion%3A%3C5.5.0.0.0.5.259" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/?search=os%3A%22EMC+Unity%22+AND+osversion%3A%3E0+AND+osversion%3A%3C5.5.0.0.0.5.259" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="os:&#34;EMC Unity&#34; AND osversion:&gt;0 AND osversion:&lt;5.5.0.0.0.5.259"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="draytek vigor2960/vigor300b command injection (hw:&#34;draytek vigor2960&#34; or hw:&#34;draytek vigor300b&#34; or hw:&#34;draytek vigor 2960&#34; or hw:&#34;draytek vigor 300b&#34;) and osversion:&gt;0 and osversion:&lt;&#34;1.5.1.5&#34; assets vulnerability" data-ql-sev="high">
      <div class="ql-card-header">
        <div class="ql-title">DrayTek Vigor2960/Vigor300B Command Injection</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><span class="ql-type-badge">assets</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>(hw:&#34;DrayTek Vigor2960&#34; OR hw:&#34;DrayTek Vigor300b&#34; OR hw:&#34;DrayTek Vigor 2960&#34; OR hw:&#34;DrayTek Vigor 300b&#34;) AND osversion:&gt;0 AND osversion:&lt;&#34;1.5.1.5&#34;</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="(hw:&#34;DrayTek Vigor2960&#34; OR hw:&#34;DrayTek Vigor300b&#34; OR hw:&#34;DrayTek Vigor 2960&#34; OR hw:&#34;DrayTek Vigor 300b&#34;) AND osversion:&gt;0 AND osversion:&lt;&#34;1.5.1.5&#34;" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/?search=%28hw%3A%22DrayTek+Vigor2960%22+OR+hw%3A%22DrayTek+Vigor300b%22+OR+hw%3A%22DrayTek+Vigor+2960%22+OR+hw%3A%22DrayTek+Vigor+300b%22%29+AND+osversion%3A%3E0+AND+osversion%3A%3C%221.5.1.5%22" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/?search=%28hw%3A%22DrayTek+Vigor2960%22+OR+hw%3A%22DrayTek+Vigor300b%22+OR+hw%3A%22DrayTek+Vigor+2960%22+OR+hw%3A%22DrayTek+Vigor+300b%22%29+AND+osversion%3A%3E0+AND+osversion%3A%3C%221.5.1.5%22" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="(hw:&#34;DrayTek Vigor2960&#34; OR hw:&#34;DrayTek Vigor300b&#34; OR hw:&#34;DrayTek Vigor 2960&#34; OR hw:&#34;DrayTek Vigor 300b&#34;) AND osversion:&gt;0 AND osversion:&lt;&#34;1.5.1.5&#34;"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="eclipse jetty 12.0 &lt; 12.0.25 http/2 madeyoureset dos (vendor:=eclipse or vendor:=&#34;mort bay&#34;) and product:jetty and (version:&gt;12 and version:&lt;12.0.25) software vulnerability" data-ql-sev="high">
      <div class="ql-card-header">
        <div class="ql-title">Eclipse Jetty 12.0 &lt; 12.0.25 HTTP/2 MadeYouReset DoS</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><span class="ql-type-badge">software</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>(vendor:=Eclipse OR vendor:=&#34;Mort Bay&#34;) AND product:Jetty AND (version:&gt;12 AND version:&lt;12.0.25)</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="(vendor:=Eclipse OR vendor:=&#34;Mort Bay&#34;) AND product:Jetty AND (version:&gt;12 AND version:&lt;12.0.25)" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/software?search=%28vendor%3A%3DEclipse+OR+vendor%3A%3D%22Mort+Bay%22%29+AND+product%3AJetty+AND+%28version%3A%3E12+AND+version%3A%3C12.0.25%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/software?search=%28vendor%3A%3DEclipse+OR+vendor%3A%3D%22Mort+Bay%22%29+AND+product%3AJetty+AND+%28version%3A%3E12+AND+version%3A%3C12.0.25%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="(vendor:=Eclipse OR vendor:=&#34;Mort Bay&#34;) AND product:Jetty AND (version:&gt;12 AND version:&lt;12.0.25)"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="erlang otp ssh server remote code execution _asset.protocols:ssh and vendor:=&#34;erlang&#34; and product:=&#34;ssh&#34; and ((version:&gt;=5.2.0 and version:&lt;5.2.10) or (version:&gt;4.0.0.0 and version:&lt;4.15.3.12) or (version:&gt;5.1.0.0 and version:&lt;5.1.4.7)) software vulnerability" data-ql-sev="high">
      <div class="ql-card-header">
        <div class="ql-title">Erlang OTP SSH Server Remote Code Execution</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><span class="ql-type-badge">software</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>_asset.protocols:ssh AND vendor:=&#34;Erlang&#34; AND product:=&#34;SSH&#34; AND ((version:&gt;=5.2.0 AND version:&lt;5.2.10) OR (version:&gt;4.0.0.0 AND version:&lt;4.15.3.12) OR (version:&gt;5.1.0.0 AND version:&lt;5.1.4.7))</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="_asset.protocols:ssh AND vendor:=&#34;Erlang&#34; AND product:=&#34;SSH&#34; AND ((version:&gt;=5.2.0 AND version:&lt;5.2.10) OR (version:&gt;4.0.0.0 AND version:&lt;4.15.3.12) OR (version:&gt;5.1.0.0 AND version:&lt;5.1.4.7))" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/software?search=_asset.protocols%3Assh+AND+vendor%3A%3D%22Erlang%22+AND+product%3A%3D%22SSH%22+AND+%28%28version%3A%3E%3D5.2.0+AND+version%3A%3C5.2.10%29+OR+%28version%3A%3E4.0.0.0+AND+version%3A%3C4.15.3.12%29+OR+%28version%3A%3E5.1.0.0+AND+version%3A%3C5.1.4.7%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/software?search=_asset.protocols%3Assh+AND+vendor%3A%3D%22Erlang%22+AND+product%3A%3D%22SSH%22+AND+%28%28version%3A%3E%3D5.2.0+AND+version%3A%3C5.2.10%29+OR+%28version%3A%3E4.0.0.0+AND+version%3A%3C4.15.3.12%29+OR+%28version%3A%3E5.1.0.0+AND+version%3A%3C5.1.4.7%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="_asset.protocols:ssh AND vendor:=&#34;Erlang&#34; AND product:=&#34;SSH&#34; AND ((version:&gt;=5.2.0 AND version:&lt;5.2.10) OR (version:&gt;4.0.0.0 AND version:&lt;4.15.3.12) OR (version:&gt;5.1.0.0 AND version:&lt;5.1.4.7))"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="fortinet fortivoice sql injection (cve-2025-58692) hw:=&#34;fortinet%&#34; and type:=&#34;sip gateway&#34; and ((osversion:&gt;&#34;7.2.0&#34; and osversion:&lt;&#34;7.2.3&#34;) or (osversion:&gt;&#34;7.0.0&#34; and osversion:&lt;&#34;7.0.8&#34;)) assets vulnerability" data-ql-sev="high">
      <div class="ql-card-header">
        <div class="ql-title">Fortinet FortiVoice SQL Injection (CVE-2025-58692)</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><span class="ql-type-badge">assets</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>hw:=&#34;Fortinet%&#34; AND type:=&#34;SIP Gateway&#34; AND ((osversion:&gt;&#34;7.2.0&#34; AND osversion:&lt;&#34;7.2.3&#34;) OR (osversion:&gt;&#34;7.0.0&#34; AND osversion:&lt;&#34;7.0.8&#34;))</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="hw:=&#34;Fortinet%&#34; AND type:=&#34;SIP Gateway&#34; AND ((osversion:&gt;&#34;7.2.0&#34; AND osversion:&lt;&#34;7.2.3&#34;) OR (osversion:&gt;&#34;7.0.0&#34; AND osversion:&lt;&#34;7.0.8&#34;))" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/?search=hw%3A%3D%22Fortinet%25%22+AND+type%3A%3D%22SIP+Gateway%22+AND+%28%28osversion%3A%3E%227.2.0%22+AND+osversion%3A%3C%227.2.3%22%29+OR+%28osversion%3A%3E%227.0.0%22+AND+osversion%3A%3C%227.0.8%22%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/?search=hw%3A%3D%22Fortinet%25%22+AND+type%3A%3D%22SIP+Gateway%22+AND+%28%28osversion%3A%3E%227.2.0%22+AND+osversion%3A%3C%227.2.3%22%29+OR+%28osversion%3A%3E%227.0.0%22+AND+osversion%3A%3C%227.0.8%22%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="hw:=&#34;Fortinet%&#34; AND type:=&#34;SIP Gateway&#34; AND ((osversion:&gt;&#34;7.2.0&#34; AND osversion:&lt;&#34;7.2.3&#34;) OR (osversion:&gt;&#34;7.0.0&#34; AND osversion:&lt;&#34;7.0.8&#34;))"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="ipmi rakp+ password hash disclosure (cve-2013-4786) _asset.protocols:ipmi and has:ipmi.rakp.hashes services vulnerability" data-ql-sev="high">
      <div class="ql-card-header">
        <div class="ql-title">IPMI RAKP+ Password Hash Disclosure (CVE-2013-4786)</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><span class="ql-type-badge">services</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>_asset.protocols:ipmi AND has:ipmi.rakp.hashes</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="_asset.protocols:ipmi AND has:ipmi.rakp.hashes" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/services?search=_asset.protocols%3Aipmi+AND+has%3Aipmi.rakp.hashes" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/services?search=_asset.protocols%3Aipmi+AND+has%3Aipmi.rakp.hashes" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="_asset.protocols:ipmi AND has:ipmi.rakp.hashes"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="isc bind multiple vulnerabilities (2025-10) vendor:=isc and product:=bind and (version:&gt;0 and ( (version:&gt;=9 and version:&lt;9.11.0) or (version:&gt;=9.11.0 and version:&lt;=9.16.50) or (version:&gt;=9.18.0 and version:&lt;=9.18.39) or (version:&gt;=9.20.0 and version:&lt;=9.20.13) or (version:&gt;=9.21.0 and version:&lt;=9.21.12) or (version:&gt;=&#34;9.11.3-s1&#34; and version:&lt;=&#34;9.16.50-s1&#34;) or (version:&gt;=&#34;9.18.11-s1&#34; and version:&lt;=&#34;9.18.39-s1&#34;) or (version:&gt;=&#34;9.20.9-s1&#34; and version:&lt;=&#34;9.20.13-s1&#34;))) software vulnerability" data-ql-sev="high">
      <div class="ql-card-header">
        <div class="ql-title">ISC BIND Multiple Vulnerabilities (2025-10)</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><span class="ql-type-badge">software</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>vendor:=ISC AND product:=BIND AND (version:&gt;0 AND ( (version:&gt;=9 AND version:&lt;9.11.0) OR (version:&gt;=9.11.0 AND version:&lt;=9.16.50) OR (version:&gt;=9.18.0 AND version:&lt;=9.18.39) OR (version:&gt;=9.20.0 AND version:&lt;=9.20.13) OR (version:&gt;=9.21.0 AND version:&lt;=9.21.12) OR (version:&gt;=&#34;9.11.3-S1&#34; AND version:&lt;=&#34;9.16.50-S1&#34;) OR (version:&gt;=&#34;9.18.11-S1&#34; AND version:&lt;=&#34;9.18.39-S1&#34;) OR (version:&gt;=&#34;9.20.9-S1&#34; AND version:&lt;=&#34;9.20.13-S1&#34;)))</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="vendor:=ISC AND product:=BIND AND (version:&gt;0 AND ( (version:&gt;=9 AND version:&lt;9.11.0) OR (version:&gt;=9.11.0 AND version:&lt;=9.16.50) OR (version:&gt;=9.18.0 AND version:&lt;=9.18.39) OR (version:&gt;=9.20.0 AND version:&lt;=9.20.13) OR (version:&gt;=9.21.0 AND version:&lt;=9.21.12) OR (version:&gt;=&#34;9.11.3-S1&#34; AND version:&lt;=&#34;9.16.50-S1&#34;) OR (version:&gt;=&#34;9.18.11-S1&#34; AND version:&lt;=&#34;9.18.39-S1&#34;) OR (version:&gt;=&#34;9.20.9-S1&#34; AND version:&lt;=&#34;9.20.13-S1&#34;)))" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/software?search=vendor%3A%3DISC+AND+product%3A%3DBIND+AND+%28version%3A%3E0+AND+%28+%28version%3A%3E%3D9+AND+version%3A%3C9.11.0%29+OR+%28version%3A%3E%3D9.11.0+AND+version%3A%3C%3D9.16.50%29+OR+%28version%3A%3E%3D9.18.0+AND+version%3A%3C%3D9.18.39%29+OR+%28version%3A%3E%3D9.20.0+AND+version%3A%3C%3D9.20.13%29+OR+%28version%3A%3E%3D9.21.0+AND+version%3A%3C%3D9.21.12%29+OR+%28version%3A%3E%3D%229.11.3-S1%22+AND+version%3A%3C%3D%229.16.50-S1%22%29+OR+%28version%3A%3E%3D%229.18.11-S1%22+AND+version%3A%3C%3D%229.18.39-S1%22%29+OR+%28version%3A%3E%3D%229.20.9-S1%22+AND+version%3A%3C%3D%229.20.13-S1%22%29%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/software?search=vendor%3A%3DISC+AND+product%3A%3DBIND+AND+%28version%3A%3E0+AND+%28+%28version%3A%3E%3D9+AND+version%3A%3C9.11.0%29+OR+%28version%3A%3E%3D9.11.0+AND+version%3A%3C%3D9.16.50%29+OR+%28version%3A%3E%3D9.18.0+AND+version%3A%3C%3D9.18.39%29+OR+%28version%3A%3E%3D9.20.0+AND+version%3A%3C%3D9.20.13%29+OR+%28version%3A%3E%3D9.21.0+AND+version%3A%3C%3D9.21.12%29+OR+%28version%3A%3E%3D%229.11.3-S1%22+AND+version%3A%3C%3D%229.16.50-S1%22%29+OR+%28version%3A%3E%3D%229.18.11-S1%22+AND+version%3A%3C%3D%229.18.39-S1%22%29+OR+%28version%3A%3E%3D%229.20.9-S1%22+AND+version%3A%3C%3D%229.20.13-S1%22%29%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="vendor:=ISC AND product:=BIND AND (version:&gt;0 AND ( (version:&gt;=9 AND version:&lt;9.11.0) OR (version:&gt;=9.11.0 AND version:&lt;=9.16.50) OR (version:&gt;=9.18.0 AND version:&lt;=9.18.39) OR (version:&gt;=9.20.0 AND version:&lt;=9.20.13) OR (version:&gt;=9.21.0 AND version:&lt;=9.21.12) OR (version:&gt;=&#34;9.11.3-S1&#34; AND version:&lt;=&#34;9.16.50-S1&#34;) OR (version:&gt;=&#34;9.18.11-S1&#34; AND version:&lt;=&#34;9.18.39-S1&#34;) OR (version:&gt;=&#34;9.20.9-S1&#34; AND version:&lt;=&#34;9.20.13-S1&#34;)))"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="langflow authentication bypass _asset.protocol:=http and vendor:=langflow and product:=langflow and (version:&gt;0 and version:&lt;1.3.0) software vulnerability" data-ql-sev="high">
      <div class="ql-card-header">
        <div class="ql-title">Langflow Authentication Bypass</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><span class="ql-type-badge">software</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>_asset.protocol:=http AND vendor:=Langflow AND product:=Langflow AND (version:&gt;0 AND version:&lt;1.3.0)</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="_asset.protocol:=http AND vendor:=Langflow AND product:=Langflow AND (version:&gt;0 AND version:&lt;1.3.0)" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/software?search=_asset.protocol%3A%3Dhttp+AND+vendor%3A%3DLangflow+AND+product%3A%3DLangflow+AND+%28version%3A%3E0+AND+version%3A%3C1.3.0%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/software?search=_asset.protocol%3A%3Dhttp+AND+vendor%3A%3DLangflow+AND+product%3A%3DLangflow+AND+%28version%3A%3E0+AND+version%3A%3C1.3.0%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="_asset.protocol:=http AND vendor:=Langflow AND product:=Langflow AND (version:&gt;0 AND version:&lt;1.3.0)"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="lantronix xport authentication bypass hw:lantronix and ((os:=&#34;lantronix xport%&#34; and not os:=&#34;lantronix xport edge%&#34;) or (lantronix.type:=&#34;xe&#34; or lantronix.type:=&#34;se&#34; or lantronix.type:=&#34;ar&#34; or lantronix.type:=&#34;eh&#34;)) assets vulnerability" data-ql-sev="high">
      <div class="ql-card-header">
        <div class="ql-title">Lantronix Xport Authentication Bypass</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><span class="ql-type-badge">assets</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>hw:lantronix AND ((os:=&#34;Lantronix XPort%&#34; AND not os:=&#34;Lantronix XPort Edge%&#34;) OR (lantronix.type:=&#34;XE&#34; OR lantronix.type:=&#34;SE&#34; OR lantronix.type:=&#34;AR&#34; OR lantronix.type:=&#34;EH&#34;))</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="hw:lantronix AND ((os:=&#34;Lantronix XPort%&#34; AND not os:=&#34;Lantronix XPort Edge%&#34;) OR (lantronix.type:=&#34;XE&#34; OR lantronix.type:=&#34;SE&#34; OR lantronix.type:=&#34;AR&#34; OR lantronix.type:=&#34;EH&#34;))" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/?search=hw%3Alantronix+AND+%28%28os%3A%3D%22Lantronix+XPort%25%22+AND+not+os%3A%3D%22Lantronix+XPort+Edge%25%22%29+OR+%28lantronix.type%3A%3D%22XE%22+OR+lantronix.type%3A%3D%22SE%22+OR+lantronix.type%3A%3D%22AR%22+OR+lantronix.type%3A%3D%22EH%22%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/?search=hw%3Alantronix+AND+%28%28os%3A%3D%22Lantronix+XPort%25%22+AND+not+os%3A%3D%22Lantronix+XPort+Edge%25%22%29+OR+%28lantronix.type%3A%3D%22XE%22+OR+lantronix.type%3A%3D%22SE%22+OR+lantronix.type%3A%3D%22AR%22+OR+lantronix.type%3A%3D%22EH%22%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="hw:lantronix AND ((os:=&#34;Lantronix XPort%&#34; AND not os:=&#34;Lantronix XPort Edge%&#34;) OR (lantronix.type:=&#34;XE&#34; OR lantronix.type:=&#34;SE&#34; OR lantronix.type:=&#34;AR&#34; OR lantronix.type:=&#34;EH&#34;))"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="mongodb pre-authentication memory leak (cve-2025-14847) (vendor:=mongodb and (product:=mongodb or product:=&#34;mongodb mongodb&#34;)) and (version:&gt;0 and ( (version:&gt;=3.6.0 and version:&lt;3.7) or (version:&gt;=4.0.0 and version:&lt;4.1) or (version:&gt;=4.2.0 and version:&lt;4.3) or (version:&gt;=4.4.0 and version:&lt;4.4.30) or (version:&gt;=5.0.0 and version:&lt;5.0.32) or (version:&gt;=6.0.0 and version:&lt;6.0.27) or (version:&gt;=7.0.0 and version:&lt;7.0.28) or (version:&gt;=8.0.0 and version:&lt;8.0.17) or (version:&gt;=8.2.0 and version:&lt;8.2.3))) software vulnerability" data-ql-sev="high">
      <div class="ql-card-header">
        <div class="ql-title">MongoDB Pre-Authentication Memory Leak (CVE-2025-14847)</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><span class="ql-type-badge">software</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>(vendor:=MongoDB AND (product:=MongoDB OR product:=&#34;MongoDB MongoDB&#34;)) AND (version:&gt;0 AND ( (version:&gt;=3.6.0 AND version:&lt;3.7) OR (version:&gt;=4.0.0 AND version:&lt;4.1) OR (version:&gt;=4.2.0 AND version:&lt;4.3) OR (version:&gt;=4.4.0 AND version:&lt;4.4.30) OR (version:&gt;=5.0.0 AND version:&lt;5.0.32) OR (version:&gt;=6.0.0 AND version:&lt;6.0.27) OR (version:&gt;=7.0.0 AND version:&lt;7.0.28) OR (version:&gt;=8.0.0 AND version:&lt;8.0.17) OR (version:&gt;=8.2.0 AND version:&lt;8.2.3)))</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="(vendor:=MongoDB AND (product:=MongoDB OR product:=&#34;MongoDB MongoDB&#34;)) AND (version:&gt;0 AND ( (version:&gt;=3.6.0 AND version:&lt;3.7) OR (version:&gt;=4.0.0 AND version:&lt;4.1) OR (version:&gt;=4.2.0 AND version:&lt;4.3) OR (version:&gt;=4.4.0 AND version:&lt;4.4.30) OR (version:&gt;=5.0.0 AND version:&lt;5.0.32) OR (version:&gt;=6.0.0 AND version:&lt;6.0.27) OR (version:&gt;=7.0.0 AND version:&lt;7.0.28) OR (version:&gt;=8.0.0 AND version:&lt;8.0.17) OR (version:&gt;=8.2.0 AND version:&lt;8.2.3)))" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/software?search=%28vendor%3A%3DMongoDB+AND+%28product%3A%3DMongoDB+OR+product%3A%3D%22MongoDB+MongoDB%22%29%29+AND+%28version%3A%3E0+AND+%28+%28version%3A%3E%3D3.6.0+AND+version%3A%3C3.7%29+OR+%28version%3A%3E%3D4.0.0+AND+version%3A%3C4.1%29+OR+%28version%3A%3E%3D4.2.0+AND+version%3A%3C4.3%29+OR+%28version%3A%3E%3D4.4.0+AND+version%3A%3C4.4.30%29+OR+%28version%3A%3E%3D5.0.0+AND+version%3A%3C5.0.32%29+OR+%28version%3A%3E%3D6.0.0+AND+version%3A%3C6.0.27%29+OR+%28version%3A%3E%3D7.0.0+AND+version%3A%3C7.0.28%29+OR+%28version%3A%3E%3D8.0.0+AND+version%3A%3C8.0.17%29+OR+%28version%3A%3E%3D8.2.0+AND+version%3A%3C8.2.3%29%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/software?search=%28vendor%3A%3DMongoDB+AND+%28product%3A%3DMongoDB+OR+product%3A%3D%22MongoDB+MongoDB%22%29%29+AND+%28version%3A%3E0+AND+%28+%28version%3A%3E%3D3.6.0+AND+version%3A%3C3.7%29+OR+%28version%3A%3E%3D4.0.0+AND+version%3A%3C4.1%29+OR+%28version%3A%3E%3D4.2.0+AND+version%3A%3C4.3%29+OR+%28version%3A%3E%3D4.4.0+AND+version%3A%3C4.4.30%29+OR+%28version%3A%3E%3D5.0.0+AND+version%3A%3C5.0.32%29+OR+%28version%3A%3E%3D6.0.0+AND+version%3A%3C6.0.27%29+OR+%28version%3A%3E%3D7.0.0+AND+version%3A%3C7.0.28%29+OR+%28version%3A%3E%3D8.0.0+AND+version%3A%3C8.0.17%29+OR+%28version%3A%3E%3D8.2.0+AND+version%3A%3C8.2.3%29%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="(vendor:=MongoDB AND (product:=MongoDB OR product:=&#34;MongoDB MongoDB&#34;)) AND (version:&gt;0 AND ( (version:&gt;=3.6.0 AND version:&lt;3.7) OR (version:&gt;=4.0.0 AND version:&lt;4.1) OR (version:&gt;=4.2.0 AND version:&lt;4.3) OR (version:&gt;=4.4.0 AND version:&lt;4.4.30) OR (version:&gt;=5.0.0 AND version:&lt;5.0.32) OR (version:&gt;=6.0.0 AND version:&lt;6.0.27) OR (version:&gt;=7.0.0 AND version:&lt;7.0.28) OR (version:&gt;=8.0.0 AND version:&lt;8.0.17) OR (version:&gt;=8.2.0 AND version:&lt;8.2.3)))"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="multiple fortinet products unauthenticated rce (cve-2025-25249) os:=&#34;fortinet fortios&#34; and os_version:&gt;0 and ((os_version:&gt;=&#34;7.6.0&#34; and os_version:&lt;=&#34;7.6.3&#34;) or (os_version:&gt;=&#34;7.4.0&#34; and os_version:&lt;=&#34;7.4.8&#34;)  or (os_version:&gt;=&#34;7.2.0&#34; and os_version:&lt;=&#34;7.2.11&#34;) or (os_version:&gt;=&#34;7.0.0&#34; and os_version:&lt;=&#34;7.0.17&#34;) or (os_version:&gt;=&#34;6.4.0&#34; and os_version:&lt;=&#34;6.4.16&#34;)) assets vulnerability" data-ql-sev="high">
      <div class="ql-card-header">
        <div class="ql-title">Multiple Fortinet Products Unauthenticated RCE (CVE-2025-25249)</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><span class="ql-type-badge">assets</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>os:=&#34;Fortinet FortiOS&#34; AND os_version:&gt;0 AND ((os_version:&gt;=&#34;7.6.0&#34; AND os_version:&lt;=&#34;7.6.3&#34;) OR (os_version:&gt;=&#34;7.4.0&#34; AND os_version:&lt;=&#34;7.4.8&#34;)  OR (os_version:&gt;=&#34;7.2.0&#34; AND os_version:&lt;=&#34;7.2.11&#34;) OR (os_version:&gt;=&#34;7.0.0&#34; AND os_version:&lt;=&#34;7.0.17&#34;) OR (os_version:&gt;=&#34;6.4.0&#34; AND os_version:&lt;=&#34;6.4.16&#34;))</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="os:=&#34;Fortinet FortiOS&#34; AND os_version:&gt;0 AND ((os_version:&gt;=&#34;7.6.0&#34; AND os_version:&lt;=&#34;7.6.3&#34;) OR (os_version:&gt;=&#34;7.4.0&#34; AND os_version:&lt;=&#34;7.4.8&#34;)  OR (os_version:&gt;=&#34;7.2.0&#34; AND os_version:&lt;=&#34;7.2.11&#34;) OR (os_version:&gt;=&#34;7.0.0&#34; AND os_version:&lt;=&#34;7.0.17&#34;) OR (os_version:&gt;=&#34;6.4.0&#34; AND os_version:&lt;=&#34;6.4.16&#34;))" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/?search=os%3A%3D%22Fortinet+FortiOS%22+AND+os_version%3A%3E0+AND+%28%28os_version%3A%3E%3D%227.6.0%22+AND+os_version%3A%3C%3D%227.6.3%22%29+OR+%28os_version%3A%3E%3D%227.4.0%22+AND+os_version%3A%3C%3D%227.4.8%22%29++OR+%28os_version%3A%3E%3D%227.2.0%22+AND+os_version%3A%3C%3D%227.2.11%22%29+OR+%28os_version%3A%3E%3D%227.0.0%22+AND+os_version%3A%3C%3D%227.0.17%22%29+OR+%28os_version%3A%3E%3D%226.4.0%22+AND+os_version%3A%3C%3D%226.4.16%22%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/?search=os%3A%3D%22Fortinet+FortiOS%22+AND+os_version%3A%3E0+AND+%28%28os_version%3A%3E%3D%227.6.0%22+AND+os_version%3A%3C%3D%227.6.3%22%29+OR+%28os_version%3A%3E%3D%227.4.0%22+AND+os_version%3A%3C%3D%227.4.8%22%29++OR+%28os_version%3A%3E%3D%227.2.0%22+AND+os_version%3A%3C%3D%227.2.11%22%29+OR+%28os_version%3A%3E%3D%227.0.0%22+AND+os_version%3A%3C%3D%227.0.17%22%29+OR+%28os_version%3A%3E%3D%226.4.0%22+AND+os_version%3A%3C%3D%226.4.16%22%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="os:=&#34;Fortinet FortiOS&#34; AND os_version:&gt;0 AND ((os_version:&gt;=&#34;7.6.0&#34; AND os_version:&lt;=&#34;7.6.3&#34;) OR (os_version:&gt;=&#34;7.4.0&#34; AND os_version:&lt;=&#34;7.4.8&#34;)  OR (os_version:&gt;=&#34;7.2.0&#34; AND os_version:&lt;=&#34;7.2.11&#34;) OR (os_version:&gt;=&#34;7.0.0&#34; AND os_version:&lt;=&#34;7.0.17&#34;) OR (os_version:&gt;=&#34;6.4.0&#34; AND os_version:&lt;=&#34;6.4.16&#34;))"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="multiple vulnerabilities in microsoft sql server (2025-07) vendor:=microsoft and (product:=&#34;sql server&#34;  or product:=&#34;sql server 20%&#34;) and ((version:&gt;=13.0.0 and version:&lt;13.0.6460.7 and not version:=&#34;13.0.6460&#34;) or (version:&gt;=14.0.0 and version:&lt;14.0.3495.9 and not version:=&#34;14.0.3495&#34;) or (version:&gt;=15.0.0 and version:&lt;15.0.4435.7 and not version:=&#34;15.0.4435&#34;) or (version:&gt;=16.0.0 and version:&lt;16.0.4200.1 and not version:=&#34;16.0.4200&#34;)) software vulnerability" data-ql-sev="high">
      <div class="ql-card-header">
        <div class="ql-title">Multiple Vulnerabilities In Microsoft SQL Server (2025-07)</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><span class="ql-type-badge">software</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>vendor:=Microsoft AND (product:=&#34;SQL Server&#34;  OR product:=&#34;SQL Server 20%&#34;) AND ((version:&gt;=13.0.0 AND version:&lt;13.0.6460.7 AND NOT version:=&#34;13.0.6460&#34;) OR (version:&gt;=14.0.0 AND version:&lt;14.0.3495.9 AND NOT version:=&#34;14.0.3495&#34;) OR (version:&gt;=15.0.0 AND version:&lt;15.0.4435.7 AND NOT version:=&#34;15.0.4435&#34;) OR (version:&gt;=16.0.0 AND version:&lt;16.0.4200.1 AND NOT version:=&#34;16.0.4200&#34;))</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="vendor:=Microsoft AND (product:=&#34;SQL Server&#34;  OR product:=&#34;SQL Server 20%&#34;) AND ((version:&gt;=13.0.0 AND version:&lt;13.0.6460.7 AND NOT version:=&#34;13.0.6460&#34;) OR (version:&gt;=14.0.0 AND version:&lt;14.0.3495.9 AND NOT version:=&#34;14.0.3495&#34;) OR (version:&gt;=15.0.0 AND version:&lt;15.0.4435.7 AND NOT version:=&#34;15.0.4435&#34;) OR (version:&gt;=16.0.0 AND version:&lt;16.0.4200.1 AND NOT version:=&#34;16.0.4200&#34;))" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/software?search=vendor%3A%3DMicrosoft+AND+%28product%3A%3D%22SQL+Server%22++OR+product%3A%3D%22SQL+Server+20%25%22%29+AND+%28%28version%3A%3E%3D13.0.0+AND+version%3A%3C13.0.6460.7+AND+NOT+version%3A%3D%2213.0.6460%22%29+OR+%28version%3A%3E%3D14.0.0+AND+version%3A%3C14.0.3495.9+AND+NOT+version%3A%3D%2214.0.3495%22%29+OR+%28version%3A%3E%3D15.0.0+AND+version%3A%3C15.0.4435.7+AND+NOT+version%3A%3D%2215.0.4435%22%29+OR+%28version%3A%3E%3D16.0.0+AND+version%3A%3C16.0.4200.1+AND+NOT+version%3A%3D%2216.0.4200%22%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/software?search=vendor%3A%3DMicrosoft+AND+%28product%3A%3D%22SQL+Server%22++OR+product%3A%3D%22SQL+Server+20%25%22%29+AND+%28%28version%3A%3E%3D13.0.0+AND+version%3A%3C13.0.6460.7+AND+NOT+version%3A%3D%2213.0.6460%22%29+OR+%28version%3A%3E%3D14.0.0+AND+version%3A%3C14.0.3495.9+AND+NOT+version%3A%3D%2214.0.3495%22%29+OR+%28version%3A%3E%3D15.0.0+AND+version%3A%3C15.0.4435.7+AND+NOT+version%3A%3D%2215.0.4435%22%29+OR+%28version%3A%3E%3D16.0.0+AND+version%3A%3C16.0.4200.1+AND+NOT+version%3A%3D%2216.0.4200%22%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="vendor:=Microsoft AND (product:=&#34;SQL Server&#34;  OR product:=&#34;SQL Server 20%&#34;) AND ((version:&gt;=13.0.0 AND version:&lt;13.0.6460.7 AND NOT version:=&#34;13.0.6460&#34;) OR (version:&gt;=14.0.0 AND version:&lt;14.0.3495.9 AND NOT version:=&#34;14.0.3495&#34;) OR (version:&gt;=15.0.0 AND version:&lt;15.0.4435.7 AND NOT version:=&#34;15.0.4435&#34;) OR (version:&gt;=16.0.0 AND version:&lt;16.0.4200.1 AND NOT version:=&#34;16.0.4200&#34;))"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="palo alto networks pan-os rce in ikev2 processing (cve-2026-0263) hw:=&#34;palo alto networks&#34; and os:=&#34;palo alto networks pan-os%&#34; and os_version:&gt;0 and ((os_version:&gt;=&#34;12.1.5&#34; and os_version:&lt;&#34;12.1.7&#34;) or (os_version:&gt;=&#34;12.1.2&#34; and os_version:&lt;&#34;12.1.4-h5&#34;) or (os_version:&gt;=&#34;11.2.11&#34; and os_version:&lt;&#34;11.2.12&#34;) or (os_version:&gt;=&#34;11.2.8&#34; and os_version:&lt;&#34;11.2.10-h6&#34;) or (os_version:&gt;=&#34;11.2.5&#34; and os_version:&lt;&#34;11.2.7-h13&#34;) or (os_version:&gt;=&#34;11.2.0&#34; and os_version:&lt;&#34;11.2.4-h17&#34;) or (os_version:&gt;=&#34;11.1.14&#34; and os_version:&lt;&#34;11.1.15&#34;) or (os_version:&gt;=&#34;11.1.11&#34; and os_version:&lt;&#34;11.1.13-h5&#34;) or (os_version:&gt;=&#34;11.1.8&#34; and os_version:&lt;&#34;11.1.10-h25&#34;) or (os_version:&gt;=&#34;11.1.7&#34; and os_version:&lt;&#34;11.1.7-h6&#34;) or (os_version:&gt;=&#34;11.1.5&#34; and os_version:&lt;&#34;11.1.6-h32&#34;) or (os_version:&gt;=&#34;11.1.0&#34; and os_version:&lt;&#34;11.1.4-h33&#34;)) assets vulnerability" data-ql-sev="high">
      <div class="ql-card-header">
        <div class="ql-title">Palo Alto Networks PAN-OS RCE In IKEv2 Processing (CVE-2026-0263)</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><span class="ql-type-badge">assets</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>hw:=&#34;Palo Alto Networks&#34; AND os:=&#34;Palo Alto Networks PAN-OS%&#34; AND os_version:&gt;0 AND ((os_version:&gt;=&#34;12.1.5&#34; AND os_version:&lt;&#34;12.1.7&#34;) OR (os_version:&gt;=&#34;12.1.2&#34; AND os_version:&lt;&#34;12.1.4-h5&#34;) OR (os_version:&gt;=&#34;11.2.11&#34; AND os_version:&lt;&#34;11.2.12&#34;) OR (os_version:&gt;=&#34;11.2.8&#34; AND os_version:&lt;&#34;11.2.10-h6&#34;) OR (os_version:&gt;=&#34;11.2.5&#34; AND os_version:&lt;&#34;11.2.7-h13&#34;) OR (os_version:&gt;=&#34;11.2.0&#34; AND os_version:&lt;&#34;11.2.4-h17&#34;) OR (os_version:&gt;=&#34;11.1.14&#34; AND os_version:&lt;&#34;11.1.15&#34;) OR (os_version:&gt;=&#34;11.1.11&#34; AND os_version:&lt;&#34;11.1.13-h5&#34;) OR (os_version:&gt;=&#34;11.1.8&#34; AND os_version:&lt;&#34;11.1.10-h25&#34;) OR (os_version:&gt;=&#34;11.1.7&#34; AND os_version:&lt;&#34;11.1.7-h6&#34;) OR (os_version:&gt;=&#34;11.1.5&#34; AND os_version:&lt;&#34;11.1.6-h32&#34;) OR (os_version:&gt;=&#34;11.1.0&#34; AND os_version:&lt;&#34;11.1.4-h33&#34;))</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="hw:=&#34;Palo Alto Networks&#34; AND os:=&#34;Palo Alto Networks PAN-OS%&#34; AND os_version:&gt;0 AND ((os_version:&gt;=&#34;12.1.5&#34; AND os_version:&lt;&#34;12.1.7&#34;) OR (os_version:&gt;=&#34;12.1.2&#34; AND os_version:&lt;&#34;12.1.4-h5&#34;) OR (os_version:&gt;=&#34;11.2.11&#34; AND os_version:&lt;&#34;11.2.12&#34;) OR (os_version:&gt;=&#34;11.2.8&#34; AND os_version:&lt;&#34;11.2.10-h6&#34;) OR (os_version:&gt;=&#34;11.2.5&#34; AND os_version:&lt;&#34;11.2.7-h13&#34;) OR (os_version:&gt;=&#34;11.2.0&#34; AND os_version:&lt;&#34;11.2.4-h17&#34;) OR (os_version:&gt;=&#34;11.1.14&#34; AND os_version:&lt;&#34;11.1.15&#34;) OR (os_version:&gt;=&#34;11.1.11&#34; AND os_version:&lt;&#34;11.1.13-h5&#34;) OR (os_version:&gt;=&#34;11.1.8&#34; AND os_version:&lt;&#34;11.1.10-h25&#34;) OR (os_version:&gt;=&#34;11.1.7&#34; AND os_version:&lt;&#34;11.1.7-h6&#34;) OR (os_version:&gt;=&#34;11.1.5&#34; AND os_version:&lt;&#34;11.1.6-h32&#34;) OR (os_version:&gt;=&#34;11.1.0&#34; AND os_version:&lt;&#34;11.1.4-h33&#34;))" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/?search=hw%3A%3D%22Palo+Alto+Networks%22+AND+os%3A%3D%22Palo+Alto+Networks+PAN-OS%25%22+AND+os_version%3A%3E0+AND+%28%28os_version%3A%3E%3D%2212.1.5%22+AND+os_version%3A%3C%2212.1.7%22%29+OR+%28os_version%3A%3E%3D%2212.1.2%22+AND+os_version%3A%3C%2212.1.4-h5%22%29+OR+%28os_version%3A%3E%3D%2211.2.11%22+AND+os_version%3A%3C%2211.2.12%22%29+OR+%28os_version%3A%3E%3D%2211.2.8%22+AND+os_version%3A%3C%2211.2.10-h6%22%29+OR+%28os_version%3A%3E%3D%2211.2.5%22+AND+os_version%3A%3C%2211.2.7-h13%22%29+OR+%28os_version%3A%3E%3D%2211.2.0%22+AND+os_version%3A%3C%2211.2.4-h17%22%29+OR+%28os_version%3A%3E%3D%2211.1.14%22+AND+os_version%3A%3C%2211.1.15%22%29+OR+%28os_version%3A%3E%3D%2211.1.11%22+AND+os_version%3A%3C%2211.1.13-h5%22%29+OR+%28os_version%3A%3E%3D%2211.1.8%22+AND+os_version%3A%3C%2211.1.10-h25%22%29+OR+%28os_version%3A%3E%3D%2211.1.7%22+AND+os_version%3A%3C%2211.1.7-h6%22%29+OR+%28os_version%3A%3E%3D%2211.1.5%22+AND+os_version%3A%3C%2211.1.6-h32%22%29+OR+%28os_version%3A%3E%3D%2211.1.0%22+AND+os_version%3A%3C%2211.1.4-h33%22%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/?search=hw%3A%3D%22Palo+Alto+Networks%22+AND+os%3A%3D%22Palo+Alto+Networks+PAN-OS%25%22+AND+os_version%3A%3E0+AND+%28%28os_version%3A%3E%3D%2212.1.5%22+AND+os_version%3A%3C%2212.1.7%22%29+OR+%28os_version%3A%3E%3D%2212.1.2%22+AND+os_version%3A%3C%2212.1.4-h5%22%29+OR+%28os_version%3A%3E%3D%2211.2.11%22+AND+os_version%3A%3C%2211.2.12%22%29+OR+%28os_version%3A%3E%3D%2211.2.8%22+AND+os_version%3A%3C%2211.2.10-h6%22%29+OR+%28os_version%3A%3E%3D%2211.2.5%22+AND+os_version%3A%3C%2211.2.7-h13%22%29+OR+%28os_version%3A%3E%3D%2211.2.0%22+AND+os_version%3A%3C%2211.2.4-h17%22%29+OR+%28os_version%3A%3E%3D%2211.1.14%22+AND+os_version%3A%3C%2211.1.15%22%29+OR+%28os_version%3A%3E%3D%2211.1.11%22+AND+os_version%3A%3C%2211.1.13-h5%22%29+OR+%28os_version%3A%3E%3D%2211.1.8%22+AND+os_version%3A%3C%2211.1.10-h25%22%29+OR+%28os_version%3A%3E%3D%2211.1.7%22+AND+os_version%3A%3C%2211.1.7-h6%22%29+OR+%28os_version%3A%3E%3D%2211.1.5%22+AND+os_version%3A%3C%2211.1.6-h32%22%29+OR+%28os_version%3A%3E%3D%2211.1.0%22+AND+os_version%3A%3C%2211.1.4-h33%22%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="hw:=&#34;Palo Alto Networks&#34; AND os:=&#34;Palo Alto Networks PAN-OS%&#34; AND os_version:&gt;0 AND ((os_version:&gt;=&#34;12.1.5&#34; AND os_version:&lt;&#34;12.1.7&#34;) OR (os_version:&gt;=&#34;12.1.2&#34; AND os_version:&lt;&#34;12.1.4-h5&#34;) OR (os_version:&gt;=&#34;11.2.11&#34; AND os_version:&lt;&#34;11.2.12&#34;) OR (os_version:&gt;=&#34;11.2.8&#34; AND os_version:&lt;&#34;11.2.10-h6&#34;) OR (os_version:&gt;=&#34;11.2.5&#34; AND os_version:&lt;&#34;11.2.7-h13&#34;) OR (os_version:&gt;=&#34;11.2.0&#34; AND os_version:&lt;&#34;11.2.4-h17&#34;) OR (os_version:&gt;=&#34;11.1.14&#34; AND os_version:&lt;&#34;11.1.15&#34;) OR (os_version:&gt;=&#34;11.1.11&#34; AND os_version:&lt;&#34;11.1.13-h5&#34;) OR (os_version:&gt;=&#34;11.1.8&#34; AND os_version:&lt;&#34;11.1.10-h25&#34;) OR (os_version:&gt;=&#34;11.1.7&#34; AND os_version:&lt;&#34;11.1.7-h6&#34;) OR (os_version:&gt;=&#34;11.1.5&#34; AND os_version:&lt;&#34;11.1.6-h32&#34;) OR (os_version:&gt;=&#34;11.1.0&#34; AND os_version:&lt;&#34;11.1.4-h33&#34;))"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="powerdns recursor multiple vulnerabilities (2025-10) vendor:=powerdns and product:=recursor and (version:&gt;0 and ( (version:&gt;=5.1 and version:&lt;5.1.8) or (version:&gt;=5.2 and version:&lt;5.2.6) or (version:&gt;=5.3 and version:&lt;5.3.1))) software vulnerability" data-ql-sev="high">
      <div class="ql-card-header">
        <div class="ql-title">PowerDNS Recursor Multiple Vulnerabilities (2025-10)</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><span class="ql-type-badge">software</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>vendor:=PowerDNS AND product:=Recursor AND (version:&gt;0 AND ( (version:&gt;=5.1 AND version:&lt;5.1.8) OR (version:&gt;=5.2 AND version:&lt;5.2.6) OR (version:&gt;=5.3 AND version:&lt;5.3.1)))</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="vendor:=PowerDNS AND product:=Recursor AND (version:&gt;0 AND ( (version:&gt;=5.1 AND version:&lt;5.1.8) OR (version:&gt;=5.2 AND version:&lt;5.2.6) OR (version:&gt;=5.3 AND version:&lt;5.3.1)))" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/software?search=vendor%3A%3DPowerDNS+AND+product%3A%3DRecursor+AND+%28version%3A%3E0+AND+%28+%28version%3A%3E%3D5.1+AND+version%3A%3C5.1.8%29+OR+%28version%3A%3E%3D5.2+AND+version%3A%3C5.2.6%29+OR+%28version%3A%3E%3D5.3+AND+version%3A%3C5.3.1%29%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/software?search=vendor%3A%3DPowerDNS+AND+product%3A%3DRecursor+AND+%28version%3A%3E0+AND+%28+%28version%3A%3E%3D5.1+AND+version%3A%3C5.1.8%29+OR+%28version%3A%3E%3D5.2+AND+version%3A%3C5.2.6%29+OR+%28version%3A%3E%3D5.3+AND+version%3A%3C5.3.1%29%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="vendor:=PowerDNS AND product:=Recursor AND (version:&gt;0 AND ( (version:&gt;=5.1 AND version:&lt;5.1.8) OR (version:&gt;=5.2 AND version:&lt;5.2.6) OR (version:&gt;=5.3 AND version:&lt;5.3.1)))"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="sap netweaver visual composer metadata uploader arbitrary file upload vendor:=&#34;sap&#34; and product:&#34;netweaver&#34; and (version:&gt;7.0 and version:&lt;7.55) software vulnerability" data-ql-sev="high">
      <div class="ql-card-header">
        <div class="ql-title">SAP NetWeaver Visual Composer Metadata Uploader Arbitrary File Upload</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><span class="ql-type-badge">software</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>vendor:=&#34;SAP&#34; AND product:&#34;NetWeaver&#34; AND (version:&gt;7.0 AND version:&lt;7.55)</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="vendor:=&#34;SAP&#34; AND product:&#34;NetWeaver&#34; AND (version:&gt;7.0 AND version:&lt;7.55)" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/software?search=vendor%3A%3D%22SAP%22+AND+product%3A%22NetWeaver%22+AND+%28version%3A%3E7.0+AND+version%3A%3C7.55%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/software?search=vendor%3A%3D%22SAP%22+AND+product%3A%22NetWeaver%22+AND+%28version%3A%3E7.0+AND+version%3A%3C7.55%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="vendor:=&#34;SAP&#34; AND product:&#34;NetWeaver&#34; AND (version:&gt;7.0 AND version:&lt;7.55)"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="samsung magicinfo path traversal vulnerability vendor:=&#34;samsung&#34; and product:&#34;magicinfo server&#34; and version:&gt;0 and version:&lt;&#34;21.1052&#34; software vulnerability" data-ql-sev="high">
      <div class="ql-card-header">
        <div class="ql-title">Samsung MagicINFO Path Traversal Vulnerability</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><span class="ql-type-badge">software</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>vendor:=&#34;Samsung&#34; AND product:&#34;MagicINFO Server&#34; AND version:&gt;0 AND version:&lt;&#34;21.1052&#34;</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="vendor:=&#34;Samsung&#34; AND product:&#34;MagicINFO Server&#34; AND version:&gt;0 AND version:&lt;&#34;21.1052&#34;" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/software?search=vendor%3A%3D%22Samsung%22+AND+product%3A%22MagicINFO+Server%22+AND+version%3A%3E0+AND+version%3A%3C%2221.1052%22" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/software?search=vendor%3A%3D%22Samsung%22+AND+product%3A%22MagicINFO+Server%22+AND+version%3A%3E0+AND+version%3A%3C%2221.1052%22" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="vendor:=&#34;Samsung&#34; AND product:&#34;MagicINFO Server&#34; AND version:&gt;0 AND version:&lt;&#34;21.1052&#34;"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="solr 5.0.0 &lt; 8.4.0 remote code execution vendor:=apache and product:solr and (version:&gt;=5.0.0 and version:&lt;8.4.0) software vulnerability" data-ql-sev="high">
      <div class="ql-card-header">
        <div class="ql-title">Solr 5.0.0 &lt; 8.4.0 Remote Code Execution</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><span class="ql-type-badge">software</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>vendor:=Apache AND product:Solr AND (version:&gt;=5.0.0 AND version:&lt;8.4.0)</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="vendor:=Apache AND product:Solr AND (version:&gt;=5.0.0 AND version:&lt;8.4.0)" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/software?search=vendor%3A%3DApache+AND+product%3ASolr+AND+%28version%3A%3E%3D5.0.0+AND+version%3A%3C8.4.0%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/software?search=vendor%3A%3DApache+AND+product%3ASolr+AND+%28version%3A%3E%3D5.0.0+AND+version%3A%3C8.4.0%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="vendor:=Apache AND product:Solr AND (version:&gt;=5.0.0 AND version:&lt;8.4.0)"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="sonicwall sonicos multiple vulnerabilities (2026-04) hw:=&#34;sonicwall%&#34; and os:=&#34;sonicwall sonicos%&#34; and os_version:&gt;0 and ((os_version:&lt;&#34;6.5.5.2-28n&#34;) or (os_version:&gt;=&#34;7.0&#34; and os_version:&lt;&#34;7.3.2-7010&#34;) or (os_version:&gt;=&#34;8.0&#34; and os_version:&lt;&#34;8.2.0-8009&#34;)) assets vulnerability" data-ql-sev="high">
      <div class="ql-card-header">
        <div class="ql-title">SonicWall SonicOS Multiple Vulnerabilities (2026-04)</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><span class="ql-type-badge">assets</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>hw:=&#34;SonicWall%&#34; AND os:=&#34;SonicWall SonicOS%&#34; AND os_version:&gt;0 AND ((os_version:&lt;&#34;6.5.5.2-28n&#34;) OR (os_version:&gt;=&#34;7.0&#34; AND os_version:&lt;&#34;7.3.2-7010&#34;) OR (os_version:&gt;=&#34;8.0&#34; AND os_version:&lt;&#34;8.2.0-8009&#34;))</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="hw:=&#34;SonicWall%&#34; AND os:=&#34;SonicWall SonicOS%&#34; AND os_version:&gt;0 AND ((os_version:&lt;&#34;6.5.5.2-28n&#34;) OR (os_version:&gt;=&#34;7.0&#34; AND os_version:&lt;&#34;7.3.2-7010&#34;) OR (os_version:&gt;=&#34;8.0&#34; AND os_version:&lt;&#34;8.2.0-8009&#34;))" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/?search=hw%3A%3D%22SonicWall%25%22+AND+os%3A%3D%22SonicWall+SonicOS%25%22+AND+os_version%3A%3E0+AND+%28%28os_version%3A%3C%226.5.5.2-28n%22%29+OR+%28os_version%3A%3E%3D%227.0%22+AND+os_version%3A%3C%227.3.2-7010%22%29+OR+%28os_version%3A%3E%3D%228.0%22+AND+os_version%3A%3C%228.2.0-8009%22%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/?search=hw%3A%3D%22SonicWall%25%22+AND+os%3A%3D%22SonicWall+SonicOS%25%22+AND+os_version%3A%3E0+AND+%28%28os_version%3A%3C%226.5.5.2-28n%22%29+OR+%28os_version%3A%3E%3D%227.0%22+AND+os_version%3A%3C%227.3.2-7010%22%29+OR+%28os_version%3A%3E%3D%228.0%22+AND+os_version%3A%3C%228.2.0-8009%22%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="hw:=&#34;SonicWall%&#34; AND os:=&#34;SonicWall SonicOS%&#34; AND os_version:&gt;0 AND ((os_version:&lt;&#34;6.5.5.2-28n&#34;) OR (os_version:&gt;=&#34;7.0&#34; AND os_version:&lt;&#34;7.3.2-7010&#34;) OR (os_version:&gt;=&#34;8.0&#34; AND os_version:&lt;&#34;8.2.0-8009&#34;))"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="sysaid help desk xml entity remote code execution vendor:=&#34;sysaid&#34; and product:&#34;help desk&#34; and version:&gt;0 and version:&lt;24.4.60 software vulnerability" data-ql-sev="high">
      <div class="ql-card-header">
        <div class="ql-title">SysAid Help Desk XML Entity Remote Code Execution</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><span class="ql-type-badge">software</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>vendor:=&#34;SysAid&#34; AND product:&#34;Help Desk&#34; AND version:&gt;0 AND version:&lt;24.4.60</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="vendor:=&#34;SysAid&#34; AND product:&#34;Help Desk&#34; AND version:&gt;0 AND version:&lt;24.4.60" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/software?search=vendor%3A%3D%22SysAid%22+AND+product%3A%22Help+Desk%22+AND+version%3A%3E0+AND+version%3A%3C24.4.60" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/software?search=vendor%3A%3D%22SysAid%22+AND+product%3A%22Help+Desk%22+AND+version%3A%3E0+AND+version%3A%3C24.4.60" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="vendor:=&#34;SysAid&#34; AND product:&#34;Help Desk&#34; AND version:&gt;0 AND version:&lt;24.4.60"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="trimble cityworks file deserialization vulnerability vendor:=&#34;trimble&#34; and product:=&#34;cityworks&#34; and version:&gt;0 and version:&lt;&#34;23.10&#34; software vulnerability" data-ql-sev="high">
      <div class="ql-card-header">
        <div class="ql-title">Trimble Cityworks File Deserialization Vulnerability</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><span class="ql-type-badge">software</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>vendor:=&#34;Trimble&#34; AND product:=&#34;Cityworks&#34; AND version:&gt;0 AND version:&lt;&#34;23.10&#34;</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="vendor:=&#34;Trimble&#34; AND product:=&#34;Cityworks&#34; AND version:&gt;0 AND version:&lt;&#34;23.10&#34;" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/software?search=vendor%3A%3D%22Trimble%22+AND+product%3A%3D%22Cityworks%22+AND+version%3A%3E0+AND+version%3A%3C%2223.10%22" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/software?search=vendor%3A%3D%22Trimble%22+AND+product%3A%3D%22Cityworks%22+AND+version%3A%3E0+AND+version%3A%3C%2223.10%22" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="vendor:=&#34;Trimble&#34; AND product:=&#34;Cityworks&#34; AND version:&gt;0 AND version:&lt;&#34;23.10&#34;"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="vmware esxi openslp heap buffer overflow os:=&#34;vmware esx%&#34; and port:427 and ( os_version:=&#34;1.%&#34; or os_version:=&#34;2.%&#34; or os_version:=&#34;3.%&#34; or os_version:=&#34;4.%&#34; or os_version:=&#34;5.%&#34; or os_version:=&#34;6.0%&#34; or os_version:=&#34;6.5.0 build-4564106&#34; or os_version:=&#34;6.5.0 build-4887370&#34; or os_version:=&#34;6.5.0 build-5146843&#34; or os_version:=&#34;6.5.0 build-5146846&#34; or os_version:=&#34;6.5.0 build-5224529&#34; or os_version:=&#34;6.5.0 build-5310538&#34; or os_version:=&#34;6.5.0 build-5969300&#34; or os_version:=&#34;6.5.0 build-5969303&#34; or os_version:=&#34;6.5.0 build-6765664&#34; or os_version:=&#34;6.5.0 build-7273056&#34; or os_version:=&#34;6.5.0 build-7388607&#34; or os_version:=&#34;6.5.0 build-7967591&#34; or os_version:=&#34;6.5.0 build-8285314&#34; or os_version:=&#34;6.5.0 build-8294253&#34; or os_version:=&#34;6.5.0 build-8935087&#34; or os_version:=&#34;6.5.0 build-9298722&#34; or os_version:=&#34;6.5.0 build-10175896&#34; or os_version:=&#34;6.5.0 build-10390116&#34; or os_version:=&#34;6.5.0 build-10719125&#34; or os_version:=&#34;6.5.0 build-10868328&#34; or os_version:=&#34;6.5.0 build-10884925&#34; or os_version:=&#34;6.5.0 build-11925212&#34; or os_version:=&#34;6.5.0 build-13004031&#34; or os_version:=&#34;6.5.0 build-13635690&#34; or os_version:=&#34;6.5.0 build-13873656&#34; or os_version:=&#34;6.5.0 build-13932383&#34; or os_version:=&#34;6.5.0 build-14320405&#34; or os_version:=&#34;6.5.0 build-14874964&#34; or os_version:=&#34;6.5.0 build-14990892&#34; or os_version:=&#34;6.5.0 build-15256468&#34; or os_version:=&#34;6.5.0 build-15177306&#34; or os_version:=&#34;6.5.0 build-15256549&#34; or os_version:=&#34;6.5.0 build-16207673&#34; or os_version:=&#34;6.5.0 build-16389870&#34; or os_version:=&#34;6.5.0 build-16576879&#34; or os_version:=&#34;6.5.0 build-16576891&#34; or os_version:=&#34;6.5.0 build-16901156&#34; or os_version:=&#34;6.5.0 build-17097218&#34; or os_version:=&#34;6.5.0 build-17167537&#34; or os_version:=&#34;6.7.0 build-8169922&#34; or os_version:=&#34;6.7.0 build-8941472&#34; or os_version:=&#34;6.7.0 build-9214924&#34; or os_version:=&#34;6.7.0 build-9484548&#34; or os_version:=&#34;6.7.0 build-10176752&#34; or os_version:=&#34;6.7.0 build-10176879&#34; or os_version:=&#34;6.7.0 build-10302608&#34; or os_version:=&#34;6.7.0 build-10764712&#34; or os_version:=&#34;6.7.0 build-11675023&#34; or os_version:=&#34;6.7.0 build-13004448&#34; or os_version:=&#34;6.7.0 build-12986307&#34; or os_version:=&#34;6.7.0 build-13006603&#34; or os_version:=&#34;6.7.0 build-13473784&#34; or os_version:=&#34;6.7.0 build-13644319&#34; or os_version:=&#34;6.7.0 build-13981272&#34; or os_version:=&#34;6.7.0 build-14141615&#34; or os_version:=&#34;6.7.0 build-14320388&#34; or os_version:=&#34;6.7.0 build-15018017&#34; or os_version:=&#34;6.7.0 build-15160134&#34; or os_version:=&#34;6.7.0 build-15160138&#34; or os_version:=&#34;6.7.0 build-15999342&#34; or os_version:=&#34;6.7.0 build-15820472&#34; or os_version:=&#34;6.7.0 build-16075168&#34; or os_version:=&#34;6.7.0 build-16316930&#34; or os_version:=&#34;6.7.0 build-16701467&#34; or os_version:=&#34;6.7.0 build-16713306&#34; or os_version:=&#34;6.7.0 build-16773714&#34; or os_version:=&#34;6.7.0 build-17167699&#34; or os_version:=&#34;6.7.0 build-17098360&#34; or os_version:=&#34;6.7.0 build-17167734&#34; or os_version:=&#34;7.0.0%&#34; or os_version:=&#34;7.0.1 build-16850804&#34; or os_version:=&#34;7.0.1 build-17119627&#34; or os_version:=&#34;7.0.1 build-17168206&#34; or os_version:=&#34;7.0.1 build-17325020&#34;) assets vulnerability" data-ql-sev="high">
      <div class="ql-card-header">
        <div class="ql-title">VMware ESXi OpenSLP Heap Buffer Overflow</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-high fd-badge-sm">High</span><span class="ql-type-badge">assets</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>os:=&#34;VMware ESX%&#34; and port:427 and ( os_version:=&#34;1.%&#34; or os_version:=&#34;2.%&#34; or os_version:=&#34;3.%&#34; or os_version:=&#34;4.%&#34; or os_version:=&#34;5.%&#34; or os_version:=&#34;6.0%&#34; or os_version:=&#34;6.5.0 build-4564106&#34; or os_version:=&#34;6.5.0 build-4887370&#34; or os_version:=&#34;6.5.0 build-5146843&#34; or os_version:=&#34;6.5.0 build-5146846&#34; or os_version:=&#34;6.5.0 build-5224529&#34; or os_version:=&#34;6.5.0 build-5310538&#34; or os_version:=&#34;6.5.0 build-5969300&#34; or os_version:=&#34;6.5.0 build-5969303&#34; or os_version:=&#34;6.5.0 build-6765664&#34; or os_version:=&#34;6.5.0 build-7273056&#34; or os_version:=&#34;6.5.0 build-7388607&#34; or os_version:=&#34;6.5.0 build-7967591&#34; or os_version:=&#34;6.5.0 build-8285314&#34; or os_version:=&#34;6.5.0 build-8294253&#34; or os_version:=&#34;6.5.0 build-8935087&#34; or os_version:=&#34;6.5.0 build-9298722&#34; or os_version:=&#34;6.5.0 build-10175896&#34; or os_version:=&#34;6.5.0 build-10390116&#34; or os_version:=&#34;6.5.0 build-10719125&#34; or os_version:=&#34;6.5.0 build-10868328&#34; or os_version:=&#34;6.5.0 build-10884925&#34; or os_version:=&#34;6.5.0 build-11925212&#34; or os_version:=&#34;6.5.0 build-13004031&#34; or os_version:=&#34;6.5.0 build-13635690&#34; or os_version:=&#34;6.5.0 build-13873656&#34; or os_version:=&#34;6.5.0 build-13932383&#34; or os_version:=&#34;6.5.0 build-14320405&#34; or os_version:=&#34;6.5.0 build-14874964&#34; or os_version:=&#34;6.5.0 build-14990892&#34; or os_version:=&#34;6.5.0 build-15256468&#34; or os_version:=&#34;6.5.0 build-15177306&#34; or os_version:=&#34;6.5.0 build-15256549&#34; or os_version:=&#34;6.5.0 build-16207673&#34; or os_version:=&#34;6.5.0 build-16389870&#34; or os_version:=&#34;6.5.0 build-16576879&#34; or os_version:=&#34;6.5.0 build-16576891&#34; or os_version:=&#34;6.5.0 build-16901156&#34; or os_version:=&#34;6.5.0 build-17097218&#34; or os_version:=&#34;6.5.0 build-17167537&#34; or os_version:=&#34;6.7.0 build-8169922&#34; or os_version:=&#34;6.7.0 build-8941472&#34; or os_version:=&#34;6.7.0 build-9214924&#34; or os_version:=&#34;6.7.0 build-9484548&#34; or os_version:=&#34;6.7.0 build-10176752&#34; or os_version:=&#34;6.7.0 build-10176879&#34; or os_version:=&#34;6.7.0 build-10302608&#34; or os_version:=&#34;6.7.0 build-10764712&#34; or os_version:=&#34;6.7.0 build-11675023&#34; or os_version:=&#34;6.7.0 build-13004448&#34; or os_version:=&#34;6.7.0 build-12986307&#34; or os_version:=&#34;6.7.0 build-13006603&#34; or os_version:=&#34;6.7.0 build-13473784&#34; or os_version:=&#34;6.7.0 build-13644319&#34; or os_version:=&#34;6.7.0 build-13981272&#34; or os_version:=&#34;6.7.0 build-14141615&#34; or os_version:=&#34;6.7.0 build-14320388&#34; or os_version:=&#34;6.7.0 build-15018017&#34; or os_version:=&#34;6.7.0 build-15160134&#34; or os_version:=&#34;6.7.0 build-15160138&#34; or os_version:=&#34;6.7.0 build-15999342&#34; or os_version:=&#34;6.7.0 build-15820472&#34; or os_version:=&#34;6.7.0 build-16075168&#34; or os_version:=&#34;6.7.0 build-16316930&#34; or os_version:=&#34;6.7.0 build-16701467&#34; or os_version:=&#34;6.7.0 build-16713306&#34; or os_version:=&#34;6.7.0 build-16773714&#34; or os_version:=&#34;6.7.0 build-17167699&#34; or os_version:=&#34;6.7.0 build-17098360&#34; or os_version:=&#34;6.7.0 build-17167734&#34; or os_version:=&#34;7.0.0%&#34; or os_version:=&#34;7.0.1 build-16850804&#34; or os_version:=&#34;7.0.1 build-17119627&#34; or os_version:=&#34;7.0.1 build-17168206&#34; or os_version:=&#34;7.0.1 build-17325020&#34;)</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="os:=&#34;VMware ESX%&#34; and port:427 and ( os_version:=&#34;1.%&#34; or os_version:=&#34;2.%&#34; or os_version:=&#34;3.%&#34; or os_version:=&#34;4.%&#34; or os_version:=&#34;5.%&#34; or os_version:=&#34;6.0%&#34; or os_version:=&#34;6.5.0 build-4564106&#34; or os_version:=&#34;6.5.0 build-4887370&#34; or os_version:=&#34;6.5.0 build-5146843&#34; or os_version:=&#34;6.5.0 build-5146846&#34; or os_version:=&#34;6.5.0 build-5224529&#34; or os_version:=&#34;6.5.0 build-5310538&#34; or os_version:=&#34;6.5.0 build-5969300&#34; or os_version:=&#34;6.5.0 build-5969303&#34; or os_version:=&#34;6.5.0 build-6765664&#34; or os_version:=&#34;6.5.0 build-7273056&#34; or os_version:=&#34;6.5.0 build-7388607&#34; or os_version:=&#34;6.5.0 build-7967591&#34; or os_version:=&#34;6.5.0 build-8285314&#34; or os_version:=&#34;6.5.0 build-8294253&#34; or os_version:=&#34;6.5.0 build-8935087&#34; or os_version:=&#34;6.5.0 build-9298722&#34; or os_version:=&#34;6.5.0 build-10175896&#34; or os_version:=&#34;6.5.0 build-10390116&#34; or os_version:=&#34;6.5.0 build-10719125&#34; or os_version:=&#34;6.5.0 build-10868328&#34; or os_version:=&#34;6.5.0 build-10884925&#34; or os_version:=&#34;6.5.0 build-11925212&#34; or os_version:=&#34;6.5.0 build-13004031&#34; or os_version:=&#34;6.5.0 build-13635690&#34; or os_version:=&#34;6.5.0 build-13873656&#34; or os_version:=&#34;6.5.0 build-13932383&#34; or os_version:=&#34;6.5.0 build-14320405&#34; or os_version:=&#34;6.5.0 build-14874964&#34; or os_version:=&#34;6.5.0 build-14990892&#34; or os_version:=&#34;6.5.0 build-15256468&#34; or os_version:=&#34;6.5.0 build-15177306&#34; or os_version:=&#34;6.5.0 build-15256549&#34; or os_version:=&#34;6.5.0 build-16207673&#34; or os_version:=&#34;6.5.0 build-16389870&#34; or os_version:=&#34;6.5.0 build-16576879&#34; or os_version:=&#34;6.5.0 build-16576891&#34; or os_version:=&#34;6.5.0 build-16901156&#34; or os_version:=&#34;6.5.0 build-17097218&#34; or os_version:=&#34;6.5.0 build-17167537&#34; or os_version:=&#34;6.7.0 build-8169922&#34; or os_version:=&#34;6.7.0 build-8941472&#34; or os_version:=&#34;6.7.0 build-9214924&#34; or os_version:=&#34;6.7.0 build-9484548&#34; or os_version:=&#34;6.7.0 build-10176752&#34; or os_version:=&#34;6.7.0 build-10176879&#34; or os_version:=&#34;6.7.0 build-10302608&#34; or os_version:=&#34;6.7.0 build-10764712&#34; or os_version:=&#34;6.7.0 build-11675023&#34; or os_version:=&#34;6.7.0 build-13004448&#34; or os_version:=&#34;6.7.0 build-12986307&#34; or os_version:=&#34;6.7.0 build-13006603&#34; or os_version:=&#34;6.7.0 build-13473784&#34; or os_version:=&#34;6.7.0 build-13644319&#34; or os_version:=&#34;6.7.0 build-13981272&#34; or os_version:=&#34;6.7.0 build-14141615&#34; or os_version:=&#34;6.7.0 build-14320388&#34; or os_version:=&#34;6.7.0 build-15018017&#34; or os_version:=&#34;6.7.0 build-15160134&#34; or os_version:=&#34;6.7.0 build-15160138&#34; or os_version:=&#34;6.7.0 build-15999342&#34; or os_version:=&#34;6.7.0 build-15820472&#34; or os_version:=&#34;6.7.0 build-16075168&#34; or os_version:=&#34;6.7.0 build-16316930&#34; or os_version:=&#34;6.7.0 build-16701467&#34; or os_version:=&#34;6.7.0 build-16713306&#34; or os_version:=&#34;6.7.0 build-16773714&#34; or os_version:=&#34;6.7.0 build-17167699&#34; or os_version:=&#34;6.7.0 build-17098360&#34; or os_version:=&#34;6.7.0 build-17167734&#34; or os_version:=&#34;7.0.0%&#34; or os_version:=&#34;7.0.1 build-16850804&#34; or os_version:=&#34;7.0.1 build-17119627&#34; or os_version:=&#34;7.0.1 build-17168206&#34; or os_version:=&#34;7.0.1 build-17325020&#34;)" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/?search=os%3A%3D%22VMware+ESX%25%22+and+port%3A427+and+%28+os_version%3A%3D%221.%25%22+or+os_version%3A%3D%222.%25%22+or+os_version%3A%3D%223.%25%22+or+os_version%3A%3D%224.%25%22+or+os_version%3A%3D%225.%25%22+or+os_version%3A%3D%226.0%25%22+or+os_version%3A%3D%226.5.0+build-4564106%22+or+os_version%3A%3D%226.5.0+build-4887370%22+or+os_version%3A%3D%226.5.0+build-5146843%22+or+os_version%3A%3D%226.5.0+build-5146846%22+or+os_version%3A%3D%226.5.0+build-5224529%22+or+os_version%3A%3D%226.5.0+build-5310538%22+or+os_version%3A%3D%226.5.0+build-5969300%22+or+os_version%3A%3D%226.5.0+build-5969303%22+or+os_version%3A%3D%226.5.0+build-6765664%22+or+os_version%3A%3D%226.5.0+build-7273056%22+or+os_version%3A%3D%226.5.0+build-7388607%22+or+os_version%3A%3D%226.5.0+build-7967591%22+or+os_version%3A%3D%226.5.0+build-8285314%22+or+os_version%3A%3D%226.5.0+build-8294253%22+or+os_version%3A%3D%226.5.0+build-8935087%22+or+os_version%3A%3D%226.5.0+build-9298722%22+or+os_version%3A%3D%226.5.0+build-10175896%22+or+os_version%3A%3D%226.5.0+build-10390116%22+or+os_version%3A%3D%226.5.0+build-10719125%22+or+os_version%3A%3D%226.5.0+build-10868328%22+or+os_version%3A%3D%226.5.0+build-10884925%22+or+os_version%3A%3D%226.5.0+build-11925212%22+or+os_version%3A%3D%226.5.0+build-13004031%22+or+os_version%3A%3D%226.5.0+build-13635690%22+or+os_version%3A%3D%226.5.0+build-13873656%22+or+os_version%3A%3D%226.5.0+build-13932383%22+or+os_version%3A%3D%226.5.0+build-14320405%22+or+os_version%3A%3D%226.5.0+build-14874964%22+or+os_version%3A%3D%226.5.0+build-14990892%22+or+os_version%3A%3D%226.5.0+build-15256468%22+or+os_version%3A%3D%226.5.0+build-15177306%22+or+os_version%3A%3D%226.5.0+build-15256549%22+or+os_version%3A%3D%226.5.0+build-16207673%22+or+os_version%3A%3D%226.5.0+build-16389870%22+or+os_version%3A%3D%226.5.0+build-16576879%22+or+os_version%3A%3D%226.5.0+build-16576891%22+or+os_version%3A%3D%226.5.0+build-16901156%22+or+os_version%3A%3D%226.5.0+build-17097218%22+or+os_version%3A%3D%226.5.0+build-17167537%22+or+os_version%3A%3D%226.7.0+build-8169922%22+or+os_version%3A%3D%226.7.0+build-8941472%22+or+os_version%3A%3D%226.7.0+build-9214924%22+or+os_version%3A%3D%226.7.0+build-9484548%22+or+os_version%3A%3D%226.7.0+build-10176752%22+or+os_version%3A%3D%226.7.0+build-10176879%22+or+os_version%3A%3D%226.7.0+build-10302608%22+or+os_version%3A%3D%226.7.0+build-10764712%22+or+os_version%3A%3D%226.7.0+build-11675023%22+or+os_version%3A%3D%226.7.0+build-13004448%22+or+os_version%3A%3D%226.7.0+build-12986307%22+or+os_version%3A%3D%226.7.0+build-13006603%22+or+os_version%3A%3D%226.7.0+build-13473784%22+or+os_version%3A%3D%226.7.0+build-13644319%22+or+os_version%3A%3D%226.7.0+build-13981272%22+or+os_version%3A%3D%226.7.0+build-14141615%22+or+os_version%3A%3D%226.7.0+build-14320388%22+or+os_version%3A%3D%226.7.0+build-15018017%22+or+os_version%3A%3D%226.7.0+build-15160134%22+or+os_version%3A%3D%226.7.0+build-15160138%22+or+os_version%3A%3D%226.7.0+build-15999342%22+or+os_version%3A%3D%226.7.0+build-15820472%22+or+os_version%3A%3D%226.7.0+build-16075168%22+or+os_version%3A%3D%226.7.0+build-16316930%22+or+os_version%3A%3D%226.7.0+build-16701467%22+or+os_version%3A%3D%226.7.0+build-16713306%22+or+os_version%3A%3D%226.7.0+build-16773714%22+or+os_version%3A%3D%226.7.0+build-17167699%22+or+os_version%3A%3D%226.7.0+build-17098360%22+or+os_version%3A%3D%226.7.0+build-17167734%22+or+os_version%3A%3D%227.0.0%25%22+or+os_version%3A%3D%227.0.1+build-16850804%22+or+os_version%3A%3D%227.0.1+build-17119627%22+or+os_version%3A%3D%227.0.1+build-17168206%22+or+os_version%3A%3D%227.0.1+build-17325020%22%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/?search=os%3A%3D%22VMware+ESX%25%22+and+port%3A427+and+%28+os_version%3A%3D%221.%25%22+or+os_version%3A%3D%222.%25%22+or+os_version%3A%3D%223.%25%22+or+os_version%3A%3D%224.%25%22+or+os_version%3A%3D%225.%25%22+or+os_version%3A%3D%226.0%25%22+or+os_version%3A%3D%226.5.0+build-4564106%22+or+os_version%3A%3D%226.5.0+build-4887370%22+or+os_version%3A%3D%226.5.0+build-5146843%22+or+os_version%3A%3D%226.5.0+build-5146846%22+or+os_version%3A%3D%226.5.0+build-5224529%22+or+os_version%3A%3D%226.5.0+build-5310538%22+or+os_version%3A%3D%226.5.0+build-5969300%22+or+os_version%3A%3D%226.5.0+build-5969303%22+or+os_version%3A%3D%226.5.0+build-6765664%22+or+os_version%3A%3D%226.5.0+build-7273056%22+or+os_version%3A%3D%226.5.0+build-7388607%22+or+os_version%3A%3D%226.5.0+build-7967591%22+or+os_version%3A%3D%226.5.0+build-8285314%22+or+os_version%3A%3D%226.5.0+build-8294253%22+or+os_version%3A%3D%226.5.0+build-8935087%22+or+os_version%3A%3D%226.5.0+build-9298722%22+or+os_version%3A%3D%226.5.0+build-10175896%22+or+os_version%3A%3D%226.5.0+build-10390116%22+or+os_version%3A%3D%226.5.0+build-10719125%22+or+os_version%3A%3D%226.5.0+build-10868328%22+or+os_version%3A%3D%226.5.0+build-10884925%22+or+os_version%3A%3D%226.5.0+build-11925212%22+or+os_version%3A%3D%226.5.0+build-13004031%22+or+os_version%3A%3D%226.5.0+build-13635690%22+or+os_version%3A%3D%226.5.0+build-13873656%22+or+os_version%3A%3D%226.5.0+build-13932383%22+or+os_version%3A%3D%226.5.0+build-14320405%22+or+os_version%3A%3D%226.5.0+build-14874964%22+or+os_version%3A%3D%226.5.0+build-14990892%22+or+os_version%3A%3D%226.5.0+build-15256468%22+or+os_version%3A%3D%226.5.0+build-15177306%22+or+os_version%3A%3D%226.5.0+build-15256549%22+or+os_version%3A%3D%226.5.0+build-16207673%22+or+os_version%3A%3D%226.5.0+build-16389870%22+or+os_version%3A%3D%226.5.0+build-16576879%22+or+os_version%3A%3D%226.5.0+build-16576891%22+or+os_version%3A%3D%226.5.0+build-16901156%22+or+os_version%3A%3D%226.5.0+build-17097218%22+or+os_version%3A%3D%226.5.0+build-17167537%22+or+os_version%3A%3D%226.7.0+build-8169922%22+or+os_version%3A%3D%226.7.0+build-8941472%22+or+os_version%3A%3D%226.7.0+build-9214924%22+or+os_version%3A%3D%226.7.0+build-9484548%22+or+os_version%3A%3D%226.7.0+build-10176752%22+or+os_version%3A%3D%226.7.0+build-10176879%22+or+os_version%3A%3D%226.7.0+build-10302608%22+or+os_version%3A%3D%226.7.0+build-10764712%22+or+os_version%3A%3D%226.7.0+build-11675023%22+or+os_version%3A%3D%226.7.0+build-13004448%22+or+os_version%3A%3D%226.7.0+build-12986307%22+or+os_version%3A%3D%226.7.0+build-13006603%22+or+os_version%3A%3D%226.7.0+build-13473784%22+or+os_version%3A%3D%226.7.0+build-13644319%22+or+os_version%3A%3D%226.7.0+build-13981272%22+or+os_version%3A%3D%226.7.0+build-14141615%22+or+os_version%3A%3D%226.7.0+build-14320388%22+or+os_version%3A%3D%226.7.0+build-15018017%22+or+os_version%3A%3D%226.7.0+build-15160134%22+or+os_version%3A%3D%226.7.0+build-15160138%22+or+os_version%3A%3D%226.7.0+build-15999342%22+or+os_version%3A%3D%226.7.0+build-15820472%22+or+os_version%3A%3D%226.7.0+build-16075168%22+or+os_version%3A%3D%226.7.0+build-16316930%22+or+os_version%3A%3D%226.7.0+build-16701467%22+or+os_version%3A%3D%226.7.0+build-16713306%22+or+os_version%3A%3D%226.7.0+build-16773714%22+or+os_version%3A%3D%226.7.0+build-17167699%22+or+os_version%3A%3D%226.7.0+build-17098360%22+or+os_version%3A%3D%226.7.0+build-17167734%22+or+os_version%3A%3D%227.0.0%25%22+or+os_version%3A%3D%227.0.1+build-16850804%22+or+os_version%3A%3D%227.0.1+build-17119627%22+or+os_version%3A%3D%227.0.1+build-17168206%22+or+os_version%3A%3D%227.0.1+build-17325020%22%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="os:=&#34;VMware ESX%&#34; and port:427 and ( os_version:=&#34;1.%&#34; or os_version:=&#34;2.%&#34; or os_version:=&#34;3.%&#34; or os_version:=&#34;4.%&#34; or os_version:=&#34;5.%&#34; or os_version:=&#34;6.0%&#34; or os_version:=&#34;6.5.0 build-4564106&#34; or os_version:=&#34;6.5.0 build-4887370&#34; or os_version:=&#34;6.5.0 build-5146843&#34; or os_version:=&#34;6.5.0 build-5146846&#34; or os_version:=&#34;6.5.0 build-5224529&#34; or os_version:=&#34;6.5.0 build-5310538&#34; or os_version:=&#34;6.5.0 build-5969300&#34; or os_version:=&#34;6.5.0 build-5969303&#34; or os_version:=&#34;6.5.0 build-6765664&#34; or os_version:=&#34;6.5.0 build-7273056&#34; or os_version:=&#34;6.5.0 build-7388607&#34; or os_version:=&#34;6.5.0 build-7967591&#34; or os_version:=&#34;6.5.0 build-8285314&#34; or os_version:=&#34;6.5.0 build-8294253&#34; or os_version:=&#34;6.5.0 build-8935087&#34; or os_version:=&#34;6.5.0 build-9298722&#34; or os_version:=&#34;6.5.0 build-10175896&#34; or os_version:=&#34;6.5.0 build-10390116&#34; or os_version:=&#34;6.5.0 build-10719125&#34; or os_version:=&#34;6.5.0 build-10868328&#34; or os_version:=&#34;6.5.0 build-10884925&#34; or os_version:=&#34;6.5.0 build-11925212&#34; or os_version:=&#34;6.5.0 build-13004031&#34; or os_version:=&#34;6.5.0 build-13635690&#34; or os_version:=&#34;6.5.0 build-13873656&#34; or os_version:=&#34;6.5.0 build-13932383&#34; or os_version:=&#34;6.5.0 build-14320405&#34; or os_version:=&#34;6.5.0 build-14874964&#34; or os_version:=&#34;6.5.0 build-14990892&#34; or os_version:=&#34;6.5.0 build-15256468&#34; or os_version:=&#34;6.5.0 build-15177306&#34; or os_version:=&#34;6.5.0 build-15256549&#34; or os_version:=&#34;6.5.0 build-16207673&#34; or os_version:=&#34;6.5.0 build-16389870&#34; or os_version:=&#34;6.5.0 build-16576879&#34; or os_version:=&#34;6.5.0 build-16576891&#34; or os_version:=&#34;6.5.0 build-16901156&#34; or os_version:=&#34;6.5.0 build-17097218&#34; or os_version:=&#34;6.5.0 build-17167537&#34; or os_version:=&#34;6.7.0 build-8169922&#34; or os_version:=&#34;6.7.0 build-8941472&#34; or os_version:=&#34;6.7.0 build-9214924&#34; or os_version:=&#34;6.7.0 build-9484548&#34; or os_version:=&#34;6.7.0 build-10176752&#34; or os_version:=&#34;6.7.0 build-10176879&#34; or os_version:=&#34;6.7.0 build-10302608&#34; or os_version:=&#34;6.7.0 build-10764712&#34; or os_version:=&#34;6.7.0 build-11675023&#34; or os_version:=&#34;6.7.0 build-13004448&#34; or os_version:=&#34;6.7.0 build-12986307&#34; or os_version:=&#34;6.7.0 build-13006603&#34; or os_version:=&#34;6.7.0 build-13473784&#34; or os_version:=&#34;6.7.0 build-13644319&#34; or os_version:=&#34;6.7.0 build-13981272&#34; or os_version:=&#34;6.7.0 build-14141615&#34; or os_version:=&#34;6.7.0 build-14320388&#34; or os_version:=&#34;6.7.0 build-15018017&#34; or os_version:=&#34;6.7.0 build-15160134&#34; or os_version:=&#34;6.7.0 build-15160138&#34; or os_version:=&#34;6.7.0 build-15999342&#34; or os_version:=&#34;6.7.0 build-15820472&#34; or os_version:=&#34;6.7.0 build-16075168&#34; or os_version:=&#34;6.7.0 build-16316930&#34; or os_version:=&#34;6.7.0 build-16701467&#34; or os_version:=&#34;6.7.0 build-16713306&#34; or os_version:=&#34;6.7.0 build-16773714&#34; or os_version:=&#34;6.7.0 build-17167699&#34; or os_version:=&#34;6.7.0 build-17098360&#34; or os_version:=&#34;6.7.0 build-17167734&#34; or os_version:=&#34;7.0.0%&#34; or os_version:=&#34;7.0.1 build-16850804&#34; or os_version:=&#34;7.0.1 build-17119627&#34; or os_version:=&#34;7.0.1 build-17168206&#34; or os_version:=&#34;7.0.1 build-17325020&#34;)"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="airplay sdk remote code execution (airborne) vendor:=apple and product:=&#34;airplay sdk&#34; and ((version:&gt;2.0 and version:&lt;2.7.1) or (version:&gt;3.0 and version:&lt;3.6.0.126)) software vulnerability" data-ql-sev="medium">
      <div class="ql-card-header">
        <div class="ql-title">AirPlay SDK Remote Code Execution (AirBorne)</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><span class="ql-type-badge">software</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>vendor:=Apple AND product:=&#34;AirPlay SDK&#34; AND ((version:&gt;2.0 AND version:&lt;2.7.1) OR (version:&gt;3.0 AND version:&lt;3.6.0.126))</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="vendor:=Apple AND product:=&#34;AirPlay SDK&#34; AND ((version:&gt;2.0 AND version:&lt;2.7.1) OR (version:&gt;3.0 AND version:&lt;3.6.0.126))" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/software?search=vendor%3A%3DApple+AND+product%3A%3D%22AirPlay+SDK%22+AND+%28%28version%3A%3E2.0+AND+version%3A%3C2.7.1%29+OR+%28version%3A%3E3.0+AND+version%3A%3C3.6.0.126%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/software?search=vendor%3A%3DApple+AND+product%3A%3D%22AirPlay+SDK%22+AND+%28%28version%3A%3E2.0+AND+version%3A%3C2.7.1%29+OR+%28version%3A%3E3.0+AND+version%3A%3C3.6.0.126%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="vendor:=Apple AND product:=&#34;AirPlay SDK&#34; AND ((version:&gt;2.0 AND version:&lt;2.7.1) OR (version:&gt;3.0 AND version:&lt;3.6.0.126))"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="cisco ios xr open port vulnerability (cve-2022-20821) ((hw:=&#34;cisco ncs%&#34; or hw:=&#34;cisco 8201&#34; or hw:=&#34;cisco 8202&#34; or hw:=&#34;cisco 8208&#34; or hw:=&#34;cisco 8212&#34; or hw:=&#34;cisco 8218&#34;) and tcp_port:=6379) assets vulnerability" data-ql-sev="medium">
      <div class="ql-card-header">
        <div class="ql-title">Cisco IOS XR Open Port Vulnerability (CVE-2022-20821)</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><span class="ql-type-badge">assets</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>((hw:=&#34;Cisco NCS%&#34; OR hw:=&#34;Cisco 8201&#34; OR hw:=&#34;Cisco 8202&#34; OR hw:=&#34;Cisco 8208&#34; OR hw:=&#34;Cisco 8212&#34; OR hw:=&#34;Cisco 8218&#34;) AND tcp_port:=6379)</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="((hw:=&#34;Cisco NCS%&#34; OR hw:=&#34;Cisco 8201&#34; OR hw:=&#34;Cisco 8202&#34; OR hw:=&#34;Cisco 8208&#34; OR hw:=&#34;Cisco 8212&#34; OR hw:=&#34;Cisco 8218&#34;) AND tcp_port:=6379)" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/?search=%28%28hw%3A%3D%22Cisco+NCS%25%22+OR+hw%3A%3D%22Cisco+8201%22+OR+hw%3A%3D%22Cisco+8202%22+OR+hw%3A%3D%22Cisco+8208%22+OR+hw%3A%3D%22Cisco+8212%22+OR+hw%3A%3D%22Cisco+8218%22%29+AND+tcp_port%3A%3D6379%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/?search=%28%28hw%3A%3D%22Cisco+NCS%25%22+OR+hw%3A%3D%22Cisco+8201%22+OR+hw%3A%3D%22Cisco+8202%22+OR+hw%3A%3D%22Cisco+8208%22+OR+hw%3A%3D%22Cisco+8212%22+OR+hw%3A%3D%22Cisco+8218%22%29+AND+tcp_port%3A%3D6379%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="((hw:=&#34;Cisco NCS%&#34; OR hw:=&#34;Cisco 8201&#34; OR hw:=&#34;Cisco 8202&#34; OR hw:=&#34;Cisco 8208&#34; OR hw:=&#34;Cisco 8212&#34; OR hw:=&#34;Cisco 8218&#34;) AND tcp_port:=6379)"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="gitlab saml authentication bypass vendor:=gitlab and product:gitlab and ((version:&gt;17.9 and version:&lt;17.9.2) or (version:&gt;17.8 and version:&lt;17.8.5) or (version:&gt;17.7 and version:&lt;17.7.7)) software vulnerability" data-ql-sev="medium">
      <div class="ql-card-header">
        <div class="ql-title">GitLab SAML Authentication Bypass</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><span class="ql-type-badge">software</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>vendor:=GitLab AND product:gitlab AND ((version:&gt;17.9 AND version:&lt;17.9.2) OR (version:&gt;17.8 AND version:&lt;17.8.5) OR (version:&gt;17.7 AND version:&lt;17.7.7))</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="vendor:=GitLab AND product:gitlab AND ((version:&gt;17.9 AND version:&lt;17.9.2) OR (version:&gt;17.8 AND version:&lt;17.8.5) OR (version:&gt;17.7 AND version:&lt;17.7.7))" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/software?search=vendor%3A%3DGitLab+AND+product%3Agitlab+AND+%28%28version%3A%3E17.9+AND+version%3A%3C17.9.2%29+OR+%28version%3A%3E17.8+AND+version%3A%3C17.8.5%29+OR+%28version%3A%3E17.7+AND+version%3A%3C17.7.7%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/software?search=vendor%3A%3DGitLab+AND+product%3Agitlab+AND+%28%28version%3A%3E17.9+AND+version%3A%3C17.9.2%29+OR+%28version%3A%3E17.8+AND+version%3A%3C17.8.5%29+OR+%28version%3A%3E17.7+AND+version%3A%3C17.7.7%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="vendor:=GitLab AND product:gitlab AND ((version:&gt;17.9 AND version:&lt;17.9.2) OR (version:&gt;17.8 AND version:&lt;17.8.5) OR (version:&gt;17.7 AND version:&lt;17.7.7))"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="juniper junos os ex series missing authentication for critical function vulnerability (cve-2023-36847) hw:=&#34;juniper ex%&#34; and os:=&#34;juniper junos os&#34; and ((os_version:&gt;&#34;0&#34; and os_version:&lt;&#34;20.4r3-s8&#34;) or (os_version:&gt;=&#34;21.1&#34; and os_version:&lt;&#34;21.2r3-s6&#34;) or (os_version:&gt;=&#34;21.3&#34; and os_version:&lt;&#34;21.3r3-s5&#34;) or (os_version:&gt;=&#34;21.4&#34; and os_version:&lt;&#34;21.4r3-s4&#34;) or (os_version:&gt;=&#34;22.1&#34; and os_version:&lt;&#34;22.1r3-s3&#34;) or (os_version:&gt;=&#34;22.2&#34; and os_version:&lt;&#34;22.2r3-s1&#34;) or (os_version:&gt;=&#34;22.3&#34; and os_version:&lt;&#34;22.3r2-s2&#34;) or (os_version:&gt;=&#34;22.4&#34; and os_version:&lt;&#34;22.4r2-s1&#34;)) assets vulnerability" data-ql-sev="medium">
      <div class="ql-card-header">
        <div class="ql-title">Juniper Junos OS EX Series Missing Authentication For Critical Function Vulnerability (CVE-2023-36847)</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><span class="ql-type-badge">assets</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>hw:=&#34;Juniper EX%&#34; AND os:=&#34;Juniper Junos OS&#34; AND ((os_version:&gt;&#34;0&#34; AND os_version:&lt;&#34;20.4R3-S8&#34;) OR (os_version:&gt;=&#34;21.1&#34; AND os_version:&lt;&#34;21.2R3-S6&#34;) OR (os_version:&gt;=&#34;21.3&#34; AND os_version:&lt;&#34;21.3R3-S5&#34;) OR (os_version:&gt;=&#34;21.4&#34; AND os_version:&lt;&#34;21.4R3-S4&#34;) OR (os_version:&gt;=&#34;22.1&#34; AND os_version:&lt;&#34;22.1R3-S3&#34;) OR (os_version:&gt;=&#34;22.2&#34; AND os_version:&lt;&#34;22.2R3-S1&#34;) OR (os_version:&gt;=&#34;22.3&#34; AND os_version:&lt;&#34;22.3R2-S2&#34;) OR (os_version:&gt;=&#34;22.4&#34; AND os_version:&lt;&#34;22.4R2-S1&#34;))</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="hw:=&#34;Juniper EX%&#34; AND os:=&#34;Juniper Junos OS&#34; AND ((os_version:&gt;&#34;0&#34; AND os_version:&lt;&#34;20.4R3-S8&#34;) OR (os_version:&gt;=&#34;21.1&#34; AND os_version:&lt;&#34;21.2R3-S6&#34;) OR (os_version:&gt;=&#34;21.3&#34; AND os_version:&lt;&#34;21.3R3-S5&#34;) OR (os_version:&gt;=&#34;21.4&#34; AND os_version:&lt;&#34;21.4R3-S4&#34;) OR (os_version:&gt;=&#34;22.1&#34; AND os_version:&lt;&#34;22.1R3-S3&#34;) OR (os_version:&gt;=&#34;22.2&#34; AND os_version:&lt;&#34;22.2R3-S1&#34;) OR (os_version:&gt;=&#34;22.3&#34; AND os_version:&lt;&#34;22.3R2-S2&#34;) OR (os_version:&gt;=&#34;22.4&#34; AND os_version:&lt;&#34;22.4R2-S1&#34;))" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/?search=hw%3A%3D%22Juniper+EX%25%22+AND+os%3A%3D%22Juniper+Junos+OS%22+AND+%28%28os_version%3A%3E%220%22+AND+os_version%3A%3C%2220.4R3-S8%22%29+OR+%28os_version%3A%3E%3D%2221.1%22+AND+os_version%3A%3C%2221.2R3-S6%22%29+OR+%28os_version%3A%3E%3D%2221.3%22+AND+os_version%3A%3C%2221.3R3-S5%22%29+OR+%28os_version%3A%3E%3D%2221.4%22+AND+os_version%3A%3C%2221.4R3-S4%22%29+OR+%28os_version%3A%3E%3D%2222.1%22+AND+os_version%3A%3C%2222.1R3-S3%22%29+OR+%28os_version%3A%3E%3D%2222.2%22+AND+os_version%3A%3C%2222.2R3-S1%22%29+OR+%28os_version%3A%3E%3D%2222.3%22+AND+os_version%3A%3C%2222.3R2-S2%22%29+OR+%28os_version%3A%3E%3D%2222.4%22+AND+os_version%3A%3C%2222.4R2-S1%22%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/?search=hw%3A%3D%22Juniper+EX%25%22+AND+os%3A%3D%22Juniper+Junos+OS%22+AND+%28%28os_version%3A%3E%220%22+AND+os_version%3A%3C%2220.4R3-S8%22%29+OR+%28os_version%3A%3E%3D%2221.1%22+AND+os_version%3A%3C%2221.2R3-S6%22%29+OR+%28os_version%3A%3E%3D%2221.3%22+AND+os_version%3A%3C%2221.3R3-S5%22%29+OR+%28os_version%3A%3E%3D%2221.4%22+AND+os_version%3A%3C%2221.4R3-S4%22%29+OR+%28os_version%3A%3E%3D%2222.1%22+AND+os_version%3A%3C%2222.1R3-S3%22%29+OR+%28os_version%3A%3E%3D%2222.2%22+AND+os_version%3A%3C%2222.2R3-S1%22%29+OR+%28os_version%3A%3E%3D%2222.3%22+AND+os_version%3A%3C%2222.3R2-S2%22%29+OR+%28os_version%3A%3E%3D%2222.4%22+AND+os_version%3A%3C%2222.4R2-S1%22%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="hw:=&#34;Juniper EX%&#34; AND os:=&#34;Juniper Junos OS&#34; AND ((os_version:&gt;&#34;0&#34; AND os_version:&lt;&#34;20.4R3-S8&#34;) OR (os_version:&gt;=&#34;21.1&#34; AND os_version:&lt;&#34;21.2R3-S6&#34;) OR (os_version:&gt;=&#34;21.3&#34; AND os_version:&lt;&#34;21.3R3-S5&#34;) OR (os_version:&gt;=&#34;21.4&#34; AND os_version:&lt;&#34;21.4R3-S4&#34;) OR (os_version:&gt;=&#34;22.1&#34; AND os_version:&lt;&#34;22.1R3-S3&#34;) OR (os_version:&gt;=&#34;22.2&#34; AND os_version:&lt;&#34;22.2R3-S1&#34;) OR (os_version:&gt;=&#34;22.3&#34; AND os_version:&lt;&#34;22.3R2-S2&#34;) OR (os_version:&gt;=&#34;22.4&#34; AND os_version:&lt;&#34;22.4R2-S1&#34;))"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="juniper junos os srx series missing authentication for critical function vulnerability (cve-2023-36846) hw:=&#34;juniper srx%&#34; and os:=&#34;juniper junos os&#34; and ((os_version:&gt;&#34;0&#34; and os_version:&lt;&#34;20.4r3-s8&#34;) or (os_version:&gt;=&#34;21.1r1&#34; and os_version:&lt;&#34;21.2r3-s6&#34;) or (os_version:&gt;=&#34;21.3&#34; and os_version:&lt;&#34;21.3r3-s5&#34;) or (os_version:&gt;=&#34;21.4&#34; and os_version:&lt;&#34;21.4r3-s5&#34;) or (os_version:&gt;=&#34;22.1&#34; and os_version:&lt;&#34;22.1r3-s3&#34;) or (os_version:&gt;=&#34;22.2&#34; and os_version:&lt;&#34;22.2r3-s2&#34;) or (os_version:&gt;=&#34;22.3&#34; and os_version:&lt;&#34;22.3r2-s2&#34;) or (os_version:&gt;=&#34;22.4&#34; and os_version:&lt;&#34;22.4r2-s1&#34;)) assets vulnerability" data-ql-sev="medium">
      <div class="ql-card-header">
        <div class="ql-title">Juniper Junos OS SRX Series Missing Authentication For Critical Function Vulnerability (CVE-2023-36846)</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><span class="ql-type-badge">assets</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>hw:=&#34;Juniper SRX%&#34; AND os:=&#34;Juniper Junos OS&#34; AND ((os_version:&gt;&#34;0&#34; AND os_version:&lt;&#34;20.4R3-S8&#34;) OR (os_version:&gt;=&#34;21.1R1&#34; AND os_version:&lt;&#34;21.2R3-S6&#34;) OR (os_version:&gt;=&#34;21.3&#34; AND os_version:&lt;&#34;21.3R3-S5&#34;) OR (os_version:&gt;=&#34;21.4&#34; AND os_version:&lt;&#34;21.4R3-S5&#34;) OR (os_version:&gt;=&#34;22.1&#34; AND os_version:&lt;&#34;22.1R3-S3&#34;) OR (os_version:&gt;=&#34;22.2&#34; AND os_version:&lt;&#34;22.2R3-S2&#34;) OR (os_version:&gt;=&#34;22.3&#34; AND os_version:&lt;&#34;22.3R2-S2&#34;) OR (os_version:&gt;=&#34;22.4&#34; AND os_version:&lt;&#34;22.4R2-S1&#34;))</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="hw:=&#34;Juniper SRX%&#34; AND os:=&#34;Juniper Junos OS&#34; AND ((os_version:&gt;&#34;0&#34; AND os_version:&lt;&#34;20.4R3-S8&#34;) OR (os_version:&gt;=&#34;21.1R1&#34; AND os_version:&lt;&#34;21.2R3-S6&#34;) OR (os_version:&gt;=&#34;21.3&#34; AND os_version:&lt;&#34;21.3R3-S5&#34;) OR (os_version:&gt;=&#34;21.4&#34; AND os_version:&lt;&#34;21.4R3-S5&#34;) OR (os_version:&gt;=&#34;22.1&#34; AND os_version:&lt;&#34;22.1R3-S3&#34;) OR (os_version:&gt;=&#34;22.2&#34; AND os_version:&lt;&#34;22.2R3-S2&#34;) OR (os_version:&gt;=&#34;22.3&#34; AND os_version:&lt;&#34;22.3R2-S2&#34;) OR (os_version:&gt;=&#34;22.4&#34; AND os_version:&lt;&#34;22.4R2-S1&#34;))" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/?search=hw%3A%3D%22Juniper+SRX%25%22+AND+os%3A%3D%22Juniper+Junos+OS%22+AND+%28%28os_version%3A%3E%220%22+AND+os_version%3A%3C%2220.4R3-S8%22%29+OR+%28os_version%3A%3E%3D%2221.1R1%22+AND+os_version%3A%3C%2221.2R3-S6%22%29+OR+%28os_version%3A%3E%3D%2221.3%22+AND+os_version%3A%3C%2221.3R3-S5%22%29+OR+%28os_version%3A%3E%3D%2221.4%22+AND+os_version%3A%3C%2221.4R3-S5%22%29+OR+%28os_version%3A%3E%3D%2222.1%22+AND+os_version%3A%3C%2222.1R3-S3%22%29+OR+%28os_version%3A%3E%3D%2222.2%22+AND+os_version%3A%3C%2222.2R3-S2%22%29+OR+%28os_version%3A%3E%3D%2222.3%22+AND+os_version%3A%3C%2222.3R2-S2%22%29+OR+%28os_version%3A%3E%3D%2222.4%22+AND+os_version%3A%3C%2222.4R2-S1%22%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/?search=hw%3A%3D%22Juniper+SRX%25%22+AND+os%3A%3D%22Juniper+Junos+OS%22+AND+%28%28os_version%3A%3E%220%22+AND+os_version%3A%3C%2220.4R3-S8%22%29+OR+%28os_version%3A%3E%3D%2221.1R1%22+AND+os_version%3A%3C%2221.2R3-S6%22%29+OR+%28os_version%3A%3E%3D%2221.3%22+AND+os_version%3A%3C%2221.3R3-S5%22%29+OR+%28os_version%3A%3E%3D%2221.4%22+AND+os_version%3A%3C%2221.4R3-S5%22%29+OR+%28os_version%3A%3E%3D%2222.1%22+AND+os_version%3A%3C%2222.1R3-S3%22%29+OR+%28os_version%3A%3E%3D%2222.2%22+AND+os_version%3A%3C%2222.2R3-S2%22%29+OR+%28os_version%3A%3E%3D%2222.3%22+AND+os_version%3A%3C%2222.3R2-S2%22%29+OR+%28os_version%3A%3E%3D%2222.4%22+AND+os_version%3A%3C%2222.4R2-S1%22%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="hw:=&#34;Juniper SRX%&#34; AND os:=&#34;Juniper Junos OS&#34; AND ((os_version:&gt;&#34;0&#34; AND os_version:&lt;&#34;20.4R3-S8&#34;) OR (os_version:&gt;=&#34;21.1R1&#34; AND os_version:&lt;&#34;21.2R3-S6&#34;) OR (os_version:&gt;=&#34;21.3&#34; AND os_version:&lt;&#34;21.3R3-S5&#34;) OR (os_version:&gt;=&#34;21.4&#34; AND os_version:&lt;&#34;21.4R3-S5&#34;) OR (os_version:&gt;=&#34;22.1&#34; AND os_version:&lt;&#34;22.1R3-S3&#34;) OR (os_version:&gt;=&#34;22.2&#34; AND os_version:&lt;&#34;22.2R3-S2&#34;) OR (os_version:&gt;=&#34;22.3&#34; AND os_version:&lt;&#34;22.3R2-S2&#34;) OR (os_version:&gt;=&#34;22.4&#34; AND os_version:&lt;&#34;22.4R2-S1&#34;))"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="juniper junos os srx series missing authentication for critical function vulnerability (cve-2023-36851) hw:=&#34;juniper srx%&#34; and os:=&#34;juniper junos os&#34; and ((os_version:&gt;=&#34;21.2&#34; and os_version:&lt;&#34;21.2r3-s8&#34;) or (os_version:&gt;=&#34;21.4&#34; and os_version:&lt;&#34;21.4r3-s6&#34;) or (os_version:&gt;=&#34;22.1&#34; and os_version:&lt;&#34;22.1r3-s5&#34;) or (os_version:&gt;=&#34;22.2&#34; and os_version:&lt;&#34;22.2r3-s3&#34;) or (os_version:&gt;=&#34;22.3&#34; and os_version:&lt;&#34;22.3r3-s2&#34;) or (os_version:&gt;=&#34;22.4&#34; and os_version:&lt;&#34;22.4r2-s2&#34;) or (os_version:&gt;=&#34;23.2&#34; and os_version:&lt;&#34;23.2r1-s2&#34;)) assets vulnerability" data-ql-sev="medium">
      <div class="ql-card-header">
        <div class="ql-title">Juniper Junos OS SRX Series Missing Authentication For Critical Function Vulnerability (CVE-2023-36851)</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><span class="ql-type-badge">assets</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>hw:=&#34;Juniper SRX%&#34; AND os:=&#34;Juniper Junos OS&#34; AND ((os_version:&gt;=&#34;21.2&#34; AND os_version:&lt;&#34;21.2R3-S8&#34;) OR (os_version:&gt;=&#34;21.4&#34; AND os_version:&lt;&#34;21.4R3-S6&#34;) OR (os_version:&gt;=&#34;22.1&#34; AND os_version:&lt;&#34;22.1R3-S5&#34;) OR (os_version:&gt;=&#34;22.2&#34; AND os_version:&lt;&#34;22.2R3-S3&#34;) OR (os_version:&gt;=&#34;22.3&#34; AND os_version:&lt;&#34;22.3R3-S2&#34;) OR (os_version:&gt;=&#34;22.4&#34; AND os_version:&lt;&#34;22.4R2-S2&#34;) OR (os_version:&gt;=&#34;23.2&#34; AND os_version:&lt;&#34;23.2R1-S2&#34;))</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="hw:=&#34;Juniper SRX%&#34; AND os:=&#34;Juniper Junos OS&#34; AND ((os_version:&gt;=&#34;21.2&#34; AND os_version:&lt;&#34;21.2R3-S8&#34;) OR (os_version:&gt;=&#34;21.4&#34; AND os_version:&lt;&#34;21.4R3-S6&#34;) OR (os_version:&gt;=&#34;22.1&#34; AND os_version:&lt;&#34;22.1R3-S5&#34;) OR (os_version:&gt;=&#34;22.2&#34; AND os_version:&lt;&#34;22.2R3-S3&#34;) OR (os_version:&gt;=&#34;22.3&#34; AND os_version:&lt;&#34;22.3R3-S2&#34;) OR (os_version:&gt;=&#34;22.4&#34; AND os_version:&lt;&#34;22.4R2-S2&#34;) OR (os_version:&gt;=&#34;23.2&#34; AND os_version:&lt;&#34;23.2R1-S2&#34;))" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/?search=hw%3A%3D%22Juniper+SRX%25%22+AND+os%3A%3D%22Juniper+Junos+OS%22+AND+%28%28os_version%3A%3E%3D%2221.2%22+AND+os_version%3A%3C%2221.2R3-S8%22%29+OR+%28os_version%3A%3E%3D%2221.4%22+AND+os_version%3A%3C%2221.4R3-S6%22%29+OR+%28os_version%3A%3E%3D%2222.1%22+AND+os_version%3A%3C%2222.1R3-S5%22%29+OR+%28os_version%3A%3E%3D%2222.2%22+AND+os_version%3A%3C%2222.2R3-S3%22%29+OR+%28os_version%3A%3E%3D%2222.3%22+AND+os_version%3A%3C%2222.3R3-S2%22%29+OR+%28os_version%3A%3E%3D%2222.4%22+AND+os_version%3A%3C%2222.4R2-S2%22%29+OR+%28os_version%3A%3E%3D%2223.2%22+AND+os_version%3A%3C%2223.2R1-S2%22%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/?search=hw%3A%3D%22Juniper+SRX%25%22+AND+os%3A%3D%22Juniper+Junos+OS%22+AND+%28%28os_version%3A%3E%3D%2221.2%22+AND+os_version%3A%3C%2221.2R3-S8%22%29+OR+%28os_version%3A%3E%3D%2221.4%22+AND+os_version%3A%3C%2221.4R3-S6%22%29+OR+%28os_version%3A%3E%3D%2222.1%22+AND+os_version%3A%3C%2222.1R3-S5%22%29+OR+%28os_version%3A%3E%3D%2222.2%22+AND+os_version%3A%3C%2222.2R3-S3%22%29+OR+%28os_version%3A%3E%3D%2222.3%22+AND+os_version%3A%3C%2222.3R3-S2%22%29+OR+%28os_version%3A%3E%3D%2222.4%22+AND+os_version%3A%3C%2222.4R2-S2%22%29+OR+%28os_version%3A%3E%3D%2223.2%22+AND+os_version%3A%3C%2223.2R1-S2%22%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="hw:=&#34;Juniper SRX%&#34; AND os:=&#34;Juniper Junos OS&#34; AND ((os_version:&gt;=&#34;21.2&#34; AND os_version:&lt;&#34;21.2R3-S8&#34;) OR (os_version:&gt;=&#34;21.4&#34; AND os_version:&lt;&#34;21.4R3-S6&#34;) OR (os_version:&gt;=&#34;22.1&#34; AND os_version:&lt;&#34;22.1R3-S5&#34;) OR (os_version:&gt;=&#34;22.2&#34; AND os_version:&lt;&#34;22.2R3-S3&#34;) OR (os_version:&gt;=&#34;22.3&#34; AND os_version:&lt;&#34;22.3R3-S2&#34;) OR (os_version:&gt;=&#34;22.4&#34; AND os_version:&lt;&#34;22.4R2-S2&#34;) OR (os_version:&gt;=&#34;23.2&#34; AND os_version:&lt;&#34;23.2R1-S2&#34;))"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="microsoft sharepoint improper authentication vulnerability (cve-2025-49705) vendor:=microsoft and product:=&#34;sharepoint server%&#34; and ((version:&gt;=16.0.4366.1000 and version:&lt;16.0.5508.1000) or (version:&gt;=16.0.10338.12107 and version:&lt;16.0.10417.20059) or (version:&gt;=16.0.14326.20620 and version:&lt;16.0.18526.20424)) software vulnerability" data-ql-sev="medium">
      <div class="ql-card-header">
        <div class="ql-title">Microsoft SharePoint Improper Authentication Vulnerability (CVE-2025-49705)</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><span class="ql-type-badge">software</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>vendor:=Microsoft AND product:=&#34;SharePoint Server%&#34; AND ((version:&gt;=16.0.4366.1000 AND version:&lt;16.0.5508.1000) OR (version:&gt;=16.0.10338.12107 AND version:&lt;16.0.10417.20059) OR (version:&gt;=16.0.14326.20620 AND version:&lt;16.0.18526.20424))</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="vendor:=Microsoft AND product:=&#34;SharePoint Server%&#34; AND ((version:&gt;=16.0.4366.1000 AND version:&lt;16.0.5508.1000) OR (version:&gt;=16.0.10338.12107 AND version:&lt;16.0.10417.20059) OR (version:&gt;=16.0.14326.20620 AND version:&lt;16.0.18526.20424))" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/software?search=vendor%3A%3DMicrosoft+AND+product%3A%3D%22SharePoint+Server%25%22+AND+%28%28version%3A%3E%3D16.0.4366.1000+AND+version%3A%3C16.0.5508.1000%29+OR+%28version%3A%3E%3D16.0.10338.12107+AND+version%3A%3C16.0.10417.20059%29+OR+%28version%3A%3E%3D16.0.14326.20620+AND+version%3A%3C16.0.18526.20424%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/software?search=vendor%3A%3DMicrosoft+AND+product%3A%3D%22SharePoint+Server%25%22+AND+%28%28version%3A%3E%3D16.0.4366.1000+AND+version%3A%3C16.0.5508.1000%29+OR+%28version%3A%3E%3D16.0.10338.12107+AND+version%3A%3C16.0.10417.20059%29+OR+%28version%3A%3E%3D16.0.14326.20620+AND+version%3A%3C16.0.18526.20424%29%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="vendor:=Microsoft AND product:=&#34;SharePoint Server%&#34; AND ((version:&gt;=16.0.4366.1000 AND version:&lt;16.0.5508.1000) OR (version:&gt;=16.0.10338.12107 AND version:&lt;16.0.10417.20059) OR (version:&gt;=16.0.14326.20620 AND version:&lt;16.0.18526.20424))"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="openssh 9.1p1 double-free _asset.protocol:=ssh and protocol:=ssh and (_service.product:=&#34;openbsd:openssh:9.1&#34; or _service.product:=&#34;openbsd:openssh:9.1p1&#34;) services vulnerability" data-ql-sev="medium">
      <div class="ql-card-header">
        <div class="ql-title">OpenSSH 9.1p1 Double-Free</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><span class="ql-type-badge">services</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>_asset.protocol:=ssh AND protocol:=ssh AND (_service.product:=&#34;OpenBSD:OpenSSH:9.1&#34; OR _service.product:=&#34;OpenBSD:OpenSSH:9.1p1&#34;)</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="_asset.protocol:=ssh AND protocol:=ssh AND (_service.product:=&#34;OpenBSD:OpenSSH:9.1&#34; OR _service.product:=&#34;OpenBSD:OpenSSH:9.1p1&#34;)" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/services?search=_asset.protocol%3A%3Dssh+AND+protocol%3A%3Dssh+AND+%28_service.product%3A%3D%22OpenBSD%3AOpenSSH%3A9.1%22+OR+_service.product%3A%3D%22OpenBSD%3AOpenSSH%3A9.1p1%22%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/services?search=_asset.protocol%3A%3Dssh+AND+protocol%3A%3Dssh+AND+%28_service.product%3A%3D%22OpenBSD%3AOpenSSH%3A9.1%22+OR+_service.product%3A%3D%22OpenBSD%3AOpenSSH%3A9.1p1%22%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="_asset.protocol:=ssh AND protocol:=ssh AND (_service.product:=&#34;OpenBSD:OpenSSH:9.1&#34; OR _service.product:=&#34;OpenBSD:OpenSSH:9.1p1&#34;)"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="plex media server 1.41.7.x to 1.42.0.x &lt; 1.42.1 undisclosed vulnerability (cve-2025-34158) vendor:=plex and product:&#34;media server&#34; and (version:&gt;0 and version:&lt;&#34;1.42.1&#34;) software vulnerability" data-ql-sev="medium">
      <div class="ql-card-header">
        <div class="ql-title">Plex Media Server 1.41.7.X To 1.42.0.X &lt; 1.42.1 Undisclosed Vulnerability (CVE-2025-34158)</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><span class="ql-type-badge">software</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>vendor:=Plex AND product:&#34;Media Server&#34; AND (version:&gt;0 AND version:&lt;&#34;1.42.1&#34;)</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="vendor:=Plex AND product:&#34;Media Server&#34; AND (version:&gt;0 AND version:&lt;&#34;1.42.1&#34;)" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/software?search=vendor%3A%3DPlex+AND+product%3A%22Media+Server%22+AND+%28version%3A%3E0+AND+version%3A%3C%221.42.1%22%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/software?search=vendor%3A%3DPlex+AND+product%3A%22Media+Server%22+AND+%28version%3A%3E0+AND+version%3A%3C%221.42.1%22%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="vendor:=Plex AND product:&#34;Media Server&#34; AND (version:&gt;0 AND version:&lt;&#34;1.42.1&#34;)"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="lighttpd web server out-of-bounds memory read product:lighttpd (_service.product:=lighttpd:lighttpd:1.4.0% or _service.product:=lighttpd:lighttpd:1.4.1% or _service.product:=lighttpd:lighttpd:1.4.2% or _service.product:=lighttpd:lighttpd:1.4.3% or _service.product:=lighttpd:lighttpd:1.4.4%) services vulnerability" data-ql-sev="medium">
      <div class="ql-card-header">
        <div class="ql-title">lighttpd Web Server Out-of-Bounds Memory Read</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-medium fd-badge-sm">Medium</span><span class="ql-type-badge">services</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>product:lighttpd (_service.product:=lighttpd:lighttpd:1.4.0% OR _service.product:=lighttpd:lighttpd:1.4.1% OR _service.product:=lighttpd:lighttpd:1.4.2% OR _service.product:=lighttpd:lighttpd:1.4.3% OR _service.product:=lighttpd:lighttpd:1.4.4%)</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="product:lighttpd (_service.product:=lighttpd:lighttpd:1.4.0% OR _service.product:=lighttpd:lighttpd:1.4.1% OR _service.product:=lighttpd:lighttpd:1.4.2% OR _service.product:=lighttpd:lighttpd:1.4.3% OR _service.product:=lighttpd:lighttpd:1.4.4%)" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/services?search=product%3Alighttpd+%28_service.product%3A%3Dlighttpd%3Alighttpd%3A1.4.0%25+OR+_service.product%3A%3Dlighttpd%3Alighttpd%3A1.4.1%25+OR+_service.product%3A%3Dlighttpd%3Alighttpd%3A1.4.2%25+OR+_service.product%3A%3Dlighttpd%3Alighttpd%3A1.4.3%25+OR+_service.product%3A%3Dlighttpd%3Alighttpd%3A1.4.4%25%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/services?search=product%3Alighttpd+%28_service.product%3A%3Dlighttpd%3Alighttpd%3A1.4.0%25+OR+_service.product%3A%3Dlighttpd%3Alighttpd%3A1.4.1%25+OR+_service.product%3A%3Dlighttpd%3Alighttpd%3A1.4.2%25+OR+_service.product%3A%3Dlighttpd%3Alighttpd%3A1.4.3%25+OR+_service.product%3A%3Dlighttpd%3Alighttpd%3A1.4.4%25%29" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="product:lighttpd (_service.product:=lighttpd:lighttpd:1.4.0% OR _service.product:=lighttpd:lighttpd:1.4.1% OR _service.product:=lighttpd:lighttpd:1.4.2% OR _service.product:=lighttpd:lighttpd:1.4.3% OR _service.product:=lighttpd:lighttpd:1.4.4%)"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="assets with active rr vulnerability finding_code:rz-finding-rapid-response-assets or finding_code:rz-finding-rapid-response-services assets vulnerability" data-ql-sev="low">
      <div class="ql-card-header">
        <div class="ql-title">Assets With Active RR Vulnerability</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><span class="ql-type-badge">assets</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>finding_code:rz-finding-rapid-response-assets OR finding_code:rz-finding-rapid-response-services</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="finding_code:rz-finding-rapid-response-assets OR finding_code:rz-finding-rapid-response-services" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/?search=finding_code%3Arz-finding-rapid-response-assets+OR+finding_code%3Arz-finding-rapid-response-services" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/?search=finding_code%3Arz-finding-rapid-response-assets+OR+finding_code%3Arz-finding-rapid-response-services" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="finding_code:rz-finding-rapid-response-assets OR finding_code:rz-finding-rapid-response-services"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="exploitable cloud assets vuln_exploitable:t and attack_surface:cloud assets vulnerability" data-ql-sev="low">
      <div class="ql-card-header">
        <div class="ql-title">Exploitable Cloud Assets</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><span class="ql-type-badge">assets</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>vuln_exploitable:t AND attack_surface:cloud</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="vuln_exploitable:t AND attack_surface:cloud" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/?search=vuln_exploitable%3At+AND+attack_surface%3Acloud" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/?search=vuln_exploitable%3At+AND+attack_surface%3Acloud" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="vuln_exploitable:t AND attack_surface:cloud"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="exploitable external assets vuln_exploitable:t and attack_surface:external assets vulnerability" data-ql-sev="low">
      <div class="ql-card-header">
        <div class="ql-title">Exploitable External Assets</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><span class="ql-type-badge">assets</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>vuln_exploitable:t AND attack_surface:external</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="vuln_exploitable:t AND attack_surface:external" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/?search=vuln_exploitable%3At+AND+attack_surface%3Aexternal" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/?search=vuln_exploitable%3At+AND+attack_surface%3Aexternal" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="vuln_exploitable:t AND attack_surface:external"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="exploitable internal assets vuln_exploitable:t and attack_surface:internal assets vulnerability" data-ql-sev="low">
      <div class="ql-card-header">
        <div class="ql-title">Exploitable Internal Assets</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><span class="ql-type-badge">assets</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>vuln_exploitable:t AND attack_surface:internal</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="vuln_exploitable:t AND attack_surface:internal" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/?search=vuln_exploitable%3At+AND+attack_surface%3Ainternal" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/?search=vuln_exploitable%3At+AND+attack_surface%3Ainternal" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="vuln_exploitable:t AND attack_surface:internal"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
    <div class="ql-card" data-ql-search="exploitable vulnerabilities exploitable:t vulnerabilities vulnerability" data-ql-sev="low">
      <div class="ql-card-header">
        <div class="ql-title">Exploitable Vulnerabilities</div>
        <div class="ql-meta"><span class="fd-badge fd-risk-low fd-badge-sm">Low</span><span class="ql-type-badge">vulnerabilities</span></div>
      </div>
      <div class="ql-code-section">
        <div class="ql-query-wrap">
          <pre><code>exploitable:t</code></pre>
          <button class="fd-copy-btn" onclick="qlCopy(this)" data-query="exploitable:t" title="Copy query"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg></button>
        </div>
        <div class="ql-action-bar">
          <a href="https://console.runzero.com/inventory/vulnerabilities?search=exploitable%3At" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> US Console</a><a href="https://console-eu.runzero.com/inventory/vulnerabilities?search=exploitable%3At" target="_blank" rel="noopener" class="rr-action"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"/><polyline points="15 3 21 3 21 9"/><line x1="10" y1="14" x2="21" y2="3"/></svg> EU Console</a><button class="rr-action" onclick="qlCopy(this)" data-query="exploitable:t"><svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect x="9" y="9" width="13" height="13" rx="2" ry="2"/><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1"/></svg> Copy</button>
        </div>
      </div>
    </div>
  </div>
</div>
</template>
<script>
(function(){var t=document.getElementById('ql-grid-content');var h=document.getElementById('ql-grid-host');if(t&&h){requestAnimationFrame(function(){h.innerHTML='';h.appendChild(t.content);t.remove();})}})();
function qlCopy(btn){
  var q=btn.getAttribute('data-query');
  var orig=btn.innerHTML;
  navigator.clipboard.writeText(q).then(function(){
    btn.classList.add('copied');
    btn.innerHTML='<svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><polyline points="20 6 9 17 4 12"/></svg>';
    setTimeout(function(){btn.classList.remove('copied');btn.innerHTML=orig;},1500);
  });
}
var qlActiveSevs=new Set(['critical','high','medium','low','info']);
function qlToggleSev(btn){
  var s=btn.getAttribute('data-sev');
  if(qlActiveSevs.has(s)){qlActiveSevs.delete(s);btn.classList.remove('active');}
  else{qlActiveSevs.add(s);btn.classList.add('active');}
  qlFilter();
}
function qlFilter(){
  var term=(document.querySelector('.ql-search').value||'').toLowerCase();
  var cards=document.querySelectorAll('.ql-card');
  var shown=0;
  cards.forEach(function(c){
    var textMatch=!term||c.getAttribute('data-ql-search').indexOf(term)!==-1;
    var sevMatch=qlActiveSevs.has(c.getAttribute('data-ql-sev'));
    var visible=textMatch&&sevMatch;
    c.classList.toggle('ql-hidden',!visible);
    if(visible) shown++;
  });
  document.getElementById('ql-match-count').textContent=shown;
  // Hide empty categories
  document.querySelectorAll('.ql-category').forEach(function(cat){
    var vis=cat.querySelectorAll('.ql-card:not(.ql-hidden)').length;
    cat.classList.toggle('ql-hidden',vis===0);
  });
}
function qlToggleCat(btn){
  var body=btn.nextElementSibling;
  var collapsed=body.classList.toggle('ql-cat-collapsed');
  btn.querySelector('.ql-cat-chevron').textContent=collapsed?'\u25B6':'\u25BC';
}
</script>

<p>runZero includes a substantial library of pre-built queries. These queries can be used to detect vulnerabilities, trigger alerts, and apply changes to assets, such as tags and ownership. These queries are categorized by use case and risk level. Custom queries can also be configured to report vulnerabilities on matching assets and services.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Rapid responses]]></title>
    <link href="https://www.runzero.com/docs/em-rapid-response/"/>
    <id>https://www.runzero.com/docs/em-rapid-response/</id>
      
      <published>2026-04-11T16:31:16+00:00</published>
      <updated>2026-04-11T16:31:16+00:00</updated>
      <summary type="html"><![CDATA[<p>runZero’s Rapid Response program provides immediate detection and notification of emerging threats. Older entries are migrated to standalone <a href="/docs/em-queries/">queries</a> or <a href="/docs/em-templates/">templates</a>.</p>
<div class="summary-chart summary-chart-compact"><div class="summary-stats"><div class="summary-stat summary-stat-hero"><div class="summary-stat-value">4</div><div class="summary-stat-label">Rapid Responses</div></div><div class="summary-divider"></div><div class="summary-stat summary-stat-hero"><div class="summary-stat-value">3</div><div class="summary-stat-label">software</div></div><div class="summary-stat summary-stat-hero"><div class="summary-stat-value">1</div><div class="summary-stat-label">assets</div></div></div></div><input type="text" class="rr-search" placeholder="Filter by name or query..." oninput="rrFilter(this.value)"><div class="rr-count"><span id="rr-match-count">4</span> of 4 rapid responses</div><div class="rr-grid">
<div class="rr-card" data-rr-search="palo alto networks pan-os globalprotect authentication bypass (cve-2026-0257) hw:=&#34;palo alto networks&#34; and os:=&#34;palo alto networks pan-os%&#34; and os_version:&gt;0 and ((os_version:&gt;=&#34;12.1.5&#34; and os_version:&lt;&#34;12.1.7&#34;) or (os_version:&gt;=&#34;12.1.2&#34; and os_version:&lt;&#34;12.1.4-h6&#34;) or (os_version:&gt;=&#34;11.2.11&#34; and os_version:&lt;&#34;11.2.12&#34;) or (os_version:&gt;=&#34;11.2.8&#34; and os_version:&lt;&#34;11.2.10-h7&#34;) or (os_version:&gt;=&#34;11.2.5&#34; and os_version:&lt;&#34;11.2.7-h14&#34;) or (os_version:&gt;=&#34;11.2.0&#34; and os_version:&lt;&#34;11.2.4-h17&#34;) or (os_version:&gt;=&#34;11.1.14&#34; and os_version:&lt;&#34;11.1.15&#34;) or (os_version:&gt;=&#34;11.1.11&#34; and os_version:&lt;&#34;11.1.13-h5&#34;) or (os_version:&gt;=&#34;11.1.8&#34; and os_version:&lt;&#34;11.1.10-h25&#34;) or (os_version:&gt;=&#34;11.1.7&#34; and os_version:&lt;&#34;11.1.7-h6&#34;) or (os_version:&gt;=&#34;11.1.5&#34; and os_version:&lt;&#34;11.1.6-h32&#34;) or (os_version:&gt;=&#34;11.1.0&#34; and os_version:&lt;&#34;11.1.4-h33&#34;) or (os_version:&gt;=&#34;10.2.17&#34; and os_version:&lt;&#34;10.2.18-h6&#34;) or (os_version:&gt;=&#34;10.2.14&#34; and os_version:&lt;&#34;10.2.16-h7&#34;) or (os_version:&gt;=&#34;10.2.11&#34; and os_version:&lt;&#34;10.2.13-h21&#34;) or (os_version:&gt;=&#34;10.2.8&#34; and os_version:&lt;&#34;10.2.10-h36&#34;) or (os_version:&gt;=&#34;10.2.0&#34; and os_version:&lt;&#34;10.2.7-h34&#34;)) pan-os is the proprietary operating system that powers all palo alto networks next-generation firewalls (ngfw) across
physical, virtual, and cloud environments. it uses a single-pass parallel processing (sp3) architecture to provide
deep visibility and control over network traffic by identifying applications, users, and content simultaneously.

certain versions of palo alto networks pan-os are affected by an authentication bypass vulnerability in the
globalprotect portal and gateway. successful exploitation allows a remote, unauthenticated attacker to bypass security
restrictions, establish an unauthorized vpn connection, and gain access to restricted networks.

there is evidence that this vulnerability is being actively *exploited in the wild*.

the following versions are affected:
- pan-os 12.1: versions 12.1.5 through 12.1.6, and 12.1.2 through 12.1.4-h*.
- pan-os 11.2: versions 11.2.11 or later, 11.2.8 through 11.2.10-h*, 11.2.5 through 11.2.7-h*, and 11.2.0 through 11.2.4-h*.
- pan-os 11.1: versions 11.1.14 or later, 11.1.11 through 11.1.13-h*, 11.1.8 through 11.1.10-h*, 11.1.7 through 11.1.7-h*, 11.1.5 through 11.1.6-h*, and 11.1.0 through 11.1.4-h*.
- pan-os 10.2: versions 10.2.17 through 10.2.18-h*, 10.2.14 through 10.2.16-h*, 10.2.11 through 10.2.13-h*, 10.2.8 through 10.2.10-h*, and 10.2.0 through 10.2.7-h*.

note: it is possible that older, unsupported pan-os versions are also vulnerable, but this has not been confirmed.

severity &amp; risk assessment
- severity: high – successful exploitation allows an attacker to establish an unauthorized vpn connection and gain access to protected networks.
- risk: high – this vulnerability can be exploited by a remote, unauthenticated attacker, meaning the barrier to entry for an attacker is low. this significantly increases the likelihood of widespread exploitation.">
  <div class="rr-card-header"><div class="rr-title">Palo Alto Networks PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257)</div></div>
  <div class="rr-meta-row"><span class="rr-meta-label">Type:</span><span class="rr-badge rr-type">assets</span><span class="rr-meta-sep"></span><span class="rr-meta-label">Published:</span><span class="rr-date">May 29, 2026</span></div>
  <div class="rr-desc-wrap">
    <div class="rr-desc-body" onclick="rrToggleDesc(this)"><p>PAN-OS is the proprietary operating system that powers all Palo Alto Networks Next-Generation Firewalls (NGFW) across
physical, virtual, and cloud environments. It uses a Single-Pass Parallel Processing (SP3) architecture to provide
deep visibility and control over network traffic by identifying applications, users, and content simultaneously.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Exposure management]]></title>
    <link href="https://www.runzero.com/docs/exposure-management/"/>
    <id>https://www.runzero.com/docs/exposure-management/</id>
      
      <published>2026-06-05T22:22:47+00:00</published>
      <updated>2026-06-05T22:22:47+00:00</updated>
      <summary type="html"><![CDATA[<p>runZero redefines exposure management with unrivaled visibility across your entire internal and external attack surface — covering IT, OT, IoT, mobile, and cloud. Uncover the unknown and unmanageable, reveal elusive exposures, and target the true risks other approaches miss.  No agents, no authentication, no appliances. And most importantly, no blind spots.</p>
<h2 id="comprehensive-asset-inventory">Comprehensive asset inventory</h2>
<p>runZero provides a comprehensive and unified asset inventory by combining <a href="/docs/discovering-assets/">active scanning</a>, <a href="/docs/traffic-sampling/">passive traffic sampling</a>, and <a href="/docs/integrations-inbound/">integrations</a> with deep fingerprinting and world-class correlation capabilities. Assets are normalized, deduplicated, and tracked as they move across your environment.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Thinkst Canary]]></title>
    <link href="https://www.runzero.com/docs/thinkst-canary/"/>
    <id>https://www.runzero.com/docs/thinkst-canary/</id>
      
      <published>2024-11-05T09:40:30+00:00</published>
      <updated>2024-11-05T09:40:30+00:00</updated>
      <summary type="html"><![CDATA[<p>All runZero editions integrate with <span class="book-index" data-book-index="Thinkst Canary">Thinkst Canary</span> by providing quick access from the Canary console to your asset data in the runZero Console. Setting up the integration is as simple as one change to your Canary settings.</p>
<h2 id="integrate-runzero-with-thinkst-canary">Integrate runZero with Thinkst Canary</h2>
<ol>
<li>Sign in to your runZero console.</li>
<li>Sign in to your Canary console.</li>
<li>Go to <strong>Global Settings</strong> under the gear icon.</li>
<li>Click on <strong>Integrations</strong>.</li>
<li>Toggle the runZero switch.</li>
</ol>
<h2 id="accessing-runzero-data-from-canary">Accessing runZero data from Canary</h2>
<p>After the integration is enabled within the Canary settings, runZero data will be available through any incident. When viewing an incident, click the magnifying glass icon under <code>source IP</code> or <code>reverse IP lookup</code> to open a search in your runZero console.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Tines]]></title>
    <link href="https://www.runzero.com/docs/tines/"/>
    <id>https://www.runzero.com/docs/tines/</id>
      
      <published>2026-05-22T14:50:01+00:00</published>
      <updated>2026-05-22T14:50:01+00:00</updated>
      <summary type="html"><![CDATA[<p>runZero integrates with <span class="book-index" data-book-index="Tines">Tines</span> to help you automate workflows related to your asset data. This helps teams leverage runZero to the fullest while optimizing the team’s workflows with automation. A <a href="https://loom.com/share/ff57a5828b584442936b20ed622d51fe">video demo</a> is available to show the final outcome of these instructions.</p>
<h2 id="tines-requirements">Requirements</h2>
<ul>
<li>A Tines account</li>
<li>runZero Export API and Organization API tokens</li>
</ul>
<p>There are two ways to integrate runZero and Tines:</p>
<ul>
<li>Follow the steps to create a <a href="/docs/tines/#tines-custom-story">custom story in Tines</a>, or</li>
<li>Use the <strong><a href="/docs/tines/#runzero-sample-story">runZero sample story</a></strong> to begin with a story outline.</li>
</ul>
<h2 id="tines-custom-story">Tines custom story</h2>
<p>A Tines story is a collection of actions that work together towards a specific goal, like a playbook. Tines has a Story Library that contains ready-made automated playbooks, or you can create a your own custom story if they don’t have one that matches your needs. That’s what we’ll need to do here.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Sumo Logic alerting]]></title>
    <link href="https://www.runzero.com/docs/sumo-logic-alerts/"/>
    <id>https://www.runzero.com/docs/sumo-logic-alerts/</id>
      
      <published>2026-05-22T14:50:01+00:00</published>
      <updated>2026-05-22T14:50:01+00:00</updated>
      <summary type="html"><![CDATA[<p>runZero integrates with <span class="book-index" data-book-index="Sumo Logic">Sumo Logic</span> to help you visualize your asset data. This helps you track your progress on reducing risk in your asset inventory over time.</p>
<p>Setting up the connection between Sumo Logic and runZero requires:</p>
<ol>
<li><a href="/docs/sumo-logic-alerts/#sumo-logic-http-source">Creating a Sumo Logic HTTP Source</a></li>
<li><a href="/docs/sumo-logic-alerts/#sumo-logic-alert-template">Creating a runZero alert template</a></li>
<li><a href="/docs/sumo-logic-alerts/#sumo-logic-rule">Creating a rule in runZero</a></li>
<li><a href="/docs/sumo-logic-alerts/#sumo-logic-handling">Handling runZero data in Sumo Logic</a></li>
<li><a href="/docs/sumo-logic-alerts/#sumo-logic-dashboard">Creating a Sumo Logic dashboard (optional)</a></li>
</ol>
<h2 id="sumo-logic-http-source">Step 1: Create a Sumo Logic HTTP Source</h2>
<ol>
<li>After logging in to Sumo Logic, navigate to <strong>Manage Data</strong> &gt; <strong>Collection</strong>.</li>
<li>Click <strong>Add Collector</strong> select <strong>Hosted Collector</strong>, provide a name, such as <code>runZero Collector</code> and click <strong>save</strong>.</li>
<li>If prompted to add a data source, click <strong>OK</strong>. Otherwise, find your Collector in the list and click <strong>Add Source</strong>.</li>
<li>Select the <a href="https://help.sumologic.com/docs/send-data/hosted-collectors/http-source/logs-metrics/"><strong>HTTP Logs and Metrics</strong></a> source, provide a name, such as <code>runZero Alerts</code>, and then click <strong>save</strong>.</li>
<li>Copy the URL provided to use in <a href="/docs/sumo-logic-alerts/#sumo-logic-alert-template">step 2</a>.</li>
</ol>
<h2 id="sumo-logic-alert-template">Step 2: Create a runZero alert template</h2>
<ol>
<li>Create an <a href="https://console.runzero.com/alerts/template/create/">alert template</a> in runZero and provide the following details:
<ul>
<li><strong>Name</strong>: Name for template</li>
<li><strong>Template type</strong>: JSON</li>
<li><strong>Subject line for message</strong>: Leave empty</li>
<li><strong>Body of message</strong>: The following JSON example will include the rule name and the search URL in the alert message body
<pre><code class="language-plaintext">{&#34;rule_name&#34;:&#34;{{rule.name}}&#34;,&#34;search_url&#34;:&#34;{{search.url}}&#34;,&#34;found&#34;: &#34;{{search.found}}&#34;,
&#34;assets_new&#34;: &#34;{{scan.assets_new}}&#34;}
</code></pre>
</li>
</ul>
</li>
<li>Create an <a href="https://console.runzero.com/alerts/channel/create/">alert channel</a> in runZero and provide the following details:
<ul>
<li><strong>Name</strong>: Name for alert channel</li>
<li><strong>Channel type</strong>: Webhook</li>
<li><strong>Webhook URL</strong>: The webhook URL you copied from Sumo Logic</li>
</ul>
</li>
</ol>
<h2 id="sumo-logic-rule">Step 3: Create a rule in runZero</h2>
<p>Now that you have your alert template and channel created, you will want to identify the triggers to alert on. Some common examples are:</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Sumo Logic asset export]]></title>
    <link href="https://www.runzero.com/docs/sumo-logic-assets/"/>
    <id>https://www.runzero.com/docs/sumo-logic-assets/</id>
      
      <published>2025-06-16T18:02:52+00:00</published>
      <updated>2025-06-16T18:02:52+00:00</updated>
      <summary type="html"><![CDATA[<p>runZero integrates with <span class="book-index" data-book-index="Sumo Logic">Sumo Logic</span> to make your asset inventory available directly in Sumo Logic. This article will show you how to export your runZero inventory into Sumo Logic for use within the SIEM.</p>
<h2 id="integrating-runzero-with-sumo-logic">Integrating runZero with Sumo Logic</h2>
<p>Setting up the connection between Sumo Logic and runZero has three options with different configuration steps.</p>
<p><strong>Option A: <a href="/docs/sumo-logic-assets/#sumo-logic-local">Local script</a></strong></p>
<ol>
<li><a href="/docs/sumo-logic-assets/#sumo-logic-local-source">Create a Sumo Logic HTTP Source</a>.</li>
<li><a href="/docs/sumo-logic-assets/#sumo-logic-local-script">Configure your host to run the provided script</a>.</li>
</ol>
<p><strong>Option B: <a href="/docs/sumo-logic-assets/#sumo-logic-lambda">AWS Lambda function</a></strong></p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Sumo Logic]]></title>
    <link href="https://www.runzero.com/docs/sumo-logic-siem/"/>
    <id>https://www.runzero.com/docs/sumo-logic-siem/</id>
      
      <published>2024-09-13T12:48:43+00:00</published>
      <updated>2024-09-13T12:48:43+00:00</updated>
      <summary type="html"><![CDATA[<p>All runZero editions integrate with <span class="book-index" data-book-index="Sumo Logic">Sumo Logic</span> to enrich asset visibility and help you visualize your asset data. Setting up the integration requires a few steps in your Sumo Logic console. The integration can be set up to support two distinct purposes:</p>
<ul>
<li><a href="/docs/sumo-logic-assets/">Complete asset visibility</a></li>
<li><a href="/docs/sumo-logic-alerts/">Targeted alerting and visualization</a></li>
</ul>
<h2 id="sumo-logic-requirements">Requirements</h2>
<ul>
<li>A Sumo Logic account</li>
<li>A runZero account and <a href="/docs/leveraging-the-api/">API key</a>.</li>
</ul>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Splunk Search]]></title>
    <link href="https://www.runzero.com/docs/splunk/"/>
    <id>https://www.runzero.com/docs/splunk/</id>
      
      <published>2024-11-05T09:40:30+00:00</published>
      <updated>2024-11-05T09:40:30+00:00</updated>
      <summary type="html"><![CDATA[<p class="licenses"><a href="https://www.runzero.com/product/pricing/"><span class="com">Community</span></a>&nbsp;<a href="https://www.runzero.com/product/pricing/"><span class="pla">Platform</span></a></p>
<p>runZero integrates with <span class="book-index" data-book-index="Splunk">Splunk</span> using a dedicated <a href="https://splunkbase.splunk.com/app/6549/">Splunk Addon</a>, compatible with Splunk 7, Splunk 8, and Splunk Cloud. With this add-on, you’ll be able to pull new or updated hosts into a <span class="book-index" data-book-index="Splunk">Splunk</span> index, where you’ll be able to analyze, visualize, and monitor them there.</p>
<p>This add-on uses the <a href="https://app.swaggerhub.com/apis/runZero/runZero/#/Splunk">Splunk API</a> from the runZero Network Discovery platform. It supports syncing assets into Splunk, with multiple inputs supported, global API key management, and optional search filters for each input. For example, you can track new assets as one input, and SMBv1 enabled assets as another input.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[ServiceNow Service Graph]]></title>
    <link href="https://www.runzero.com/docs/servicenow-connector/"/>
    <id>https://www.runzero.com/docs/servicenow-connector/</id>
      
      <published>2025-01-21T12:26:41+00:00</published>
      <updated>2025-01-21T12:26:41+00:00</updated>
      <summary type="html"><![CDATA[<p class="licenses"><a href="https://www.runzero.com/product/pricing/"><span class="pla">Platform</span></a></p>
<p>The <span class="book-index" data-book-index="Service Graph connector">Service Graph connector</span> for runZero allows you to bring runZero assets into your <span class="book-index" data-book-index="ServiceNow">ServiceNow</span> <span class="book-index" data-book-index="CMDB">CMDB</span> as CIs, and optionally periodically update the CIs with fresh information from runZero scans.</p>
<p>The Service Graph Connector fetches and transforms data using ServiceNow <span class="book-index" data-book-index="IntegrationHub ETL">IntegrationHub ETL</span>, and passes it through the Identification and Reconciliation Engine (<span class="book-index" data-book-index="IRE">IRE</span>). This allows specific fields and CI class mappings to be fine-tuned from the ServiceNow console. You can also specify a runZero search query to determine which assets get brought in by the connector.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[SecurityGate.io]]></title>
    <link href="https://www.runzero.com/docs/securitygate/"/>
    <id>https://www.runzero.com/docs/securitygate/</id>
      
      <published>2026-04-11T03:07:33+00:00</published>
      <updated>2026-04-11T03:07:33+00:00</updated>
      <summary type="html"><![CDATA[<p>All runZero editions integrate with <span class="book-index" data-book-index="SecurityGate.io">SecurityGate.io</span> to enrich asset visibility in support of your risk assessment program. Setting up the integration requires a few steps in your SecurityGate.io console.</p>
<h2 id="securitygate-requirements">Requirements</h2>
<ul>
<li>Configuring the SecurityGate.io integration requires a <a href="/docs/managing-your-team/#account-api-keys">runZero API key</a>.</li>
</ul>
<div class="alert alert-info">
<svg class="alert-icon" xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewbox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><circle cx="12" cy="12" r="10"></circle><line x1="12" y1="16" x2="12" y2="12"></line><line x1="12" y1="8" x2="12.01" y2="8"></line></svg>
<div class="alert-body">
The SecurityGate.io integration will pull runZero asset data from across all organizations.
</div>
</div>
<h2 id="integrate-runzero-with-securitygateio">Integrate runZero with SecurityGate.io</h2>
<ol>
<li>Sign in to your SecurityGate.io console.</li>
<li>Go to <strong>My Account</strong> under the <strong>Hello</strong> dropdown menu.</li>
<li>Click on <strong>Integration Manager</strong>.</li>
<li>Select <strong>Add New Integration</strong>.</li>
<li>Choose <em>Rumble</em> from the <strong>Integration Partner</strong> dropdown menu.</li>
<li>Provide the <strong>Account API Key</strong>, <strong>Server URL</strong>, and <strong>API Version</strong>.</li>
<li>Click <strong>Test Connection</strong>. If the test is successful, click <strong>OK</strong> to save the configuration.</li>
</ol>
<h2 id="viewing-runzero-data-in-securitygateio">Viewing runZero data in SecurityGate.io</h2>
<p>After the integration is enabled within SecurityGate.io, runZero data will be available through the Asset Inventory page.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Panther]]></title>
    <link href="https://www.runzero.com/docs/panther/"/>
    <id>https://www.runzero.com/docs/panther/</id>
      
      <published>2024-02-22T16:30:44+00:00</published>
      <updated>2024-02-22T16:30:44+00:00</updated>
      <summary type="html"><![CDATA[<p>runZero data can be imported into your <a href="https://panther.com/">Panther</a> instance for enhanced logging and alerting.</p>
<h2 id="panther-requirements">Requirements</h2>
<ul>
<li>A <span class="book-index" data-book-index="Panther">Panther</span> account with the required permissions,</li>
<li>An AWS S3 bucket, and</li>
<li>Exported .jsonl files from runZero that have been uploaded into your AWS S3 bucket.</li>
</ul>
<h3 id="panther-custom-schema">Step 1: Adding a custom schema</h3>
<ol>
<li>Go to <strong>Configure &gt; Schemas</strong> and select <strong>Create New</strong>.</li>
<li>Add a name.</li>
<li>Upload a sample log to automatically parse the runZero output schema.</li>
</ol>
<h3 id="panther-custom-log-source">Step 2: Adding a custom log source</h3>
<ol>
<li>Go to <strong>Configure &gt; Log Sources</strong> and select <strong>Create New</strong>.</li>
<li>Complete the <strong>Basic Information</strong> section.</li>
<li>Opt to configure S3 prefixes and schemas now and select the custom schema you created.</li>
<li>Configure the IAM role:
<ul>
<li>Opt to configure <strong>Using the AWS Console UI</strong>.</li>
<li>Click <strong>Launch Console UI</strong>.</li>
<li>Review the stack in AWS, then check the box to approve, and click to deploy the stack.</li>
<li>When the deployment completes, navigate to the <strong>Resources</strong> tab and select the <strong>LogProcessingRole</strong> that was created.</li>
<li>Copy the ARN from that role into the field on the Panther console.</li>
</ul>
</li>
<li>Configure an alarm if logs are not processed (optional).</li>
</ol>
<p>Once completed, any .jsonl files added to the specified AWS S3 bucket will be automatically ingested and processed by Panther.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Atlassian Insight &amp; Jira Service Management]]></title>
    <link href="https://www.runzero.com/docs/atlassian-jira-service-management/"/>
    <id>https://www.runzero.com/docs/atlassian-jira-service-management/</id>
      
      <published>2026-04-11T03:07:33+00:00</published>
      <updated>2026-04-11T03:07:33+00:00</updated>
      <summary type="html"><![CDATA[<p>All runZero editions integrate with <span class="book-index" data-book-index="Jira Service Management">Jira Service Management</span> via an import in <span class="book-index" data-book-index="Atlassian Insight">Atlassian Insight</span>. runZero asset data is then imported into the CMDB.</p>
<p>Follow these steps to perform a basic import.</p>
<h2 id="step-1-export-runzero-asset-data">Step 1: Export runZero asset data</h2>
<p>You can export data using the <strong>Export</strong> button from the runZero inventory or the Export API.</p>
<p>The following are sample commands for the export API that include common export fields but omit the tags field. You must replace the token <code>ETxxx...</code> with your account’s export token from the <a href="https://console.runzero.com/inventory/export_api">Inventory export API page</a>.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Outbound integrations]]></title>
    <link href="https://www.runzero.com/docs/integrations-outbound/"/>
    <id>https://www.runzero.com/docs/integrations-outbound/</id>
      
      <published>2023-11-16T09:57:19+00:00</published>
      <updated>2023-11-16T09:57:19+00:00</updated>
      <summary type="html"><![CDATA[<h2 id="using-runzero-data-to-enrich-other-tools">Using runZero data to enrich other tools</h2>
<p>In addition to being able to enrich your runZero inventory with data from your <a href="/docs/integrations-inbound/">other IT and security tools</a>, the runZero platform offers <a href="https://console.runzero.com/integrations/">egress integrations with several platforms</a>. By leveraging product APIs and export/import functionality, runZero can provide additional asset context in other IT and security tools.</p>
<p>The following integrations are available to send your runZero data into other platforms:</p>
<h3 id="it-service-management">IT service management</h3>
<ul>
<li><a href="/docs/atlassian-jira-service-management/">Atlassian Insight &amp; Jira Service Management</a></li>
<li><a href="/docs/servicenow-connector/">ServiceNow CMDB</a></li>
</ul>
<h3 id="detection-and-investigation">Detection and investigation</h3>
<ul>
<li><a href="/docs/panther/">Panther</a></li>
<li><a href="/docs/splunk/">Splunk Search</a></li>
<li><a href="/docs/sumo-logic-siem/">Sumo Logic</a></li>
<li><a href="/docs/tines/">Tines</a></li>
<li><a href="/docs/thinkst-canary/">Thinkst Canary</a></li>
</ul>
<h3 id="integrations-outbound-vm">Vulnerabilities and risk</h3>
<ul>
<li><a href="/docs/securitygate/">SecurityGate.io</a></li>
</ul>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Wiz]]></title>
    <link href="https://www.runzero.com/docs/wiz/"/>
    <id>https://www.runzero.com/docs/wiz/</id>
      
      <published>2025-11-13T17:01:34+00:00</published>
      <updated>2025-11-13T17:01:34+00:00</updated>
      <summary type="html"><![CDATA[<p class="licenses"><a href="https://www.runzero.com/product/pricing/"><span class="com">Community</span></a>&nbsp;<a href="https://www.runzero.com/product/pricing/"><span class="pla">Platform</span></a></p>
<p>runZero integrates with <span class="book-index" data-book-index="Wiz">Wiz</span> by importing data from the <a href="https://docs.wiz.io/wiz-docs/docs/wiz-api-introduction">Wiz API</a>. This integration allows you to sync data about your cloud assets, software, and vulnerabilities from Wiz to provide better visibility of your cloud assets and security posture.</p>
<h2 id="wiz-getting-started">Getting started with Wiz</h2>
<p>To set up an integration with Wiz, you’ll need to:</p>
<ol>
<li>Create a Service Account in Wiz with permissions to read graph resources, read reports, and create reports.</li>
<li>Configure the Wiz credential in runZero.</li>
<li>Choose whether to configure the integration as <a href="/docs/integrations-inbound/#integration-probe-connector">a scan probe or connector task</a>.</li>
<li>Activate the integration to pull your data into runZero.</li>
</ol>
<h2 id="wiz-requirements">Requirements</h2>
<p>Before you can set up the Wiz integration:</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[VMware]]></title>
    <link href="https://www.runzero.com/docs/vmware/"/>
    <id>https://www.runzero.com/docs/vmware/</id>
      
      <published>2025-06-16T18:02:52+00:00</published>
      <updated>2025-06-16T18:02:52+00:00</updated>
      <summary type="html"><![CDATA[<p class="licenses"><a href="https://www.runzero.com/product/pricing/"><span class="com">Community</span></a>&nbsp;<a href="https://www.runzero.com/product/pricing/"><span class="pla">Platform</span></a></p>
<p>runZero Platform supports synchronization of <span class="book-index" data-book-index="VMware">VMware</span> <span class="book-index" data-book-index="vCenter">vCenter</span> and <span class="book-index" data-book-index="ESXi">ESXi</span> <span class="book-index" data-book-index="virtual machine">virtual machine</span> inventories.</p>
<h2 id="setting-up-vmware-credentials">Setting up VMware credentials</h2>
<p>Unlike other APIs, the VMware synchronization process is configured as part of your regular runZero Explorer scans. The first step is to set up a set of VMware credentials.</p>
<p>On the <a href="https://console.runzero.com/credentials">Scanning with credentials</a> page, click <em>Add Credential</em> and choose a credential type of <em>VMware vCenter/ESXi Username and Password</em>, and enter the appropriate username and password. The correct username syntax in most cases is <code>user@domain.com</code>. The VMware account used requires at least <strong>read-only</strong> access.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Tenable Security Center]]></title>
    <link href="https://www.runzero.com/docs/tenable-sc/"/>
    <id>https://www.runzero.com/docs/tenable-sc/</id>
      
      <published>2025-06-16T18:02:52+00:00</published>
      <updated>2025-06-16T18:02:52+00:00</updated>
      <summary type="html"><![CDATA[<p class="licenses"><a href="https://www.runzero.com/product/pricing/"><span class="com">Community</span></a>&nbsp;<a href="https://www.runzero.com/product/pricing/"><span class="pla">Platform</span></a></p>
<p>runZero integrates with Tenable Security Center (previously <span class="book-index" data-book-index="Tenable.sc">Tenable.sc</span>) by importing data from the Tenable Security Center <a href="https://docs.tenable.com/security-center/api/">API</a>.</p>
<h2 id="tenablesc-getting-started">Getting started with Tenable Security Center</h2>
<p>To set up an integration with Tenable Security Center, you’ll need to:</p>
<ol>
<li>Create an API key for a user that has access to view and query vulnerabilities in Tenable Security Center.</li>
<li>Configure the Tenable Security Center credential in runZero.</li>
<li>Choose whether to configure the integration as <a href="/docs/integrations-inbound/#integration-probe-connector">a scan probe or connector task</a>.</li>
<li>Activate the integration to pull your data into runZero.</li>
</ol>
<h2 id="tenablesc-requirements">Requirements</h2>
<p>Before you can set up the Tenable Security Center integration:</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Tenable Nessus]]></title>
    <link href="https://www.runzero.com/docs/tenable-nessus/"/>
    <id>https://www.runzero.com/docs/tenable-nessus/</id>
      
      <published>2025-04-09T14:04:18+00:00</published>
      <updated>2025-04-09T14:04:18+00:00</updated>
      <summary type="html"><![CDATA[<p class="licenses"><a href="https://www.runzero.com/product/pricing/"><span class="com">Community</span></a>&nbsp;<a href="https://www.runzero.com/product/pricing/"><span class="pla">Platform</span></a></p>
<p>runZero integrates with <span class="book-index" data-book-index="Tenable Nessus">Tenable Nessus</span> using two methods. For all versions of <span class="book-index" data-book-index="Nessus">Nessus</span>, runZero can import Nessus files (<code>.nessus</code>) that were exported from your Nessus instance. Exports from Tenable Security Center are also supported. For Nessus Professional users, the runZero integration can pull scan data from the <a href="/docs/tenable-nessuspro/">Nessus Professional API</a>.</p>
<h2 id="nessus-getting-started">Getting started with Tenable Nessus</h2>
<p>To use the Tenable Nessus integration, you’ll need to:</p>
<ol>
<li>Export vulnerability scan results as Nessus files.</li>
<li>Import the Nessus files through the inventory pages.</li>
</ol>
<h2 id="nessus-requirements">Requirements</h2>
<p>Before you can set up the Nessus integration:</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Nessus Professional]]></title>
    <link href="https://www.runzero.com/docs/tenable-nessuspro/"/>
    <id>https://www.runzero.com/docs/tenable-nessuspro/</id>
      
      <published>2025-06-16T18:02:52+00:00</published>
      <updated>2025-06-16T18:02:52+00:00</updated>
      <summary type="html"><![CDATA[<p class="licenses"><a href="https://www.runzero.com/product/pricing/"><span class="com">Community</span></a>&nbsp;<a href="https://www.runzero.com/product/pricing/"><span class="pla">Platform</span></a></p>
<p>runZero integrates with <span class="book-index" data-book-index="Tenable Nessus Professional">Nessus Professional</span> by importing data from the Tenable <a href="https://developer.tenable.com/docs/welcome/">API</a>.</p>
<h2 id="nessuspro-getting-started">Getting started with Nessus Professional</h2>
<p>To set up an integration with <span class="book-index" data-book-index="Nessus Professional">Nessus Professional</span>, you’ll need to:</p>
<ol>
<li>Create an Administrator API key in an access group with <em>Can View</em> <a href="https://developer.tenable.com/docs/permissions">permission</a> to <em>Manage Assets</em>.</li>
<li>Configure the Nessus Professional credential in runZero.</li>
<li>Choose whether to configure the integration as <a href="/docs/integrations-inbound/#integration-probe-connector">a scan probe or connector task</a>.</li>
<li>Activate the integration to pull your data into runZero.</li>
</ol>
<h2 id="nessuspro-requirements">Requirements</h2>
<p>Before you can set up the Nessus Professional integration:</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Tenable Vulnerability Management]]></title>
    <link href="https://www.runzero.com/docs/tenable-vm/"/>
    <id>https://www.runzero.com/docs/tenable-vm/</id>
      
      <published>2025-11-17T19:23:01+00:00</published>
      <updated>2025-11-17T19:23:01+00:00</updated>
      <summary type="html"><![CDATA[<p class="licenses"><a href="https://www.runzero.com/product/pricing/"><span class="com">Community</span></a>&nbsp;<a href="https://www.runzero.com/product/pricing/"><span class="pla">Platform</span></a></p>
<p>runZero integrates with Tenable Vulnerability Management (previously <span class="book-index" data-book-index="Tenable.io">Tenable.io</span>) by importing data from the
Tenable <a href="https://developer.tenable.com/docs/welcome/">API</a>.</p>
<h2 id="tenablevm-getting-started">Getting started with Tenable Vulnerability Management</h2>
<p>To set up an integration with Tenable Vulnerability Management, you’ll need to:</p>
<ol>
<li>Create an Administrator API key in an access group with <code>Can View</code> <a href="https://developer.tenable.com/docs/permissions">permission</a> to <code>Manage Assets</code>.
Optionally, this must have the Scan Manager role in order to retrieve agent health data.</li>
<li>Configure the Tenable Vulnerability Management credential in runZero.</li>
<li>Choose whether to configure the integration as <a href="/docs/integrations-inbound/#integration-probe-connector">a scan probe or connector task</a>.</li>
<li>Activate the integration to pull your data into runZero.</li>
</ol>
<h2 id="tenablevm-requirements">Requirements</h2>
<p>Before you can set up the Tenable Vulnerability Management integration:</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Tenable]]></title>
    <link href="https://www.runzero.com/docs/tenable/"/>
    <id>https://www.runzero.com/docs/tenable/</id>
      
      <published>2023-09-22T23:02:50+00:00</published>
      <updated>2023-09-22T23:02:50+00:00</updated>
      <summary type="html"><![CDATA[<p class="licenses"><a href="https://www.runzero.com/product/pricing/"><span class="com">Community</span></a>&nbsp;<a href="https://www.runzero.com/product/pricing/"><span class="pla">Platform</span></a></p>
<p>runZero integrates with <span class="book-index" data-book-index="Tenable Vulnerability Management">Tenable Vulnerability Management</span> (previously <span class="book-index" data-book-index="Tenable.io">Tenable.io</span>), <span class="book-index" data-book-index="Tenable Nessus">Tenable Nessus</span>, and <span class="book-index" data-book-index="Tenable Security Center">Tenable Security Center</span> to enrich your asset inventory and gain visibility into vulnerabilities detected in your environment. The <a href="/docs/tenable-vm/">Tenable Vulnerability Management</a>, <a href="/docs/tenable-nessuspro/">Nessus Professional</a>, and <a href="/docs/tenable-sc/">Tenable Security Center</a> integrations pull data from the Tenable API, while all versions of <a href="/docs/tenable-nessus/">Tenable Nessus</a> and Tenable Security Center (previously <span class="book-index" data-book-index="Tenable.sc">Tenable.sc</span>) are also supported through Nessus v2 file imports (<code>.nessus</code>).</p>
<p>Note that at this time, only the main <a href="https://www.tenable.com/products/tenable-io/">Tenable Vulnerability Management</a> cloud API endpoint at <code>https://cloud.tenable.com</code> is supported as an API integration.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Tanium API Gateway]]></title>
    <link href="https://www.runzero.com/docs/tanium/"/>
    <id>https://www.runzero.com/docs/tanium/</id>
      
      <published>2025-08-04T10:54:44+00:00</published>
      <updated>2025-08-04T10:54:44+00:00</updated>
      <summary type="html"><![CDATA[<p class="licenses"><a href="https://www.runzero.com/product/pricing/"><span class="com">Community</span></a>&nbsp;<a href="https://www.runzero.com/product/pricing/"><span class="pla">Platform</span></a></p>
<p>runZero integrates with <span class="book-index" data-book-index="Tanium">Tanium</span> by importing data from the <a href="https://developer.tanium.com/apis/tanium_gateway_schema/queries/endpoints">Tanium Gateway API</a>. This integration allows you to sync data about your endpoints, applications, and vulnerabilities from Tanium to provide better visibility over your network.</p>
<h2 id="tanium-getting-started">Getting started with Tanium</h2>
<p>To set up an integration with Tanium, you’ll need to:</p>
<ol>
<li>Generate an API token with the necessary permissions.</li>
<li>Configure the Tanium credential in runZero.</li>
<li>Choose whether to configure the integration as <a href="/docs/integrations-inbound/#integration-probe-connector">a scan probe or connector task</a>.</li>
<li>Activate the integration to pull your data into runZero.</li>
</ol>
<h2 id="tanium-step1">Step 1: Generate an API key in Tanium Dashboard</h2>
<ol>
<li>Sign in to Tanium and navigate to <strong>Administration &gt; Roles</strong>.</li>
<li>Create a role with the necessary permissions:
<ol>
<li>Search for the <strong>Gateway User</strong> role.</li>
<li>Select it and click the <strong>Clone</strong> button that appears to create a copy of this role.</li>
<li>On the <strong>Clone Role</strong> screen, enable <strong>Platform Content Permissions &gt; Sensor &gt; Read</strong> and add these Content Sets (via the <strong>n+</strong> button beside the green check):
<ul>
<li>Base</li>
<li>Comply</li>
<li>Comply Reporting</li>
<li>Core AD Query Content</li>
<li>Core Content</li>
<li>Reserved</li>
<li>Tanium Data Service</li>
</ul>
</li>
<li>Save the role.</li>
</ol>
</li>
<li>Navigate to <strong>Administration &gt; Personas</strong> and click <strong>New Persona</strong> to create a persona using the role you just created:
<ol>
<li>Name the persona.</li>
<li>Under <strong>Manage Roles</strong>, search for and apply your new role.</li>
<li>Under <strong>Computer Groups</strong>, add the groups you need, or check <strong>Unrestricted Management Rights</strong> to allow access to all Computer Groups.</li>
<li>Assign a user or service account which has the permissions granted to the persona.</li>
<li>Save the persona.</li>
</ol>
</li>
<li>Navigate to <strong>Administration &gt; API Tokens</strong> and click <strong>New API Token</strong>.
<ol>
<li>Enter a name and select a TTL.</li>
<li>Select the persona you just created from the dropdown (you may need to refresh the page for it to appear).</li>
<li>Enter IP addresses to allow requests from:
<ul>
<li>If you will run the integration via an Explorer or CLI, enter the IP addresses or ranges of your host(s);</li>
<li>Otherwise, enter <code>0.0.0.0/0</code>.</li>
</ul>
</li>
<li>Save the API token.</li>
</ol>
</li>
</ol>
<h2 id="tanium-step2">Step 2: Add the Tanium API token to runZero</h2>
<ol>
<li>Go to the <a href="https://console.runzero.com/credentials/new">Credentials page</a> in runZero.</li>
<li>Choose <strong>Tanium API Token</strong> from the list of credential types.</li>
<li>Provide a name for the credential, like <code>Tanium</code>.</li>
<li>Provide the following information:
<ul>
<li><strong>Tanium API URL</strong> - Your Tanium API Gateway URL. The full URL will be something like <code>https://&lt;customername&gt;-api.cloud.tanium.com/plugin/products/gateway/graphql</code>. If the path (<code>/plugin/products/gateway/graphql</code>) is omitted, it will be added automatically when the API is called.</li>
<li><strong>Tanium API token</strong> - The API token (including the <code>token-</code> prefix) created in step 1.</li>
<li><strong>Insecure</strong> - Enable this option to approve authenticating with untrusted endpoints. When enabled, certificate validation is disabled. Use with caution.</li>
</ul>
</li>
<li>If you want other organizations to be able to use this credential, select the <em>Make this a global credential</em> option. Otherwise, you can configure access on a per-organization basis.</li>
<li>Verify and save the credential.</li>
</ol>
<p>You’re now ready to set up and activate the connection to bring in data from Tanium.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Shodan]]></title>
    <link href="https://www.runzero.com/docs/shodan/"/>
    <id>https://www.runzero.com/docs/shodan/</id>
      
      <published>2026-05-26T13:36:08+00:00</published>
      <updated>2026-05-26T13:36:08+00:00</updated>
      <summary type="html"><![CDATA[<p class="licenses"><a href="https://www.runzero.com/product/pricing/"><span class="com">Community</span></a>&nbsp;<a href="https://www.runzero.com/product/pricing/"><span class="pla">Platform</span></a></p>
<p>runZero integrates with <span class="book-index" data-book-index="Shodan">Shodan</span> by importing data from the <a href="https://developer.shodan.io/api">Shodan API</a>. This integration allows you to sync data about your externally-facing assets and services from Shodan to provide better visibility of your internet footprint and cyber hygiene.</p>
<h2 id="shodan-getting-started">Getting started</h2>
<p>To set up the Shodan integration, you’ll need to:</p>
<ol>
<li>Add the Shodan API key in runZero.</li>
<li>Choose whether to configure the integration as <a href="/docs/integrations-inbound/#integration-probe-connector">a scan probe or connector task</a>.</li>
<li>Activate the Shodan integration to sync your data with runZero.</li>
</ol>
<h2 id="shodan-requirements">Requirements</h2>
<p>Before you can set up the Shodan integration:</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[SentinelOne]]></title>
    <link href="https://www.runzero.com/docs/sentinelone/"/>
    <id>https://www.runzero.com/docs/sentinelone/</id>
      
      <published>2026-04-11T03:07:33+00:00</published>
      <updated>2026-04-11T03:07:33+00:00</updated>
      <summary type="html"><![CDATA[<p class="licenses"><a href="https://www.runzero.com/product/pricing/"><span class="com">Community</span></a>&nbsp;<a href="https://www.runzero.com/product/pricing/"><span class="pla">Platform</span></a></p>
<p>runZero integrates with <span class="book-index" data-book-index="SentinelOne">SentinelOne</span> by importing data from the <a href="https://www.sentinelone.com/faq/">SentinelOne API</a>. This integration allows you to sync and enrich your asset inventory, import software installed on assets, and import vulnerabilities affecting the installed software. Adding your SentinelOne data to runZero makes it easier to find things like endpoints that are missing required software or identify vulnerable endpoints.</p>
<div class="alert alert-info">
<svg class="alert-icon" xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewbox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><circle cx="12" cy="12" r="10"></circle><line x1="12" y1="16" x2="12" y2="12"></line><line x1="12" y1="8" x2="12.01" y2="8"></line></svg>
<div class="alert-body">
Any IP address reported by SentinelOne will be treated as a secondary address, not a primary address, since these IPs can be stale and may not be associated with a specific network or site.
</div>
</div>
<h2 id="sentinelone-getting-started">Getting started</h2>
<p>To set up the SentinelOne integration, you’ll need to:</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Nexpose]]></title>
    <link href="https://www.runzero.com/docs/rapid7-nexpose/"/>
    <id>https://www.runzero.com/docs/rapid7-nexpose/</id>
      
      <published>2025-06-16T18:02:52+00:00</published>
      <updated>2025-06-16T18:02:52+00:00</updated>
      <summary type="html"><![CDATA[<p class="licenses"><a href="https://www.runzero.com/product/pricing/"><span class="com">Community</span></a>&nbsp;<a href="https://www.runzero.com/product/pricing/"><span class="pla">Platform</span></a></p>
<p>runZero integrates with <span class="book-index" data-book-index="Rapid7 Nexpose">Rapid7 Nexpose</span> by importing files that were exported from your <span class="book-index" data-book-index="Nexpose">Nexpose</span> instance.</p>
<h2 id="nexpose-getting-started">Getting started with Rapid7 Nexpose</h2>
<p>To use the Rapid7 Nexpose integration, you’ll need to:</p>
<ol>
<li>Download an XML Export or XML Export 2.0 report from Nexpose.</li>
<li>Import the Nexpose files through the inventory pages.</li>
</ol>
<h2 id="nexpose-requirements">Requirements</h2>
<p>Before you can set up the Nexpose integration:</p>
<ul>
<li>Make sure you have access to the Nexpose portal.</li>
</ul>
<h3 id="step-1-export-nexpose-vulnerability-scan-report">Step 1: Export Nexpose vulnerability scan report</h3>
<ol>
<li>Sign in to Nexpose with the account being used for the runZero integration.</li>
<li>Go to the Reports page and select <em>Create a report</em>.</li>
<li>From the Export tab, select either XML Report or XML Report 2.0.</li>
<li>Set the scan, asset, asset group, or site scope.</li>
<li>Click <em>Save &amp; Run the Report</em>.</li>
<li>When the report completes, save the report to a local file.</li>
</ol>
<h3 id="step-2-import-the-nexpose-files-into-runzero">Step 2: Import the Nexpose files into runZero</h3>
<ol>
<li>Go to the <a href="https://console.runzero.com/inventory">Inventory page</a> in runZero.</li>
<li>Choose <strong>Import</strong> &gt; <strong>Nexpose XML Export (.xml)</strong> from the list of import types.</li>
<li>On the import data page:
<ul>
<li>Choose the site you want to add your assets to.</li>
<li>Set tags to apply to the imported assets (optional).</li>
<li>Set the <a href="/docs/rapid7/#rapid7-scoring">severity and risk levels</a> to ingest (optional).</li>
<li>Set the <strong>Fingerprint only</strong> toggle to <em>Yes</em> if you want vulnerability records to be ingested for fingerprint analysis but not stored in your runZero vulnerability inventory (optional).</li>
</ul>
</li>
</ol>
<h3 id="step-3-view-nexpose-assets-and-vulnerabilities">Step 3: View Nexpose assets and vulnerabilities</h3>
<p>After a successful sync, you can <a href="https://console.runzero.com/inventory">go to your inventory</a> to view your Nexpose assets. These assets will have a Rapid7 icon listed in the <strong>Source</strong> column.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[InsightVM]]></title>
    <link href="https://www.runzero.com/docs/rapid7-insightvm/"/>
    <id>https://www.runzero.com/docs/rapid7-insightvm/</id>
      
      <published>2026-06-05T11:14:32+00:00</published>
      <updated>2026-06-05T11:14:32+00:00</updated>
      <summary type="html"><![CDATA[<p class="licenses"><a href="https://www.runzero.com/product/pricing/"><span class="com">Community</span></a>&nbsp;<a href="https://www.runzero.com/product/pricing/"><span class="pla">Platform</span></a></p>
<p>runZero integrates with <span class="book-index" data-book-index="Rapid7 InsightVM">Rapid7 InsightVM</span> by importing data from the <a href="https://help.rapid7.com/insightvm/en-us/api/index.html">InsightVM API</a>.</p>
<p>Both Rapid7 InsightVM Cloud and on-premises <span class="book-index" data-book-index="InsightVM">InsightVM</span> are supported. For on-premises use you will need to use the InsightVM connector <a href="/docs/rapid7-insightvm/#step-2-choose-how-to-configure-the-rapid7-integration">as a scan probe</a> from a runZero Explorer which has network access to the InsightVM deployment.</p>
<p>The Insight Platform API is distinct from the InsightVM API, and is not supported.</p>
<h2 id="insightvm-getting-started">Getting started with InsightVM</h2>
<p>To set up the InsightVM integration, you’ll need to:</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Rapid7]]></title>
    <link href="https://www.runzero.com/docs/rapid7/"/>
    <id>https://www.runzero.com/docs/rapid7/</id>
      
      <published>2023-09-22T23:02:50+00:00</published>
      <updated>2023-09-22T23:02:50+00:00</updated>
      <summary type="html"><![CDATA[<p class="licenses"><a href="https://www.runzero.com/product/pricing/"><span class="com">Community</span></a>&nbsp;<a href="https://www.runzero.com/product/pricing/"><span class="pla">Platform</span></a></p>
<p>runZero integrates with Rapid7’s <a href="/docs/rapid7-insightvm/"><span class="book-index" data-book-index="InsightVM">InsightVM</span></a> and <a href="/docs/rapid7-nexpose/"><span class="book-index" data-book-index="Nexpose">Nexpose</span></a> to enrich your asset inventory and gain visibility into vulnerabilities detected in your environment.</p>
<h2 id="rapid7-asset-inventory">Asset inventory</h2>
<p>There is a column on the asset inventory page showing the count of vulnerabilities detected by Rapid7 for each asset. When a single asset is selected, the vulnerabilities table lists all the results related to that asset. The vulnerability count can be impacted by the type of vulnerability scan as well as the import settings selected.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Palo Alto Prisma Cloud]]></title>
    <link href="https://www.runzero.com/docs/prisma/"/>
    <id>https://www.runzero.com/docs/prisma/</id>
      
      <published>2025-10-29T09:01:24+00:00</published>
      <updated>2025-10-29T09:01:24+00:00</updated>
      <summary type="html"><![CDATA[<p class="licenses"><a href="https://www.runzero.com/product/pricing/"><span class="com">Community</span></a>&nbsp;<a href="https://www.runzero.com/product/pricing/"><span class="pla">Platform</span></a></p>
<p>runZero integrates with Palo Alto <span class="book-index" data-book-index="Prisma Cloud">Prisma Cloud</span> by importing data from the <a href="https://pan.dev/prisma-cloud/api/">Prisma API</a>. This integration allows you to sync data about your cloud assets and vulnerabilities from Prisma to provide better visibility of your cloud assets and security posture. The supported Prisma cloud sources are AWS, Azure, and GCP.</p>
<h2 id="prisma-getting-started">Getting started with Prisma</h2>
<p>To set up an integration with Prisma, you’ll need to:</p>
<ol>
<li>Create a Palo Alto Prisma Cloud credential in runZero.</li>
<li>Choose whether to configure the integration as <a href="/docs/integrations-inbound/#integration-probe-connector">a scan probe or connector task</a>.</li>
<li>Activate the integration to pull your data into runZero.</li>
</ol>
<h2 id="Prisma-step1">Step 1: Obtain your Prisma API credentials</h2>
<ol>
<li>Follow the <a href="https://pan.dev/prisma-cloud/api/cspm/#cloud-security-user-roles">Prisma documentation</a> to create a Prisma cloud user role with sufficient permissions. See <a href="https://docs.prismacloud.io/en/enterprise-edition/content-collections/administration/prisma-cloud-administrator-roles">user role descriptions</a> for more information.</li>
<li>Obtain your Prisma Cloud API access key and secret key. These will be used to authenticate against the Prisma Cloud API. Follow the <a href="https://pan.dev/prisma-cloud/api/cspm/#cloud-security-api-authorization">Prisma documentation</a> to configure them properly.</li>
<li>Identify your API URL. This will be sent to you from Palo Alto in your fulfillment email. See <a href="https://pan.dev/prisma-cloud/api/cspm/api-urls/">possible URL values</a>.</li>
</ol>
<h2 id="Prisma-step2">Step 2: Add the Prisma credential to runZero</h2>
<ol>
<li>Go to the <a href="https://console.runzero.com/credentials/new">Credentials page</a> in runZero. Provide a name for the credentials, like <code>Palo Alto Networks Prisma Cloud</code>.</li>
<li>Choose <strong>Prisma Client Secret</strong> from the list of credential types.</li>
<li>Create your Prisma service account via the settings page in the Prisma portal, and then provide the following information:
<ul>
<li><strong>Prisma Cloud Access Key</strong> - The access key you obtained from the steps above.</li>
<li><strong>Prisma Cloud Secret Key</strong> - The secret key you obtained from the steps above.</li>
<li><strong>Prisma API URL</strong> - The API Endpoint URL used to access the Prisma API.</li>
</ul>
</li>
<li>If you want other organizations to be able to use this credential, select the <em>Make this a global credential</em> option. Otherwise, you can configure access on a per-organization basis.</li>
<li>Save the credential.</li>
</ol>
<p>You’re now ready to set up and activate the connection to bring in data from Prisma Cloud.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Palo Alto Networks Firewall]]></title>
    <link href="https://www.runzero.com/docs/palo-alto/"/>
    <id>https://www.runzero.com/docs/palo-alto/</id>
      
      <published>2026-02-13T16:41:49+00:00</published>
      <updated>2026-02-13T16:41:49+00:00</updated>
      <summary type="html"><![CDATA[<p class="licenses"><a href="https://www.runzero.com/product/pricing/"><span class="com">Community</span></a>&nbsp;<a href="https://www.runzero.com/product/pricing/"><span class="pla">Platform</span></a></p>
<p>runZero integrates with Palo Alto Networks Firewall using the <a href="https://docs.paloaltonetworks.com/ngfw/api/api-authentication-and-security/pan-os-api-authentication">PAN-OS XML API</a> to provide additional network visibility, enhance network context, and improve <a href="https://help.runzero.com/docs/switch-topology-report/">reporting</a>.</p>
<h2 id="panos-getting-started">Getting started</h2>
<p>To set up the Palo Alto Networks Firewall integration, you’ll need to:</p>
<ul>
<li>Create or obtain API Keys to use with the Palo Alto Networks Firewall XML API.</li>
<li>Add the Palo Alto Networks Firewall API key in runZero.</li>
<li>Perform Palo Alto Networks Firewall synchronization</li>
</ul>
<h2 id="panos-requirements">Requirements</h2>
<ul>
<li>Before you can set up the Palo Alto Networks Firewall integration, make sure you have an API Key for your PAN OS XML.</li>
<li>Prior to adding a Palo Alto Networks Firewall credential, scan your Palo Alto Networks Firewall with a runZero Explorer
if you want to use trusted authentication (optional).</li>
</ul>
<h2 id="step-1-add-the-panos-credential-to-runzero">Step 1: Add the Palo Alto Networks Firewall credential to runZero</h2>
<ol>
<li>Go to the <a href="https://console.runzero.com/credentials/new">Add credential</a> page in runZero. Provide a name for the credentials, like <strong>PAN-OS Firewall</strong>.</li>
<li>Choose <strong>Palo Alto Networks Firewall API Key</strong> from the list of credential types.</li>
<li>Provide the following information:
<ul>
<li><strong>Palo Alto Networks API key</strong> - The API key you want to use with the Palo Alto Networks Firewall integration. Ensure the XML API is enabled by following the steps in this guide: <a href="https://docs.paloaltonetworks.com/ngfw/api/api-authentication-and-security/pan-os-api-authentication">https://docs.paloaltonetworks.com/ngfw/api/api-authentication-and-security/pan-os-api-authentication</a>. Once the XML API is enabled, you can generate the API key by following the steps in this guide: <a href="https://docs.paloaltonetworks.com/ngfw/api/api-authentication-and-security/generate-api-key">https://docs.paloaltonetworks.com/ngfw/api/api-authentication-and-security/generate-api-key</a></li>
<li><strong>Palo Alto Networks insecure</strong> - Set this to <code>Yes</code> if you want to attempt authentication without a verified thumbprint.</li>
<li><strong>Palo Alto Networks thumbprints</strong> (optional) - A set of <code>IP[:port]=SHA256:B64HASH</code> or <code>hostname.domain.tld=SHA256:B64HASH</code> pairs to trust for authentication.
<ul>
<li>You will need to scan your Palo Alto Networks firewalls with runZero in order to obtain the TLS thumbprint. The <a href="https://console.runzero.com/reports/analysis/sattr?f=pan.api.thumbprint&amp;sf=protocol&amp;sfv=http%09tls&amp;t=Service%20Attribute%20Report%20%5Bpan.api.thumbprint%5D">PAN API thumbprints service attribute report</a> lists all previously seen thumbprints.</li>
</ul>
</li>
<li><strong>CIDR allow list</strong> - Set which IP addresses this API Key will be sent to in the <strong>CIDR allow list</strong>.</li>
</ul>
</li>
<li>If you want all other organizations to be able to use this credential, select the Make this a global credential option. Otherwise, you can configure access on a per-organization basis.</li>
<li>Save the credential.</li>
</ol>
<p>You’re now ready to set up and activate the connection to bring in data from Palo Alto Networks Firewall.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Qualys VMDR]]></title>
    <link href="https://www.runzero.com/docs/qualys/"/>
    <id>https://www.runzero.com/docs/qualys/</id>
      
      <published>2026-04-11T03:07:33+00:00</published>
      <updated>2026-04-11T03:07:33+00:00</updated>
      <summary type="html"><![CDATA[<p class="licenses"><a href="https://www.runzero.com/product/pricing/"><span class="com">Community</span></a>&nbsp;<a href="https://www.runzero.com/product/pricing/"><span class="pla">Platform</span></a></p>
<p>runZero integrates with <span class="book-index" data-book-index="Qualys VMDR">Qualys VMDR</span> by importing data from the Qualys KnowledgeBase <a href="https://www.qualys.com/docs/qualys-api-vmpc-user-guide.pdf">API</a>.</p>
<h2 id="qualys-asset-inventory">Asset inventory</h2>
<p>There is a column on the asset inventory page showing the count of vulnerabilities detected by Qualys for each asset. When a single asset is selected, the vulnerabilities table lists all the results related to that asset. The vulnerability count can be impacted by the type of vulnerability scan as well as the import settings selected.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[NetBox CMDB]]></title>
    <link href="https://www.runzero.com/docs/netbox/"/>
    <id>https://www.runzero.com/docs/netbox/</id>
      
      <published>2026-01-16T12:08:14+00:00</published>
      <updated>2026-01-16T12:08:14+00:00</updated>
      <summary type="html"><![CDATA[<p class="licenses"><a href="https://www.runzero.com/product/pricing/"><span class="com">Community</span></a>&nbsp;<a href="https://www.runzero.com/product/pricing/"><span class="pla">Platform</span></a></p>
<p>runZero integrates with <span class="book-index" data-book-index="NetBox">NetBox</span> configuration management database (CMDB) using the <a href="https://demo.netbox.dev/api/schema/swagger-ui/">NetBox REST API</a> to
enrich your asset inventory.</p>
<h2 id="netbox-limitations">NetBox limitations</h2>
<p>runZero explicitly supports NetBox version 4. Older versions (3.x) may be compatible, but are not specifically tested
or supported.</p>
<p>Since NetBox data entry is free-form, the runZero integration may not be a good fit for your organization, and we
strongly recommend testing this integration in a Project first before configuring it for a production Organization.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Miradore MDM]]></title>
    <link href="https://www.runzero.com/docs/miradore/"/>
    <id>https://www.runzero.com/docs/miradore/</id>
      
      <published>2025-06-16T18:02:52+00:00</published>
      <updated>2025-06-16T18:02:52+00:00</updated>
      <summary type="html"><![CDATA[<p class="licenses"><a href="https://www.runzero.com/product/pricing/"><span class="com">Community</span></a>&nbsp;<a href="https://www.runzero.com/product/pricing/"><span class="pla">Platform</span></a></p>
<p>runZero integrates with <span class="book-index" data-book-index="Miradore">Miradore</span> mobile device management (MDM) to deliver greater visibility into your mobile assets. This integration imports data from the <a href="https://www.miradore.com/knowledge/integrations/miradore-api/">Miradore API</a> to enrich your asset inventory. Syncing with Miradore allows you to view information about device hardware, OS version, associated user, and more. This integration imports all enrolled devices.</p>
<h2 id="miradore-getting-started">Getting started</h2>
<p>To set up the Miradore integration, you’ll need to:</p>
<ol>
<li>Sign in to your Miradore web portal and create a new API key.</li>
<li>Add the Miradore credential to runZero, which includes the endpoint hostname and API key.</li>
<li>Choose whether to configure the integration as <a href="/docs/integrations-inbound/#integration-probe-connector">a scan probe or connector task</a>.</li>
<li>Activate the Miradore integration to sync your data with runZero.</li>
</ol>
<h2 id="miradore-requirements">Requirements</h2>
<p>Before you can set up the Miradore integration:</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Microsoft Intune]]></title>
    <link href="https://www.runzero.com/docs/microsoft-intune/"/>
    <id>https://www.runzero.com/docs/microsoft-intune/</id>
      
      <published>2025-12-10T09:53:45+00:00</published>
      <updated>2025-12-10T09:53:45+00:00</updated>
      <summary type="html"><![CDATA[<p class="licenses"><a href="https://www.runzero.com/product/pricing/"><span class="com">Community</span></a>&nbsp;<a href="https://www.runzero.com/product/pricing/"><span class="pla">Platform</span></a></p>
<p>runZero integrates with <span class="book-index" data-book-index="Microsoft Intune">Microsoft Intune</span> to allow you to sync and enrich your asset inventory. Adding your Microsoft
Intune data to runZero makes it easier to find unmanaged assets on your network. Data added includes
the <a href="https://learn.microsoft.com/en-us/mem/intune/apps/app-discovered-apps#details-of-discovered-apps">discovered apps</a> from Intune. Managed apps (those pushed to devices by Intune) are not currently reported.</p>
<h2 id="intune-getting-started">Getting started</h2>
<p>To set up the Microsoft Intune integration, you’ll need to:</p>
<ol>
<li>
<p>Configure Microsoft Intune to allow API access from runZero.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Microsoft Entra ID]]></title>
    <link href="https://www.runzero.com/docs/microsoft-entra-id/"/>
    <id>https://www.runzero.com/docs/microsoft-entra-id/</id>
      
      <published>2026-04-11T03:07:33+00:00</published>
      <updated>2026-04-11T03:07:33+00:00</updated>
      <summary type="html"><![CDATA[<p class="licenses"><a href="https://www.runzero.com/product/pricing/"><span class="com">Community</span></a>&nbsp;<a href="https://www.runzero.com/product/pricing/"><span class="pla">Platform</span></a></p>
<p>runZero integrates with Microsoft <span class="book-index" data-book-index="Entra ID">Entra ID</span> (formerly <span class="book-index" data-book-index="Azure AD">Azure AD</span>) to allow you to sync and enrich your asset inventory, as well as gain visibility into Entra ID users and groups. Adding your Entra ID data to runZero makes it easier to find assets that are not part of your domain.</p>
<p>Note that Entra ID is still referred to as Azure AD within the runZero product.</p>
<h2 id="azure-ad-getting-started">Getting started</h2>
<p>To set up the Entra ID integration, you’ll need to:</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Microsoft Endpoint Configuration Manager (MECM)]]></title>
    <link href="https://www.runzero.com/docs/mecm/"/>
    <id>https://www.runzero.com/docs/mecm/</id>
      
      <published>2025-06-16T18:02:52+00:00</published>
      <updated>2025-06-16T18:02:52+00:00</updated>
      <summary type="html"><![CDATA[<p class="licenses"><a href="https://www.runzero.com/product/pricing/"><span class="com">Community</span></a>&nbsp;<a href="https://www.runzero.com/product/pricing/"><span class="pla">Platform</span></a></p>
<p>runZero integrates with <span class="book-index" data-book-index="Microsoft Endpoint Configuration Manager">Microsoft Endpoint Configuration Manager</span> (MECM), formerly System Center Configuration Manager (SCCM), by importing data from the MECM MSSQL database. This integration allows you to sync data about your devices from MECM, making it easier to find unmanaged devices in your network.</p>
<h2 id="mecm-getting-started">Getting started with MECM</h2>
<p>To set up an integration with MECM, you’ll need to:</p>
<ol>
<li>Identify or create a database user with read access to the MECM database.</li>
<li>Configure the MECM credential in runZero.</li>
<li>Choose whether to configure the integration as <a href="/docs/integrations-inbound/#integration-probe-connector">a scan probe or connector task</a>.</li>
<li>Activate the integration to pull your data into runZero.</li>
</ol>
<h2 id="mecm-step1">Step 1: Identify or create a database user for access to MECM</h2>
<ol>
<li>Identify an existing database user with read access to the database.</li>
<li>Alternatively, create a dedicated read-only database user for this integration. More details on creating a new database user can be found in Microsoft’s documentation - <a href="https://learn.microsoft.com/en-us/sql/relational-databases/security/authentication-access/create-a-database-user?view=sql-server-ver16">Create a database user</a>.</li>
</ol>
<h2 id="mecm-step2">Step 2: Add the MECM database connection string to runZero</h2>
<ol>
<li>Go to the <a href="https://console.runzero.com/credentials/new">Credentials page</a> in runZero.</li>
<li>Choose <strong>MECM Database Connection String</strong> from the list of credential types.</li>
<li>Provide a name for the credential, like <code>MECM</code>.</li>
<li>Provide the database connection string, using one of the following formats:
<ul>
<li><code>Server=host,port;Database=database-name;User Id=user-id;Password=password;</code><br>
When using this format, the values should not contain a semicolon (;). You can use single or double quotes to escape any special characters.</li>
<li><code>sqlserver://username:password@host/instance?database=value&amp;param=value</code></li>
</ul>
</li>
<li>If you want other organizations to be able to use this credential, select the <em>Make this a global credential</em> option. Otherwise, you can configure access on a per-organization basis.</li>
<li>Save the credential.</li>
</ol>
<p>You’re now ready to set up and activate the connection to bring in data from MECM.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Microsoft Azure]]></title>
    <link href="https://www.runzero.com/docs/azure/"/>
    <id>https://www.runzero.com/docs/azure/</id>
      
      <published>2025-09-23T10:44:06+00:00</published>
      <updated>2025-09-23T10:44:06+00:00</updated>
      <summary type="html"><![CDATA[<p class="licenses"><a href="https://www.runzero.com/product/pricing/"><span class="com">Community</span></a>&nbsp;<a href="https://www.runzero.com/product/pricing/"><span class="pla">Platform</span></a></p>
<p>runZero integrates with <span class="book-index" data-book-index="Microsoft Azure">Microsoft Azure</span> to deliver greater visibility into your cloud assets. This integration imports data through each applicable API to enrich your asset inventory:</p>
<ul>
<li><a href="https://docs.microsoft.com/en-us/rest/api/compute/virtual-machines">Virtual Machines API</a></li>
<li><a href="https://docs.microsoft.com/en-us/rest/api/compute/virtual-machine-scale-sets">Virtual Machine Scale Sets API</a></li>
<li><a href="https://docs.microsoft.com/en-us/rest/api/load-balancer/load-balancers">Load Balancers API</a></li>
<li><a href="https://docs.microsoft.com/en-us/rest/api/sql/">AzureSQL API</a></li>
<li><a href="https://docs.microsoft.com/en-us/rest/api/appservice/web-apps">Web Apps API</a></li>
</ul>
<p>Syncing with Azure allows you to view information about your asset’s OS profile, storage profile, and more. This integration imports assets that are in a running state.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Microsoft Active Directory]]></title>
    <link href="https://www.runzero.com/docs/microsoft-active-directory/"/>
    <id>https://www.runzero.com/docs/microsoft-active-directory/</id>
      
      <published>2026-04-11T03:07:33+00:00</published>
      <updated>2026-04-11T03:07:33+00:00</updated>
      <summary type="html"><![CDATA[<p class="licenses"><a href="https://www.runzero.com/product/pricing/"><span class="com">Community</span></a>&nbsp;<a href="https://www.runzero.com/product/pricing/"><span class="pla">Platform</span></a></p>
<p>runZero integrates with Microsoft Active Directory (AD) via <span class="book-index" data-book-index="LDAP">LDAP</span> to allow you to sync and enrich your asset inventory, as well as gain visibility into domain users and groups. Adding your AD data to runZero makes it easier to find assets that are not part of your domain.</p>
<h2 id="ldap-getting-started">Getting started</h2>
<p>To set up the Active Directory integration, you’ll need to:</p>
<ol>
<li>Add the AD credential in runZero.</li>
<li>Choose whether to configure the integration as <a href="/docs/integrations-inbound/#integration-probe-connector">a scan probe or connector task</a>.</li>
<li>Activate the Active Directory integration to sync your data with runZero.</li>
</ol>
<h2 id="ldap-requirements">Requirements</h2>
<p>Before you can set up the LDAP integration, make sure you have credentials for an LDAP account.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Microsoft 365 Defender]]></title>
    <link href="https://www.runzero.com/docs/microsoft-365-defender/"/>
    <id>https://www.runzero.com/docs/microsoft-365-defender/</id>
      
      <published>2026-03-17T10:16:47+00:00</published>
      <updated>2026-03-17T10:16:47+00:00</updated>
      <summary type="html"><![CDATA[<p class="licenses"><a href="https://www.runzero.com/product/pricing/"><span class="com">Community</span></a>&nbsp;<a href="https://www.runzero.com/product/pricing/"><span class="pla">Platform</span></a></p>
<p>runZero integrates with <span class="book-index" data-book-index="Microsoft 365 Defender">Microsoft 365 Defender</span> to allow you to sync and enrich your asset, software, and vulnerability inventory. Adding your <span class="book-index" data-book-index="Microsoft 365">Microsoft 365</span> <span class="book-index" data-book-index="Defender">Defender</span> data to runZero makes it easier to find assets missing EDR protection.</p>
<h2 id="microsoft-365-defender-getting-started">Getting started</h2>
<p>To set up the Microsoft 365 Defender integration, you’ll need to:</p>
<ol>
<li>Configure Microsoft 365 Defender to allow API access through runZero.</li>
<li>Add the Microsoft 365 Defender credential in runZero.</li>
<li>Choose whether to configure the integration as <a href="/docs/integrations-inbound/#integration-probe-connector">a scan probe or connector task</a>.</li>
<li>Activate the Microsoft 365 Defender integration to sync your data with runZero.</li>
</ol>
<h2 id="microsoft-365-defender-requirements">Requirements</h2>
<p>Before you can set up the Microsoft 365 Defender integration:</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Google Workspace]]></title>
    <link href="https://www.runzero.com/docs/google-workspace/"/>
    <id>https://www.runzero.com/docs/google-workspace/</id>
      
      <published>2026-04-11T03:07:33+00:00</published>
      <updated>2026-04-11T03:07:33+00:00</updated>
      <summary type="html"><![CDATA[<p class="licenses"><a href="https://www.runzero.com/product/pricing/"><span class="com">Community</span></a>&nbsp;<a href="https://www.runzero.com/product/pricing/"><span class="pla">Platform</span></a></p>
<p>runZero integrates with <span class="book-index" data-book-index="Google Workspace">Google Workspace</span> to allow you to sync and enrich your asset inventory, as well as gain visibility into users and groups. Adding your Google Workspace data to runZero makes it easier to find unmanaged assets on your network. The Google Workspace integration supports ChromeOS, Mobile, and Endpoint <a href="https://cloud.google.com/asset-inventory/docs/supported-asset-types">registered asset types</a>.</p>
<h2 id="googleworkspace-requirements">Requirements</h2>
<ul>
<li>Verify or create a new <a href="https://cloud.google.com/iam/docs/creating-managing-service-accounts#creating">Google service account</a> in whichever project is most suitable.</li>
<li><a href="https://cloud.google.com/iam/docs/creating-managing-service-account-keys#creating">Create and download a key</a> for the Google service account. Save this JSON file.</li>
<li>Verify that you have the <code>Admin SDK</code> and <code>Cloud Identity</code> APIs enabled for the project. Use the search box in the <a href="https://console.cloud.google.com/apis/library">API Library</a> to find each API and then enable it.</li>
<li>Enable domain-wide delegation in the <a href="https://admin.google.com/ac/owl/domainwidedelegation">Google Workspace console</a>
<ul>
<li>Add a new API client using the unique numeric ID of service account as the Client ID</li>
<li>Enable the following OAuth scopes for this API client:
<pre><code>https://www.googleapis.com/auth/admin.directory.user.readonly,
https://www.googleapis.com/auth/admin.directory.group.readonly,
https://www.googleapis.com/auth/admin.directory.device.mobile.readonly,
https://www.googleapis.com/auth/admin.directory.device.chromeos.readonly,
https://www.googleapis.com/auth/cloud-identity.devices.readonly
</code></pre>
</li>
<li>Optionally, enter each OAuth scope individually:</li>
<li><code>https://www.googleapis.com/auth/admin.directory.user.readonly</code></li>
<li><code>https://www.googleapis.com/auth/admin.directory.group.readonly</code></li>
<li><code>https://www.googleapis.com/auth/admin.directory.device.mobile.readonly</code></li>
<li><code>https://www.googleapis.com/auth/admin.directory.device.chromeos.readonly</code></li>
<li><code>https://www.googleapis.com/auth/cloud-identity.devices.readonly</code></li>
</ul>
</li>
</ul>
<h2 id="how-to-set-up-the-google-workspace-integration">How to set up the Google Workspace integration</h2>
<p>These are the high-level steps to set up the Google Cloud Platform integration:</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Google Cloud Platform]]></title>
    <link href="https://www.runzero.com/docs/google-cloud-platform/"/>
    <id>https://www.runzero.com/docs/google-cloud-platform/</id>
      
      <published>2025-06-16T18:02:52+00:00</published>
      <updated>2025-06-16T18:02:52+00:00</updated>
      <summary type="html"><![CDATA[<p class="licenses"><a href="https://www.runzero.com/product/pricing/"><span class="com">Community</span></a>&nbsp;<a href="https://www.runzero.com/product/pricing/"><span class="pla">Platform</span></a></p>
<p>The <span class="book-index" data-book-index="Google Cloud Platform">Google Cloud Platform</span> (<span class="book-index" data-book-index="GCP">GCP</span>) integration provides visibility into your cloud assets by synchronizing your GCP cloud inventories with runZero. runZero also integrates with other cloud providers, such as <a href="/docs/azure/">Microsoft Azure</a> and <a href="/docs/aws/">Amazon AWS</a>. Similarly to other integrations, you will need to add the <a href="/docs/scanning-credentials/">Scanning with credentials</a> needed to authenticate to GCP and set up a connector in runZero. runZero will pull in GCP compute instance VMs, pulling in GCP attributes that will be viewable from each asset.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Dragos]]></title>
    <link href="https://www.runzero.com/docs/dragos/"/>
    <id>https://www.runzero.com/docs/dragos/</id>
      
      <published>2025-09-10T14:32:03+00:00</published>
      <updated>2025-09-10T14:32:03+00:00</updated>
      <summary type="html"><![CDATA[<p class="licenses"><a href="https://www.runzero.com/product/pricing/"><span class="com">Community</span></a>&nbsp;<a href="https://www.runzero.com/product/pricing/"><span class="pla">Platform</span></a></p>
<p>runZero integrates with <span class="book-index" data-book-index="Dragos">Dragos</span> to help expand your OT visibility by importing assets and vulnerabilities from
the Dragos API.</p>
<h2 id="dragos-getting-started">Getting started with Dragos</h2>
<p>To set up an integration with Dragos, you’ll need to:</p>
<ol>
<li>Generate a Dragos API ID and API Secret with the following privileges:
<ul>
<li>asset:read</li>
<li>detection:read</li>
<li>vulnerability:read</li>
</ul>
</li>
<li>Configure the Dragos credential in runZero.</li>
<li>Activate the integration to pull your data into runZero.</li>
</ol>
<h2 id="dragos-step1">Step 1: Generate a Dragos API ID and API Secret</h2>
<ol>
<li>Log into the Dragos console and navigate to Admin, then navigate to Users. Under the user, click the Add New API Key button.</li>
<li>When the Generate New API Key box appears, name your API ID and API Secret, then click Generate Key.</li>
<li>Copy the ID and Secret for later.</li>
</ol>
<h2 id="dragos-step2">Step 2: Add the Dragos API ID and API Secret to runZero</h2>
<ol>
<li>Go to the <a href="https://console.runzero.com/credentials/new">Credentials page</a> in runZero.</li>
<li>Choose <strong>Dragos API ID &amp; Secret</strong> from the list of credential types.</li>
<li>Provide a name for the credential, like <code>Dragos</code>.</li>
<li>Provide the following information:
<ul>
<li><strong>Dragos API ID</strong> - Your Dragos API ID from Step 1.</li>
<li><strong>Dragos API Secret</strong> - Your Dragos API Secret from Step 1.</li>
<li><strong>Dragos API URL</strong> - The URL to your Dragos instance, without any trailing slashes. For example, <code>https://my.instance.dragos.cloud</code>.</li>
<li><strong>Insecure</strong> - Enable this option to approve authenticating with untrusted endpoints. When enabled, certificate validation is disabled. Use with caution.</li>
</ul>
</li>
<li>If you want other organizations to be able to use this credential, select the <em>Make this a global credential</em> option. Otherwise, you can configure access on a per-organization basis.</li>
<li>Verify and save the credential. Note that if the URL provided is an internal IP address, verification is unsupported, but the credential can be saved and the integration will still be usable when run on an Explorer.</li>
</ol>
<p>You’re now ready to set up and activate the connection to bring in data from Dragos.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Starlark library usage examples]]></title>
    <link href="https://www.runzero.com/docs/custom-integration-starlark-libraries/"/>
    <id>https://www.runzero.com/docs/custom-integration-starlark-libraries/</id>
      
      <published>2025-11-04T09:50:39+00:00</published>
      <updated>2025-11-04T09:50:39+00:00</updated>
      <summary type="html"><![CDATA[<p class="licenses"><a href="https://www.runzero.com/product/pricing/"><span class="com">Community</span></a>&nbsp;<a href="https://www.runzero.com/product/pricing/"><span class="pla">Platform</span></a></p>
<p>This document provides sample usage for common runZero Starlark libraries used in custom integration scripts.</p>
<h2 id="starlark-lib-requests">requests</h2>
<pre><code class="language-starlark">load(&#39;requests&#39;, &#39;Session&#39;, &#39;Cookie&#39;)
load(&#39;json&#39;, json_decode=&#39;decode&#39;)

def requests_example():
    session = Session()
    session.headers.set(&#39;Accept&#39;, &#39;application/json&#39;)
    session.headers.set(&#39;User-Agent&#39;, &#39;Mozilla/5.0&#39;)
    session.headers.set(&#39;User-Agent&#39;, None)  # remove header

    url = &#39;https://hacker-news.firebaseio.com/v0/topstories.json&#39;
    session.cookies.set(url, {&#34;test_cookie&#34;: &#34;cookie_value&#34;})

    response = session.get(url)
    if response and response.status_code == 200:
        data = json_decode(response.body)
        print(&#34;Top story IDs:&#34;, data[:5])
    else:
        print(&#34;Failed to fetch stories&#34;)
</code></pre>
<h2 id="starlark-lib-http">http</h2>
<pre><code class="language-starlark">load(&#39;http&#39;, http_post=&#39;post&#39;, http_get=&#39;get&#39;, &#39;url_encode&#39;)

def fetch_example():
    url = &#34;https://hacker-news.firebaseio.com/v0/topstories.json&#34;
    headers = {&#34;Accept&#34;: &#34;application/json&#34;}
    
    response = http_get(url, headers=headers)
    
    if response and response.status_code == 200:
        print(&#34;Top stories retrieved successfully.&#34;)
    else:
        print(&#34;Request failed with status:&#34;, response.status_code)
</code></pre>
<h2 id="starlark-lib-net">net</h2>
<pre><code class="language-starlark">load(&#39;net&#39;, &#39;ip_address&#39;)

def parse_ip_list():
    ips = [&#34;192.168.1.1&#34;, &#34;2607:f8b0:4005:805::200e&#34;]
    for ip in ips:
        addr = ip_address(ip)
        print(&#34;IP:&#34;, addr, &#34;Version:&#34;, addr.version)
</code></pre>
<h2 id="starlark-lib-json">json</h2>
<pre><code class="language-starlark">load(&#39;json&#39;, json_encode=&#39;encode&#39;, json_decode=&#39;decode&#39;)

def test_json_handling():
    data = {&#34;name&#34;: &#34;runZero&#34;, &#34;features&#34;: [&#34;scan&#34;, &#34;API&#34;, &#34;integrations&#34;]}
    
    encoded = json_encode(data)
    print(&#34;Encoded JSON:&#34;, encoded)
    
    decoded = json_decode(encoded)
    print(&#34;Decoded:&#34;, decoded[&#34;name&#34;])
</code></pre>
<h2 id="starlark-lib-time">time</h2>
<pre><code class="language-starlark">load(&#39;time&#39;, &#39;parse_time&#39;)

def parse_example_time():
    time_str = &#34;2025-05-01T15:00:00Z&#34;
    parsed = parse_time(time_str)
    print(&#34;Parsed time:&#34;, parsed)

    # Emit Unix epoch time in seconds for use in certain time fields
    epoch = parsed.unix
    print(&#34;Epoch time:&#34;, epoch)
</code></pre>
<h2 id="starlark-lib-uuid">uuid</h2>
<pre><code class="language-starlark">load(&#39;uuid&#39;, &#39;new_uuid&#39;)

def create_unique_id():
    uid = new_uuid()
    print(&#34;Generated UUID:&#34;, uid)
</code></pre>
<h2 id="starlark-lib-gzip">gzip</h2>
<pre><code class="language-starlark">load(&#39;gzip&#39;, gzip_decompress=&#39;decompress&#39;, gzip_compress=&#39;compress&#39;)

def gzip_example():
    original = &#34;Hello, runZero!&#34;.encode(&#34;utf-8&#34;)

    # Compress the data
    compressed = gzip_compress(original)
    print(&#34;Compressed length:&#34;, len(compressed))

    # Decompress it back
    decompressed = gzip_decompress(compressed)
    print(&#34;Decompressed value:&#34;, decompressed.decode(&#34;utf-8&#34;))

</code></pre>
<h2 id="starlark-lib-base64">base64</h2>
<pre><code class="language-starlark">load(&#39;base64&#39;, base64_encode=&#39;encode&#39;, base64_decode=&#39;decode&#39;)

def b64_example():
    username = &#34;xxx&#34;
    password = &#34;yyy&#34;
    enc = base64_encode(username + &#34;:&#34; + password)
    dec = base64_decode(enc)
    return (enc, dec)
</code></pre>
<h2 id="starlark-lib-crypto">crypto</h2>
<pre><code class="language-starlark">load(&#39;crypto&#39;, &#39;sha256&#39;, &#39;sha512&#39;, &#39;sha1&#39;, &#39;md5&#39;)

def main(*args, **kwargs):
    access_key = kwargs[&#39;access_key&#39;]
    access_secret = kwargs[&#39;access_secret&#39;]

    input = &#34;test&#34;

    sha256_hash = sha256(input)
    if str(sha256_hash) != &#39;9f86d081884c7d659a2feaa0c55ad015a3bf4f1b2b0b822cd15d6c15b0f00a08&#39;:
        print(&#34;sha256_hash [fail]: {}&#34;.format(sha256_hash))
    else:
        print(&#34;sha256_hash [pass]: {}&#34;.format(sha256_hash))

    sha512_hash = sha512(input)
    if str(sha512_hash) != &#39;ee26b0dd4af7e749aa1a8ee3c10ae9923f618980772e473f8819a5d4940e0db27ac185f8a0e1d5f84f88bc887fd67b143732c304cc5fa9ad8e6f57f50028a8ff&#39;:
        print(&#34;sha512_hash [fail]: {}&#34;.format(sha512_hash))
    else:
        print(&#34;sha512_hash [pass]: {}&#34;.format(sha512_hash))

    sha1_hash = sha1(input)
    if str(sha1_hash) != &#39;a94a8fe5ccb19ba61c4c0873d391e987982fbbd3&#39;:
        print(&#34;sha1_hash [fail]: {}&#34;.format(sha1_hash))
    else:
        print(&#34;sha1_hash [pass]: {}&#34;.format(sha1_hash))

    md5_hash = md5(input)
    if str(md5_hash) != &#39;098f6bcd4621d373cade4e832627b4f6&#39;:
        print(&#34;md5_hash [fail]: {}&#34;.format(md5_hash))
    else:
        print(&#34;md5_hash [pass]: {}&#34;.format(md5_hash))

    return True
</code></pre>
<h2 id="starlark-lib-flatten-json">flatten (json)</h2>
<pre><code class="language-starlark">load(&#39;flatten_json&#39;, &#39;flatten&#39;)

def main(*args, **kwargs):
    nested_json = {&#34;foo&#34;: &#34;bar&#34;, &#34;a&#34;: {&#34;b&#34;: &#34;c&#34;}}
    flattened_json = flatten(nested_json)
    return True
</code></pre>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Custom Integration Scripts]]></title>
    <link href="https://www.runzero.com/docs/custom-integration-scripts/"/>
    <id>https://www.runzero.com/docs/custom-integration-scripts/</id>
      
      <published>2025-11-04T09:50:39+00:00</published>
      <updated>2025-11-04T09:50:39+00:00</updated>
      <summary type="html"><![CDATA[<p class="licenses"><a href="https://www.runzero.com/product/pricing/"><span class="com">Community</span></a>&nbsp;<a href="https://www.runzero.com/product/pricing/"><span class="pla">Platform</span></a></p>
<p>To set up the <span class="book-index" data-book-index="custom integration">custom integration</span> script, you will need to:</p>
<ol>
<li>Write the script.</li>
<li>Optionally add credentials.</li>
<li>Create an integration task.</li>
</ol>
<h2 id="step-1-write-integration-script">Step 1: Write integration script</h2>
<p>The script can be written in <a href="https://github.com/google/starlark-go/blob/master/doc/spec.md#starlark-in-go-language-definition"><span class="book-index" data-book-index="Starlark">Starlark</span></a>, a Python-like language with some notable differences:</p>
<ol>
<li>There is no exception handling (<code>try/catch</code>)</li>
<li>There is no f-string <code>f&#39;{var}&#39;</code> formatting - <code>&#34;{}&#34;.format(var)</code> is the supported method of string interpolation.</li>
</ol>
<h3 id="step-1a-entrypoint">Step 1a: Entrypoint</h3>
<p>The <span class="book-index" data-book-index="script">script</span> needs an entrypoint, a function that gets called by the runZero service and returns the Inventory Assets discovered by the script.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[CrowdStrike Falcon]]></title>
    <link href="https://www.runzero.com/docs/crowdstrike/"/>
    <id>https://www.runzero.com/docs/crowdstrike/</id>
      
      <published>2026-04-11T03:07:33+00:00</published>
      <updated>2026-04-11T03:07:33+00:00</updated>
      <summary type="html"><![CDATA[<p class="licenses"><a href="https://www.runzero.com/product/pricing/"><span class="com">Community</span></a>&nbsp;<a href="https://www.runzero.com/product/pricing/"><span class="pla">Platform</span></a></p>
<p>runZero integrates with <span class="book-index" data-book-index="CrowdStrike">CrowdStrike</span> by importing data through the <a href="https://www.crowdstrike.com/blog/tech-center/get-access-falcon-apis/">CrowdStrike Falcon API</a>. This integration allows you to sync and enrich your asset inventory, as well as ingesting vulnerability data from Falcon Spotlight and software data from Falcon Discover. Adding your CrowdStrike data to runZero makes it easier to find things like endpoints that are missing an EDR agent.</p>
<h2 id="crowdstrike-getting-started">Getting started</h2>
<p>To set up the CrowdStrike integration, you’ll need to:</p>
<ol>
<li>Configure CrowdStrike to allow API access through runZero.</li>
<li>Add the CrowdStrike credentials, which will include the client ID and client secret, and CrowdStrike base API URL in runZero.</li>
<li>Choose whether to configure the integration as <a href="/docs/integrations-inbound/#integration-probe-connector">a scan probe or connector task</a>.</li>
<li>Activate the CrowdStrike integration to sync your data with runZero.</li>
</ol>
<h2 id="crowdstrike-requirements">Requirements</h2>
<p>Before you can set up the CrowdStrike integration:</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Cisco Meraki Dashboard]]></title>
    <link href="https://www.runzero.com/docs/meraki/"/>
    <id>https://www.runzero.com/docs/meraki/</id>
      
      <published>2025-06-16T18:02:52+00:00</published>
      <updated>2025-06-16T18:02:52+00:00</updated>
      <summary type="html"><![CDATA[<p class="licenses"><a href="https://www.runzero.com/product/pricing/"><span class="com">Community</span></a>&nbsp;<a href="https://www.runzero.com/product/pricing/"><span class="pla">Platform</span></a></p>
<p>runZero integrates with <span class="book-index" data-book-index="Cisco Meraki Dashboard">Cisco Meraki Dashboard</span> by importing data from the <a href="https://documentation.meraki.com/General_Administration/Other_Topics/Cisco_Meraki_Dashboard_API">Cisco Meraki Dashboard API</a>. This integration allows you to sync data about your devices and network clients from Meraki to provide better visibility of your network.</p>
<h2 id="meraki-getting-started">Getting started with Meraki</h2>
<p>To set up an integration with Meraki, you’ll need to:</p>
<ol>
<li>Generate an API key for your Cisco Meraki Dashboard administrator account.</li>
<li>Configure the Meraki credential in runZero.</li>
<li>Choose whether to configure the integration as <a href="/docs/integrations-inbound/#integration-probe-connector">a scan probe or connector task</a>.</li>
<li>Activate the integration to pull your data into runZero.</li>
</ol>
<h2 id="meraki-requirements">Requirements</h2>
<p>Before you can set up the Meraki integration:</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Censys Search &amp; Data]]></title>
    <link href="https://www.runzero.com/docs/censys/"/>
    <id>https://www.runzero.com/docs/censys/</id>
      
      <published>2025-04-09T14:04:18+00:00</published>
      <updated>2025-04-09T14:04:18+00:00</updated>
      <summary type="html"><![CDATA[<p class="licenses"><a href="https://www.runzero.com/product/pricing/"><span class="com">Community</span></a>&nbsp;<a href="https://www.runzero.com/product/pricing/"><span class="pla">Platform</span></a></p>
<p>runZero supports importing assets from the <a href="https://support.censys.io/hc/en-us/categories/4405770552724-Censys-Search">Censys Search API</a> and the <a href="https://support.censys.io/hc/en-us/sections/4405799086740-Universal-Internet-Data-Set">Censys Internet Dataset</a>.</p>
<ul>
<li><a href="/docs/censys/#censys-search-api">Importing assets from the Censys Search API</a></li>
<li><a href="/docs/censys/#censys-universal-internet-dataset">Importing assets from the Censys Universal Internet Dataset</a></li>
</ul>
<h2 id="censys-search-api">Censys Search API</h2>
<p>To get started with the <span class="book-index" data-book-index="Censys Search">Censys Search</span> API, you will need to register for a <a href="https://censys.io/register">Censys Search account</a>. Once you have done so, you can find your API credentials in the <a href="https://search.censys.io/account/api">My Account</a> section.</p>
<p>In runZero, go to the Credentials page, and click <a href="https://console.runzero.com/credentials/new">Add Credential</a>. Select <em>Censys Search API Key</em> as the credential type, and enter your API ID and API secret.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Enriching scans with EC2]]></title>
    <link href="https://www.runzero.com/docs/enriching-assets-with-ec2-metadata/"/>
    <id>https://www.runzero.com/docs/enriching-assets-with-ec2-metadata/</id>
      
      <published>2024-04-03T16:14:21+00:00</published>
      <updated>2024-04-03T16:14:21+00:00</updated>
      <summary type="html"><![CDATA[<p class="licenses"><a href="https://www.runzero.com/product/pricing/"><span class="com">Community</span></a>&nbsp;<a href="https://www.runzero.com/product/pricing/"><span class="pla">Platform</span></a></p>
<p>As part of a discovery scan, runZero will automatically enrich scanned assets with data from the <span class="book-index" data-book-index="AWS">AWS</span> <span class="book-index" data-book-index="EC2">EC2</span> API when available. runZero assets will be updated with internal IP addresses, external IP addresses, hostnames, MAC addresses, and tags, along with other EC2-specific attributes, such as the account ID and instance type.</p>
<p>No additional configuration is needed in runZero to get this data enrichment. However, you may need to <a href="/docs/enriching-assets-with-ec2-metadata/#add-permissions-to-describe-instances">modify the permissions</a> associated with the instance’s <span class="book-index" data-book-index="IAM">IAM</span> role.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Amazon Web Services]]></title>
    <link href="https://www.runzero.com/docs/aws/"/>
    <id>https://www.runzero.com/docs/aws/</id>
      
      <published>2026-05-08T11:07:19+00:00</published>
      <updated>2026-05-08T11:07:19+00:00</updated>
      <summary type="html"><![CDATA[<p class="licenses"><a href="https://www.runzero.com/product/pricing/"><span class="com">Community</span></a>&nbsp;<a href="https://www.runzero.com/product/pricing/"><span class="pla">Platform</span></a></p>
<p>runZero integrates with <span class="book-index" data-book-index="Amazon Web Services">Amazon Web Services</span> (<span class="book-index" data-book-index="AWS">AWS</span>) to provide better visibility across your cloud environment. This integration imports data from each applicable API to add detailed information to your asset inventory:</p>
<ul>
<li><a href="https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Welcome.html">AWS EC2 API</a></li>
<li><a href="https://docs.aws.amazon.com/AmazonRDS/latest/UserGuide/ProgrammingGuide.html">AWS RDS API</a></li>
<li><a href="https://docs.aws.amazon.com/elasticloadbalancing/2012-06-01/APIReference/Welcome.html">AWS ELBv1 API</a></li>
<li><a href="https://docs.aws.amazon.com/elasticloadbalancing/latest/APIReference/Welcome.html">AWS ELBv2 API</a></li>
<li><a href="https://docs.aws.amazon.com/lambda/latest/dg/API_Reference.html">AWS Lambda API</a></li>
<li><a href="https://docs.aws.amazon.com/fsx/latest/APIReference/API_Operations.html">AWS FSx API</a></li>
</ul>
<p>Syncing with AWS allows you to quickly identify the number of EC2 instances, elastic load balancers, relational database services, FSx file systems, and VPCs you have running, as well as their region, account, and more.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Inbound integrations]]></title>
    <link href="https://www.runzero.com/docs/integrations-inbound/"/>
    <id>https://www.runzero.com/docs/integrations-inbound/</id>
      
      <published>2025-10-28T15:22:01+00:00</published>
      <updated>2025-10-28T15:22:01+00:00</updated>
      <summary type="html"><![CDATA[<h2 id="enriching-runzero-results-with-data-from-other-tools">Enriching runZero results with data from other tools</h2>
<p>The runZero platform offers integrations with several sources of asset data, allowing users to enrich their asset inventory and identify assets and subnets that are not effectively managed or protected. By leveraging product APIs and export/import functionality, runZero can pull data from many IT and security tools to extend visibility across your organization’s network.</p>
<iframe src="https://demo.arcade.software/cmdTTVVTRLztVKvfWMlf?embed" loading="lazy" allowfullscreen="" title="Walkthroughs - Setting up an Integration"></iframe>
<h2 id="supported-integrations">Supported integrations</h2>
<h3 id="cloud-and-virtualization">Cloud and virtualization</h3>
<ul>
<li><a href="/docs/aws/">Amazon Web Services</a></li>
<li><a href="/docs/google-cloud-platform/">Google Cloud Platform</a></li>
<li><a href="/docs/azure/">Microsoft Azure</a></li>
<li><a href="/docs/prisma/">Prisma</a></li>
<li><a href="/docs/vmware/">VMware</a></li>
<li><a href="/docs/wiz/">Wiz</a></li>
</ul>
<h3 id="endpoint-protection">Endpoint protection</h3>
<ul>
<li><a href="/docs/crowdstrike/">CrowdStrike Falcon</a></li>
<li><a href="/docs/microsoft-365-defender/">Microsoft 365 Defender</a></li>
<li><a href="/docs/microsoft-intune/">Microsoft Intune</a></li>
<li><a href="/docs/miradore/">Miradore MDM</a></li>
<li><a href="/docs/sentinelone/">SentinelOne</a></li>
<li><a href="/docs/tanium/">Tanium API Gateway</a></li>
</ul>
<h3 id="endpoint-management">Endpoint management</h3>
<ul>
<li><a href="/docs/mecm/">Microsoft Endpoint Configuration Manager (MECM)</a></li>
</ul>
<h3 id="asset-and-identity-management">Asset and identity management</h3>
<ul>
<li><a href="/docs/google-workspace/">Google Workspace</a></li>
<li><a href="/docs/microsoft-active-directory/">Microsoft Active Directory</a></li>
<li><a href="/docs/microsoft-entra-id/">Microsoft Entra ID</a> (formerly Azure AD)</li>
</ul>
<h3 id="integrations-inbound-vm">Vulnerabilities and risk</h3>
<ul>
<li><a href="/docs/censys/">Censys Search &amp; Data</a></li>
<li><a href="/docs/dragos/">Dragos</a></li>
<li><a href="/docs/qualys/">Qualys VMDR</a></li>
<li><a href="/docs/rapid7/">Rapid7</a>
<ul>
<li><a href="/docs/rapid7-insightvm/">InsightVM</a></li>
<li><a href="/docs/rapid7-nexpose/">Nexpose</a></li>
</ul>
</li>
<li><a href="/docs/shodan/">Shodan</a></li>
<li><a href="/docs/tenable/">Tenable</a>
<ul>
<li><a href="/docs/tenable-vm/">Tenable Vulnerability Management</a></li>
<li><a href="/docs/tenable-nessuspro/">Tenable Nessus Professional</a></li>
<li><a href="/docs/tenable-sc/">Tenable Security Center</a></li>
<li><a href="/docs/tenable-nessus/">Tenable Nessus (file import)</a></li>
</ul>
</li>
</ul>
<h3 id="network-management">Network management</h3>
<ul>
<li><a href="/docs/meraki/">Cisco Meraki Dashboard</a></li>
</ul>
<h3 id="custom-integrations">Custom integrations</h3>
<p class="licenses"><a href="https://www.runzero.com/product/pricing/"><span class="com">Community</span></a>&nbsp;<a href="https://www.runzero.com/product/pricing/"><span class="pla">Platform</span></a></p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Scanning IoT and OT]]></title>
    <link href="https://www.runzero.com/docs/troubleshooting-iot-and-ot/"/>
    <id>https://www.runzero.com/docs/troubleshooting-iot-and-ot/</id>
      
      <published>2026-05-10T19:03:44+00:00</published>
      <updated>2026-05-10T19:03:44+00:00</updated>
      <summary type="html"><![CDATA[<h2 id="can-i-safely-scan-my-iot-and-ot-environments">Can I safely scan my IoT and OT environments?</h2>
<p>Yes. <span class="book-index" data-book-index="IoT">IoT</span> and <span class="book-index" data-book-index="OT">OT</span> equipment is often sensitive to high packet rates or malformed traffic, and past experiences with aggressive scanners have led many teams to put a “don’t scan” rule in place for these networks. runZero was purpose-built to operate safely in these environments, so most organizations can confidently include their IoT and OT assets in their active inventory.</p>
<p>runZero discovers assets using a lightweight active scan engine called the <a href="/docs/installing-an-explorer/">Explorer</a>. The Explorer can be deployed almost anywhere on your network — no SPAN or TAP ports to configure, and no agents to install on individual devices. Because discovery is performed actively from a single point on the network, you don’t have to modify the environment you’re trying to inventory.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Default ports]]></title>
    <link href="https://www.runzero.com/docs/troubleshooting-ports-scanned/"/>
    <id>https://www.runzero.com/docs/troubleshooting-ports-scanned/</id>
      
      <published>2026-05-01T02:59:28+00:00</published>
      <updated>2026-05-01T02:59:28+00:00</updated>
      <summary type="html"><![CDATA[<p>runZero scans include extensive defaults and can be configured to cover any TCP or UDP port range.</p>
<h2 id="what-tcp-ports-does-runzero-scan">What TCP ports does runZero scan?</h2>
<p>runZero scans the following TCP ports by default:</p>
<p class="ports">
<span>7</span>
<span>13</span>
<span>17</span>
<span>21</span>
<span>22</span>
<span>23</span>
<span>25</span>
<span>37</span>
<span>53</span>
<span>80</span>
<span>88</span>
<span>102</span>
<span>110</span>
<span>111</span>
<span>113</span>
<span>135</span>
<span>137</span>
<span>139</span>
<span>143</span>
<span>179</span>
<span>264</span>
<span>389</span>
<span>427</span>
<span>443</span>
<span>444</span>
<span>445</span>
<span>464</span>
<span>465</span>
<span>502</span>
<span>512</span>
<span>513</span>
<span>514</span>
<span>515</span>
<span>523</span>
<span>535</span>
<span>541</span>
<span>554</span>
<span>587</span>
<span>593</span>
<span>631</span>
<span>636</span>
<span>749</span>
<span>750</span>
<span>789</span>
<span>873</span>
<span>902</span>
<span>992</span>
<span>993</span>
<span>995</span>
<span>1080</span>
<span>1081</span>
<span>1099</span>
<span>1153</span>
<span>1200</span>
<span>1217</span>
<span>1433</span>
<span>1434</span>
<span>1494</span>
<span>1502</span>
<span>1521</span>
<span>1522</span>
<span>1525</span>
<span>1718</span>
<span>1720</span>
<span>1723</span>
<span>1883</span>
<span>1911</span>
<span>1935</span>
<span>1962</span>
<span>2000</span>
<span>2049</span>
<span>2121</span>
<span>2181</span>
<span>2222</span>
<span>2323</span>
<span>2375</span>
<span>2376</span>
<span>2379</span>
<span>2404</span>
<span>2443</span>
<span>2455</span>
<span>2483</span>
<span>2484</span>
<span>2525</span>
<span>2598</span>
<span>2775</span>
<span>2888</span>
<span>2947</span>
<span>3000</span>
<span>3023</span>
<span>3050</span>
<span>3080</span>
<span>3260</span>
<span>3268</span>
<span>3269</span>
<span>3306</span>
<span>3389</span>
<span>3390</span>
<span>3690</span>
<span>3868</span>
<span>3888</span>
<span>3999</span>
<span>4000</span>
<span>4001</span>
<span>4190</span>
<span>4222</span>
<span>4369</span>
<span>4545</span>
<span>4567</span>
<span>4712</span>
<span>4786</span>
<span>4840</span>
<span>4843</span>
<span>4911</span>
<span>4949</span>
<span>5000</span>
<span>5005</span>
<span>5006</span>
<span>5007</span>
<span>5037</span>
<span>5060</span>
<span>5061</span>
<span>5094</span>
<span>5222</span>
<span>5223</span>
<span>5269</span>
<span>5353</span>
<span>5355</span>
<span>5432</span>
<span>5433</span>
<span>5555</span>
<span>5666</span>
<span>5671</span>
<span>5672</span>
<span>5800</span>
<span>5900</span>
<span>5901</span>
<span>5902</span>
<span>5903</span>
<span>5930</span>
<span>5938</span>
<span>5984</span>
<span>5985</span>
<span>5986</span>
<span>6000</span>
<span>6001</span>
<span>6002</span>
<span>6003</span>
<span>6004</span>
<span>6005</span>
<span>6006</span>
<span>6007</span>
<span>6008</span>
<span>6009</span>
<span>6010</span>
<span>6011</span>
<span>6012</span>
<span>6013</span>
<span>6014</span>
<span>6015</span>
<span>6106</span>
<span>6222</span>
<span>6333</span>
<span>6334</span>
<span>6379</span>
<span>6432</span>
<span>6443</span>
<span>6481</span>
<span>6514</span>
<span>6556</span>
<span>6568</span>
<span>6650</span>
<span>6651</span>
<span>6667</span>
<span>6668</span>
<span>6669</span>
<span>6697</span>
<span>7000</span>
<span>7001</span>
<span>7070</span>
<span>7473</span>
<span>7474</span>
<span>7519</span>
<span>7676</span>
<span>7687</span>
<span>7734</span>
<span>7878</span>
<span>8000</span>
<span>8001</span>
<span>8002</span>
<span>8003</span>
<span>8004</span>
<span>8080</span>
<span>8081</span>
<span>8082</span>
<span>8086</span>
<span>8098</span>
<span>8161</span>
<span>8181</span>
<span>8193</span>
<span>8200</span>
<span>8222</span>
<span>8291</span>
<span>8443</span>
<span>8453</span>
<span>8500</span>
<span>8554</span>
<span>8728</span>
<span>8787</span>
<span>8788</span>
<span>8883</span>
<span>8888</span>
<span>8889</span>
<span>8983</span>
<span>9000</span>
<span>9001</span>
<span>9042</span>
<span>9050</span>
<span>9080</span>
<span>9090</span>
<span>9092</span>
<span>9093</span>
<span>9094</span>
<span>9100</span>
<span>9101</span>
<span>9102</span>
<span>9150</span>
<span>9160</span>
<span>9200</span>
<span>9418</span>
<span>9443</span>
<span>9595</span>
<span>9999</span>
<span>10000</span>
<span>10001</span>
<span>10050</span>
<span>10051</span>
<span>11211</span>
<span>11222</span>
<span>11740</span>
<span>13400</span>
<span>16379</span>
<span>18000</span>
<span>18245</span>
<span>19000</span>
<span>19530</span>
<span>20000</span>
<span>20256</span>
<span>20547</span>
<span>22222</span>
<span>25565</span>
<span>26379</span>
<span>27017</span>
<span>27018</span>
<span>27019</span>
<span>28017</span>
<span>33060</span>
<span>44818</span>
<span>48050</span>
<span>48898</span>
<span>50000</span>
<span>50001</span>
<span>54921</span>
<span>54922</span>
<span>54923</span>
<span>60000</span>
<span>61616</span>
<span>61617</span>
<span>62078</span>
</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Protocol support]]></title>
    <link href="https://www.runzero.com/docs/troubleshooting-protocols-supported/"/>
    <id>https://www.runzero.com/docs/troubleshooting-protocols-supported/</id>
      
      <published>2026-05-01T22:14:59+00:00</published>
      <updated>2026-05-01T22:14:59+00:00</updated>
      <summary type="html"><![CDATA[<div class="nt-tag-cloud" aria-label="Protocol tags"><span class="nt-tag-cloud-item nt-tag-cloud-size-2" style="--tag-hue:10" data-pl-tag-link="aaa" onclick="plFilterByTag('aaa')" role="button" tabindex="0">aaa <strong>4</strong></span> <span class="nt-tag-cloud-item nt-tag-cloud-size-2" style="--tag-hue:135" data-pl-tag-link="ai" onclick="plFilterByTag('ai')" role="button" tabindex="0">ai <strong>5</strong></span> <span class="nt-tag-cloud-item nt-tag-cloud-size-2" style="--tag-hue:279" data-pl-tag-link="auth" onclick="plFilterByTag('auth')" role="button" tabindex="0">auth <strong>5</strong></span> <span class="nt-tag-cloud-item nt-tag-cloud-size-2" style="--tag-hue:224" data-pl-tag-link="automotive" onclick="plFilterByTag('automotive')" role="button" tabindex="0">automotive <strong>2</strong></span> <span class="nt-tag-cloud-item nt-tag-cloud-size-4" style="--tag-hue:308" data-pl-tag-link="backplane" onclick="plFilterByTag('backplane')" role="button" tabindex="0">backplane <strong>20</strong></span> <span class="nt-tag-cloud-item nt-tag-cloud-size-2" style="--tag-hue:119" data-pl-tag-link="backup" onclick="plFilterByTag('backup')" role="button" tabindex="0">backup <strong>2</strong></span> <span class="nt-tag-cloud-item nt-tag-cloud-size-2" style="--tag-hue:127" data-pl-tag-link="building-automation" onclick="plFilterByTag('building-automation')" role="button" tabindex="0">building-automation <strong>5</strong></span> <span class="nt-tag-cloud-item nt-tag-cloud-size-1" style="--tag-hue:158" data-pl-tag-link="camera" onclick="plFilterByTag('camera')" role="button" tabindex="0">camera <strong>1</strong></span> <span class="nt-tag-cloud-item nt-tag-cloud-size-5" style="--tag-hue:194" data-pl-tag-link="clear" onclick="plFilterByTag('clear')" role="button" tabindex="0">clear <strong>60</strong></span> <span class="nt-tag-cloud-item nt-tag-cloud-size-4" style="--tag-hue:352" data-pl-tag-link="database" onclick="plFilterByTag('database')" role="button" tabindex="0">database <strong>18</strong></span> <span class="nt-tag-cloud-item nt-tag-cloud-size-4" style="--tag-hue:7" data-pl-tag-link="deep" onclick="plFilterByTag('deep')" role="button" tabindex="0">deep <strong>24</strong></span> <span class="nt-tag-cloud-item nt-tag-cloud-size-2" style="--tag-hue:336" data-pl-tag-link="directory" onclick="plFilterByTag('directory')" role="button" tabindex="0">directory <strong>2</strong></span> <span class="nt-tag-cloud-item nt-tag-cloud-size-5" style="--tag-hue:101" data-pl-tag-link="discovery" onclick="plFilterByTag('discovery')" role="button" tabindex="0">discovery <strong>55</strong></span> <span class="nt-tag-cloud-item nt-tag-cloud-size-2" style="--tag-hue:255" data-pl-tag-link="email" onclick="plFilterByTag('email')" role="button" tabindex="0">email <strong>4</strong></span> <span class="nt-tag-cloud-item nt-tag-cloud-size-3" style="--tag-hue:203" data-pl-tag-link="encrypted" onclick="plFilterByTag('encrypted')" role="button" tabindex="0">encrypted <strong>9</strong></span> <span class="nt-tag-cloud-item nt-tag-cloud-size-3" style="--tag-hue:243" data-pl-tag-link="file" onclick="plFilterByTag('file')" role="button" tabindex="0">file <strong>9</strong></span> <span class="nt-tag-cloud-item nt-tag-cloud-size-2" style="--tag-hue:64" data-pl-tag-link="gaming" onclick="plFilterByTag('gaming')" role="button" tabindex="0">gaming <strong>4</strong></span> <span class="nt-tag-cloud-item nt-tag-cloud-size-1" style="--tag-hue:229" data-pl-tag-link="integration" onclick="plFilterByTag('integration')" role="button" tabindex="0">integration <strong>1</strong></span> <span class="nt-tag-cloud-item nt-tag-cloud-size-4" style="--tag-hue:55" data-pl-tag-link="iot" onclick="plFilterByTag('iot')" role="button" tabindex="0">iot <strong>35</strong></span> <span class="nt-tag-cloud-item nt-tag-cloud-size-3" style="--tag-hue:262" data-pl-tag-link="legacy" onclick="plFilterByTag('legacy')" role="button" tabindex="0">legacy <strong>11</strong></span> <span class="nt-tag-cloud-item nt-tag-cloud-size-5" style="--tag-hue:295" data-pl-tag-link="light" onclick="plFilterByTag('light')" role="button" tabindex="0">light <strong>80</strong></span> <span class="nt-tag-cloud-item nt-tag-cloud-size-2" style="--tag-hue:227" data-pl-tag-link="media" onclick="plFilterByTag('media')" role="button" tabindex="0">media <strong>2</strong></span> <span class="nt-tag-cloud-item nt-tag-cloud-size-3" style="--tag-hue:223" data-pl-tag-link="messaging" onclick="plFilterByTag('messaging')" role="button" tabindex="0">messaging <strong>15</strong></span> <span class="nt-tag-cloud-item nt-tag-cloud-size-5" style="--tag-hue:4" data-pl-tag-link="mgmt" onclick="plFilterByTag('mgmt')" role="button" tabindex="0">mgmt <strong>75</strong></span> <span class="nt-tag-cloud-item nt-tag-cloud-size-3" style="--tag-hue:257" data-pl-tag-link="mobile-core" onclick="plFilterByTag('mobile-core')" role="button" tabindex="0">mobile-core <strong>13</strong></span> <span class="nt-tag-cloud-item nt-tag-cloud-size-3" style="--tag-hue:183" data-pl-tag-link="monitoring" onclick="plFilterByTag('monitoring')" role="button" tabindex="0">monitoring <strong>8</strong></span> <span class="nt-tag-cloud-item nt-tag-cloud-size-3" style="--tag-hue:113" data-pl-tag-link="multicast" onclick="plFilterByTag('multicast')" role="button" tabindex="0">multicast <strong>10</strong></span> <span class="nt-tag-cloud-item nt-tag-cloud-size-2" style="--tag-hue:97" data-pl-tag-link="naming" onclick="plFilterByTag('naming')" role="button" tabindex="0">naming <strong>4</strong></span> <span class="nt-tag-cloud-item nt-tag-cloud-size-1" style="--tag-hue:317" data-pl-tag-link="network" onclick="plFilterByTag('network')" role="button" tabindex="0">network <strong>1</strong></span> <span class="nt-tag-cloud-item nt-tag-cloud-size-5" style="--tag-hue:350" data-pl-tag-link="ot" onclick="plFilterByTag('ot')" role="button" tabindex="0">ot <strong>54</strong></span> <span class="nt-tag-cloud-item nt-tag-cloud-size-3" style="--tag-hue:198" data-pl-tag-link="passive" onclick="plFilterByTag('passive')" role="button" tabindex="0">passive <strong>15</strong></span> <span class="nt-tag-cloud-item nt-tag-cloud-size-3" style="--tag-hue:64" data-pl-tag-link="printing" onclick="plFilterByTag('printing')" role="button" tabindex="0">printing <strong>10</strong></span> <span class="nt-tag-cloud-item nt-tag-cloud-size-2" style="--tag-hue:339" data-pl-tag-link="proxy" onclick="plFilterByTag('proxy')" role="button" tabindex="0">proxy <strong>2</strong></span> <span class="nt-tag-cloud-item nt-tag-cloud-size-4" style="--tag-hue:124" data-pl-tag-link="remote-access" onclick="plFilterByTag('remote-access')" role="button" tabindex="0">remote-access <strong>16</strong></span> <span class="nt-tag-cloud-item nt-tag-cloud-size-2" style="--tag-hue:81" data-pl-tag-link="routing" onclick="plFilterByTag('routing')" role="button" tabindex="0">routing <strong>2</strong></span> <span class="nt-tag-cloud-item nt-tag-cloud-size-3" style="--tag-hue:123" data-pl-tag-link="security" onclick="plFilterByTag('security')" role="button" tabindex="0">security <strong>6</strong></span> <span class="nt-tag-cloud-item nt-tag-cloud-size-1" style="--tag-hue:299" data-pl-tag-link="siem" onclick="plFilterByTag('siem')" role="button" tabindex="0">siem <strong>1</strong></span> <span class="nt-tag-cloud-item nt-tag-cloud-size-3" style="--tag-hue:54" data-pl-tag-link="storage" onclick="plFilterByTag('storage')" role="button" tabindex="0">storage <strong>8</strong></span> <span class="nt-tag-cloud-item nt-tag-cloud-size-2" style="--tag-hue:236" data-pl-tag-link="time" onclick="plFilterByTag('time')" role="button" tabindex="0">time <strong>2</strong></span> <span class="nt-tag-cloud-item nt-tag-cloud-size-5" style="--tag-hue:234" data-pl-tag-link="tls" onclick="plFilterByTag('tls')" role="button" tabindex="0">tls <strong>50</strong></span> <span class="nt-tag-cloud-item nt-tag-cloud-size-3" style="--tag-hue:195" data-pl-tag-link="voip" onclick="plFilterByTag('voip')" role="button" tabindex="0">voip <strong>14</strong></span> <span class="nt-tag-cloud-item nt-tag-cloud-size-3" style="--tag-hue:151" data-pl-tag-link="vpn" onclick="plFilterByTag('vpn')" role="button" tabindex="0">vpn <strong>10</strong></span> <span class="nt-tag-cloud-item nt-tag-cloud-size-4" style="--tag-hue:145" data-pl-tag-link="web" onclick="plFilterByTag('web')" role="button" tabindex="0">web <strong>22</strong></span> </div><div class="nt-toolbar"><input type="text" class="nt-search pl-search" placeholder="Filter by protocol, port, transport, or tag..." oninput="plFilter()"><div class="nt-sev-filters"><button class="fd-risk-btn active" data-pl-transport="tcp" onclick="plToggleTransport(this)">TCP <strong>235</strong></button><button class="fd-risk-btn active" data-pl-transport="udp" onclick="plToggleTransport(this)">UDP <strong>106</strong></button><button class="fd-risk-btn active" data-pl-transport="tls" onclick="plToggleTransport(this)">TLS <strong>3</strong></button><button class="fd-risk-btn active" data-pl-transport="sctp" onclick="plToggleTransport(this)">SCTP <strong>8</strong></button></div></div><div class="nt-count"><span id="pl-match-count">328</span> of 328 protocols</div><div id="pl-grid-host" class="nt-grid"><div class="deferred-loading">Loading protocols…</div></div>
<template id="pl-grid-content">
<div class="nt-card" data-pl-search="acop atlas copco open protocol atlas copco open protocol is a tightening-controller protocol used by power focus and power macs controllers on manufacturing assembly lines. negotiates the protocol revision and queries controller identity, returning the supplier code, controller name, controller serial and software version, tool software version, and cell and channel identifiers. tcp ot 4545" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>acop</code> &mdash; Atlas Copco Open Protocol</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Atlas Copco Open Protocol is a tightening-controller protocol used by Power Focus and Power MACS controllers on manufacturing assembly lines. Negotiates the protocol revision and queries controller identity, returning the supplier code, controller name, controller serial and software version, tool software version, and cell and channel identifiers.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 4545</span></div>
  <div class="nt-tags"><span class="nt-tag">ot</span></div>
</div>
<div class="nt-card" data-pl-search="acpp apple airport configuration protocol apple airport configuration protocol is the management protocol used by airport utility to provision apple airport base stations and time capsules. connects to the acpp listener and records the raw banner returned by the device. tcp mgmt" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>acpp</code> &mdash; Apple AirPort Configuration Protocol</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Apple AirPort Configuration Protocol is the management protocol used by AirPort Utility to provision Apple AirPort base stations and Time Capsules. Connects to the ACPP listener and records the raw banner returned by the device.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">mgmt</span></div>
</div>
<div class="nt-card" data-pl-search="activemq apache activemq openwire apache activemq openwire is the native binary wire protocol used by jms clients to talk to activemq message brokers. performs an openwire handshake and returns the broker version, host jvm and os, and negotiated wire-format options. tcp messaging 8161 61616 61617" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>activemq</code> &mdash; Apache ActiveMQ OpenWire</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Apache ActiveMQ OpenWire is the native binary wire protocol used by JMS clients to talk to ActiveMQ message brokers. Performs an OpenWire handshake and returns the broker version, host JVM and OS, and negotiated wire-format options.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Ports:</span> 8161, 61616, 61617</span></div>
  <div class="nt-tags"><span class="nt-tag">messaging</span></div>
</div>
<div class="nt-card" data-pl-search="adb android debug bridge android debug bridge is a developer protocol used to debug, install, and control android devices over the network (typically on rooted phones, tvs, and iot devices). probes for an open adb endpoint and returns the device&#39;s access state and adb banner. tcp mgmt remote-access 5037 5555" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>adb</code> &mdash; Android Debug Bridge</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Android Debug Bridge is a developer protocol used to debug, install, and control Android devices over the network (typically on rooted phones, TVs, and IoT devices). Probes for an open ADB endpoint and returns the device&#39;s access state and ADB banner.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Ports:</span> 5037, 5555</span></div>
  <div class="nt-tags"><span class="nt-tag">mgmt</span><span class="nt-tag">remote-access</span></div>
</div>
<div class="nt-card" data-pl-search="ads beckhoff ads/ams beckhoff ads/ams is the automation device specification / automation message specification protocol used to communicate with twincat runtimes on beckhoff plcs and industrial pcs. issues a readdeviceinfo request and returns the device name, ams netid, and twincat runtime version. tcp udp ot 48898" data-pl-transports="tcp udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>ads</code> &mdash; Beckhoff ADS/AMS</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Beckhoff ADS/AMS is the Automation Device Specification / Automation Message Specification protocol used to communicate with TwinCAT runtimes on Beckhoff PLCs and industrial PCs. Issues a ReadDeviceInfo request and returns the device name, AMS NetID, and TwinCAT runtime version.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 48898</span></div>
  <div class="nt-tags"><span class="nt-tag">ot</span></div>
</div>
<div class="nt-card" data-pl-search="airplay apple airplay airplay is apple&#39;s wireless streaming protocol used by ios, macos, and apple tv devices to mirror displays and stream audio/video. detected from the _airplay._tcp and _raop._tcp mdns records and http banners advertised by airplay receivers. tcp discovery iot" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>airplay</code> &mdash; Apple AirPlay</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">AirPlay is Apple&#39;s wireless streaming protocol used by iOS, macOS, and Apple TV devices to mirror displays and stream audio/video. Detected from the _airplay._tcp and _raop._tcp mDNS records and HTTP banners advertised by AirPlay receivers.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">iot</span></div>
</div>
<div class="nt-card" data-pl-search="ajp apache jserv protocol (ajp) apache jserv protocol (ajp) is a binary protocol used by reverse-proxy front-ends (apache httpd mod_proxy_ajp, nginx, iis) to bridge http requests to a back-end tomcat or jboss application server, typically on tcp/8009. runzero attributes services as ajp from external integration data (shodan) and from banner / port hints; no active ajp probe is sent. tcp clear web" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>ajp</code> &mdash; Apache JServ Protocol (AJP)</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Apache JServ Protocol (AJP) is a binary protocol used by reverse-proxy front-ends (Apache httpd mod_proxy_ajp, nginx, IIS) to bridge HTTP requests to a back-end Tomcat or JBoss application server, typically on TCP/8009. runZero attributes services as AJP from external integration data (Shodan) and from banner / port hints; no active AJP probe is sent.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">clear</span><span class="nt-tag">web</span></div>
</div>
<div class="nt-card" data-pl-search="amqp amqp 0-9-1 amqp 0-9-1 is the advanced message queuing protocol used by rabbitmq and other brokers for message-oriented middleware. exchanges the protocol-header preamble and returns the negotiated amqp version, broker product and version, runtime platform, cluster name, advertised sasl mechanisms, and tls requirement. tcp messaging tls 5671 5672" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>amqp</code> &mdash; AMQP 0-9-1</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">AMQP 0-9-1 is the Advanced Message Queuing Protocol used by RabbitMQ and other brokers for message-oriented middleware. Exchanges the protocol-header preamble and returns the negotiated AMQP version, broker product and version, runtime platform, cluster name, advertised SASL mechanisms, and TLS requirement.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Ports:</span> 5671, 5672</span></div>
  <div class="nt-tags"><span class="nt-tag">messaging</span><span class="nt-tag">tls</span></div>
</div>
<div class="nt-card" data-pl-search="anydesk anydesk anydesk is a proprietary tls-wrapped remote-desktop protocol used by the anydesk client and host software on windows, macos, linux, android, and ios endpoints. performs a tls handshake on the anydesk listener and inspects the peer certificate to fingerprint the service, returning the certificate subject, issuer, and a self-signed flag. tls light remote-access 6568 7070" data-pl-transports="tls">
  <div class="nt-card-header">
    <div class="nt-title"><code>anydesk</code></div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tls">TLS</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">AnyDesk is a proprietary TLS-wrapped remote-desktop protocol used by the AnyDesk client and host software on Windows, macOS, Linux, Android, and iOS endpoints. Performs a TLS handshake on the AnyDesk listener and inspects the peer certificate to fingerprint the service, returning the certificate subject, issuer, and a self-signed flag.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Ports:</span> 6568, 7070</span></div>
  <div class="nt-tags"><span class="nt-tag">light</span><span class="nt-tag">remote-access</span></div>
</div>
<div class="nt-card" data-pl-search="ard apple remote desktop apple remote desktop is a discovery protocol used by macos systems to advertise themselves to apple remote desktop administrators on udp/3283. runzero sends the ard discovery request, validates the response type, and returns the advertised hostname and apple machine model from the reply. udp discovery light remote-access 3283" data-pl-transports="udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>ard</code> &mdash; Apple Remote Desktop</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Apple Remote Desktop is a discovery protocol used by macOS systems to advertise themselves to Apple Remote Desktop administrators on UDP/3283. runZero sends the ARD discovery request, validates the response type, and returns the advertised hostname and Apple machine model from the reply.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 3283</span></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">light</span><span class="nt-tag">remote-access</span></div>
</div>
<div class="nt-card" data-pl-search="arp address resolution protocol address resolution protocol is a layer-2 protocol used to resolve ipv4 addresses to ethernet mac addresses on the local broadcast segment. runzero sends arp requests for each target on the local network to discover live hosts, captures the mac address from each reply for asset attribution and oui-based vendor identification, and passively records arp traffic observed during the scan. tcp discovery multicast passive" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>arp</code> &mdash; Address Resolution Protocol</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Address Resolution Protocol is a Layer-2 protocol used to resolve IPv4 addresses to Ethernet MAC addresses on the local broadcast segment. runZero sends ARP requests for each target on the local network to discover live hosts, captures the MAC address from each reply for asset attribution and OUI-based vendor identification, and passively records ARP traffic observed during the scan.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">multicast</span><span class="nt-tag">passive</span></div>
</div>
<div class="nt-card" data-pl-search="atg automatic tank gauge automatic tank gauge is a veeder-root serial protocol tunneled over tcp (commonly port 10001) used by atg consoles such as the tls-3xx and tls-4xx series found in fuel-station forecourts. issues the i20100 in-tank inventory and i90200 system-revision commands and returns the station name, console software and module revisions, tank count, and per-tank product names. tcp ot 10001" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>atg</code> &mdash; Automatic Tank Gauge</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Automatic Tank Gauge is a Veeder-Root serial protocol tunneled over TCP (commonly port 10001) used by ATG consoles such as the TLS-3xx and TLS-4xx series found in fuel-station forecourts. Issues the I20100 in-tank inventory and I90200 system-revision commands and returns the station name, console software and module revisions, tank count, and per-tank product names.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 10001</span></div>
  <div class="nt-tags"><span class="nt-tag">ot</span></div>
</div>
<div class="nt-card" data-pl-search="backupexec veritas backup exec agent veritas backup exec agent is the host-side service used by the backup exec server to coordinate jobs with protected hosts. identifies the agent from its tcp banner and tags the asset as veritas backup exec. tcp backup mgmt 6106" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>backupexec</code> &mdash; Veritas Backup Exec Agent</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Veritas Backup Exec Agent is the host-side service used by the Backup Exec server to coordinate jobs with protected hosts. Identifies the agent from its TCP banner and tags the asset as Veritas Backup Exec.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 6106</span></div>
  <div class="nt-tags"><span class="nt-tag">backup</span><span class="nt-tag">mgmt</span></div>
</div>
<div class="nt-card" data-pl-search="bacnet bacnet/ip bacnet/ip is a building-automation protocol used for hvac, lighting, access control, and other building systems. issues who-is and readproperty requests and returns the device instance, vendor, model, firmware, and a summary of objects and routing devices behind the gateway. udp backplane building-automation deep ot 46808 47808 47809 47810 47811 47812 47813 47814 47815 47816 47817 47818 47819 47820 47821 47822 47823 47824 48808" data-pl-transports="udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>bacnet</code> &mdash; BACnet/IP</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">BACnet/IP is a building-automation protocol used for HVAC, lighting, access control, and other building systems. Issues Who-Is and ReadProperty requests and returns the device instance, vendor, model, firmware, and a summary of objects and routing devices behind the gateway.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Ports:</span> 46808, 47808, 47809, 47810, 47811, 47812, 47813, 47814, 47815, 47816, 47817, 47818, 47819, 47820, 47821, 47822, 47823, 47824, 48808</span></div>
  <div class="nt-tags"><span class="nt-tag">backplane</span><span class="nt-tag">building-automation</span><span class="nt-tag">deep</span><span class="nt-tag">ot</span></div>
</div>
<div class="nt-card" data-pl-search="banner generic tcp banner generic tcp banner is a fallback collector used when no protocol-specific matcher fires. reads the first response bytes and returns the raw banner text for downstream fingerprinting. tcp discovery light" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>banner</code> &mdash; Generic TCP Banner</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Generic TCP Banner is a fallback collector used when no protocol-specific matcher fires. Reads the first response bytes and returns the raw banner text for downstream fingerprinting.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">light</span></div>
</div>
<div class="nt-card" data-pl-search="bedrock minecraft bedrock minecraft bedrock is the game-server query and discovery protocol used by minecraft bedrock edition clients. sends an unconnected ping and returns the server uptime, guid, and the raw advertisement payload (motd and version fields). udp gaming light 19132" data-pl-transports="udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>bedrock</code> &mdash; Minecraft Bedrock</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Minecraft Bedrock is the game-server query and discovery protocol used by Minecraft Bedrock Edition clients. Sends an Unconnected Ping and returns the server uptime, GUID, and the raw advertisement payload (MOTD and version fields).</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 19132</span></div>
  <div class="nt-tags"><span class="nt-tag">gaming</span><span class="nt-tag">light</span></div>
</div>
<div class="nt-card" data-pl-search="bgp border gateway protocol border gateway protocol is the inter-domain routing protocol used between autonomous systems on the internet and inside large networks. attempts an open exchange and returns the bgp version, advertised as number, bgp identifier, and supported capabilities. tcp routing 179" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>bgp</code> &mdash; Border Gateway Protocol</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Border Gateway Protocol is the inter-domain routing protocol used between autonomous systems on the Internet and inside large networks. Attempts an OPEN exchange and returns the BGP version, advertised AS number, BGP identifier, and supported capabilities.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 179</span></div>
  <div class="nt-tags"><span class="nt-tag">routing</span></div>
</div>
<div class="nt-card" data-pl-search="bitdefender-app bitdefender endpoint bitdefender endpoint is a proprietary check-in channel exposed by bitdefender, netgear armor, and threattrack mobile-security and vpn agents on android and ios endpoints. runzero passively matches the agent&#39;s json app_id payload from observed banners and reports the bitdefender vendor along with the application identifier and software version of each detected product. tcp light mgmt security 7519" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>bitdefender-app</code> &mdash; Bitdefender Endpoint</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Bitdefender Endpoint is a proprietary check-in channel exposed by Bitdefender, NETGEAR Armor, and ThreatTrack mobile-security and VPN agents on Android and iOS endpoints. runZero passively matches the agent&#39;s JSON app_id payload from observed banners and reports the Bitdefender vendor along with the application identifier and software version of each detected product.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 7519</span></div>
  <div class="nt-tags"><span class="nt-tag">light</span><span class="nt-tag">mgmt</span><span class="nt-tag">security</span></div>
</div>
<div class="nt-card" data-pl-search="bjnp canon bjnp canon bjnp is a vendor-specific printing and scanning protocol used by canon&#39;s network drivers. sends a bjnp discovery probe and returns the device type (printer or scanner), mac address, and ipv4/ipv6 address advertised in the reply. udp discovery printing 8611 8612" data-pl-transports="udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>bjnp</code> &mdash; Canon BJNP</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Canon BJNP is a vendor-specific printing and scanning protocol used by Canon&#39;s network drivers. Sends a BJNP discovery probe and returns the device type (printer or scanner), MAC address, and IPv4/IPv6 address advertised in the reply.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Ports:</span> 8611, 8612</span></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">printing</span></div>
</div>
<div class="nt-card" data-pl-search="brother brother network discovery brother network discovery is a udp-based broadcast protocol used by brother printers and multi-function devices to announce themselves and respond to driver/management discovery probes. runzero parses the response to recover the printer model, firmware revision, and serial number. udp discovery iot" data-pl-transports="udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>brother</code> &mdash; Brother Network Discovery</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Brother Network Discovery is a UDP-based broadcast protocol used by Brother printers and multi-function devices to announce themselves and respond to driver/management discovery probes. runZero parses the response to recover the printer model, firmware revision, and serial number.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">iot</span></div>
</div>
<div class="nt-card" data-pl-search="brother-scanner brother network discovery brother network discovery is the scanner protocol used by brother network devices. identifies the service from its +ok 200 / -ng 401 reply and tags the asset as a brother scanner. tcp discovery light printing 54921 54922 54923" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>brother-scanner</code> &mdash; Brother Network Discovery</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Brother Network Discovery is the scanner protocol used by Brother network devices. Identifies the service from its +OK 200 / -NG 401 reply and tags the asset as a Brother scanner.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Ports:</span> 54921, 54922, 54923</span></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">light</span><span class="nt-tag">printing</span></div>
</div>
<div class="nt-card" data-pl-search="bsap-ip emerson bsap/ip emerson bsap/ip is the bristol standard asynchronous protocol over ip used by emerson controlwave and bristol rtus in oil &amp; gas scada. queries node identification and, when enabled, walks the bsap local-address hierarchy to enumerate child rtus, returning rtu identity, firmware, and topology summaries. udp backplane deep ot 1234 1235" data-pl-transports="udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>bsap-ip</code> &mdash; Emerson BSAP/IP</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Emerson BSAP/IP is the Bristol Standard Asynchronous Protocol over IP used by Emerson ControlWave and Bristol RTUs in oil &amp; gas SCADA. Queries node identification and, when enabled, walks the BSAP local-address hierarchy to enumerate child RTUs, returning RTU identity, firmware, and topology summaries.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Ports:</span> 1234, 1235</span></div>
  <div class="nt-tags"><span class="nt-tag">backplane</span><span class="nt-tag">deep</span><span class="nt-tag">ot</span></div>
</div>
<div class="nt-card" data-pl-search="c12.22 ansi c12.22 ansi c12.22 is the metering-network transport used by electric-utility advanced-metering-infrastructure head-ends and relays. issues an epsem identification request and returns the device serial number, ed class, and c12.22 standard version. tcp backplane deep ot 1153" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>c12.22</code> &mdash; ANSI C12.22</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">ANSI C12.22 is the metering-network transport used by electric-utility advanced-metering-infrastructure head-ends and relays. Issues an EPSEM Identification request and returns the device serial number, ED class, and C12.22 standard version.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 1153</span></div>
  <div class="nt-tags"><span class="nt-tag">backplane</span><span class="nt-tag">deep</span><span class="nt-tag">ot</span></div>
</div>
<div class="nt-card" data-pl-search="c37118 ieee c37.118 synchrophasor ieee c37.118 synchrophasor is the streaming protocol used by phasor measurement units and phasor data concentrators on the electric grid. requests cfg-2 and header frames and returns pmu/pdc identification, station and channel naming, and reporting rate. tcp backplane deep ot 4712" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>c37118</code> &mdash; IEEE C37.118 Synchrophasor</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">IEEE C37.118 Synchrophasor is the streaming protocol used by Phasor Measurement Units and Phasor Data Concentrators on the electric grid. Requests CFG-2 and header frames and returns PMU/PDC identification, station and channel naming, and reporting rate.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 4712</span></div>
  <div class="nt-tags"><span class="nt-tag">backplane</span><span class="nt-tag">deep</span><span class="nt-tag">ot</span></div>
</div>
<div class="nt-card" data-pl-search="cacti cacti network monitoring web ui cacti network monitoring web ui is the open-source rrdtool-based network graphing and monitoring console deployed by network and it operations teams. the http extractor matches the cacti login page title, parses the embedded versioninfo string, and returns the cacti.version attribute and cacti software identification. tcp light tls web" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>cacti</code> &mdash; Cacti Network Monitoring Web UI</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Cacti Network Monitoring Web UI is the open-source RRDtool-based network graphing and monitoring console deployed by network and IT operations teams. The HTTP extractor matches the Cacti login page title, parses the embedded versionInfo string, and returns the cacti.version attribute and Cacti software identification.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">light</span><span class="nt-tag">tls</span><span class="nt-tag">web</span></div>
</div>
<div class="nt-card" data-pl-search="cassandra apache cassandra cql apache cassandra cql is the native client protocol used to query the cassandra wide-column store. performs a startup/options exchange and returns the cluster name, cql version, and cassandra release. tcp database tls 9042 9160" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>cassandra</code> &mdash; Apache Cassandra CQL</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Apache Cassandra CQL is the native client protocol used to query the Cassandra wide-column store. Performs a STARTUP/OPTIONS exchange and returns the cluster name, CQL version, and Cassandra release.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Ports:</span> 9042, 9160</span></div>
  <div class="nt-tags"><span class="nt-tag">database</span><span class="nt-tag">tls</span></div>
</div>
<div class="nt-card" data-pl-search="cdp cisco discovery protocol cisco discovery protocol is a layer-2 announcement protocol used by cisco devices to advertise themselves to neighbors. passively decodes cdp frames and returns the device id, software version, platform, capabilities, native vlan, and management addresses advertised by the neighbor. tcp udp discovery mgmt passive" data-pl-transports="tcp udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>cdp</code> &mdash; Cisco Discovery Protocol</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Cisco Discovery Protocol is a Layer-2 announcement protocol used by Cisco devices to advertise themselves to neighbors. Passively decodes CDP frames and returns the device ID, software version, platform, capabilities, native VLAN, and management addresses advertised by the neighbor.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">mgmt</span><span class="nt-tag">passive</span></div>
</div>
<div class="nt-card" data-pl-search="ceph ceph ceph is a cluster-internal messenger protocol used by ceph distributed storage daemons (mon, mgr, osd, mds) to communicate. runzero identifies ceph services from the &#34;ceph v&#34; banner returned on connection and tags the asset as a ceph storage node. tcp storage" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>ceph</code></div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Ceph is a cluster-internal messenger protocol used by Ceph distributed storage daemons (mon, mgr, osd, mds) to communicate. runZero identifies Ceph services from the &#34;ceph v&#34; banner returned on connection and tags the asset as a Ceph storage node.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">storage</span></div>
</div>
<div class="nt-card" data-pl-search="chargen character generator character generator is a legacy diagnostic service (rfc 864) that emits a stream of printable characters. records the response banner to confirm the service. tcp legacy light" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>chargen</code> &mdash; Character Generator</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Character Generator is a legacy diagnostic service (RFC 864) that emits a stream of printable characters. Records the response banner to confirm the service.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">legacy</span><span class="nt-tag">light</span></div>
</div>
<div class="nt-card" data-pl-search="checkmk checkmk agent checkmk agent is the host-side metric exporter used by the checkmk server to collect host metrics. reads the agent banner and returns the agent version, build date, host operating system, architecture, and configured hostname. tcp mgmt monitoring 6556" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>checkmk</code> &mdash; Checkmk Agent</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Checkmk Agent is the host-side metric exporter used by the Checkmk server to collect host metrics. Reads the agent banner and returns the agent version, build date, host operating system, architecture, and configured hostname.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 6556</span></div>
  <div class="nt-tags"><span class="nt-tag">mgmt</span><span class="nt-tag">monitoring</span></div>
</div>
<div class="nt-card" data-pl-search="chromecast google chromecast chromecast is the google cast device discovery and control protocol used by chromecast, google tv, google nest hub, and cast-enabled speakers. detected via the _googlecast._tcp mdns record and the device&#39;s http /setup/eureka_info endpoint, which exposes the device name, model, build, and timezone. tcp discovery iot" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>chromecast</code> &mdash; Google Chromecast</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Chromecast is the Google Cast device discovery and control protocol used by Chromecast, Google TV, Google Nest Hub, and Cast-enabled speakers. Detected via the _googlecast._tcp mDNS record and the device&#39;s HTTP /setup/eureka_info endpoint, which exposes the device name, model, build, and timezone.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">iot</span></div>
</div>
<div class="nt-card" data-pl-search="cip common industrial protocol common industrial protocol is an industrial automation protocol used by rockwell/allen-bradley and other vendors for plc and i/o communication. issues the list identity and get attributes all requests and returns vendor, product code, revision, serial, product name, and device-type information for the controller and any backplane modules. tcp udp backplane deep ot 44818" data-pl-transports="tcp udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>cip</code> &mdash; Common Industrial Protocol</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Common Industrial Protocol is an industrial automation protocol used by Rockwell/Allen-Bradley and other vendors for PLC and I/O communication. Issues the List Identity and Get Attributes All requests and returns vendor, product code, revision, serial, product name, and device-type information for the controller and any backplane modules.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 44818</span></div>
  <div class="nt-tags"><span class="nt-tag">backplane</span><span class="nt-tag">deep</span><span class="nt-tag">ot</span></div>
</div>
<div class="nt-card" data-pl-search="cisco-phone cisco ip phone web interface cisco ip phone web interface is the embedded http server exposed by cisco spa, 7900-series, 8800-series, and unified ip phones. runzero attributes services as cisco-phone from recog banner matches and uses the response to recover the model, firmware version, mac address, and call-manager configuration. tcp clear voip" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>cisco-phone</code> &mdash; Cisco IP Phone Web Interface</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Cisco IP Phone Web Interface is the embedded HTTP server exposed by Cisco SPA, 7900-series, 8800-series, and Unified IP Phones. runZero attributes services as cisco-phone from Recog banner matches and uses the response to recover the model, firmware version, MAC address, and call-manager configuration.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">clear</span><span class="nt-tag">voip</span></div>
</div>
<div class="nt-card" data-pl-search="ciscosmi cisco smart install cisco smart install is a zero-touch deployment protocol commonly abused for unauthenticated configuration access. sends the smart install probe, tags the asset as cisco ios, and records the raw response payload. tcp mgmt 4786" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>ciscosmi</code> &mdash; Cisco Smart Install</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Cisco Smart Install is a zero-touch deployment protocol commonly abused for unauthenticated configuration access. Sends the Smart Install probe, tags the asset as Cisco IOS, and records the raw response payload.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 4786</span></div>
  <div class="nt-tags"><span class="nt-tag">mgmt</span></div>
</div>
<div class="nt-card" data-pl-search="citrix citrix ica browser citrix ica browser is a udp/1604 service used by citrix xenapp and virtual apps and desktops clients to locate published applications and server farms. runzero sends an ica browser request and parses the reply to return the server-farm name and the list of advertised published applications. udp discovery remote-access 1604" data-pl-transports="udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>citrix</code> &mdash; Citrix ICA Browser</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Citrix ICA Browser is a UDP/1604 service used by Citrix XenApp and Virtual Apps and Desktops clients to locate published applications and server farms. runZero sends an ICA Browser request and parses the reply to return the server-farm name and the list of advertised published applications.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 1604</span></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">remote-access</span></div>
</div>
<div class="nt-card" data-pl-search="citrixica citrix ica citrix ica is the remote-presentation protocol used to deliver published apps and desktops from citrix virtual apps and desktops. detects the ica banner signature on the listener, tags the asset as citrix virtual apps, and records the response banner and a short hex prefix. tcp remote-access 1494 2598" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>citrixica</code> &mdash; Citrix ICA</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Citrix ICA is the remote-presentation protocol used to deliver published apps and desktops from Citrix Virtual Apps and Desktops. Detects the ICA banner signature on the listener, tags the asset as Citrix Virtual Apps, and records the response banner and a short hex prefix.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Ports:</span> 1494, 2598</span></div>
  <div class="nt-tags"><span class="nt-tag">remote-access</span></div>
</div>
<div class="nt-card" data-pl-search="cldap connectionless ldap connectionless ldap is a udp-based directory protocol used to query directory servers without setting up a tcp connection. issues a rootdse search and returns the ldap attributes parsed from the reply (vendor name and version, supported controls, extensions, capabilities, and sasl mechanisms). udp directory discovery 389" data-pl-transports="udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>cldap</code> &mdash; Connectionless LDAP</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Connectionless LDAP is a UDP-based directory protocol used to query directory servers without setting up a TCP connection. Issues a rootDSE search and returns the LDAP attributes parsed from the reply (vendor name and version, supported controls, extensions, capabilities, and SASL mechanisms).</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 389</span></div>
  <div class="nt-tags"><span class="nt-tag">directory</span><span class="nt-tag">discovery</span></div>
</div>
<div class="nt-card" data-pl-search="click click modular router click modular router is the control socket exposed by hosts running the click software router. identifies the service from the click::controlsocket banner and tags the asset accordingly. tcp light mgmt 7734" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>click</code> &mdash; Click Modular Router</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Click Modular Router is the control socket exposed by hosts running the Click software router. Identifies the service from the Click::ControlSocket banner and tags the asset accordingly.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 7734</span></div>
  <div class="nt-tags"><span class="nt-tag">light</span><span class="nt-tag">mgmt</span></div>
</div>
<div class="nt-card" data-pl-search="coap coap coap is the constrained application protocol (rfc 7252) used by constrained devices and iot deployments for resource-oriented messaging. issues a get on /.well-known/core and returns the coap version, message type, response code, options, content format, and the resource list or payload from the reply. udp iot 5683 5684" data-pl-transports="udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>coap</code></div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">CoAP is the Constrained Application Protocol (RFC 7252) used by constrained devices and IoT deployments for resource-oriented messaging. Issues a GET on /.well-known/core and returns the CoAP version, message type, response code, options, content format, and the resource list or payload from the reply.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Ports:</span> 5683, 5684</span></div>
  <div class="nt-tags"><span class="nt-tag">iot</span></div>
</div>
<div class="nt-card" data-pl-search="cockpit cockpit linux web console cockpit linux web console is the web-based linux server-management console shipped with red hat, fedora, centos stream, and debian, typically served over tls on tcp/9090. the http extractor matches the embedded environment json in the login page and returns the host name, os pretty name, and os variant identifiers. tcp light tls web" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>cockpit</code> &mdash; Cockpit Linux Web Console</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Cockpit Linux Web Console is the web-based Linux server-management console shipped with Red Hat, Fedora, CentOS Stream, and Debian, typically served over TLS on TCP/9090. The HTTP extractor matches the embedded environment JSON in the login page and returns the host name, OS pretty name, and OS variant identifiers.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">light</span><span class="nt-tag">tls</span><span class="nt-tag">web</span></div>
</div>
<div class="nt-card" data-pl-search="codesys codesys v3 runtime codesys v3 runtime is the iec 61131-3 controller runtime used by many oems (wago, beckhoff, schneider, eaton, ...). issues the runtime identification request and returns the runtime vendor, product, version, and target identification. tcp ot 1200 1217 2455 11740" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>codesys</code> &mdash; CODESYS V3 Runtime</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">CODESYS V3 Runtime is the IEC 61131-3 controller runtime used by many OEMs (WAGO, Beckhoff, Schneider, Eaton, ...). Issues the runtime identification request and returns the runtime vendor, product, version, and target identification.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Ports:</span> 1200, 1217, 2455, 11740</span></div>
  <div class="nt-tags"><span class="nt-tag">ot</span></div>
</div>
<div class="nt-card" data-pl-search="codesys2 codesys v2 runtime codesys v2 runtime is the older 3s codesys v2 controller runtime used by industrial controllers from many oems. performs the v2 login probe and returns the runtime version and target identification. tcp ot 1200 2455" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>codesys2</code> &mdash; CODESYS V2 Runtime</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">CODESYS V2 Runtime is the older 3S CODESYS V2 controller runtime used by industrial controllers from many OEMs. Performs the V2 login probe and returns the runtime version and target identification.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Ports:</span> 1200, 2455</span></div>
  <div class="nt-tags"><span class="nt-tag">ot</span></div>
</div>
<div class="nt-card" data-pl-search="cognex cognex in-sight cognex in-sight is an operator-access service exposed by cognex in-sight industrial machine-vision cameras for configuration and monitoring on factory networks. runzero identifies in-sight cameras from the proprietary banner returned on connection and tags the asset as a cognex vision system. tcp light ot" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>cognex</code> &mdash; Cognex In-Sight</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Cognex In-Sight is an operator-access service exposed by Cognex In-Sight industrial machine-vision cameras for configuration and monitoring on factory networks. runZero identifies In-Sight cameras from the proprietary banner returned on connection and tags the asset as a Cognex vision system.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">light</span><span class="nt-tag">ot</span></div>
</div>
<div class="nt-card" data-pl-search="common-socket-connection raritan common socket connection raritan common socket connection is a proprietary management transport used by raritan kvm-over-ip switches, dominion serial consoles, and rack pdus, typically on tcp/5000. runzero identifies csc services from the raritan banner returned on connection and tags the asset as a raritan management device. tcp clear light mgmt" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>common-socket-connection</code> &mdash; Raritan Common Socket Connection</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Raritan Common Socket Connection is a proprietary management transport used by Raritan KVM-over-IP switches, Dominion serial consoles, and rack PDUs, typically on TCP/5000. runZero identifies CSC services from the Raritan banner returned on connection and tags the asset as a Raritan management device.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">clear</span><span class="nt-tag">light</span><span class="nt-tag">mgmt</span></div>
</div>
<div class="nt-card" data-pl-search="companion-link apple companionlink apple companionlink is a discovery and pairing service used by apple devices (ios, macos, tvos, homepod) to negotiate airplay, homekit, and continuity sessions with paired peers, advertised via _companion-link._tcp on bonjour. runzero attributes the service from the mdns / port hint and reports the asset as apple companionlink. tcp iot light" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>companion-link</code> &mdash; Apple CompanionLink</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Apple CompanionLink is a discovery and pairing service used by Apple devices (iOS, macOS, tvOS, HomePod) to negotiate AirPlay, HomeKit, and Continuity sessions with paired peers, advertised via _companion-link._tcp on Bonjour. runZero attributes the service from the mDNS / port hint and reports the asset as Apple CompanionLink.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">iot</span><span class="nt-tag">light</span></div>
</div>
<div class="nt-card" data-pl-search="comtrol comtrol device discovery comtrol device discovery is the broadcast protocol used by comtrol/pepperl+fuchs rocketlinx switches and devicemaster serial servers to advertise their presence on the network. runzero parses the response to recover the model name, hardware/firmware revision, mac address, ip configuration, and serial number. tcp discovery ot" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>comtrol</code> &mdash; Comtrol Device Discovery</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Comtrol Device Discovery is the broadcast protocol used by Comtrol/Pepperl+Fuchs RocketLinx switches and DeviceMaster serial servers to advertise their presence on the network. runZero parses the response to recover the model name, hardware/firmware revision, MAC address, IP configuration, and serial number.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">ot</span></div>
</div>
<div class="nt-card" data-pl-search="confluence atlassian confluence atlassian confluence is a wiki and team-collaboration server available in server, data center, and cloud editions. the http probe fetches confluence login, dashboard, and version endpoints and returns the product name, edition, and build number. tcp light tls web" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>confluence</code> &mdash; Atlassian Confluence</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Atlassian Confluence is a wiki and team-collaboration server available in Server, Data Center, and Cloud editions. The HTTP probe fetches Confluence login, dashboard, and version endpoints and returns the product name, edition, and build number.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">light</span><span class="nt-tag">tls</span><span class="nt-tag">web</span></div>
</div>
<div class="nt-card" data-pl-search="consul hashicorp consul consul is hashicorp&#39;s service-mesh and key/value store. detected on the consul http api (tcp/8500), where the /v1/status/leader and /v1/agent/self endpoints disclose the datacenter, node name, build version, and raft leader of the cluster. tcp clear mgmt 8500" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>consul</code> &mdash; HashiCorp Consul</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Consul is HashiCorp&#39;s service-mesh and key/value store. Detected on the Consul HTTP API (TCP/8500), where the /v1/status/leader and /v1/agent/self endpoints disclose the datacenter, node name, build version, and Raft leader of the cluster.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 8500</span></div>
  <div class="nt-tags"><span class="nt-tag">clear</span><span class="nt-tag">mgmt</span></div>
</div>
<div class="nt-card" data-pl-search="couchdb apache couchdb couchdb is the apache document-oriented database fronted by an http/json api. detected from the welcome document at /, which discloses the couchdb version, vendor name, uuid, and -- on misconfigured deployments -- whether the admin party is enabled. tcp clear mgmt 5984" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>couchdb</code> &mdash; Apache CouchDB</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">CouchDB is the Apache document-oriented database fronted by an HTTP/JSON API. Detected from the welcome document at /, which discloses the CouchDB version, vendor name, UUID, and -- on misconfigured deployments -- whether the admin party is enabled.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 5984</span></div>
  <div class="nt-tags"><span class="nt-tag">clear</span><span class="nt-tag">mgmt</span></div>
</div>
<div class="nt-card" data-pl-search="crestron crestron discovery crestron discovery is a vendor protocol used to locate crestron control processors and av equipment. sends the discovery probe and returns the device hostname, model, and firmware version. udp building-automation discovery light 41794" data-pl-transports="udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>crestron</code> &mdash; Crestron Discovery</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Crestron Discovery is a vendor protocol used to locate Crestron control processors and AV equipment. Sends the discovery probe and returns the device hostname, model, and firmware version.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 41794</span></div>
  <div class="nt-tags"><span class="nt-tag">building-automation</span><span class="nt-tag">discovery</span><span class="nt-tag">light</span></div>
</div>
<div class="nt-card" data-pl-search="crimsonv3 red lion crimson 3 red lion crimson 3 is a configuration and runtime protocol used to read data from red lion graphite, da-series, and other industrial hmis and gateways. reads the manufacturer (register 0x012b) and model (register 0x012a) registers and returns those strings. tcp ot 789" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>crimsonv3</code> &mdash; Red Lion Crimson 3</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Red Lion Crimson 3 is a configuration and runtime protocol used to read data from Red Lion Graphite, DA-series, and other industrial HMIs and gateways. Reads the manufacturer (register 0x012b) and model (register 0x012a) registers and returns those strings.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 789</span></div>
  <div class="nt-tags"><span class="nt-tag">ot</span></div>
</div>
<div class="nt-card" data-pl-search="crowd atlassian crowd atlassian crowd is a centralized sso and identity-management product. runzero attributes services as crowd from recog matches against the application&#39;s http banners and login pages, recovering the product version and build information. tcp clear mgmt" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>crowd</code> &mdash; Atlassian Crowd</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Atlassian Crowd is a centralized SSO and identity-management product. runZero attributes services as Crowd from Recog matches against the application&#39;s HTTP banners and login pages, recovering the product version and build information.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">clear</span><span class="nt-tag">mgmt</span></div>
</div>
<div class="nt-card" data-pl-search="cspv4 allen-bradley cspv4 / pccc allen-bradley cspv4 / pccc is a legacy controller protocol used by slc 5/05 and micrologix plcs for register access. issues a pccc identify request and returns the controller family, processor type, and series/revision string. tcp backplane deep ot 2222" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>cspv4</code> &mdash; Allen-Bradley CSPv4 / PCCC</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Allen-Bradley CSPv4 / PCCC is a legacy controller protocol used by SLC 5/05 and MicroLogix PLCs for register access. Issues a PCCC identify request and returns the controller family, processor type, and series/revision string.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 2222</span></div>
  <div class="nt-tags"><span class="nt-tag">backplane</span><span class="nt-tag">deep</span><span class="nt-tag">ot</span></div>
</div>
<div class="nt-card" data-pl-search="cups common unix printing system cups is the common unix printing system administrative web interface. runzero matches the cups http banner and the ipp server header, returning the cupsd version and host operating system. tcp clear iot 631" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>cups</code> &mdash; Common Unix Printing System</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">CUPS is the Common Unix Printing System administrative web interface. runZero matches the CUPS HTTP banner and the IPP server header, returning the cupsd version and host operating system.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 631</span></div>
  <div class="nt-tags"><span class="nt-tag">clear</span><span class="nt-tag">iot</span></div>
</div>
<div class="nt-card" data-pl-search="dahua-dhip dahua dhip dahua dhip is a proprietary discovery and management protocol used by dahua and oem-rebranded ip cameras and nvrs (amcrest, lorex, and similar). sends the single-byte dhip discovery probe and returns the device serial, machine name, vendor, firmware version, mac, and ipv4/ipv6 configuration. udp discovery iot light 37810" data-pl-transports="udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>dahua-dhip</code> &mdash; Dahua DHIP</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Dahua DHIP is a proprietary discovery and management protocol used by Dahua and OEM-rebranded IP cameras and NVRs (Amcrest, Lorex, and similar). Sends the single-byte DHIP discovery probe and returns the device serial, machine name, vendor, firmware version, MAC, and IPv4/IPv6 configuration.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 37810</span></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">iot</span><span class="nt-tag">light</span></div>
</div>
<div class="nt-card" data-pl-search="daytime daytime daytime is a legacy diagnostic service (rfc 867) that returns the current date and time. records the response banner, parses the timestamp, and infers an os hint from the format. tcp udp legacy light 13" data-pl-transports="tcp udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>daytime</code></div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Daytime is a legacy diagnostic service (RFC 867) that returns the current date and time. Records the response banner, parses the timestamp, and infers an OS hint from the format.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 13</span></div>
  <div class="nt-tags"><span class="nt-tag">legacy</span><span class="nt-tag">light</span></div>
</div>
<div class="nt-card" data-pl-search="db2 ibm db2 ibm db2 is a relational database protocol used by db2 luw and db2 for z/os clients. performs a drda excsat/accsec exchange and returns the server product identifier, version, and platform. tcp udp database 523 50000 50001 60000" data-pl-transports="tcp udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>db2</code> &mdash; IBM Db2</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">IBM Db2 is a relational database protocol used by Db2 LUW and Db2 for z/OS clients. Performs a DRDA EXCSAT/ACCSEC exchange and returns the server product identifier, version, and platform.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Ports:</span> 523, 50000, 50001, 60000</span></div>
  <div class="nt-tags"><span class="nt-tag">database</span></div>
</div>
<div class="nt-card" data-pl-search="dcerpc dce/rpc endpoint mapper dce/rpc endpoint mapper is the rpc locator used to enumerate rpc services on windows hosts. queries the endpoint mapper and returns a summary of registered rpc interfaces, their uuids, versions, and bindings. tcp mgmt 135 593" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>dcerpc</code> &mdash; DCE/RPC Endpoint Mapper</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">DCE/RPC Endpoint Mapper is the RPC locator used to enumerate RPC services on Windows hosts. Queries the endpoint mapper and returns a summary of registered RPC interfaces, their UUIDs, versions, and bindings.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Ports:</span> 135, 593</span></div>
  <div class="nt-tags"><span class="nt-tag">mgmt</span></div>
</div>
<div class="nt-card" data-pl-search="dhcp dhcp dhcp is the dynamic host configuration protocol used to lease ipv4 addresses and network configuration. sends a dhcpdiscover and returns the offered server identifier, lease parameters, and any vendor-class identification revealed by the response. udp discovery 67 68" data-pl-transports="udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>dhcp</code></div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">DHCP is the Dynamic Host Configuration Protocol used to lease IPv4 addresses and network configuration. Sends a DHCPDISCOVER and returns the offered server identifier, lease parameters, and any vendor-class identification revealed by the response.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Ports:</span> 67, 68</span></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span></div>
</div>
<div class="nt-card" data-pl-search="diameter diameter (tcp) diameter (tcp) is an authentication, authorization, and accounting protocol over tcp; the successor to radius, widely used in mobile-core networks. sends a capabilities-exchange-request and returns the origin host, realm, vendor, product name, and supported applications. tcp aaa mobile-core tls 3868" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>diameter</code> &mdash; Diameter (TCP)</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Diameter (TCP) is an authentication, authorization, and accounting protocol over TCP; the successor to RADIUS, widely used in mobile-core networks. Sends a Capabilities-Exchange-Request and returns the origin host, realm, vendor, product name, and supported applications.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 3868</span></div>
  <div class="nt-tags"><span class="nt-tag">aaa</span><span class="nt-tag">mobile-core</span><span class="nt-tag">tls</span></div>
</div>
<div class="nt-card" data-pl-search="diametersctp diameter (sctp) diameter (sctp) is the diameter (rfc 6733) aaa protocol carried over sctp, used between mobile-core elements (diameter edge agent, dra, hss, pcrf, mme). sends a capabilities-exchange-request and returns the origin host, realm, vendor, product name, and supported applications. sctp tcp aaa mobile-core tls 3868" data-pl-transports="sctp tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>diametersctp</code> &mdash; Diameter (SCTP)</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="sctp">SCTP</span><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Diameter (SCTP) is the Diameter (RFC 6733) AAA protocol carried over SCTP, used between mobile-core elements (Diameter Edge Agent, DRA, HSS, PCRF, MME). Sends a Capabilities-Exchange-Request and returns the origin host, realm, vendor, product name, and supported applications.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 3868</span></div>
  <div class="nt-tags"><span class="nt-tag">aaa</span><span class="nt-tag">mobile-core</span><span class="nt-tag">tls</span></div>
</div>
<div class="nt-card" data-pl-search="digi digi addp digi addp is the advanced device discovery protocol used by digi international serial servers, cellular gateways (transport, ix, ex), and embedded modules to advertise themselves on the local network. runzero sends digi, dvkt, and dgdp discovery requests on udp/2362 and parses the tlv reply to return the device mac, ip, model, firmware version, and hardware revision. udp discovery iot light 2362" data-pl-transports="udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>digi</code> &mdash; Digi ADDP</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Digi ADDP is the Advanced Device Discovery Protocol used by Digi International serial servers, cellular gateways (TransPort, IX, EX), and embedded modules to advertise themselves on the local network. runZero sends DIGI, DVKT, and DGDP discovery requests on UDP/2362 and parses the TLV reply to return the device MAC, IP, model, firmware version, and hardware revision.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 2362</span></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">iot</span><span class="nt-tag">light</span></div>
</div>
<div class="nt-card" data-pl-search="dnp3 dnp3 dnp3 is distributed network protocol 3 (ieee 1815) used in electric, water, and oil &amp; gas scada between control centers (masters) and rtus/ieds (outstations). performs an unsolicited link-layer test and an object group 0 read and returns the outstation address, vendor, model, firmware, and device-attributes summary. tcp backplane deep ot 20000" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>dnp3</code></div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">DNP3 is Distributed Network Protocol 3 (IEEE 1815) used in electric, water, and oil &amp; gas SCADA between control centers (masters) and RTUs/IEDs (outstations). Performs an unsolicited link-layer test and an Object Group 0 read and returns the outstation address, vendor, model, firmware, and device-attributes summary.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 20000</span></div>
  <div class="nt-tags"><span class="nt-tag">backplane</span><span class="nt-tag">deep</span><span class="nt-tag">ot</span></div>
</div>
<div class="nt-card" data-pl-search="dns dns dns is the domain name system used to resolve hostnames to addresses and other resource records. issues version.bind, hostname.bind, and recursion-test queries and returns the resolver software identification, recursion availability, and observed chaos-class metadata. tcp udp naming 53 5353 5355" data-pl-transports="tcp udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>dns</code></div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">DNS is the Domain Name System used to resolve hostnames to addresses and other resource records. Issues version.bind, hostname.bind, and recursion-test queries and returns the resolver software identification, recursion availability, and observed CHAOS-class metadata.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Ports:</span> 53, 5353, 5355</span></div>
  <div class="nt-tags"><span class="nt-tag">naming</span></div>
</div>
<div class="nt-card" data-pl-search="docker docker engine api docker engine api is the http control plane exposed by dockerd. runzero queries /version and /info on unauthenticated daemons (typically tcp/2375 or 2376) to recover the engine version, api version, kernel version, operating system, architecture, and container runtime. tcp clear mgmt 2375 2376" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>docker</code> &mdash; Docker Engine API</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Docker Engine API is the HTTP control plane exposed by dockerd. runZero queries /version and /info on unauthenticated daemons (typically TCP/2375 or 2376) to recover the engine version, API version, kernel version, operating system, architecture, and container runtime.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Ports:</span> 2375, 2376</span></div>
  <div class="nt-tags"><span class="nt-tag">clear</span><span class="nt-tag">mgmt</span></div>
</div>
<div class="nt-card" data-pl-search="doip diagnostics over ip diagnostics over ip is an automotive diagnostics protocol used to reach in-vehicle ecus (uds/kwp) over ethernet. issues a vehicle identification request and (when enabled) entity status, returning vin, eid/gid, logical addresses, and reachable ecu summaries behind the gateway. tcp udp automotive backplane deep ot 13400" data-pl-transports="tcp udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>doip</code> &mdash; Diagnostics over IP</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Diagnostics over IP is an automotive diagnostics protocol used to reach in-vehicle ECUs (UDS/KWP) over Ethernet. Issues a Vehicle Identification Request and (when enabled) Entity Status, returning VIN, EID/GID, logical addresses, and reachable ECU summaries behind the gateway.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 13400</span></div>
  <div class="nt-tags"><span class="nt-tag">automotive</span><span class="nt-tag">backplane</span><span class="nt-tag">deep</span><span class="nt-tag">ot</span></div>
</div>
<div class="nt-card" data-pl-search="dotnet-remoting .net remoting .net remoting is a microsoft rpc framework used by legacy .net framework applications for cross-process and cross-host rpc. identifies the service from the .net remoting binary-protocol prefix in the connection banner and saves the raw banner. tcp mgmt 9090" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>dotnet-remoting</code> &mdash; .NET Remoting</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">.NET Remoting is a Microsoft RPC framework used by legacy .NET Framework applications for cross-process and cross-host RPC. Identifies the service from the .NET Remoting binary-protocol prefix in the connection banner and saves the raw banner.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 9090</span></div>
  <div class="nt-tags"><span class="nt-tag">mgmt</span></div>
</div>
<div class="nt-card" data-pl-search="drbd drbd drbd is the distributed replicated block device protocol used to replicate block devices between linux nodes for high availability. identifies the service from the connection-error banner observed on tcp/8787 and saves the raw banner. tcp light storage 8787" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>drbd</code></div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">DRBD is the Distributed Replicated Block Device protocol used to replicate block devices between Linux nodes for high availability. Identifies the service from the connection-error banner observed on TCP/8787 and saves the raw banner.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 8787</span></div>
  <div class="nt-tags"><span class="nt-tag">light</span><span class="nt-tag">storage</span></div>
</div>
<div class="nt-card" data-pl-search="drobo-nasd drobo nasd drobo nasd is the management daemon used by drobo dashboard to administer drobo storage appliances. identifies the daemon from the drinasd banner returned on tcp/5000 and saves the raw banner. tcp light mgmt storage 5000" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>drobo-nasd</code> &mdash; Drobo NASd</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Drobo NASd is the management daemon used by Drobo Dashboard to administer Drobo storage appliances. Identifies the daemon from the DRINASD banner returned on TCP/5000 and saves the raw banner.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 5000</span></div>
  <div class="nt-tags"><span class="nt-tag">light</span><span class="nt-tag">mgmt</span><span class="nt-tag">storage</span></div>
</div>
<div class="nt-card" data-pl-search="dtls dtls dtls is datagram transport layer security (rfc 6347/9147), the udp/sctp variant of tls, used by webrtc, coap, openvpn, eap-ttls, and other datagram services. performs a dtls clienthello and returns the negotiated version, cipher suite, and any presented certificate metadata. udp encrypted 443 3391 4433 5246 5349 5684 12346 12366 12386 12406 12426" data-pl-transports="udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>dtls</code></div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">DTLS is Datagram Transport Layer Security (RFC 6347/9147), the UDP/SCTP variant of TLS, used by WebRTC, CoAP, OpenVPN, EAP-TTLS, and other datagram services. Performs a DTLS ClientHello and returns the negotiated version, cipher suite, and any presented certificate metadata.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Ports:</span> 443, 3391, 4433, 5246, 5349, 5684, 12346, 12366, 12386, 12406, 12426</span></div>
  <div class="nt-tags"><span class="nt-tag">encrypted</span></div>
</div>
<div class="nt-card" data-pl-search="echo echo echo is a legacy diagnostic service (rfc 862) that echoes received bytes. records the response to confirm the service and to detect amplification-capable hosts. tcp udp legacy light 7" data-pl-transports="tcp udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>echo</code></div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Echo is a legacy diagnostic service (RFC 862) that echoes received bytes. Records the response to confirm the service and to detect amplification-capable hosts.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 7</span></div>
  <div class="nt-tags"><span class="nt-tag">legacy</span><span class="nt-tag">light</span></div>
</div>
<div class="nt-card" data-pl-search="eero-ebid eero ebid eero ebid is a proprietary discovery protocol used by amazon eero mesh wi-fi access points to advertise the extender beacon identifier between mesh nodes on the local segment. runzero attributes the service from the ebid hint and applies eero-specific fingerprinting to identify the asset as an eero mesh extender. udp discovery iot passive" data-pl-transports="udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>eero-ebid</code> &mdash; eero EBID</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">eero EBID is a proprietary discovery protocol used by Amazon eero mesh Wi-Fi access points to advertise the extender beacon identifier between mesh nodes on the local segment. runZero attributes the service from the EBID hint and applies eero-specific fingerprinting to identify the asset as an eero mesh extender.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">iot</span><span class="nt-tag">passive</span></div>
</div>
<div class="nt-card" data-pl-search="eerogw eero gateway eero gateway is a proprietary discovery protocol used by amazon eero mesh gateways to advertise themselves to companion mobile applications on the local network. runzero attributes the service from the eero gateway hint and applies eero-specific fingerprinting to identify the asset as an eero gateway node. udp discovery iot passive" data-pl-transports="udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>eerogw</code> &mdash; eero Gateway</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">eero Gateway is a proprietary discovery protocol used by Amazon eero mesh gateways to advertise themselves to companion mobile applications on the local network. runZero attributes the service from the eero gateway hint and applies eero-specific fingerprinting to identify the asset as an eero gateway node.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">iot</span><span class="nt-tag">passive</span></div>
</div>
<div class="nt-card" data-pl-search="elasticsearch elasticsearch elasticsearch is the elastic search/analytics engine. runzero queries the root http endpoint to recover the cluster name, node name, elasticsearch version, lucene version, and build hash. tcp clear mgmt 9200" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>elasticsearch</code></div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Elasticsearch is the Elastic search/analytics engine. runZero queries the root HTTP endpoint to recover the cluster name, node name, Elasticsearch version, Lucene version, and build hash.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 9200</span></div>
  <div class="nt-tags"><span class="nt-tag">clear</span><span class="nt-tag">mgmt</span></div>
</div>
<div class="nt-card" data-pl-search="epm dce/rpc endpoint mapper service epm is the surface name used by runzero for services attributed to the microsoft dce/rpc endpoint mapper following recog/banner-based fingerprinting. the lower-level wire protocol is decoded as dcerpc; this label captures hosts where only fingerprint evidence (banners, version strings) was available. tcp clear mgmt 135" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>epm</code> &mdash; DCE/RPC Endpoint Mapper Service</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">EPM is the surface name used by runZero for services attributed to the Microsoft DCE/RPC Endpoint Mapper following Recog/banner-based fingerprinting. The lower-level wire protocol is decoded as dcerpc; this label captures hosts where only fingerprint evidence (banners, version strings) was available.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 135</span></div>
  <div class="nt-tags"><span class="nt-tag">clear</span><span class="nt-tag">mgmt</span></div>
</div>
<div class="nt-card" data-pl-search="epmd erlang port mapper daemon epmd is the erlang port mapper daemon used by erlang and elixir distributed nodes (including rabbitmq and couchdb) to advertise registered node names and the dynamic ports they listen on. runzero issues the names_req to enumerate registered nodes and their listening ports. tcp clear mgmt 4369" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>epmd</code> &mdash; Erlang Port Mapper Daemon</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">EPMD is the Erlang Port Mapper Daemon used by Erlang and Elixir distributed nodes (including RabbitMQ and CouchDB) to advertise registered node names and the dynamic ports they listen on. runZero issues the NAMES_REQ to enumerate registered nodes and their listening ports.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 4369</span></div>
  <div class="nt-tags"><span class="nt-tag">clear</span><span class="nt-tag">mgmt</span></div>
</div>
<div class="nt-card" data-pl-search="epo trellix/mcafee epolicy orchestrator (epo) trellix/mcafee epolicy orchestrator (epo) is the central management console for trellix (formerly mcafee) endpoint-security agents. the http probe fetches the epo login page and returns the product name, build number, and version metadata exposed in the page markup. tcp light security tls web" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>epo</code> &mdash; Trellix/McAfee ePolicy Orchestrator (ePO)</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Trellix/McAfee ePolicy Orchestrator (ePO) is the central management console for Trellix (formerly McAfee) endpoint-security agents. The HTTP probe fetches the ePO login page and returns the product name, build number, and version metadata exposed in the page markup.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">light</span><span class="nt-tag">security</span><span class="nt-tag">tls</span><span class="nt-tag">web</span></div>
</div>
<div class="nt-card" data-pl-search="erlangdp erlang distribution erlang distribution is the inter-node messaging protocol used between erlang and elixir nodes. queries epmd for registered node names and (when nodes are discovered) performs a distribution handshake on the first node, returning the epmd names list, node name and hostname, distribution version, supported flags, and handshake status. tcp messaging 4369" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>erlangdp</code> &mdash; Erlang Distribution</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Erlang Distribution is the inter-node messaging protocol used between Erlang and Elixir nodes. Queries EPMD for registered node names and (when nodes are discovered) performs a distribution handshake on the first node, returning the EPMD names list, node name and hostname, distribution version, supported flags, and handshake status.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 4369</span></div>
  <div class="nt-tags"><span class="nt-tag">messaging</span></div>
</div>
<div class="nt-card" data-pl-search="erldp erlang distribution protocol erlang distribution protocol is the distribution protocol used between erlang and elixir vm nodes for inter-node messaging (also commonly referred to as erldp). runzero matches the erlang distribution handshake on the wire and reports the protocol alongside the active erlangdp scanner so port-scan results are tagged consistently with epmd-discovered nodes. tcp clear messaging" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>erldp</code> &mdash; Erlang Distribution Protocol</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Erlang Distribution Protocol is the distribution protocol used between Erlang and Elixir VM nodes for inter-node messaging (also commonly referred to as ErlDP). runZero matches the Erlang distribution handshake on the wire and reports the protocol alongside the active erlangdp scanner so port-scan results are tagged consistently with EPMD-discovered nodes.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">clear</span><span class="nt-tag">messaging</span></div>
</div>
<div class="nt-card" data-pl-search="etcd etcd v3 api etcd is the distributed key-value store used by kubernetes and other coreos-derived projects. detected via the v3 http/grpc api (typically tcp/2379), where /version reports the etcd-server and etcd-cluster versions. tcp clear mgmt 2379" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>etcd</code> &mdash; etcd v3 API</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">etcd is the distributed key-value store used by Kubernetes and other CoreOS-derived projects. Detected via the v3 HTTP/gRPC API (typically TCP/2379), where /version reports the etcd-server and etcd-cluster versions.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 2379</span></div>
  <div class="nt-tags"><span class="nt-tag">clear</span><span class="nt-tag">mgmt</span></div>
</div>
<div class="nt-card" data-pl-search="etcd2 etcd v2 api etcd2 is the legacy v2 http api exposed by older etcd deployments. detected via /v2/stats/self and /version, which expose the cluster name, member id, and etcd version on unauthenticated installations. tcp clear mgmt 2379 4001" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>etcd2</code> &mdash; etcd v2 API</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">etcd2 is the legacy v2 HTTP API exposed by older etcd deployments. Detected via /v2/stats/self and /version, which expose the cluster name, member ID, and etcd version on unauthenticated installations.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Ports:</span> 2379, 4001</span></div>
  <div class="nt-tags"><span class="nt-tag">clear</span><span class="nt-tag">mgmt</span></div>
</div>
<div class="nt-card" data-pl-search="ethercat ethercat ethercat (ethernet for control automation technology, iec 61158) fieldbus used for high-speed motion control and distributed i/o on machine-control and cnc segments. queries master and slave registers and returns the master vendor identification and a summary of slaves discovered on the segment. udp backplane deep ot 34980" data-pl-transports="udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>ethercat</code></div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">EtherCAT (Ethernet for Control Automation Technology, IEC 61158) fieldbus used for high-speed motion control and distributed I/O on machine-control and CNC segments. Queries master and slave registers and returns the master vendor identification and a summary of slaves discovered on the segment.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 34980</span></div>
  <div class="nt-tags"><span class="nt-tag">backplane</span><span class="nt-tag">deep</span><span class="nt-tag">ot</span></div>
</div>
<div class="nt-card" data-pl-search="fgfm fortigate to fortimanager fgfm is the proprietary tls-wrapped management protocol used by fortinet fortigate firewalls to register with and receive configuration from a fortimanager. detected by the fgfm tls server certificate and banner; runzero records the device serial number and model where exposed. tcp clear mgmt 541" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>fgfm</code> &mdash; FortiGate to FortiManager</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">FGFM is the proprietary TLS-wrapped management protocol used by Fortinet FortiGate firewalls to register with and receive configuration from a FortiManager. Detected by the FGFM TLS server certificate and banner; runZero records the device serial number and model where exposed.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 541</span></div>
  <div class="nt-tags"><span class="nt-tag">clear</span><span class="nt-tag">mgmt</span></div>
</div>
<div class="nt-card" data-pl-search="finger finger finger is a legacy user-information service (rfc 1288) historically exposed on tcp/79, today seen mostly on cisco ios devices and embedded printers. runzero reads the finger banner returned on connection and extracts the printer model (hp jetdirect-style) or cisco ios identification, and reports the service for legacy-protocol exposure tracking. tcp legacy" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>finger</code></div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Finger is a legacy user-information service (RFC 1288) historically exposed on TCP/79, today seen mostly on Cisco IOS devices and embedded printers. runZero reads the Finger banner returned on connection and extracts the printer model (HP JetDirect-style) or Cisco IOS identification, and reports the service for legacy-protocol exposure tracking.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">legacy</span></div>
</div>
<div class="nt-card" data-pl-search="fins omron fins omron fins is the factory interface network service used by omron cj, cs, nj, and nx plcs and related automation devices on factory floors. runzero records fins-derived asset attributes (controller model, firmware) emitted by the active omronfins scanner and uses the fins protocol identifier when categorizing assets and assigning ot asset functions. udp ot 9600" data-pl-transports="udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>fins</code> &mdash; Omron FINS</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Omron FINS is the Factory Interface Network Service used by Omron CJ, CS, NJ, and NX PLCs and related automation devices on factory floors. runZero records FINS-derived asset attributes (controller model, firmware) emitted by the active omronfins scanner and uses the FINS protocol identifier when categorizing assets and assigning OT asset functions.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 9600</span></div>
  <div class="nt-tags"><span class="nt-tag">ot</span></div>
</div>
<div class="nt-card" data-pl-search="firebird firebird sql firebird sql is the relational database wire protocol used by the firebird open-source database engine. performs the firebird connection handshake and returns the server architecture, protocol version, and firebird release. tcp database 3050" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>firebird</code> &mdash; Firebird SQL</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Firebird SQL is the relational database wire protocol used by the Firebird open-source database engine. Performs the Firebird connection handshake and returns the server architecture, protocol version, and Firebird release.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 3050</span></div>
  <div class="nt-tags"><span class="nt-tag">database</span></div>
</div>
<div class="nt-card" data-pl-search="focas fanuc focas fanuc focas is an ethernet protocol used to monitor and control fanuc cnc machine tools and robots (open cnc api specification, focas2/ethernet). issues the system-info call and returns the cnc series, version, machine number, and (when enabled) per-path machining data. tcp backplane deep ot 8193" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>focas</code> &mdash; Fanuc FOCAS</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Fanuc FOCAS is an Ethernet protocol used to monitor and control Fanuc CNC machine tools and robots (Open CNC API Specification, FOCAS2/Ethernet). Issues the system-info call and returns the CNC series, version, machine number, and (when enabled) per-path machining data.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 8193</span></div>
  <div class="nt-tags"><span class="nt-tag">backplane</span><span class="nt-tag">deep</span><span class="nt-tag">ot</span></div>
</div>
<div class="nt-card" data-pl-search="fortigate-to-fortimanager fortigate-to-fortimanager fortigate-to-fortimanager is the fortinet fgfm management protocol used by fortimanager to manage fortigate firewalls. inspects the fgfm tls handshake and returns the fortigate model, firmware, and serial number embedded in the certificate. tcp mgmt security 541" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>fortigate-to-fortimanager</code></div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">FortiGate-to-FortiManager is the Fortinet FGFM management protocol used by FortiManager to manage FortiGate firewalls. Inspects the FGFM TLS handshake and returns the FortiGate model, firmware, and serial number embedded in the certificate.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 541</span></div>
  <div class="nt-tags"><span class="nt-tag">mgmt</span><span class="nt-tag">security</span></div>
</div>
<div class="nt-card" data-pl-search="fox tridium niagara fox tridium niagara fox is the building-automation control protocol used by niagara framework jace controllers and supervisors. sends the fox hello and returns the fox version, station name, host id, host name, os name and version, jvm name and version, brand identifier, and authentication agent. tcp building-automation ot 1911 4911" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>fox</code> &mdash; Tridium Niagara Fox</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Tridium Niagara Fox is the building-automation control protocol used by Niagara Framework JACE controllers and supervisors. Sends the Fox hello and returns the Fox version, station name, host ID, host name, OS name and version, JVM name and version, brand identifier, and authentication agent.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Ports:</span> 1911, 4911</span></div>
  <div class="nt-tags"><span class="nt-tag">building-automation</span><span class="nt-tag">ot</span></div>
</div>
<div class="nt-card" data-pl-search="ftp ftp ftp is the standardized file-transfer protocol (rfc 959). reads the ftp greeting and issues syst/help/auth probes, returning the server software, system type, supported features, and tls-availability indicators. tcp clear file tls 21 2121 9090" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>ftp</code></div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">FTP is the standardized file-transfer protocol (RFC 959). Reads the FTP greeting and issues SYST/HELP/AUTH probes, returning the server software, system type, supported features, and TLS-availability indicators.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Ports:</span> 21, 2121, 9090</span></div>
  <div class="nt-tags"><span class="nt-tag">clear</span><span class="nt-tag">file</span><span class="nt-tag">tls</span></div>
</div>
<div class="nt-card" data-pl-search="ganglia ganglia ganglia is a distributed monitoring system commonly deployed on hpc clusters and linux server farms. runzero identifies ganglia services from the ganglia_xml document returned by gmond/gmetad and captures the banner so cluster identification and host metrics are available for inventory. tcp monitoring" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>ganglia</code></div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Ganglia is a distributed monitoring system commonly deployed on HPC clusters and Linux server farms. runZero identifies Ganglia services from the GANGLIA_XML document returned by gmond/gmetad and captures the banner so cluster identification and host metrics are available for inventory.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">monitoring</span></div>
</div>
<div class="nt-card" data-pl-search="gesrtp ge srtp ge srtp is the service request transport protocol used to communicate with ge/emerson pacsystems, series 90, and rx3i/rx7i plcs. issues a controller-identification request and returns the model, firmware, sweep state, and slot configuration. tcp ot 18245" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>gesrtp</code> &mdash; GE SRTP</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">GE SRTP is the Service Request Transport Protocol used to communicate with GE/Emerson PACSystems, Series 90, and RX3i/RX7i PLCs. Issues a controller-identification request and returns the model, firmware, sweep state, and slot configuration.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 18245</span></div>
  <div class="nt-tags"><span class="nt-tag">ot</span></div>
</div>
<div class="nt-card" data-pl-search="giop giop / corba iiop giop / corba iiop is the omg general inter-orb protocol (the wire format under corba iiop). identifies the service from the giop magic in the connection banner. tcp mgmt 535" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>giop</code> &mdash; GIOP / CORBA IIOP</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">GIOP / CORBA IIOP is the OMG General Inter-ORB Protocol (the wire format under CORBA IIOP). Identifies the service from the GIOP magic in the connection banner.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 535</span></div>
  <div class="nt-tags"><span class="nt-tag">mgmt</span></div>
</div>
<div class="nt-card" data-pl-search="git git smart protocol git smart protocol is the native transport used by git:// servers for clones, fetches, and pushes. sends an upload-pack advertisement request and returns the advertised refs summary, server capabilities, and head reference. tcp file 9418" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>git</code> &mdash; Git Smart Protocol</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Git Smart Protocol is the native transport used by git:// servers for clones, fetches, and pushes. Sends an upload-pack advertisement request and returns the advertised refs summary, server capabilities, and HEAD reference.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 9418</span></div>
  <div class="nt-tags"><span class="nt-tag">file</span></div>
</div>
<div class="nt-card" data-pl-search="git-http git smart http service git smart http service is the git smart-http transport (git-upload-pack and git-receive-pack endpoints) used by gitlab, gitea, bitbucket, cgit, and bare git-http servers for clones, fetches, and pushes. the http extractor matches the _gitlab_session cookie and parses the manifest body, returning the git-http protocol attribution and the gitlab manifest hash. tcp light tls web" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>git-http</code> &mdash; Git Smart HTTP Service</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Git Smart HTTP Service is the Git smart-HTTP transport (git-upload-pack and git-receive-pack endpoints) used by GitLab, Gitea, Bitbucket, cgit, and bare git-http servers for clones, fetches, and pushes. The HTTP extractor matches the _gitlab_session cookie and parses the manifest body, returning the git-http protocol attribution and the GitLab manifest hash.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">light</span><span class="nt-tag">tls</span><span class="nt-tag">web</span></div>
</div>
<div class="nt-card" data-pl-search="googlewifi google wifi / nest wifi google wifi is the local management api exposed by google wifi and nest wifi mesh access points. detected via mdns (_googlecast._tcp) and the local http setup endpoints, which reveal the device&#39;s hardware model, build version, and mesh role. tcp discovery iot" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>googlewifi</code> &mdash; Google Wifi / Nest Wifi</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Google Wifi is the local management API exposed by Google Wifi and Nest Wifi mesh access points. Detected via mDNS (_googlecast._tcp) and the local HTTP setup endpoints, which reveal the device&#39;s hardware model, build version, and mesh role.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">iot</span></div>
</div>
<div class="nt-card" data-pl-search="gpsd gpsd gpsd is the gps daemon json-over-tcp protocol used to share location and timing data from connected gnss receivers. sends a ?watch request and identifies the service from the gpsd banner returned in the response. tcp iot 2947" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>gpsd</code></div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">GPSD is the GPS daemon JSON-over-TCP protocol used to share location and timing data from connected GNSS receivers. Sends a ?WATCH request and identifies the service from the GPSD banner returned in the response.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 2947</span></div>
  <div class="nt-tags"><span class="nt-tag">iot</span></div>
</div>
<div class="nt-card" data-pl-search="gtpc gtp-c gtp-c is the gprs tunneling protocol control plane that carries signaling between mobile-core nodes (sgsn/ggsn, mme/sgw/pgw). sends an echo request and returns the gtp version, restart counter, and supported features. udp mobile-core 2123 2152" data-pl-transports="udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>gtpc</code> &mdash; GTP-C</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">GTP-C is the GPRS Tunneling Protocol control plane that carries signaling between mobile-core nodes (SGSN/GGSN, MME/SGW/PGW). Sends an Echo Request and returns the GTP version, restart counter, and supported features.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Ports:</span> 2123, 2152</span></div>
  <div class="nt-tags"><span class="nt-tag">mobile-core</span></div>
</div>
<div class="nt-card" data-pl-search="gtpprime gtp&#39; gtp&#39; is the gtp charging variant used to ship cdrs from mobile network elements to a charging gateway. sends an echo request and returns the gtp&#39; version and node identification. udp mobile-core 3386" data-pl-transports="udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>gtpprime</code> &mdash; GTP&#39;</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">GTP&#39; is the GTP charging variant used to ship CDRs from mobile network elements to a Charging Gateway. Sends an Echo Request and returns the GTP&#39; version and node identification.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 3386</span></div>
  <div class="nt-tags"><span class="nt-tag">mobile-core</span></div>
</div>
<div class="nt-card" data-pl-search="gtpu gtp-u gtp-u is the gprs tunneling protocol user plane that encapsulates subscriber traffic between mobile-core nodes and base stations. sends an echo request and returns the gtp-u version and observed extension-header support. udp mobile-core 2152" data-pl-transports="udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>gtpu</code> &mdash; GTP-U</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">GTP-U is the GPRS Tunneling Protocol user plane that encapsulates subscriber traffic between mobile-core nodes and base stations. Sends an Echo Request and returns the GTP-U version and observed extension-header support.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 2152</span></div>
  <div class="nt-tags"><span class="nt-tag">mobile-core</span></div>
</div>
<div class="nt-card" data-pl-search="gvcp gige vision control gige vision control is the aia gvcp protocol used to discover, configure, and trigger industrial machine-vision cameras over ethernet. sends a discovery_cmd and returns the camera manufacturer, model, serial, firmware, mac, and supported gvcp version. udp discovery ot 3956" data-pl-transports="udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>gvcp</code> &mdash; GigE Vision Control</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">GigE Vision Control is the AIA GVCP protocol used to discover, configure, and trigger industrial machine-vision cameras over Ethernet. Sends a Discovery_Cmd and returns the camera manufacturer, model, serial, firmware, MAC, and supported GVCP version.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 3956</span></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">ot</span></div>
</div>
<div class="nt-card" data-pl-search="gvsp gige vision streaming gige vision streaming is the aia gvsp protocol used to transport image and chunk data from machine-vision cameras to host applications. passively classifies stream packets and returns the streaming state, packet format, and block identifier. udp ot passive 20202" data-pl-transports="udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>gvsp</code> &mdash; GigE Vision Streaming</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">GigE Vision Streaming is the AIA GVSP protocol used to transport image and chunk data from machine-vision cameras to host applications. Passively classifies stream packets and returns the streaming state, packet format, and block identifier.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 20202</span></div>
  <div class="nt-tags"><span class="nt-tag">ot</span><span class="nt-tag">passive</span></div>
</div>
<div class="nt-card" data-pl-search="h323 h.323 h.323 is the itu-t multimedia conferencing/voip signaling protocol. sends a setup probe and returns the gatekeeper/endpoint identification and supported codec/feature summary. tcp voip 1720" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>h323</code> &mdash; H.323</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">H.323 is the ITU-T multimedia conferencing/VoIP signaling protocol. Sends a Setup probe and returns the gatekeeper/endpoint identification and supported codec/feature summary.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 1720</span></div>
  <div class="nt-tags"><span class="nt-tag">voip</span></div>
</div>
<div class="nt-card" data-pl-search="hartip hart-ip hart-ip is an industrial protocol used to tunnel hart process-instrument traffic over tcp/udp through gateways and multiplexers. issues hart command 0 and returns the gateway identification, and (when enabled) walks sub-device indices via cmd 84 to enumerate connected field instruments. tcp backplane deep ot 5094" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>hartip</code> &mdash; HART-IP</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">HART-IP is an industrial protocol used to tunnel HART process-instrument traffic over TCP/UDP through gateways and multiplexers. Issues HART command 0 and returns the gateway identification, and (when enabled) walks sub-device indices via Cmd 84 to enumerate connected field instruments.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 5094</span></div>
  <div class="nt-tags"><span class="nt-tag">backplane</span><span class="nt-tag">deep</span><span class="nt-tag">ot</span></div>
</div>
<div class="nt-card" data-pl-search="hicp hms hicp/shicp hms hicp/shicp is the hms industrial networks discovery protocol used to discover and configure anybus and netbiter industrial gateways. sends the hicp discovery probe and returns the device hostname, mac, ip configuration, and firmware revision. udp discovery ot 3250" data-pl-transports="udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>hicp</code> &mdash; HMS HICP/SHICP</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">HMS HICP/SHICP is the HMS Industrial Networks discovery protocol used to discover and configure Anybus and Netbiter industrial gateways. Sends the HICP discovery probe and returns the device hostname, MAC, IP configuration, and firmware revision.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 3250</span></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">ot</span></div>
</div>
<div class="nt-card" data-pl-search="hiddiscoveryd hid discoveryd hid discoveryd is the discovery service used to locate hid vertx/edge access-control panels and readers. sends the discovery probe and returns the device model, firmware, and primary network configuration. udp building-automation discovery iot light 4070" data-pl-transports="udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>hiddiscoveryd</code> &mdash; HID DiscoveryD</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">HID DiscoveryD is the discovery service used to locate HID VertX/Edge access-control panels and readers. Sends the discovery probe and returns the device model, firmware, and primary network configuration.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 4070</span></div>
  <div class="nt-tags"><span class="nt-tag">building-automation</span><span class="nt-tag">discovery</span><span class="nt-tag">iot</span><span class="nt-tag">light</span></div>
</div>
<div class="nt-card" data-pl-search="hikvision hikvision ip camera/nvr web hikvision ip camera/nvr web is the http management interface for hikvision (and oem) ip cameras and recorders. identifies the product family from the www-authenticate realm and pins the firmware version using either the embedded ?version= query strings on the login page assets, or the last-modified header on /doc/page/login.asp combined with a known build-date table. tcp camera iot light web" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>hikvision</code> &mdash; Hikvision IP Camera/NVR Web</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Hikvision IP Camera/NVR Web is the HTTP management interface for Hikvision (and OEM) IP cameras and recorders. Identifies the product family from the WWW-Authenticate realm and pins the firmware version using either the embedded ?version= query strings on the login page assets, or the Last-Modified header on /doc/page/login.asp combined with a known build-date table.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">camera</span><span class="nt-tag">iot</span><span class="nt-tag">light</span><span class="nt-tag">web</span></div>
</div>
<div class="nt-card" data-pl-search="hostmeta web host metadata web host metadata is the document defined by rfc 6415 and exposed at /.well-known/host-meta or host-meta.json, commonly used by federated-identity, webfinger, and activitypub deployments. runzero sets the hostmeta protocol on the asset when the active http probe successfully retrieves the document and surfaces the discovered links for inventory. tcp light web" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>hostmeta</code> &mdash; Web Host Metadata</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Web Host Metadata is the document defined by RFC 6415 and exposed at /.well-known/host-meta or host-meta.json, commonly used by federated-identity, WebFinger, and ActivityPub deployments. runZero sets the hostmeta protocol on the asset when the active HTTP probe successfully retrieves the document and surfaces the discovered links for inventory.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">light</span><span class="nt-tag">web</span></div>
</div>
<div class="nt-card" data-pl-search="hsms semi hsms / secs-gem semi hsms / secs-gem is the high-speed secs message services transport that carries secs-ii/gem messages for semiconductor fab equipment (semi e37). performs the hsms select handshake and an s1f1 are-you-there, returning the equipment model identifier, software revision, and (when enabled) equipment constant subsystem summary. tcp backplane deep ot 5000" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>hsms</code> &mdash; SEMI HSMS / SECS-GEM</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">SEMI HSMS / SECS-GEM is the High-Speed SECS Message Services transport that carries SECS-II/GEM messages for semiconductor fab equipment (SEMI E37). Performs the HSMS Select handshake and an S1F1 Are-You-There, returning the equipment model identifier, software revision, and (when enabled) Equipment Constant subsystem summary.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 5000</span></div>
  <div class="nt-tags"><span class="nt-tag">backplane</span><span class="nt-tag">deep</span><span class="nt-tag">ot</span></div>
</div>
<div class="nt-card" data-pl-search="http http http is the hypertext transfer protocol used by the world wide web and most modern apis. issues head/get probes and runs http-specific extractors, returning server software, response codes and headers, page titles and generators, favicons, and any application fingerprints recognized by extractor rules. tcp tls web 80 3000 4567 5000 5985 8000 8001 8080 8081 8082 8200 8443 8888 9001 9080 9090 9100" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>http</code></div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">HTTP is the Hypertext Transfer Protocol used by the World Wide Web and most modern APIs. Issues HEAD/GET probes and runs HTTP-specific extractors, returning server software, response codes and headers, page titles and generators, favicons, and any application fingerprints recognized by extractor rules.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Ports:</span> 80, 3000, 4567, 5000, 5985, 8000, 8001, 8080, 8081, 8082, 8200, 8443, 8888, 9001, 9080, 9090, 9100</span></div>
  <div class="nt-tags"><span class="nt-tag">tls</span><span class="nt-tag">web</span></div>
</div>
<div class="nt-card" data-pl-search="http2 http/2 http/2 is a binary, multiplexed framing protocol for http (rfc 7540), negotiated via tls alpn or the http/2 cleartext upgrade. runzero negotiates http/2 when offered and feeds the response into the standard http analyzer so headers, server identification, and tls attributes are captured. tcp tls web" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>http2</code> &mdash; HTTP/2</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">HTTP/2 is a binary, multiplexed framing protocol for HTTP (RFC 7540), negotiated via TLS ALPN or the HTTP/2 cleartext upgrade. runZero negotiates HTTP/2 when offered and feeds the response into the standard HTTP analyzer so headers, server identification, and TLS attributes are captured.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">tls</span><span class="nt-tag">web</span></div>
</div>
<div class="nt-card" data-pl-search="https https https is http carried over tls, the dominant transport for web applications, rest apis, and management uis. implemented in runzero as the standard http scanner over a tls connection; the protocol is reported as https (rather than http) whenever the connection negotiates tls or the port hint is flagged as tls-only, and the full tls handshake metadata (certificate, ciphers, fingerprints) is recorded alongside the http response. tcp encrypted tls web" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>https</code></div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">HTTPS is HTTP carried over TLS, the dominant transport for web applications, REST APIs, and management UIs. Implemented in runZero as the standard HTTP scanner over a TLS connection; the protocol is reported as https (rather than http) whenever the connection negotiates TLS or the port hint is flagged as TLS-only, and the full TLS handshake metadata (certificate, ciphers, fingerprints) is recorded alongside the HTTP response.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">encrypted</span><span class="nt-tag">tls</span><span class="nt-tag">web</span></div>
</div>
<div class="nt-card" data-pl-search="iax2 iax2 iax2 is the inter-asterisk exchange version 2 voip signaling and media protocol used between asterisk pbxes. sends a poke and returns the responder&#39;s iax2 version and pbx identification. udp voip 4569" data-pl-transports="udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>iax2</code></div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">IAX2 is the Inter-Asterisk eXchange version 2 VoIP signaling and media protocol used between Asterisk PBXes. Sends a POKE and returns the responder&#39;s IAX2 version and PBX identification.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 4569</span></div>
  <div class="nt-tags"><span class="nt-tag">voip</span></div>
</div>
<div class="nt-card" data-pl-search="icmp icmp echo (ping) icmp echo (ping) is the ipv4/ipv6 icmp echo request/reply exchange (rfc 792, rfc 4443) issued by the host-discovery probe to confirm host liveness, capture round-trip times, and observe ttl/hop-limit and ip tos fields. tcp discovery light" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>icmp</code> &mdash; ICMP Echo (Ping)</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">ICMP Echo (Ping) is the IPv4/IPv6 ICMP Echo Request/Reply exchange (RFC 792, RFC 4443) issued by the host-discovery probe to confirm host liveness, capture round-trip times, and observe TTL/Hop-Limit and IP TOS fields.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">light</span></div>
</div>
<div class="nt-card" data-pl-search="ics-trace ics passive trace ics passive trace is a synthetic protocol used internally to record evidence from passive analysis of ics/ot traffic when active ot probing is disabled. runzero attributes the asset under ics-trace and emits the protocol identifiers and attributes observed in the passive trace. tcp ot passive" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>ics-trace</code> &mdash; ICS Passive Trace</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">ICS Passive Trace is a synthetic protocol used internally to record evidence from passive analysis of ICS/OT traffic when active OT probing is disabled. runZero attributes the asset under ics-trace and emits the protocol identifiers and attributes observed in the passive trace.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">ot</span><span class="nt-tag">passive</span></div>
</div>
<div class="nt-card" data-pl-search="ident ident ident is the identification protocol (rfc 1413), a legacy user-identity lookup service. sends an ident query against the connecting socket and returns the operating-system field and any user-identity string disclosed by the response. tcp legacy light 113" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>ident</code></div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Ident is the Identification Protocol (RFC 1413), a legacy user-identity lookup service. Sends an ident query against the connecting socket and returns the operating-system field and any user-identity string disclosed by the response.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 113</span></div>
  <div class="nt-tags"><span class="nt-tag">legacy</span><span class="nt-tag">light</span></div>
</div>
<div class="nt-card" data-pl-search="idrac dell idrac idrac is the dell integrated dell remote access controller out-of-band management interface. runzero attributes services as idrac from the ssh/https banners, redfish endpoints, and tls certificates issued for the controller, recovering the firmware version and service tag. tcp clear mgmt" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>idrac</code> &mdash; Dell iDRAC</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">iDRAC is the Dell Integrated Dell Remote Access Controller out-of-band management interface. runZero attributes services as iDRAC from the SSH/HTTPS banners, redfish endpoints, and TLS certificates issued for the controller, recovering the firmware version and service tag.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">clear</span><span class="nt-tag">mgmt</span></div>
</div>
<div class="nt-card" data-pl-search="iec104 iec 60870-5-104 iec 60870-5-104 is a scada telecontrol protocol used between control centers and rtus/substation gateways, primarily in electric power and rail. sends testfr (and, when enabled, startdt/general interrogation) and returns the common asdu address, originator address, and any device-identity asdus received. tcp deep ot 2404" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>iec104</code> &mdash; IEC 60870-5-104</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">IEC 60870-5-104 is a SCADA telecontrol protocol used between control centers and RTUs/substation gateways, primarily in electric power and rail. Sends TESTFR (and, when enabled, STARTDT/General Interrogation) and returns the common ASDU address, originator address, and any device-identity ASDUs received.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 2404</span></div>
  <div class="nt-tags"><span class="nt-tag">deep</span><span class="nt-tag">ot</span></div>
</div>
<div class="nt-card" data-pl-search="iec61850-goose iec 61850 goose iec 61850 goose is the generic object oriented substation event layer-2 multicast protocol (ethertype 0x88b8) used by substation ieds for peer-to-peer trip and status signaling. runzero passively decodes goose frames, attributes the publisher mac as an iec 61850 ied, and records the gocb reference and dataset. tcp multicast ot passive" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>iec61850-goose</code> &mdash; IEC 61850 GOOSE</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">IEC 61850 GOOSE is the Generic Object Oriented Substation Event Layer-2 multicast protocol (EtherType 0x88B8) used by substation IEDs for peer-to-peer trip and status signaling. runZero passively decodes GOOSE frames, attributes the publisher MAC as an IEC 61850 IED, and records the GoCB reference and dataset.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">multicast</span><span class="nt-tag">ot</span><span class="nt-tag">passive</span></div>
</div>
<div class="nt-card" data-pl-search="iec61850-mms iec 61850 mms iec 61850 mms is the manufacturing message specification mapping used by substation intelligent electronic devices for monitoring, control, and reporting. opens an mms session and (when enabled) issues identify, returning the ied vendor, model, firmware, and logical-device summary. tcp backplane deep ot 102" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>iec61850-mms</code> &mdash; IEC 61850 MMS</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">IEC 61850 MMS is the Manufacturing Message Specification mapping used by substation Intelligent Electronic Devices for monitoring, control, and reporting. Opens an MMS session and (when enabled) issues Identify, returning the IED vendor, model, firmware, and logical-device summary.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 102</span></div>
  <div class="nt-tags"><span class="nt-tag">backplane</span><span class="nt-tag">deep</span><span class="nt-tag">ot</span></div>
</div>
<div class="nt-card" data-pl-search="iec61850-sv iec 61850 sampled values iec 61850 sampled values is the layer-2 multicast protocol (ethertype 0x88ba) used by substation merging units to publish synchronized current and voltage measurements to protection and control ieds. runzero passively decodes sv frames, attributes the publisher mac as a merging unit, and records the svcb reference and dataset. tcp multicast ot passive" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>iec61850-sv</code> &mdash; IEC 61850 Sampled Values</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">IEC 61850 Sampled Values is the Layer-2 multicast protocol (EtherType 0x88BA) used by substation merging units to publish synchronized current and voltage measurements to protection and control IEDs. runZero passively decodes SV frames, attributes the publisher MAC as a merging unit, and records the SvCB reference and dataset.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">multicast</span><span class="nt-tag">ot</span><span class="nt-tag">passive</span></div>
</div>
<div class="nt-card" data-pl-search="igel igel discovery igel discovery is the discovery protocol used by igel os thin clients to advertise themselves to the igel universal management suite (ums), deployed in vdi and remote-desktop environments. sends the igel discovery probe and returns the endpoint hostname, hardware model, igel os version, mac, and the ums-server registration state. udp discovery light mgmt 30005" data-pl-transports="udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>igel</code> &mdash; IGEL Discovery</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">IGEL Discovery is the discovery protocol used by IGEL OS thin clients to advertise themselves to the IGEL Universal Management Suite (UMS), deployed in VDI and remote-desktop environments. Sends the IGEL discovery probe and returns the endpoint hostname, hardware model, IGEL OS version, MAC, and the UMS-server registration state.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 30005</span></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">light</span><span class="nt-tag">mgmt</span></div>
</div>
<div class="nt-card" data-pl-search="igel-discovery igel ums discovery igel ums discovery is the udp broadcast used by igel os thin clients to locate their universal management suite server. distinct from the igel management protocol decoded over tcp, this entry captures discovery-only sightings on udp/30005. udp discovery mgmt 30005" data-pl-transports="udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>igel-discovery</code> &mdash; IGEL UMS Discovery</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">IGEL UMS Discovery is the UDP broadcast used by IGEL OS thin clients to locate their Universal Management Suite server. Distinct from the igel management protocol decoded over TCP, this entry captures discovery-only sightings on UDP/30005.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 30005</span></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">mgmt</span></div>
</div>
<div class="nt-card" data-pl-search="iis microsoft internet information services (iis) microsoft internet information services (iis) is the http server bundled with windows server, commonly hosting asp.net, outlook web access, and sharepoint. the http fingerprinter inspects server and x-powered-by headers and default landing pages and returns the iis version and asp.net version hints. tcp light tls web" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>iis</code> &mdash; Microsoft Internet Information Services (IIS)</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Microsoft Internet Information Services (IIS) is the HTTP server bundled with Windows Server, commonly hosting ASP.NET, Outlook Web Access, and SharePoint. The HTTP fingerprinter inspects Server and X-Powered-By headers and default landing pages and returns the IIS version and ASP.NET version hints.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">light</span><span class="nt-tag">tls</span><span class="nt-tag">web</span></div>
</div>
<div class="nt-card" data-pl-search="ike ike ike is the internet key exchange protocol used to negotiate ipsec security associations. sends ikev1/ikev2 sa proposals and vendor-id probes and returns the negotiated proposal summary, supported transforms, and any vendor-id strings that disclose the gateway implementation. udp vpn 500 4500" data-pl-transports="udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>ike</code></div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">IKE is the Internet Key Exchange protocol used to negotiate IPsec security associations. Sends IKEv1/IKEv2 SA proposals and vendor-ID probes and returns the negotiated proposal summary, supported transforms, and any vendor-ID strings that disclose the gateway implementation.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Ports:</span> 500, 4500</span></div>
  <div class="nt-tags"><span class="nt-tag">vpn</span></div>
</div>
<div class="nt-card" data-pl-search="ikev2 ikev2 ikev2 is the internet key exchange version 2 protocol (rfc 7296) used by ipsec vpn gateways on udp/500 and udp/4500. runzero sends an ike_sa_init request and parses the responder spi, accepted transform set, and any vendor-id payloads that disclose the gateway implementation. udp vpn 500 4500" data-pl-transports="udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>ikev2</code></div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">IKEv2 is the Internet Key Exchange version 2 protocol (RFC 7296) used by IPsec VPN gateways on UDP/500 and UDP/4500. runZero sends an IKE_SA_INIT request and parses the responder SPI, accepted transform set, and any vendor-ID payloads that disclose the gateway implementation.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Ports:</span> 500, 4500</span></div>
  <div class="nt-tags"><span class="nt-tag">vpn</span></div>
</div>
<div class="nt-card" data-pl-search="imap imap imap is the internet message access protocol used by mail clients to read messages from a server. reads the imap greeting and runs capability and id commands, returning the server software, supported authentication mechanisms, and starttls availability. tcp email tls 143 993" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>imap</code></div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">IMAP is the Internet Message Access Protocol used by mail clients to read messages from a server. Reads the IMAP greeting and runs CAPABILITY and ID commands, returning the server software, supported authentication mechanisms, and STARTTLS availability.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Ports:</span> 143, 993</span></div>
  <div class="nt-tags"><span class="nt-tag">email</span><span class="nt-tag">tls</span></div>
</div>
<div class="nt-card" data-pl-search="infinispan infinispan hot rod infinispan hot rod is a binary client/server protocol used by red hat data grid and jboss-family caches. performs the hot rod ping and returns the server version, topology identifier, and supported protocol version. tcp database 11222" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>infinispan</code> &mdash; Infinispan Hot Rod</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Infinispan Hot Rod is a binary client/server protocol used by Red Hat Data Grid and JBoss-family caches. Performs the Hot Rod ping and returns the server version, topology identifier, and supported protocol version.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 11222</span></div>
  <div class="nt-tags"><span class="nt-tag">database</span></div>
</div>
<div class="nt-card" data-pl-search="influxdb influxdb influxdb is the time-series database from influxdata. runzero queries /ping and /health on the http api to recover the server build, x-influxdb-version header, and on permissive deployments the list of available databases. tcp clear mgmt 8086" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>influxdb</code></div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">InfluxDB is the time-series database from InfluxData. runZero queries /ping and /health on the HTTP API to recover the server build, X-Influxdb-Version header, and on permissive deployments the list of available databases.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 8086</span></div>
  <div class="nt-tags"><span class="nt-tag">clear</span><span class="nt-tag">mgmt</span></div>
</div>
<div class="nt-card" data-pl-search="intermapper intermapper intermapper is the probe interface exposed by fortra (formerly helpsystems) intermapper network-monitoring agents installed on monitored servers and appliances to report status to a central intermapper server. reads the intermapper service banner and returns the product name and agent version. tcp light monitoring 8181" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>intermapper</code></div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">InterMapper is the probe interface exposed by Fortra (formerly HelpSystems) InterMapper network-monitoring agents installed on monitored servers and appliances to report status to a central InterMapper server. Reads the InterMapper service banner and returns the product name and agent version.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 8181</span></div>
  <div class="nt-tags"><span class="nt-tag">light</span><span class="nt-tag">monitoring</span></div>
</div>
<div class="nt-card" data-pl-search="ipmi ipmi ipmi is the intelligent platform management interface used for out-of-band server management on bmcs (ilo, idrac, imm). performs an ipmi 2.0 rmcp+ get channel authentication capabilities exchange and, when credentials are configured, returns supported cipher suites, authentication algorithms, and the bmc vendor/firmware identification. udp auth mgmt 623" data-pl-transports="udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>ipmi</code></div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">IPMI is the Intelligent Platform Management Interface used for out-of-band server management on BMCs (iLO, iDRAC, IMM). Performs an IPMI 2.0 RMCP+ Get Channel Authentication Capabilities exchange and, when credentials are configured, returns supported cipher suites, authentication algorithms, and the BMC vendor/firmware identification.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 623</span></div>
  <div class="nt-tags"><span class="nt-tag">auth</span><span class="nt-tag">mgmt</span></div>
</div>
<div class="nt-card" data-pl-search="ipp ipp ipp is the internet printing protocol used by cups, airprint, and most modern network printers. issues get-printer-attributes and returns the printer make/model, location, firmware, supported document formats, and feature attributes. tcp printing tls 631" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>ipp</code></div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">IPP is the Internet Printing Protocol used by CUPS, AirPrint, and most modern network printers. Issues Get-Printer-Attributes and returns the printer make/model, location, firmware, supported document formats, and feature attributes.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 631</span></div>
  <div class="nt-tags"><span class="nt-tag">printing</span><span class="nt-tag">tls</span></div>
</div>
<div class="nt-card" data-pl-search="ipp-browse ipp browse ipp browse is the legacy cups browse protocol used by macos and linux print servers to advertise ipp print queues to the local segment via udp/631 broadcasts. runzero passively decodes browse packets and active responses and returns the advertised queue uri, printer name, and cups server identification, attributing the asset as a print server. udp discovery light multicast printing 631" data-pl-transports="udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>ipp-browse</code> &mdash; IPP Browse</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">IPP Browse is the legacy CUPS browse protocol used by macOS and Linux print servers to advertise IPP print queues to the local segment via UDP/631 broadcasts. runZero passively decodes browse packets and active responses and returns the advertised queue URI, printer name, and CUPS server identification, attributing the asset as a print server.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 631</span></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">light</span><span class="nt-tag">multicast</span><span class="nt-tag">printing</span></div>
</div>
<div class="nt-card" data-pl-search="ippbrowse ipp browse ipp browse is the legacy cups browse protocol used by unix print servers to advertise ipp print queues via udp/631 broadcasts. passively decodes browse packets and returns the advertised queue uri, printer name, and cups server identification. udp discovery light multicast printing 631" data-pl-transports="udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>ippbrowse</code> &mdash; IPP Browse</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">IPP Browse is the legacy CUPS browse protocol used by Unix print servers to advertise IPP print queues via UDP/631 broadcasts. Passively decodes browse packets and returns the advertised queue URI, printer name, and CUPS server identification.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 631</span></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">light</span><span class="nt-tag">multicast</span><span class="nt-tag">printing</span></div>
</div>
<div class="nt-card" data-pl-search="ipsec ipsec ipsec is the ip security suite used to authenticate and encrypt ip packets, typically for site-to-site and remote-access vpns. sends esp/ah and ike liveness probes and returns the gateway responsiveness, nat-t support, and any ike-vendor strings disclosed. udp encrypted vpn 500 4500" data-pl-transports="udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>ipsec</code></div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">IPsec is the IP Security suite used to authenticate and encrypt IP packets, typically for site-to-site and remote-access VPNs. Sends ESP/AH and IKE liveness probes and returns the gateway responsiveness, NAT-T support, and any IKE-vendor strings disclosed.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Ports:</span> 500, 4500</span></div>
  <div class="nt-tags"><span class="nt-tag">encrypted</span><span class="nt-tag">vpn</span></div>
</div>
<div class="nt-card" data-pl-search="irc irc irc is the internet relay chat protocol, a text-based group messaging protocol. reads the irc server greeting and runs a nick/user probe, returning the server software, version, and 005-numeric capability summary. tcp clear messaging tls 6667 6668 6669 6697 7000 7001" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>irc</code></div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">IRC is the Internet Relay Chat protocol, a text-based group messaging protocol. Reads the IRC server greeting and runs a NICK/USER probe, returning the server software, version, and 005-numeric capability summary.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Ports:</span> 6667, 6668, 6669, 6697, 7000, 7001</span></div>
  <div class="nt-tags"><span class="nt-tag">clear</span><span class="nt-tag">messaging</span><span class="nt-tag">tls</span></div>
</div>
<div class="nt-card" data-pl-search="iscsi iscsi iscsi is the internet small computer systems interface protocol used to expose block storage over ip. sends a sendtargets request and returns the iscsi target name list, target portals, and authentication-method summary. tcp storage 3260" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>iscsi</code></div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">iSCSI is the Internet Small Computer Systems Interface protocol used to expose block storage over IP. Sends a SendTargets request and returns the iSCSI Target Name list, target portals, and authentication-method summary.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 3260</span></div>
  <div class="nt-tags"><span class="nt-tag">storage</span></div>
</div>
<div class="nt-card" data-pl-search="iua iua (sctp) iua (sctp) is the isdn user adaptation layer (rfc 4233) carried over sctp, used to backhaul isdn signaling in sigtran networks. verifies the sctp association and iua payload protocol identifier and returns endpoint identification. sctp voip 9900" data-pl-transports="sctp">
  <div class="nt-card-header">
    <div class="nt-title"><code>iua</code> &mdash; IUA (SCTP)</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="sctp">SCTP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">IUA (SCTP) is the ISDN User Adaptation Layer (RFC 4233) carried over SCTP, used to backhaul ISDN signaling in SIGTRAN networks. Verifies the SCTP association and IUA payload protocol identifier and returns endpoint identification.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 9900</span></div>
  <div class="nt-tags"><span class="nt-tag">voip</span></div>
</div>
<div class="nt-card" data-pl-search="jabber jabber jabber is the legacy product name for xmpp, still used by cisco jabber, ejabberd, openfire, and similar chat/presence servers. runzero identifies jabber services from the &lt;stream:stream&gt; or jabber.org-namespaced response returned on connection and tags the asset alongside the active xmpp scanner results. tcp messaging tls" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>jabber</code></div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Jabber is the legacy product name for XMPP, still used by Cisco Jabber, ejabberd, Openfire, and similar chat/presence servers. runZero identifies Jabber services from the &lt;stream:stream&gt; or jabber.org-namespaced response returned on connection and tags the asset alongside the active xmpp scanner results.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">messaging</span><span class="nt-tag">tls</span></div>
</div>
<div class="nt-card" data-pl-search="java-object java object serialization java object serialization is the binary stream format produced by java.io.objectoutputstream, often indicating exposed rmi, jmx, or jboss endpoints when seen on the wire. inspects the magic header and returns the serialization-protocol version and any class-name hints disclosed in the stream. tcp light mgmt" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>java-object</code> &mdash; Java Object Serialization</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Java Object Serialization is the binary stream format produced by java.io.ObjectOutputStream, often indicating exposed RMI, JMX, or JBoss endpoints when seen on the wire. Inspects the magic header and returns the serialization-protocol version and any class-name hints disclosed in the stream.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">light</span><span class="nt-tag">mgmt</span></div>
</div>
<div class="nt-card" data-pl-search="java-rmi java rmi java rmi is the remote method invocation protocol used by java applications. performs the jrmp handshake and a registry list, returning the rmi-registry version and the names and stub classes of bound objects. tcp mgmt 1099" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>java-rmi</code> &mdash; Java RMI</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Java RMI is the Remote Method Invocation protocol used by Java applications. Performs the JRMP handshake and a registry list, returning the RMI-registry version and the names and stub classes of bound objects.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 1099</span></div>
  <div class="nt-tags"><span class="nt-tag">mgmt</span></div>
</div>
<div class="nt-card" data-pl-search="jdbc-hsqldb hypersql jdbc hypersql jdbc is the jdbc database server protocol used by the hypersql (hsqldb) engine. identifies the service from the &#39;hsqldb jdbc network listener&#39; banner returned on connection. tcp database 9001" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>jdbc-hsqldb</code> &mdash; HyperSQL JDBC</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">HyperSQL JDBC is the JDBC database server protocol used by the HyperSQL (HSQLDB) engine. Identifies the service from the &#39;HSQLDB JDBC Network Listener&#39; banner returned on connection.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 9001</span></div>
  <div class="nt-tags"><span class="nt-tag">database</span></div>
</div>
<div class="nt-card" data-pl-search="jdwp java debug wire protocol java debug wire protocol is the unauthenticated jvm debugging transport used by ides and debuggers to control a jvm. performs the jdwp handshake and version command, returning the jdk version, jvm vendor, and process description. tcp mgmt 3999 5000 5005 8000 8453 8787 8788 9001 18000" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>jdwp</code> &mdash; Java Debug Wire Protocol</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Java Debug Wire Protocol is the unauthenticated JVM debugging transport used by IDEs and debuggers to control a JVM. Performs the JDWP handshake and Version command, returning the JDK version, JVM vendor, and process description.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Ports:</span> 3999, 5000, 5005, 8000, 8453, 8787, 8788, 9001, 18000</span></div>
  <div class="nt-tags"><span class="nt-tag">mgmt</span></div>
</div>
<div class="nt-card" data-pl-search="jetdirect hp jetdirect hp jetdirect is the raw printing protocol on tcp/9100 (pjl banner port). sends a pjl info id/status probe and returns the printer make/model, firmware, page count, and pjl device-attribute summary. tcp light printing 9100 9101 9102" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>jetdirect</code> &mdash; HP JetDirect</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">HP JetDirect is the raw printing protocol on TCP/9100 (PJL banner port). Sends a PJL INFO ID/STATUS probe and returns the printer make/model, firmware, page count, and PJL device-attribute summary.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Ports:</span> 9100, 9101, 9102</span></div>
  <div class="nt-tags"><span class="nt-tag">light</span><span class="nt-tag">printing</span></div>
</div>
<div class="nt-card" data-pl-search="jira atlassian jira atlassian jira is an issue-tracking and project-management server available in server, data center, and cloud editions. the http probe fetches jira login, dashboard, and rest endpoints and returns the product name, edition, and build number. tcp light tls web 80 443 8080" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>jira</code> &mdash; Atlassian Jira</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Atlassian Jira is an issue-tracking and project-management server available in Server, Data Center, and Cloud editions. The HTTP probe fetches Jira login, dashboard, and REST endpoints and returns the product name, edition, and build number.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Ports:</span> 80, 443, 8080</span></div>
  <div class="nt-tags"><span class="nt-tag">light</span><span class="nt-tag">tls</span><span class="nt-tag">web</span></div>
</div>
<div class="nt-card" data-pl-search="jms jms / jmx-rmi port mapper jms / jmx-rmi port mapper is the openmq/glassfish imqbroker port-mapper service that publishes the names, transports, and ports of bound jms and jmx-rmi endpoints (default tcp/7676). queries the port mapper and returns the broker version and the bound endpoint names, transports, and ports. tcp messaging mgmt 7676" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>jms</code> &mdash; JMS / JMX-RMI Port Mapper</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">JMS / JMX-RMI Port Mapper is the OpenMQ/GlassFish imqbroker port-mapper service that publishes the names, transports, and ports of bound JMS and JMX-RMI endpoints (default TCP/7676). Queries the port mapper and returns the broker version and the bound endpoint names, transports, and ports.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 7676</span></div>
  <div class="nt-tags"><span class="nt-tag">messaging</span><span class="nt-tag">mgmt</span></div>
</div>
<div class="nt-card" data-pl-search="kafka apache kafka apache kafka is a distributed event-streaming wire protocol. sends an apiversions request and returns the broker identifier, supported api versions, and (when an unauthenticated metadatarequest is permitted) cluster and topic-name summaries. tcp messaging tls 9092 9093 9094" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>kafka</code> &mdash; Apache Kafka</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Apache Kafka is a distributed event-streaming wire protocol. Sends an ApiVersions request and returns the broker identifier, supported API versions, and (when an unauthenticated MetadataRequest is permitted) cluster and topic-name summaries.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Ports:</span> 9092, 9093, 9094</span></div>
  <div class="nt-tags"><span class="nt-tag">messaging</span><span class="nt-tag">tls</span></div>
</div>
<div class="nt-card" data-pl-search="kasa tp-link kasa tp-link kasa is the smart-home control protocol used by kasa plugs, bulbs, and switches. sends the obfuscated sys_info query and returns the device alias, model, firmware, hardware version, and mac. tcp iot light 9999" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>kasa</code> &mdash; TP-Link Kasa</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">TP-Link Kasa is the smart-home control protocol used by Kasa plugs, bulbs, and switches. Sends the obfuscated SYS_INFO query and returns the device alias, model, firmware, hardware version, and MAC.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 9999</span></div>
  <div class="nt-tags"><span class="nt-tag">iot</span><span class="nt-tag">light</span></div>
</div>
<div class="nt-card" data-pl-search="kerberos kerberos kerberos is the network authentication protocol used by active directory and many enterprise services. sends an as-req for a benign principal and returns the realm, kdc error code, and supported encryption types. tcp udp aaa 88 464 749 750" data-pl-transports="tcp udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>kerberos</code></div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Kerberos is the network authentication protocol used by Active Directory and many enterprise services. Sends an AS-REQ for a benign principal and returns the realm, KDC error code, and supported encryption types.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Ports:</span> 88, 464, 749, 750</span></div>
  <div class="nt-tags"><span class="nt-tag">aaa</span></div>
</div>
<div class="nt-card" data-pl-search="knxnet knxnet/ip knxnet/ip is the ip-tunneling encapsulation used to tunnel and route knx building-automation telegrams (lighting, hvac, shading). sends a search_request and returns the device serial, mac, knx individual address, supported services, and friendly name. udp building-automation ot 3671" data-pl-transports="udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>knxnet</code> &mdash; KNXnet/IP</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">KNXnet/IP is the IP-tunneling encapsulation used to tunnel and route KNX building-automation telegrams (lighting, HVAC, shading). Sends a SEARCH_REQUEST and returns the device serial, MAC, KNX individual address, supported services, and friendly name.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 3671</span></div>
  <div class="nt-tags"><span class="nt-tag">building-automation</span><span class="nt-tag">ot</span></div>
</div>
<div class="nt-card" data-pl-search="l2t l2tp (udp 1701) l2tp (udp 1701) is the layer 2 tunneling protocol on udp/1701, used by vpn concentrators and remote-access gateways (often paired with ipsec) to tunnel ppp sessions. sends an l2tp sccrq and returns the host name, vendor name, and firmware revision avps disclosed by the responder. udp vpn 1701 2228" data-pl-transports="udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>l2t</code> &mdash; L2TP (UDP 1701)</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">L2TP (UDP 1701) is the Layer 2 Tunneling Protocol on UDP/1701, used by VPN concentrators and remote-access gateways (often paired with IPsec) to tunnel PPP sessions. Sends an L2TP SCCRQ and returns the host name, vendor name, and firmware revision AVPs disclosed by the responder.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Ports:</span> 1701, 2228</span></div>
  <div class="nt-tags"><span class="nt-tag">vpn</span></div>
</div>
<div class="nt-card" data-pl-search="l2tp l2tp l2tp is the layer 2 tunneling protocol used to carry ppp sessions, commonly with ipsec for vpn. sends an sccrq and returns the host name, vendor name, and firmware revision avps. udp vpn 1701" data-pl-transports="udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>l2tp</code></div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">L2TP is the Layer 2 Tunneling Protocol used to carry PPP sessions, commonly with IPsec for VPN. Sends an SCCRQ and returns the host name, vendor name, and firmware revision AVPs.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 1701</span></div>
  <div class="nt-tags"><span class="nt-tag">vpn</span></div>
</div>
<div class="nt-card" data-pl-search="landesk ivanti / landesk agent ivanti / landesk agent is the endpoint-management agent for ivanti (formerly landesk). reads the agent banner and returns the agent version and bound management server. tcp light mgmt 9595" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>landesk</code> &mdash; Ivanti / LANDesk Agent</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Ivanti / LANDesk Agent is the endpoint-management agent for Ivanti (formerly LANDesk). Reads the agent banner and returns the agent version and bound management server.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 9595</span></div>
  <div class="nt-tags"><span class="nt-tag">light</span><span class="nt-tag">mgmt</span></div>
</div>
<div class="nt-card" data-pl-search="langflow langflow langflow is an open-source visual builder for llm-powered applications. runzero attributes services as langflow from recog matches against the application&#39;s http responses and openapi document, recovering the application version. tcp ai clear web" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>langflow</code></div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Langflow is an open-source visual builder for LLM-powered applications. runZero attributes services as Langflow from Recog matches against the application&#39;s HTTP responses and OpenAPI document, recovering the application version.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">ai</span><span class="nt-tag">clear</span><span class="nt-tag">web</span></div>
</div>
<div class="nt-card" data-pl-search="lantronix lantronix discovery lantronix discovery is the discovery protocol used to locate lantronix serial-to-ethernet device servers. sends the discovery probe and returns the device model, firmware, mac, and configured serial-port settings. udp discovery iot light 30718" data-pl-transports="udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>lantronix</code> &mdash; Lantronix Discovery</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Lantronix Discovery is the discovery protocol used to locate Lantronix serial-to-Ethernet device servers. Sends the discovery probe and returns the device model, firmware, MAC, and configured serial-port settings.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 30718</span></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">iot</span><span class="nt-tag">light</span></div>
</div>
<div class="nt-card" data-pl-search="ldap ldap ldap is the lightweight directory access protocol (rfc 4511) used by active directory, openldap, 389 directory server, and other directory services for authentication and identity lookups. queries the rootdse and returns the supported ldap versions, naming contexts, supported controls, and any forest or domain identifiers exposed. tcp auth directory tls 389 636 3268 3269" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>ldap</code></div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">LDAP is the Lightweight Directory Access Protocol (RFC 4511) used by Active Directory, OpenLDAP, 389 Directory Server, and other directory services for authentication and identity lookups. Queries the rootDSE and returns the supported LDAP versions, naming contexts, supported controls, and any forest or domain identifiers exposed.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Ports:</span> 389, 636, 3268, 3269</span></div>
  <div class="nt-tags"><span class="nt-tag">auth</span><span class="nt-tag">directory</span><span class="nt-tag">tls</span></div>
</div>
<div class="nt-card" data-pl-search="lexmark lexmark discovery lexmark discovery is the printer/mfp network discovery protocol used by lexmark devices. sends the discovery probe and returns the device model, serial, firmware, and printer/mfp capabilities. tcp discovery light printing 10000" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>lexmark</code> &mdash; Lexmark Discovery</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Lexmark Discovery is the printer/MFP network discovery protocol used by Lexmark devices. Sends the discovery probe and returns the device model, serial, firmware, and printer/MFP capabilities.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 10000</span></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">light</span><span class="nt-tag">printing</span></div>
</div>
<div class="nt-card" data-pl-search="librechat librechat librechat is an open-source self-hosted llm chat front-end. runzero attributes services as librechat from recog matches against the web ui banners and configuration endpoints. tcp ai clear web 443 3080" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>librechat</code></div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">LibreChat is an open-source self-hosted LLM chat front-end. runZero attributes services as LibreChat from Recog matches against the web UI banners and configuration endpoints.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Ports:</span> 443, 3080</span></div>
  <div class="nt-tags"><span class="nt-tag">ai</span><span class="nt-tag">clear</span><span class="nt-tag">web</span></div>
</div>
<div class="nt-card" data-pl-search="lldp link layer discovery protocol link layer discovery protocol is the ieee 802.1ab layer-2 discovery protocol used by switches, routers, ip phones, and hypervisors to advertise themselves to neighbors. runzero passively decodes lldp frames seen during the scan and returns the chassis id, port id, system name, system description, capabilities, and management addresses of each neighbor. tcp discovery mgmt multicast passive" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>lldp</code> &mdash; Link Layer Discovery Protocol</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Link Layer Discovery Protocol is the IEEE 802.1AB Layer-2 discovery protocol used by switches, routers, IP phones, and hypervisors to advertise themselves to neighbors. runZero passively decodes LLDP frames seen during the scan and returns the chassis ID, port ID, system name, system description, capabilities, and management addresses of each neighbor.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">mgmt</span><span class="nt-tag">multicast</span><span class="nt-tag">passive</span></div>
</div>
<div class="nt-card" data-pl-search="llmnr llmnr llmnr is link-local multicast name resolution (rfc 4795) used by windows hosts to resolve single-label names on the local link when dns is unavailable. sends an llmnr query and returns the responding hostname and the ip version of the answering host. udp light multicast naming 5355" data-pl-transports="udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>llmnr</code></div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">LLMNR is Link-Local Multicast Name Resolution (RFC 4795) used by Windows hosts to resolve single-label names on the local link when DNS is unavailable. Sends an LLMNR query and returns the responding hostname and the IP version of the answering host.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 5355</span></div>
  <div class="nt-tags"><span class="nt-tag">light</span><span class="nt-tag">multicast</span><span class="nt-tag">naming</span></div>
</div>
<div class="nt-card" data-pl-search="lockdownd apple lockdownd apple lockdownd pairing service exposed on tcp/62078 by iphone, ipad, and ipod touch devices and used by itunes, finder, apple configurator, and mdm tooling. reads the lockdownd query response and returns the device class, product type, ios or ipados version, serial number, and unique device identifier (udid). tcp light mgmt 62078" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>lockdownd</code> &mdash; Apple lockdownd</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Apple lockdownd pairing service exposed on TCP/62078 by iPhone, iPad, and iPod touch devices and used by iTunes, Finder, Apple Configurator, and MDM tooling. Reads the lockdownd query response and returns the device class, product type, iOS or iPadOS version, serial number, and unique device identifier (UDID).</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 62078</span></div>
  <div class="nt-tags"><span class="nt-tag">light</span><span class="nt-tag">mgmt</span></div>
</div>
<div class="nt-card" data-pl-search="lpd lpd lpd is the standardized bsd line-printer protocol (rfc 1179). sends a receive-job command and returns the raw printer banner from the daemon for downstream make and model fingerprinting. tcp light printing 515" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>lpd</code></div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">LPD is the standardized BSD line-printer protocol (RFC 1179). Sends a Receive-Job command and returns the raw printer banner from the daemon for downstream make and model fingerprinting.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 515</span></div>
  <div class="nt-tags"><span class="nt-tag">light</span><span class="nt-tag">printing</span></div>
</div>
<div class="nt-card" data-pl-search="lsv2 heidenhain lsv/2 heidenhain lsv/2 is a control protocol used by heidenhain tnc cnc controls (tnc 640, itnc 530, tnc 320). queries control identification and returns the nc software type, version, and (when enabled) nc software-options bitmask. tcp deep ot 8000 8001 8002 8003 8004 19000" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>lsv2</code> &mdash; Heidenhain LSV/2</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Heidenhain LSV/2 is a control protocol used by Heidenhain TNC CNC controls (TNC 640, iTNC 530, TNC 320). Queries control identification and returns the NC software type, version, and (when enabled) NC software-options bitmask.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Ports:</span> 8000, 8001, 8002, 8003, 8004, 19000</span></div>
  <div class="nt-tags"><span class="nt-tag">deep</span><span class="nt-tag">ot</span></div>
</div>
<div class="nt-card" data-pl-search="lwm2m oma lwm2m oma lwm2m is the oma lightweight m2m device-management protocol layered on coap and used to manage constrained iot endpoints, sensors, and cellular modules. sends a coap get for /.well-known/core and returns whether the lwm2m registration directory and bootstrap-server resources are advertised along with a server-implementation hint. udp iot mgmt 5683 5783" data-pl-transports="udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>lwm2m</code> &mdash; OMA LwM2M</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">OMA LwM2M is the OMA Lightweight M2M device-management protocol layered on CoAP and used to manage constrained IoT endpoints, sensors, and cellular modules. Sends a CoAP GET for /.well-known/core and returns whether the LwM2M registration directory and bootstrap-server resources are advertised along with a server-implementation hint.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Ports:</span> 5683, 5783</span></div>
  <div class="nt-tags"><span class="nt-tag">iot</span><span class="nt-tag">mgmt</span></div>
</div>
<div class="nt-card" data-pl-search="m2pa m2pa (sctp) m2pa (sctp) is the mtp2 peer adaptation layer (rfc 4165) over sctp used in sigtran to carry ss7 mtp2 between signaling gateways. establishes an sctp association, verifies the m2pa payload protocol identifier, and returns the m2pa message class, message type, link state, and any error code or info string in the reply. sctp mobile-core voip 3565" data-pl-transports="sctp">
  <div class="nt-card-header">
    <div class="nt-title"><code>m2pa</code> &mdash; M2PA (SCTP)</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="sctp">SCTP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">M2PA (SCTP) is the MTP2 Peer Adaptation Layer (RFC 4165) over SCTP used in SIGTRAN to carry SS7 MTP2 between signaling gateways. Establishes an SCTP association, verifies the M2PA payload protocol identifier, and returns the M2PA message class, message type, link state, and any error code or info string in the reply.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 3565</span></div>
  <div class="nt-tags"><span class="nt-tag">mobile-core</span><span class="nt-tag">voip</span></div>
</div>
<div class="nt-card" data-pl-search="m2ua m2ua (sctp) m2ua (sctp) is the mtp2 user adaptation layer (rfc 3331) over sctp used in sigtran deployments. establishes an sctp association, verifies the m2ua payload protocol identifier, and returns the m2ua message class, message type, and any error code or info string in the reply. sctp mobile-core voip 2904" data-pl-transports="sctp">
  <div class="nt-card-header">
    <div class="nt-title"><code>m2ua</code> &mdash; M2UA (SCTP)</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="sctp">SCTP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">M2UA (SCTP) is the MTP2 User Adaptation Layer (RFC 3331) over SCTP used in SIGTRAN deployments. Establishes an SCTP association, verifies the M2UA payload protocol identifier, and returns the M2UA message class, message type, and any error code or info string in the reply.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 2904</span></div>
  <div class="nt-tags"><span class="nt-tag">mobile-core</span><span class="nt-tag">voip</span></div>
</div>
<div class="nt-card" data-pl-search="m3ua m3ua (sctp) m3ua (sctp) is the mtp3 user adaptation layer (rfc 4666) over sctp, the most common ss7-over-ip transport. establishes an sctp association, verifies the m3ua payload protocol identifier, and returns the m3ua message class, message type, and any error code or info string in the reply. sctp mobile-core voip 2905" data-pl-transports="sctp">
  <div class="nt-card-header">
    <div class="nt-title"><code>m3ua</code> &mdash; M3UA (SCTP)</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="sctp">SCTP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">M3UA (SCTP) is the MTP3 User Adaptation Layer (RFC 4666) over SCTP, the most common SS7-over-IP transport. Establishes an SCTP association, verifies the M3UA payload protocol identifier, and returns the M3UA message class, message type, and any error code or info string in the reply.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 2905</span></div>
  <div class="nt-tags"><span class="nt-tag">mobile-core</span><span class="nt-tag">voip</span></div>
</div>
<div class="nt-card" data-pl-search="managesieve managesieve managesieve is a protocol used by mail clients to manage sieve mail-filter scripts on the server. reads the capabilities response and returns the implementation name, version, supported sasl mechanisms, and starttls availability. tcp email tls 2000 4190" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>managesieve</code></div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">ManageSieve is a protocol used by mail clients to manage Sieve mail-filter scripts on the server. Reads the capabilities response and returns the implementation name, version, supported SASL mechanisms, and STARTTLS availability.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Ports:</span> 2000, 4190</span></div>
  <div class="nt-tags"><span class="nt-tag">email</span><span class="nt-tag">tls</span></div>
</div>
<div class="nt-card" data-pl-search="matter matter matter is the connectivity standards alliance smart-home application protocol used by matter-certified devices over wi-fi and thread. runzero identifies matter devices from _matter._tcp mdns records, parses the vp and dt txt fields, and resolves them against the bundled matter vendor table to return the vendor name, product name, and device type. udp discovery iot passive" data-pl-transports="udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>matter</code></div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Matter is the Connectivity Standards Alliance smart-home application protocol used by Matter-certified devices over Wi-Fi and Thread. runZero identifies Matter devices from _matter._tcp mDNS records, parses the VP and DT TXT fields, and resolves them against the bundled Matter vendor table to return the vendor name, product name, and device type.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">iot</span><span class="nt-tag">passive</span></div>
</div>
<div class="nt-card" data-pl-search="mbus-tcp m-bus over tcp m-bus over tcp is the en 13757 meter-bus protocol tunneled over tcp, used by gateways aggregating utility meters (heat, water, gas, electric). sends req_ud2 to the gateway and (when enabled) walks primary addresses 1-250 to enumerate connected meters, returning meter manufacturer, identification, version, and medium. tcp backplane deep ot 8888 8889" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>mbus-tcp</code> &mdash; M-Bus over TCP</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">M-Bus over TCP is the EN 13757 Meter-Bus protocol tunneled over TCP, used by gateways aggregating utility meters (heat, water, gas, electric). Sends REQ_UD2 to the gateway and (when enabled) walks primary addresses 1-250 to enumerate connected meters, returning meter manufacturer, identification, version, and medium.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Ports:</span> 8888, 8889</span></div>
  <div class="nt-tags"><span class="nt-tag">backplane</span><span class="nt-tag">deep</span><span class="nt-tag">ot</span></div>
</div>
<div class="nt-card" data-pl-search="mcp model context protocol model context protocol (mcp) is anthropic&#39;s json-rpc protocol used by ai agents to connect to external tools and data sources. runzero attributes services as mcp from recog matches against the server&#39;s http/sse handshake and the initialize response, which exposes the server name, version, and advertised capabilities. tcp ai clear" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>mcp</code> &mdash; Model Context Protocol</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Model Context Protocol (MCP) is Anthropic&#39;s JSON-RPC protocol used by AI agents to connect to external tools and data sources. runZero attributes services as MCP from Recog matches against the server&#39;s HTTP/SSE handshake and the initialize response, which exposes the server name, version, and advertised capabilities.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">ai</span><span class="nt-tag">clear</span></div>
</div>
<div class="nt-card" data-pl-search="mdns mdns mdns is multicast dns used by bonjour, avahi, and other zero-configuration networking stacks. sends a service-enumeration query and returns the advertised service types, instance names, ports, hostnames, and txt-record metadata. udp discovery light multicast naming 5353" data-pl-transports="udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>mdns</code></div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">mDNS is Multicast DNS used by Bonjour, Avahi, and other zero-configuration networking stacks. Sends a service-enumeration query and returns the advertised service types, instance names, ports, hostnames, and TXT-record metadata.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 5353</span></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">light</span><span class="nt-tag">multicast</span><span class="nt-tag">naming</span></div>
</div>
<div class="nt-card" data-pl-search="megaco megaco / h.248 megaco / h.248 is a media gateway control protocol (rfc 3525) used between softswitches and media gateways in carrier and enterprise voip networks. sends a servicechange probe and returns the media-gateway identifier (mid) and the negotiated h.248 protocol version. udp voip 2944 2945" data-pl-transports="udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>megaco</code> &mdash; Megaco / H.248</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Megaco / H.248 is a media gateway control protocol (RFC 3525) used between softswitches and media gateways in carrier and enterprise VoIP networks. Sends a ServiceChange probe and returns the media-gateway identifier (MID) and the negotiated H.248 protocol version.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Ports:</span> 2944, 2945</span></div>
  <div class="nt-tags"><span class="nt-tag">voip</span></div>
</div>
<div class="nt-card" data-pl-search="melsecq mitsubishi melsec-q mitsubishi melsec-q is a protocol used to communicate with mitsubishi melsec plcs. issues a cpu model-name read using slmp 3e (and, when enabled, 4e) and returns the cpu model name and cpu type code along with the matching melsec product cpe. tcp backplane deep ot 5006 5007" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>melsecq</code> &mdash; Mitsubishi MELSEC-Q</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Mitsubishi MELSEC-Q is a protocol used to communicate with Mitsubishi MELSEC PLCs. Issues a CPU model-name read using SLMP 3E (and, when enabled, 4E) and returns the CPU model name and CPU type code along with the matching MELSEC product CPE.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Ports:</span> 5006, 5007</span></div>
  <div class="nt-tags"><span class="nt-tag">backplane</span><span class="nt-tag">deep</span><span class="nt-tag">ot</span></div>
</div>
<div class="nt-card" data-pl-search="memcache memcached (text) memcached (text) is the ascii text wire protocol exposed by the memcached distributed in-memory key-value cache and compatible servers. issues a text version/stats request and returns the daemon version, current connections, and items and bytes held in cache. tcp udp clear database tls 11211" data-pl-transports="tcp udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>memcache</code> &mdash; Memcached (text)</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Memcached (text) is the ASCII text wire protocol exposed by the Memcached distributed in-memory key-value cache and compatible servers. Issues a text VERSION/STATS request and returns the daemon version, current connections, and items and bytes held in cache.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 11211</span></div>
  <div class="nt-tags"><span class="nt-tag">clear</span><span class="nt-tag">database</span><span class="nt-tag">tls</span></div>
</div>
<div class="nt-card" data-pl-search="memcached memcached memcached is a high-performance in-memory key/value cache. runzero issues the version, stats, and stats settings commands to recover the daemon version, uptime, current connections, item count, and configured memory limits. misconfigured udp-exposed servers are also flagged as ddos-amplification reflectors. tcp udp clear mgmt 11211" data-pl-transports="tcp udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>memcached</code></div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Memcached is a high-performance in-memory key/value cache. runZero issues the version, stats, and stats settings commands to recover the daemon version, uptime, current connections, item count, and configured memory limits. Misconfigured UDP-exposed servers are also flagged as DDoS-amplification reflectors.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 11211</span></div>
  <div class="nt-tags"><span class="nt-tag">clear</span><span class="nt-tag">mgmt</span></div>
</div>
<div class="nt-card" data-pl-search="meshcop thread mesh commissioning thread mesh commissioning is the mesh commissioning protocol used by thread border routers (apple homepod, google nest hub, eero, nordic otbr) to advertise commissioning endpoints to companion mobile apps. runzero attributes the asset as a thread border router from the meshcop hint and surfaces the advertised network name, extended pan id, and vendor identification. udp discovery iot passive" data-pl-transports="udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>meshcop</code> &mdash; Thread Mesh Commissioning</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Thread Mesh Commissioning is the Mesh Commissioning Protocol used by Thread border routers (Apple HomePod, Google Nest Hub, eero, Nordic OTBR) to advertise commissioning endpoints to companion mobile apps. runZero attributes the asset as a Thread border router from the meshcop hint and surfaces the advertised network name, extended PAN ID, and vendor identification.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">iot</span><span class="nt-tag">passive</span></div>
</div>
<div class="nt-card" data-pl-search="mgcp mgcp mgcp is the media gateway control protocol (rfc 3435) used between call agents and media gateways in voip networks. sends an auep probe and returns the response code along with any endpoint identifiers and packages disclosed in the reply. udp voip 2427 2727" data-pl-transports="udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>mgcp</code></div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">MGCP is the Media Gateway Control Protocol (RFC 3435) used between call agents and media gateways in VoIP networks. Sends an AUEP probe and returns the response code along with any endpoint identifiers and packages disclosed in the reply.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Ports:</span> 2427, 2727</span></div>
  <div class="nt-tags"><span class="nt-tag">voip</span></div>
</div>
<div class="nt-card" data-pl-search="mikrotik-bandwidth mikrotik bandwidth test server mikrotik bandwidth test server is the proprietary throughput-testing service exposed by mikrotik routeros devices. runzero detects the listener via its banner; presence indicates the device is reachable for line-rate tests, which can be abused for amplification. tcp clear mgmt 2000" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>mikrotik-bandwidth</code> &mdash; MikroTik Bandwidth Test Server</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">MikroTik Bandwidth Test Server is the proprietary throughput-testing service exposed by MikroTik RouterOS devices. runZero detects the listener via its banner; presence indicates the device is reachable for line-rate tests, which can be abused for amplification.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 2000</span></div>
  <div class="nt-tags"><span class="nt-tag">clear</span><span class="nt-tag">mgmt</span></div>
</div>
<div class="nt-card" data-pl-search="mikrotikwinbox mikrotik winbox mikrotik winbox is the protocol used by the winbox utility to administer routeros devices. sends the index-request and returns the routeros architecture, version, and bootloader identification. tcp mgmt 2000 8291 8728" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>mikrotikwinbox</code> &mdash; MikroTik Winbox</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">MikroTik Winbox is the protocol used by the Winbox utility to administer RouterOS devices. Sends the index-request and returns the RouterOS architecture, version, and bootloader identification.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Ports:</span> 2000, 8291, 8728</span></div>
  <div class="nt-tags"><span class="nt-tag">mgmt</span></div>
</div>
<div class="nt-card" data-pl-search="milvus milvus vector database milvus is an open-source vector database used by retrieval-augmented llm applications. runzero attributes services as milvus from recog matches against the grpc and http endpoints and the management ui banners. tcp ai clear mgmt 19530" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>milvus</code> &mdash; Milvus Vector Database</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Milvus is an open-source vector database used by retrieval-augmented LLM applications. runZero attributes services as Milvus from Recog matches against the gRPC and HTTP endpoints and the management UI banners.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 19530</span></div>
  <div class="nt-tags"><span class="nt-tag">ai</span><span class="nt-tag">clear</span><span class="nt-tag">mgmt</span></div>
</div>
<div class="nt-card" data-pl-search="minecraft minecraft java minecraft java is the server query/list-ping protocol used by minecraft java edition. sends a status-request and returns the server motd, version, protocol number, current and maximum player counts, and any sample player names disclosed. tcp gaming 25565" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>minecraft</code> &mdash; Minecraft Java</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Minecraft Java is the server query/list-ping protocol used by Minecraft Java Edition. Sends a status-request and returns the server MOTD, version, protocol number, current and maximum player counts, and any sample player names disclosed.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 25565</span></div>
  <div class="nt-tags"><span class="nt-tag">gaming</span></div>
</div>
<div class="nt-card" data-pl-search="mms iso 9506 mms (iec 61850) iso 9506 mms (iec 61850) is the manufacturing message specification over rfc 1006/cotp, the application protocol used by iec 61850 substation intelligent electronic devices (ieds). the probe issues an a-associate plus mms initiate-request and parses the initiate-response for vendor identity, negotiated mms version, and supported services. tcp backplane deep ot 102" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>mms</code> &mdash; ISO 9506 MMS (IEC 61850)</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">ISO 9506 MMS (IEC 61850) is the Manufacturing Message Specification over RFC 1006/COTP, the application protocol used by IEC 61850 substation Intelligent Electronic Devices (IEDs). The probe issues an A-ASSOCIATE plus MMS Initiate-Request and parses the Initiate-Response for vendor identity, negotiated MMS version, and supported services.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 102</span></div>
  <div class="nt-tags"><span class="nt-tag">backplane</span><span class="nt-tag">deep</span><span class="nt-tag">ot</span></div>
</div>
<div class="nt-card" data-pl-search="modbus modbus/tcp modbus/tcp is a protocol used to read and write registers on plcs, rtus, drives, and meters. issues a read device identification (function 43/mei 14) and returns the vendor, product code, revision, vendor url, product name, and (when configured) extended identification objects. tcp backplane deep ot 502" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>modbus</code> &mdash; Modbus/TCP</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Modbus/TCP is a protocol used to read and write registers on PLCs, RTUs, drives, and meters. Issues a Read Device Identification (function 43/MEI 14) and returns the vendor, product code, revision, vendor URL, product name, and (when configured) extended identification objects.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 502</span></div>
  <div class="nt-tags"><span class="nt-tag">backplane</span><span class="nt-tag">deep</span><span class="nt-tag">ot</span></div>
</div>
<div class="nt-card" data-pl-search="mongodb mongodb wire protocol mongodb wire protocol is the document-database wire protocol used by mongodb drivers. sends an unauthenticated ismaster/hello and returns the server version, build environment, replica-set role, and observed authentication requirements. tcp database tls 27017 27018 27019 28017" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>mongodb</code> &mdash; MongoDB Wire Protocol</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">MongoDB Wire Protocol is the document-database wire protocol used by MongoDB drivers. Sends an unauthenticated isMaster/hello and returns the server version, build environment, replica-set role, and observed authentication requirements.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Ports:</span> 27017, 27018, 27019, 28017</span></div>
  <div class="nt-tags"><span class="nt-tag">database</span><span class="nt-tag">tls</span></div>
</div>
<div class="nt-card" data-pl-search="mountd nfs mountd nfs mountd is the companion daemon to nfs that authorizes mount requests and enumerates exports, registered through rpcbind on unix file servers and nas appliances. runzero locates mountd through rpcbind, sends an export (procedure 5) call for each advertised version, and returns the exported directory list and per-export host or netgroup access lists. tcp udp file storage" data-pl-transports="tcp udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>mountd</code> &mdash; NFS mountd</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">NFS mountd is the companion daemon to NFS that authorizes mount requests and enumerates exports, registered through rpcbind on Unix file servers and NAS appliances. runZero locates mountd through rpcbind, sends an EXPORT (procedure 5) call for each advertised version, and returns the exported directory list and per-export host or netgroup access lists.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">file</span><span class="nt-tag">storage</span></div>
</div>
<div class="nt-card" data-pl-search="mqtt mqtt mqtt is a lightweight publish/subscribe messaging protocol used by iot devices and brokers. sends a connect and returns the broker&#39;s connack response code, supported mqtt version, and any properties advertised by the broker. tcp iot messaging tls 1883 8883" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>mqtt</code></div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">MQTT is a lightweight publish/subscribe messaging protocol used by IoT devices and brokers. Sends a CONNECT and returns the broker&#39;s CONNACK response code, supported MQTT version, and any properties advertised by the broker.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Ports:</span> 1883, 8883</span></div>
  <div class="nt-tags"><span class="nt-tag">iot</span><span class="nt-tag">messaging</span><span class="nt-tag">tls</span></div>
</div>
<div class="nt-card" data-pl-search="mssql microsoft sql server (tds) microsoft sql server (tds) is the tabular data stream protocol used by microsoft sql server and sybase ase database engines for client-server query traffic. sends a tds prelogin and returns the server version, encryption requirement, and named-instance identification. tcp udp database tls 1433 1434" data-pl-transports="tcp udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>mssql</code> &mdash; Microsoft SQL Server (TDS)</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Microsoft SQL Server (TDS) is the Tabular Data Stream protocol used by Microsoft SQL Server and Sybase ASE database engines for client-server query traffic. Sends a TDS PRELOGIN and returns the server version, encryption requirement, and named-instance identification.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Ports:</span> 1433, 1434</span></div>
  <div class="nt-tags"><span class="nt-tag">database</span><span class="nt-tag">tls</span></div>
</div>
<div class="nt-card" data-pl-search="mssql-replica microsoft sql server replica microsoft sql server replica is the always-on availability-group and database-mirroring endpoint that exchanges replica traffic on tcp/5022 separately from the user tds endpoint on tcp/1433. runzero hints tcp/5022 as mssql-replica during the mssql probe and tags the asset as a sql server replica endpoint when the standard tds handshake is not offered. tcp clear database light" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>mssql-replica</code> &mdash; Microsoft SQL Server Replica</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Microsoft SQL Server Replica is the Always-On availability-group and database-mirroring endpoint that exchanges replica traffic on TCP/5022 separately from the user TDS endpoint on TCP/1433. runZero hints TCP/5022 as mssql-replica during the MSSQL probe and tags the asset as a SQL Server replica endpoint when the standard TDS handshake is not offered.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">clear</span><span class="nt-tag">database</span><span class="nt-tag">light</span></div>
</div>
<div class="nt-card" data-pl-search="mtconnect mtconnect mtconnect is a protocol used by cnc machine tools, robots, and additive-manufacturing systems to publish device state over an http/xml rest api. issues a get /probe and returns the agent version, instance id, sender host, and per-device manufacturer, model, serial number, and uuid. tcp discovery ot 5000 7878" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>mtconnect</code></div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">MTConnect is a protocol used by CNC machine tools, robots, and additive-manufacturing systems to publish device state over an HTTP/XML REST API. Issues a GET /probe and returns the agent version, instance ID, sender host, and per-device manufacturer, model, serial number, and UUID.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Ports:</span> 5000, 7878</span></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">ot</span></div>
</div>
<div class="nt-card" data-pl-search="munin munin munin is the protocol used by the munin master to poll plugins on hosts. reads the node banner and returns the node hostname, munin version, and configured plugin list summary. tcp monitoring 4949" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>munin</code></div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Munin is the protocol used by the Munin master to poll plugins on hosts. Reads the node banner and returns the node hostname, Munin version, and configured plugin list summary.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 4949</span></div>
  <div class="nt-tags"><span class="nt-tag">monitoring</span></div>
</div>
<div class="nt-card" data-pl-search="mysql mysql / mariadb mysql / mariadb is the binary client-server wire protocol used by mysql, mariadb, and percona server database engines. reads the server-greeting packet and (when credentials are configured) authenticates, returning the server version, capability flags, supported authentication plugins, and tls availability. tcp database tls 3306 33060" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>mysql</code> &mdash; MySQL / MariaDB</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">MySQL / MariaDB is the binary client-server wire protocol used by MySQL, MariaDB, and Percona Server database engines. Reads the server-greeting packet and (when credentials are configured) authenticates, returning the server version, capability flags, supported authentication plugins, and TLS availability.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Ports:</span> 3306, 33060</span></div>
  <div class="nt-tags"><span class="nt-tag">database</span><span class="nt-tag">tls</span></div>
</div>
<div class="nt-card" data-pl-search="mysqlx mysql x protocol mysql x protocol is a protocol-buffer-based wire protocol exposed by mysql server (default tcp/33060) for mysql shell and x devapi document-store and crud clients. sends a capabilitiesget message and returns the supported x-protocol capabilities and tls requirements. tcp database 33060" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>mysqlx</code> &mdash; MySQL X Protocol</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">MySQL X Protocol is a Protocol-Buffer-based wire protocol exposed by MySQL Server (default TCP/33060) for MySQL Shell and X DevAPI document-store and CRUD clients. Sends a CapabilitiesGet message and returns the supported X-Protocol capabilities and TLS requirements.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 33060</span></div>
  <div class="nt-tags"><span class="nt-tag">database</span></div>
</div>
<div class="nt-card" data-pl-search="natpmp nat-pmp nat-pmp is a protocol used by clients to request port forwards from a nat gateway (rfc 6886). sends a public-address request and returns the gateway&#39;s external ipv4 address, response code, and seconds-since-epoch counter. udp light mgmt 5351" data-pl-transports="udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>natpmp</code> &mdash; NAT-PMP</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">NAT-PMP is a protocol used by clients to request port forwards from a NAT gateway (RFC 6886). Sends a public-address request and returns the gateway&#39;s external IPv4 address, response code, and seconds-since-epoch counter.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 5351</span></div>
  <div class="nt-tags"><span class="nt-tag">light</span><span class="nt-tag">mgmt</span></div>
</div>
<div class="nt-card" data-pl-search="nats nats nats is a lightweight publish/subscribe and request/reply messaging system. reads the nats info message and returns the server identifier, version, host, port, and authorization/tls requirements. tcp clear messaging tls 4222 6222 8222" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>nats</code></div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">NATS is a lightweight publish/subscribe and request/reply messaging system. Reads the NATS INFO message and returns the server identifier, version, host, port, and authorization/TLS requirements.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Ports:</span> 4222, 6222, 8222</span></div>
  <div class="nt-tags"><span class="nt-tag">clear</span><span class="nt-tag">messaging</span><span class="nt-tag">tls</span></div>
</div>
<div class="nt-card" data-pl-search="ndmp ndmp ndmp is the network data management protocol used by enterprise backup software to coordinate backups of nas devices. opens a connect_open session and returns the ndmp protocol version reported by the server along with the connection status and any reason text. tcp backup storage 10000" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>ndmp</code></div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">NDMP is the Network Data Management Protocol used by enterprise backup software to coordinate backups of NAS devices. Opens a CONNECT_OPEN session and returns the NDMP protocol version reported by the server along with the connection status and any reason text.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 10000</span></div>
  <div class="nt-tags"><span class="nt-tag">backup</span><span class="nt-tag">storage</span></div>
</div>
<div class="nt-card" data-pl-search="neo4j neo4j bolt neo4j bolt is the graph-database wire protocol used by neo4j drivers and clients. performs the bolt handshake and returns the negotiated bolt version and server release. tcp database tls 7473 7474 7687" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>neo4j</code> &mdash; Neo4j Bolt</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Neo4j Bolt is the graph-database wire protocol used by Neo4j drivers and clients. Performs the Bolt handshake and returns the negotiated Bolt version and server release.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Ports:</span> 7473, 7474, 7687</span></div>
  <div class="nt-tags"><span class="nt-tag">database</span><span class="nt-tag">tls</span></div>
</div>
<div class="nt-card" data-pl-search="netbios netbios session service netbios session service is the tcp/139 transport used by the legacy netbios-over-tcp framing of smb. runzero records the session-service banner alongside the netbios name and workstation/server resource records reported by the host. the application-layer smb protocol is decoded separately. tcp clear mgmt 137" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>netbios</code> &mdash; NetBIOS Session Service</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">NetBIOS Session Service is the TCP/139 transport used by the legacy NetBIOS-over-TCP framing of SMB. runZero records the session-service banner alongside the NetBIOS name and workstation/server resource records reported by the host. The application-layer SMB protocol is decoded separately.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 137</span></div>
  <div class="nt-tags"><span class="nt-tag">clear</span><span class="nt-tag">mgmt</span></div>
</div>
<div class="nt-card" data-pl-search="netbios-dgm netbios datagram service netbios datagram service is the udp/138 broadcast/datagram side of netbios-over-tcp. runzero observes datagrams to recover the netbios computer and workgroup names announced by windows hosts and smb servers. udp discovery 138" data-pl-transports="udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>netbios-dgm</code> &mdash; NetBIOS Datagram Service</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">NetBIOS Datagram Service is the UDP/138 broadcast/datagram side of NetBIOS-over-TCP. runZero observes datagrams to recover the NetBIOS computer and workgroup names announced by Windows hosts and SMB servers.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 138</span></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span></div>
</div>
<div class="nt-card" data-pl-search="netbios-ns netbios name service netbios name service is a protocol used for legacy windows name registration and resolution. sends a netbios node-status query and returns the registered names, node type, and any associated mac address. udp naming 137 138" data-pl-transports="udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>netbios-ns</code> &mdash; NetBIOS Name Service</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">NetBIOS Name Service is a protocol used for legacy Windows name registration and resolution. Sends a NetBIOS node-status query and returns the registered names, node type, and any associated MAC address.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Ports:</span> 137, 138</span></div>
  <div class="nt-tags"><span class="nt-tag">naming</span></div>
</div>
<div class="nt-card" data-pl-search="netis netis netis is an identifier for netis and netcore soho routers, including the well-known udp/53413 administrative backdoor exposed by historical firmware. runzero attributes the service from the netis-specific hint and tags the asset as a netis router so the historical backdoor exposure is surfaced in inventory and reports. udp iot mgmt" data-pl-transports="udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>netis</code></div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Netis is an identifier for Netis and Netcore SOHO routers, including the well-known UDP/53413 administrative backdoor exposed by historical firmware. runZero attributes the service from the netis-specific hint and tags the asset as a Netis router so the historical backdoor exposure is surfaced in inventory and reports.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">iot</span><span class="nt-tag">mgmt</span></div>
</div>
<div class="nt-card" data-pl-search="netop-remote-control netop remote control netop remote control is a commercial remote-administration product from netop (formerly danware), commonly deployed in classroom, kiosk, and retail environments. runzero attributes the asset from the netop host banner observed on the standard service port and tags the service as remote-access for inventory and exposure reporting. tcp clear light remote-access" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>netop-remote-control</code> &mdash; Netop Remote Control</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Netop Remote Control is a commercial remote-administration product from Netop (formerly Danware), commonly deployed in classroom, kiosk, and retail environments. runZero attributes the asset from the Netop host banner observed on the standard service port and tags the service as remote-access for inventory and exposure reporting.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">clear</span><span class="nt-tag">light</span><span class="nt-tag">remote-access</span></div>
</div>
<div class="nt-card" data-pl-search="nfs nfs nfs is the network file system used to share files across unix-like systems (sun rpc program 100003). issues a nfs null ping and a mount export call (via portmap) and returns the supported nfs versions and the list of exported filesystems and allowed clients. tcp udp file storage 2049" data-pl-transports="tcp udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>nfs</code></div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">NFS is the Network File System used to share files across Unix-like systems (Sun RPC program 100003). Issues a NFS NULL ping and a MOUNT EXPORT call (via portmap) and returns the supported NFS versions and the list of exported filesystems and allowed clients.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 2049</span></div>
  <div class="nt-tags"><span class="nt-tag">file</span><span class="nt-tag">storage</span></div>
</div>
<div class="nt-card" data-pl-search="nrpe nagios nrpe nagios nrpe is the protocol used by nagios/icinga to run checks on remote hosts. sends a _nrpe_check probe and returns the nrpe protocol version and any version banner disclosed. tcp monitoring tls 5666" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>nrpe</code> &mdash; Nagios NRPE</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Nagios NRPE is the protocol used by Nagios/Icinga to run checks on remote hosts. Sends a _NRPE_CHECK probe and returns the NRPE protocol version and any version banner disclosed.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 5666</span></div>
  <div class="nt-tags"><span class="nt-tag">monitoring</span><span class="nt-tag">tls</span></div>
</div>
<div class="nt-card" data-pl-search="ntp ntp ntp is the network time protocol used to synchronize clocks across networks (rfc 5905). sends mode-3 client and mode-6 control queries and returns the stratum, reference identifier, refid clock source, and (when enabled) implementation/version strings disclosed by mode-6 readvar. udp time 123" data-pl-transports="udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>ntp</code></div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">NTP is the Network Time Protocol used to synchronize clocks across networks (RFC 5905). Sends mode-3 client and mode-6 control queries and returns the stratum, reference identifier, refid clock source, and (when enabled) implementation/version strings disclosed by mode-6 readvar.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 123</span></div>
  <div class="nt-tags"><span class="nt-tag">time</span></div>
</div>
<div class="nt-card" data-pl-search="omronfins omron fins omron fins is the factory interface network service protocol used to communicate with omron cj/cs/nj/nx plcs and related automation devices. issues a controller data read (0501) and returns the controller model and firmware version along with the fins handshake banner. udp ot 9600" data-pl-transports="udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>omronfins</code> &mdash; Omron FINS</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Omron FINS is the Factory Interface Network Service protocol used to communicate with Omron CJ/CS/NJ/NX PLCs and related automation devices. Issues a Controller Data Read (0501) and returns the controller model and firmware version along with the FINS handshake banner.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 9600</span></div>
  <div class="nt-tags"><span class="nt-tag">ot</span></div>
</div>
<div class="nt-card" data-pl-search="opcda opc classic (opc da) opc classic (opc da) is the ole for process control data-access standard layered over microsoft dcom, widely deployed in legacy scada, hmi, and historian gateways. runzero detects opc da servers when the dcerpc scanner observes the opcenum interface uuid advertised by the endpoint mapper. tcp deep ot" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>opcda</code> &mdash; OPC Classic (OPC DA)</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">OPC Classic (OPC DA) is the OLE for Process Control data-access standard layered over Microsoft DCOM, widely deployed in legacy SCADA, HMI, and historian gateways. runZero detects OPC DA servers when the DCERPC scanner observes the OPCEnum interface UUID advertised by the endpoint mapper.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">deep</span><span class="nt-tag">ot</span></div>
</div>
<div class="nt-card" data-pl-search="opcua opc ua opc ua is a vendor-neutral industrial information-model and data-access standard. performs a getendpoints request and returns the application uri, product uri, server-certificate metadata, and per-endpoint security policies and identity tokens. tcp backplane deep ot 4840 4843 48050" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>opcua</code> &mdash; OPC UA</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">OPC UA is a vendor-neutral industrial information-model and data-access standard. Performs a GetEndpoints request and returns the application URI, product URI, server-certificate metadata, and per-endpoint security policies and identity tokens.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Ports:</span> 4840, 4843, 48050</span></div>
  <div class="nt-tags"><span class="nt-tag">backplane</span><span class="nt-tag">deep</span><span class="nt-tag">ot</span></div>
</div>
<div class="nt-card" data-pl-search="openvpn openvpn openvpn is the tunnel control-channel protocol used by openvpn community edition and openvpn access server vpn gateways. sends a p_control_hard_reset_client_v2 packet and returns the local and remote openvpn session identifiers from the server&#39;s hard-reset reply. udp encrypted vpn 1194" data-pl-transports="udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>openvpn</code></div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">OpenVPN is the tunnel control-channel protocol used by OpenVPN Community Edition and OpenVPN Access Server VPN gateways. Sends a P_CONTROL_HARD_RESET_CLIENT_V2 packet and returns the local and remote OpenVPN session identifiers from the server&#39;s hard-reset reply.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 1194</span></div>
  <div class="nt-tags"><span class="nt-tag">encrypted</span><span class="nt-tag">vpn</span></div>
</div>
<div class="nt-card" data-pl-search="oracle oracle tns oracle tns is the transparent network substrate listener protocol used by oracle database servers. sends a tns connect carrying a version command and returns the listener version, instance name, and supported services. tcp database 1521 1522 1525 2483 2484" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>oracle</code> &mdash; Oracle TNS</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Oracle TNS is the Transparent Network Substrate listener protocol used by Oracle Database servers. Sends a TNS Connect carrying a VERSION command and returns the listener version, instance name, and supported services.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Ports:</span> 1521, 1522, 1525, 2483, 2484</span></div>
  <div class="nt-tags"><span class="nt-tag">database</span></div>
</div>
<div class="nt-card" data-pl-search="oracledb oracle database (tns) oracle database (tns) is a lightweight oracle net listener probe used to identify oracle database servers without negotiating a session. sends a minimal tns connect, parses the refuse/accept/resend reply, and returns the packet type, vsnnum, error code, and disclosed listener version. tcp database 1521 1522 1525" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>oracledb</code> &mdash; Oracle Database (TNS)</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Oracle Database (TNS) is a lightweight Oracle Net listener probe used to identify Oracle Database servers without negotiating a session. Sends a minimal TNS Connect, parses the Refuse/Accept/Resend reply, and returns the packet type, VSNNUM, error code, and disclosed listener version.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Ports:</span> 1521, 1522, 1525</span></div>
  <div class="nt-tags"><span class="nt-tag">database</span></div>
</div>
<div class="nt-card" data-pl-search="orion solarwinds orion platform solarwinds orion platform is a windows-based network-management suite that bundles npm, ncm, nta, ipam, sam, udt, and related modules. the http extractor matches the orion footer in the web console, parses the platform release and component list, and returns orion.version, orion.components, and solarwinds orion software identification. tcp light tls web" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>orion</code> &mdash; SolarWinds Orion Platform</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">SolarWinds Orion Platform is a Windows-based network-management suite that bundles NPM, NCM, NTA, IPAM, SAM, UDT, and related modules. The HTTP extractor matches the Orion footer in the web console, parses the platform release and component list, and returns orion.version, orion.components, and SolarWinds Orion software identification.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">light</span><span class="nt-tag">tls</span><span class="nt-tag">web</span></div>
</div>
<div class="nt-card" data-pl-search="panasonictv panasonic tv panasonic tv is the network control service exposed by panasonic viera and similar consumer smart tvs for remote-control companion apps. runzero identifies these televisions from the proprietary control-protocol banner returned on connection, applies panasonic tv fingerprinting, and attributes the asset as a panasonic television. tcp iot light" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>panasonictv</code> &mdash; Panasonic TV</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Panasonic TV is the network control service exposed by Panasonic Viera and similar consumer smart TVs for remote-control companion apps. runZero identifies these televisions from the proprietary control-protocol banner returned on connection, applies Panasonic TV fingerprinting, and attributes the asset as a Panasonic television.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">iot</span><span class="nt-tag">light</span></div>
</div>
<div class="nt-card" data-pl-search="panxmlapi palo alto networks pan-os xml api palo alto networks pan-os xml api is the authenticated management api (system info, arp/mac/neighbor caches, interfaces) issued against palo alto networks firewalls and panorama. used by the runzero scanner with a user-supplied api key to enumerate adjacent assets and device facts. tcp auth deep tls" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>panxmlapi</code> &mdash; Palo Alto Networks PAN-OS XML API</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Palo Alto Networks PAN-OS XML API is the authenticated management API (system info, ARP/MAC/neighbor caches, interfaces) issued against Palo Alto Networks firewalls and Panorama. Used by the runZero scanner with a user-supplied API key to enumerate adjacent assets and device facts.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">auth</span><span class="nt-tag">deep</span><span class="nt-tag">tls</span></div>
</div>
<div class="nt-card" data-pl-search="pca symantec pcanywhere symantec pcanywhere is a remote-access protocol. sends the pcanywhere status probe and returns the host name, status, and capability flags disclosed in the response. udp light remote-access 5632" data-pl-transports="udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>pca</code> &mdash; Symantec pcAnywhere</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Symantec pcAnywhere is a remote-access protocol. Sends the pcAnywhere status probe and returns the host name, status, and capability flags disclosed in the response.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 5632</span></div>
  <div class="nt-tags"><span class="nt-tag">light</span><span class="nt-tag">remote-access</span></div>
</div>
<div class="nt-card" data-pl-search="pcworx phoenix contact pcworx phoenix contact pcworx is a runtime protocol used to program and interact with ilc-series and other phoenix contact controllers. queries controller identification and returns the plc type, model number, and firmware version, date, and time. tcp ot 1962" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>pcworx</code> &mdash; Phoenix Contact PCWorx</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Phoenix Contact PCWorx is a runtime protocol used to program and interact with ILC-series and other Phoenix Contact controllers. Queries controller identification and returns the PLC type, model number, and firmware version, date, and time.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 1962</span></div>
  <div class="nt-tags"><span class="nt-tag">ot</span></div>
</div>
<div class="nt-card" data-pl-search="pega pega platform pega platform is a low-code business process management and crm application server from pegasystems used for enterprise workflow automation. the http extractor matches pega in the page title or body, parses the version span, and returns the pega.version attribute and pegasystems pega software identification. tcp light tls web" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>pega</code> &mdash; Pega Platform</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Pega Platform is a low-code business process management and CRM application server from Pegasystems used for enterprise workflow automation. The HTTP extractor matches Pega in the page title or body, parses the version span, and returns the pega.version attribute and Pegasystems Pega software identification.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">light</span><span class="nt-tag">tls</span><span class="nt-tag">web</span></div>
</div>
<div class="nt-card" data-pl-search="pfcp pfcp pfcp is the packet forwarding control protocol used in 5g/lte mobile cores between control-plane and user-plane functions. sends a pfcp heartbeat request and returns the recovery time stamp and supported feature flags. udp mobile-core 8805" data-pl-transports="udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>pfcp</code></div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">PFCP is the Packet Forwarding Control Protocol used in 5G/LTE mobile cores between control-plane and user-plane functions. Sends a PFCP Heartbeat Request and returns the recovery time stamp and supported feature flags.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 8805</span></div>
  <div class="nt-tags"><span class="nt-tag">mobile-core</span></div>
</div>
<div class="nt-card" data-pl-search="pop3 pop3 pop3 is the post office protocol version 3 used by mail clients to retrieve messages from a server. reads the pop3 greeting and runs capa, returning the server software banner, supported capabilities, and starttls availability. tcp email tls 110 995" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>pop3</code></div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">POP3 is the Post Office Protocol version 3 used by mail clients to retrieve messages from a server. Reads the POP3 greeting and runs CAPA, returning the server software banner, supported capabilities, and STARTTLS availability.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Ports:</span> 110, 995</span></div>
  <div class="nt-tags"><span class="nt-tag">email</span><span class="nt-tag">tls</span></div>
</div>
<div class="nt-card" data-pl-search="postgres postgresql postgresql is the frontend/backend wire protocol used by postgresql database servers and compatible engines such as amazon rds/aurora and cockroachdb. performs an sslrequest followed by a startupmessage and returns the server version, supported authentication mechanisms, advertised server parameters, and tls availability. tcp database tls 5432 5433 6432" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>postgres</code> &mdash; PostgreSQL</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">PostgreSQL is the frontend/backend wire protocol used by PostgreSQL database servers and compatible engines such as Amazon RDS/Aurora and CockroachDB. Performs an SSLRequest followed by a StartupMessage and returns the server version, supported authentication mechanisms, advertised server parameters, and TLS availability.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Ports:</span> 5432, 5433, 6432</span></div>
  <div class="nt-tags"><span class="nt-tag">database</span><span class="nt-tag">tls</span></div>
</div>
<div class="nt-card" data-pl-search="postgresql postgresql postgresql is the open-source object-relational database. runzero negotiates the postgresql frontend/backend protocol to obtain the server version, advertised authentication methods, and tls support. the shorter &#34;postgres&#34; identifier is the default protocol name; this entry covers detections that reported the long form. tcp clear mgmt 5432" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>postgresql</code></div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">PostgreSQL is the open-source object-relational database. runZero negotiates the PostgreSQL frontend/backend protocol to obtain the server version, advertised authentication methods, and TLS support. The shorter &#34;postgres&#34; identifier is the default protocol name; this entry covers detections that reported the long form.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 5432</span></div>
  <div class="nt-tags"><span class="nt-tag">clear</span><span class="nt-tag">mgmt</span></div>
</div>
<div class="nt-card" data-pl-search="powerlink ethernet powerlink ethernet powerlink is a real-time industrial ethernet protocol from the epsg, used for deterministic motion control and i/o between managing nodes and controlled nodes on machine tools, packaging lines, and robotics cells. passively decodes powerlink frames and returns the node identifier, vendor identifier, product code, and revision. udp ot passive" data-pl-transports="udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>powerlink</code> &mdash; Ethernet POWERLINK</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Ethernet POWERLINK is a real-time industrial Ethernet protocol from the EPSG, used for deterministic motion control and I/O between managing nodes and controlled nodes on machine tools, packaging lines, and robotics cells. Passively decodes POWERLINK frames and returns the node identifier, vendor identifier, product code, and revision.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">ot</span><span class="nt-tag">passive</span></div>
</div>
<div class="nt-card" data-pl-search="pptp pptp pptp is the microsoft point-to-point tunneling protocol legacy vpn. sends a start-control-connection-request and returns the protocol version, vendor, firmware revision, and host name. tcp vpn 1723" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>pptp</code></div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">PPTP is the Microsoft Point-to-Point Tunneling Protocol legacy VPN. Sends a Start-Control-Connection-Request and returns the protocol version, vendor, firmware revision, and host name.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 1723</span></div>
  <div class="nt-tags"><span class="nt-tag">vpn</span></div>
</div>
<div class="nt-card" data-pl-search="printerid printer identification printer identification is a vendor-specific service exposed on tcp/9200 by hp, lexmark, and other network printers and mfps. runzero parses the model string returned by the device, records it as printerid.model, and uses the value as a synthetic fingerprint to identify the printer make and model during asset categorization. tcp light printing" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>printerid</code> &mdash; Printer Identification</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Printer Identification is a vendor-specific service exposed on TCP/9200 by HP, Lexmark, and other network printers and MFPs. runZero parses the model string returned by the device, records it as printerid.model, and uses the value as a synthetic fingerprint to identify the printer make and model during asset categorization.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">light</span><span class="nt-tag">printing</span></div>
</div>
<div class="nt-card" data-pl-search="proconos phoenix contact proconos phoenix contact proconos is the plc runtime protocol from kw-software/phoenix contact, used by ilc, rfc, and oem-rebadged controllers running the proconos or proconos eclr runtime. issues a runtime identification query and returns the ladder-logic runtime version, plc type, project name, boot project, and project source-code identifier. tcp ot 20547" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>proconos</code> &mdash; Phoenix Contact ProConOS</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Phoenix Contact ProConOS is the PLC runtime protocol from KW-Software/Phoenix Contact, used by ILC, RFC, and OEM-rebadged controllers running the ProConOS or ProConOS eCLR runtime. Issues a runtime identification query and returns the ladder-logic runtime version, PLC type, project name, boot project, and project source-code identifier.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 20547</span></div>
  <div class="nt-tags"><span class="nt-tag">ot</span></div>
</div>
<div class="nt-card" data-pl-search="profinet profinet profinet is an industrial ethernet protocol used for cyclic and acyclic real-time communication with profinet i/o devices and plcs. performs a read identification request and returns the device vendor, order number, serial, software/hardware revision, and (when enabled) discovered slot/subslot module list. udp backplane deep ot 34962 34963 34964" data-pl-transports="udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>profinet</code></div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">PROFINET is an industrial Ethernet protocol used for cyclic and acyclic real-time communication with PROFINET I/O devices and PLCs. Performs a Read Identification request and returns the device vendor, order number, serial, software/hardware revision, and (when enabled) discovered slot/subslot module list.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Ports:</span> 34962, 34963, 34964</span></div>
  <div class="nt-tags"><span class="nt-tag">backplane</span><span class="nt-tag">deep</span><span class="nt-tag">ot</span></div>
</div>
<div class="nt-card" data-pl-search="profinet-dcp profinet dcp profinet dcp is the discovery and basic configuration protocol used at layer 2 to identify and assign names/ips to profinet stations. passively decodes dcp identify announcements and returns the station name, vendor and device identifiers, and device role. udp discovery ot passive" data-pl-transports="udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>profinet-dcp</code> &mdash; PROFINET DCP</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">PROFINET DCP is the Discovery and basic Configuration Protocol used at Layer 2 to identify and assign names/IPs to PROFINET stations. Passively decodes DCP Identify announcements and returns the station name, vendor and device identifiers, and device role.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">ot</span><span class="nt-tag">passive</span></div>
</div>
<div class="nt-card" data-pl-search="prosoft prosoft discovery service prosoft discovery service is the udp discovery protocol used by prosoft technology industrial gateways and radios. runzero parses the response to recover the device model, firmware revision, mac address, and ip configuration. tcp discovery ot 1718" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>prosoft</code> &mdash; ProSoft Discovery Service</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">ProSoft Discovery Service is the UDP discovery protocol used by ProSoft Technology industrial gateways and radios. runZero parses the response to recover the device model, firmware revision, MAC address, and IP configuration.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 1718</span></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">ot</span></div>
</div>
<div class="nt-card" data-pl-search="psdisco playstation discovery playstation discovery is the sony playstation 4/5 console-discovery service (http/1.1-style srch messages on udp/987 and udp/9302) used by remote play and second-screen companion apps. sends a srch probe and decodes the response, returning the host id, host name, host type, system version, discovery-protocol version, and running-app title metadata. udp discovery gaming iot light 987 9302" data-pl-transports="udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>psdisco</code> &mdash; PlayStation Discovery</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">PlayStation Discovery is the Sony PlayStation 4/5 console-discovery service (HTTP/1.1-style SRCH messages on UDP/987 and UDP/9302) used by Remote Play and second-screen companion apps. Sends a SRCH probe and decodes the response, returning the host id, host name, host type, system version, discovery-protocol version, and running-app title metadata.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Ports:</span> 987, 9302</span></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">gaming</span><span class="nt-tag">iot</span><span class="nt-tag">light</span></div>
</div>
<div class="nt-card" data-pl-search="pulsar apache pulsar apache pulsar is the binary client/broker protocol used by pulsar messaging brokers and pulsar functions deployments for pub/sub messaging and event streaming. sends a connect command and returns the broker server version, protocol version, and authentication-method requirements. tcp messaging 6650 6651" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>pulsar</code> &mdash; Apache Pulsar</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Apache Pulsar is the binary client/broker protocol used by Pulsar messaging brokers and Pulsar Functions deployments for pub/sub messaging and event streaming. Sends a CONNECT command and returns the broker server version, protocol version, and authentication-method requirements.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Ports:</span> 6650, 6651</span></div>
  <div class="nt-tags"><span class="nt-tag">messaging</span></div>
</div>
<div class="nt-card" data-pl-search="qdrant qdrant vector database qdrant is an open-source vector search database used by retrieval-augmented llm applications. runzero attributes services as qdrant from recog matches against the http api root and the /metrics endpoint, which expose the server version. tcp ai clear mgmt 6333 6334" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>qdrant</code> &mdash; Qdrant Vector Database</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Qdrant is an open-source vector search database used by retrieval-augmented LLM applications. runZero attributes services as Qdrant from Recog matches against the HTTP API root and the /metrics endpoint, which expose the server version.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Ports:</span> 6333, 6334</span></div>
  <div class="nt-tags"><span class="nt-tag">ai</span><span class="nt-tag">clear</span><span class="nt-tag">mgmt</span></div>
</div>
<div class="nt-card" data-pl-search="qotd quote of the day quote of the day is the rfc 865 diagnostic service historically exposed by unix inetd hosts and frequently abused for udp amplification. passively decodes qotd replies in tcp and udp captures and returns the protocol tag along with the truncated quote text or banner observed in the response. tcp udp legacy light 17" data-pl-transports="tcp udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>qotd</code> &mdash; Quote of the Day</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Quote of the Day is the RFC 865 diagnostic service historically exposed by Unix inetd hosts and frequently abused for UDP amplification. Passively decodes QOTD replies in TCP and UDP captures and returns the protocol tag along with the truncated quote text or banner observed in the response.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 17</span></div>
  <div class="nt-tags"><span class="nt-tag">legacy</span><span class="nt-tag">light</span></div>
</div>
<div class="nt-card" data-pl-search="qualys qualys cloud agent / scanner appliance qualys cloud agent / scanner appliance is the web management interface exposed by qualys vulnerability-management components, including the on-premises scanner appliance and cloud agent ui. the http fingerprinter inspects these pages and returns the product name, appliance role, and any version identifiers disclosed. tcp light security tls web" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>qualys</code> &mdash; Qualys Cloud Agent / Scanner Appliance</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Qualys Cloud Agent / Scanner Appliance is the web management interface exposed by Qualys vulnerability-management components, including the on-premises Scanner Appliance and Cloud Agent UI. The HTTP fingerprinter inspects these pages and returns the product name, appliance role, and any version identifiers disclosed.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">light</span><span class="nt-tag">security</span><span class="nt-tag">tls</span><span class="nt-tag">web</span></div>
</div>
<div class="nt-card" data-pl-search="quic quic quic is the ietf transport (rfc 9000), an encrypted udp-based transport that carries http/3 and is increasingly used by cdns, web servers, and saas endpoints. runzero attributes the service as quic when the long-header initial packet is observed on a probed udp port and tags the asset for web / tls exposure tracking. udp encrypted tls web" data-pl-transports="udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>quic</code></div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">QUIC is the IETF transport (RFC 9000), an encrypted UDP-based transport that carries HTTP/3 and is increasingly used by CDNs, web servers, and SaaS endpoints. runZero attributes the service as QUIC when the long-header Initial packet is observed on a probed UDP port and tags the asset for web / TLS exposure tracking.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">encrypted</span><span class="nt-tag">tls</span><span class="nt-tag">web</span></div>
</div>
<div class="nt-card" data-pl-search="radius radius radius is an aaa protocol used in wi-fi, vpn, and network-access control. sends an access-request with an invalid principal and returns the response code, any reply-message and nas-identifier, and the list of attributes present in the reply. udp aaa 1645 1646 1812 1813" data-pl-transports="udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>radius</code></div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">RADIUS is an AAA protocol used in Wi-Fi, VPN, and network-access control. Sends an Access-Request with an invalid principal and returns the response code, any Reply-Message and NAS-Identifier, and the list of attributes present in the reply.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Ports:</span> 1645, 1646, 1812, 1813</span></div>
  <div class="nt-tags"><span class="nt-tag">aaa</span></div>
</div>
<div class="nt-card" data-pl-search="raritan-csc raritan commandcenter raritan commandcenter is the common socket connection (csc) management protocol used by raritan commandcenter secure gateway appliances and adjacent raritan kvm/serial console managers. passively detects the &lt;csc/&gt; banner emitted on connection and tags the asset as a raritan commandcenter device. tcp light mgmt" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>raritan-csc</code> &mdash; Raritan CommandCenter</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Raritan CommandCenter is the Common Socket Connection (CSC) management protocol used by Raritan CommandCenter Secure Gateway appliances and adjacent Raritan KVM/serial console managers. Passively detects the &lt;CSC/&gt; banner emitted on connection and tags the asset as a Raritan CommandCenter device.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">light</span><span class="nt-tag">mgmt</span></div>
</div>
<div class="nt-card" data-pl-search="rdp rdp rdp is the microsoft remote desktop protocol used by windows remote desktop services. performs an x.224 connection-request and returns the supported security protocols, nla requirement, and (when tls is offered) certificate-derived hostname/version metadata. tcp remote-access tls 3389 3390" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>rdp</code></div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">RDP is the Microsoft Remote Desktop Protocol used by Windows Remote Desktop Services. Performs an X.224 Connection-Request and returns the supported security protocols, NLA requirement, and (when TLS is offered) certificate-derived hostname/version metadata.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Ports:</span> 3389, 3390</span></div>
  <div class="nt-tags"><span class="nt-tag">remote-access</span><span class="nt-tag">tls</span></div>
</div>
<div class="nt-card" data-pl-search="redis redis redis is an in-memory data-structure store and message broker. issues ping/info/auth probes and returns the redis version, role, mode, and authentication or protected-mode requirements. tcp database tls 6379 16379 26379" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>redis</code></div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Redis is an in-memory data-structure store and message broker. Issues PING/INFO/AUTH probes and returns the Redis version, role, mode, and authentication or protected-mode requirements.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Ports:</span> 6379, 16379, 26379</span></div>
  <div class="nt-tags"><span class="nt-tag">database</span><span class="nt-tag">tls</span></div>
</div>
<div class="nt-card" data-pl-search="rexec rexec rexec is the bsd remote execution protocol (legacy, transmits credentials in cleartext). detects an rexec listener and returns the responsiveness and any host-identification banner observed. tcp clear legacy light remote-access 512" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>rexec</code></div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">rexec is the BSD Remote Execution protocol (legacy, transmits credentials in cleartext). Detects an rexec listener and returns the responsiveness and any host-identification banner observed.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 512</span></div>
  <div class="nt-tags"><span class="nt-tag">clear</span><span class="nt-tag">legacy</span><span class="nt-tag">light</span><span class="nt-tag">remote-access</span></div>
</div>
<div class="nt-card" data-pl-search="riak riak protocol buffers riak is a distributed nosql key/value store from basho. this entry covers the protocol buffers transport on tcp/8087 used by the native riak clients; the http api is reported separately as riak-http. tcp clear mgmt 8098" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>riak</code> &mdash; Riak Protocol Buffers</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Riak is a distributed NoSQL key/value store from Basho. This entry covers the Protocol Buffers transport on TCP/8087 used by the native Riak clients; the HTTP API is reported separately as riak-http.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 8098</span></div>
  <div class="nt-tags"><span class="nt-tag">clear</span><span class="nt-tag">mgmt</span></div>
</div>
<div class="nt-card" data-pl-search="riak-http riak http api riak http api is the rest interface exposed by basho riak nodes (typically tcp/8098). runzero queries /stats and /riak/ to recover the node name, ring size, and riak version. tcp clear mgmt 8098" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>riak-http</code> &mdash; Riak HTTP API</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Riak HTTP API is the REST interface exposed by Basho Riak nodes (typically TCP/8098). runZero queries /stats and /riak/ to recover the node name, ring size, and Riak version.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 8098</span></div>
  <div class="nt-tags"><span class="nt-tag">clear</span><span class="nt-tag">mgmt</span></div>
</div>
<div class="nt-card" data-pl-search="rip rip rip is a distance-vector igp. sends a rip request and returns the rip version and any advertised routes disclosed by the responder. udp routing 520" data-pl-transports="udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>rip</code></div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">RIP is a distance-vector IGP. Sends a RIP Request and returns the RIP version and any advertised routes disclosed by the responder.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 520</span></div>
  <div class="nt-tags"><span class="nt-tag">routing</span></div>
</div>
<div class="nt-card" data-pl-search="rlogin rlogin rlogin is the legacy bsd remote-login protocol (rfc 1282) superseded by ssh. runzero records the banner and any login prompt returned by the server, and flags the service as a clear-text credential exposure. tcp clear mgmt 513" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>rlogin</code></div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">rlogin is the legacy BSD remote-login protocol (RFC 1282) superseded by SSH. runZero records the banner and any login prompt returned by the server, and flags the service as a clear-text credential exposure.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 513</span></div>
  <div class="nt-tags"><span class="nt-tag">clear</span><span class="nt-tag">mgmt</span></div>
</div>
<div class="nt-card" data-pl-search="roomalert avtech room alert avtech room alert is an environmental monitoring appliance. reads the device banner and returns the model, os version, mac address, and ip address. tcp iot light monitoring 9999" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>roomalert</code> &mdash; AVTECH Room Alert</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">AVTECH Room Alert is an environmental monitoring appliance. Reads the device banner and returns the model, OS version, MAC address, and IP address.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 9999</span></div>
  <div class="nt-tags"><span class="nt-tag">iot</span><span class="nt-tag">light</span><span class="nt-tag">monitoring</span></div>
</div>
<div class="nt-card" data-pl-search="rpcbind onc rpc / rpcbind onc rpc / rpcbind is the portmap service used to discover sun rpc programs (nfs, nis, ...). queries the portmap dump and returns the registered program list with versions, protocols, and ports. tcp udp discovery mgmt 111" data-pl-transports="tcp udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>rpcbind</code> &mdash; ONC RPC / rpcbind</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">ONC RPC / rpcbind is the portmap service used to discover Sun RPC programs (NFS, NIS, ...). Queries the portmap dump and returns the registered program list with versions, protocols, and ports.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 111</span></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">mgmt</span></div>
</div>
<div class="nt-card" data-pl-search="rsync rsync (ssh-tunneled) rsync is the rsync daemon wire protocol exposed on tcp/873 by file mirrors, backup servers, and software-distribution archives. reads the server greeting, performs the version handshake, and returns the protocol version, raw banner, and module list when the server permits enumeration. tcp file 873" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>rsync</code> &mdash; rsync (SSH-tunneled)</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">rsync is the rsync daemon wire protocol exposed on TCP/873 by file mirrors, backup servers, and software-distribution archives. Reads the server greeting, performs the version handshake, and returns the protocol version, raw banner, and module list when the server permits enumeration.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 873</span></div>
  <div class="nt-tags"><span class="nt-tag">file</span></div>
</div>
<div class="nt-card" data-pl-search="rsyncd rsync daemon rsync daemon is the standalone rsync service (rsync://) listening on tcp/873. reads the daemon greeting and lists modules, returning the rsync version, available module names, and module comments. tcp clear file light 873" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>rsyncd</code> &mdash; rsync daemon</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">rsync daemon is the standalone rsync service (rsync://) listening on TCP/873. Reads the daemon greeting and lists modules, returning the rsync version, available module names, and module comments.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 873</span></div>
  <div class="nt-tags"><span class="nt-tag">clear</span><span class="nt-tag">file</span><span class="nt-tag">light</span></div>
</div>
<div class="nt-card" data-pl-search="rtmp rtmp rtmp is the adobe real-time messaging protocol used to stream audio, video, and data between flash players and media servers. performs the rtmp handshake and returns the protocol version byte echoed by the server. tcp media 1935" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>rtmp</code></div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">RTMP is the Adobe Real-Time Messaging Protocol used to stream audio, video, and data between Flash players and media servers. Performs the RTMP handshake and returns the protocol version byte echoed by the server.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 1935</span></div>
  <div class="nt-tags"><span class="nt-tag">media</span></div>
</div>
<div class="nt-card" data-pl-search="rtps omg rtps / dds omg rtps / dds is the real-time publish-subscribe wire protocol from the object management group; underlies dds in robotics, ros 2, and industrial iot. sends an spdp participant announcement and returns the participant guid, vendor identifier and name, and protocol version. udp discovery messaging ot 7400 7401 7410 7411" data-pl-transports="udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>rtps</code> &mdash; OMG RTPS / DDS</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">OMG RTPS / DDS is the Real-Time Publish-Subscribe wire protocol from the Object Management Group; underlies DDS in robotics, ROS 2, and industrial IoT. Sends an SPDP participant announcement and returns the participant GUID, vendor identifier and name, and protocol version.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Ports:</span> 7400, 7401, 7410, 7411</span></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">messaging</span><span class="nt-tag">ot</span></div>
</div>
<div class="nt-card" data-pl-search="rtsp rtsp rtsp is a streaming-control protocol used by ip cameras, nvrs, and media servers to control streams. issues an options request and returns the server software, supported methods, and any session-description metadata disclosed by describe. tcp iot media tls 554 8554" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>rtsp</code></div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">RTSP is a streaming-control protocol used by IP cameras, NVRs, and media servers to control streams. Issues an OPTIONS request and returns the server software, supported methods, and any session-description metadata disclosed by DESCRIBE.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Ports:</span> 554, 8554</span></div>
  <div class="nt-tags"><span class="nt-tag">iot</span><span class="nt-tag">media</span><span class="nt-tag">tls</span></div>
</div>
<div class="nt-card" data-pl-search="s7comm siemens s7comm siemens s7comm is the protocol used to program and exchange data with simatic s7-300, s7-400, s7-1200, and s7-1500 plcs. issues szl identification reads and returns the module name, plant identification, copyright, serial, module type, hardware/firmware version, and (when enabled) backplane rack/slot module list. tcp backplane deep ot 102" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>s7comm</code> &mdash; Siemens S7Comm</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Siemens S7Comm is the protocol used to program and exchange data with SIMATIC S7-300, S7-400, S7-1200, and S7-1500 PLCs. Issues SZL identification reads and returns the module name, plant identification, copyright, serial, module type, hardware/firmware version, and (when enabled) backplane rack/slot module list.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 102</span></div>
  <div class="nt-tags"><span class="nt-tag">backplane</span><span class="nt-tag">deep</span><span class="nt-tag">ot</span></div>
</div>
<div class="nt-card" data-pl-search="sadp hikvision sadp hikvision sadp is the search active devices protocol used to discover hikvision and oem ip cameras and nvrs. sends a sadp inquiry and returns the device serial, model, firmware, mac, ip configuration, and activation state. udp discovery iot light multicast 37020" data-pl-transports="udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>sadp</code> &mdash; Hikvision SADP</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Hikvision SADP is the Search Active Devices Protocol used to discover Hikvision and OEM IP cameras and NVRs. Sends a SADP Inquiry and returns the device serial, model, firmware, MAC, IP configuration, and activation state.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 37020</span></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">iot</span><span class="nt-tag">light</span><span class="nt-tag">multicast</span></div>
</div>
<div class="nt-card" data-pl-search="sccp cisco sccp / skinny cisco sccp / skinny is a call-control protocol used by cisco ip phones registering with callmanager/unified communications manager. sends a register message and returns the call-manager response and station identification. tcp voip 2000 2443" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>sccp</code> &mdash; Cisco SCCP / Skinny</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Cisco SCCP / Skinny is a call-control protocol used by Cisco IP phones registering with CallManager/Unified Communications Manager. Sends a Register message and returns the call-manager response and station identification.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Ports:</span> 2000, 2443</span></div>
  <div class="nt-tags"><span class="nt-tag">voip</span></div>
</div>
<div class="nt-card" data-pl-search="sctptun sctp tunnel sctp tunnel is runzero&#39;s identifier for sctp-over-udp encapsulation (rfc 6951) used to traverse middleboxes that block native sctp. it is reported when an sctp init is observed inside a udp/9899 datagram. udp clear mgmt 9899" data-pl-transports="udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>sctptun</code> &mdash; SCTP Tunnel</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">SCTP Tunnel is runZero&#39;s identifier for SCTP-over-UDP encapsulation (RFC 6951) used to traverse middleboxes that block native SCTP. It is reported when an SCTP INIT is observed inside a UDP/9899 datagram.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 9899</span></div>
  <div class="nt-tags"><span class="nt-tag">clear</span><span class="nt-tag">mgmt</span></div>
</div>
<div class="nt-card" data-pl-search="securemote check point securemote check point securemote is a check point vpn topology discovery service. sends the topology query and returns the gateway hostname and server identifier disclosed in the response. tcp security vpn 264" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>securemote</code> &mdash; Check Point SecuRemote</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Check Point SecuRemote is a Check Point VPN topology discovery service. Sends the topology query and returns the gateway hostname and server identifier disclosed in the response.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 264</span></div>
  <div class="nt-tags"><span class="nt-tag">security</span><span class="nt-tag">vpn</span></div>
</div>
<div class="nt-card" data-pl-search="sentinel redis sentinel redis sentinel is the high-availability supervisor for redis. runzero issues sentinel ping and sentinel master to recover the sentinel version, monitored master name, and quorum configuration on unauthenticated instances. tcp clear mgmt 26379" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>sentinel</code> &mdash; Redis Sentinel</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Redis Sentinel is the high-availability supervisor for Redis. runZero issues SENTINEL ping and SENTINEL master to recover the sentinel version, monitored master name, and quorum configuration on unauthenticated instances.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 26379</span></div>
  <div class="nt-tags"><span class="nt-tag">clear</span><span class="nt-tag">mgmt</span></div>
</div>
<div class="nt-card" data-pl-search="sercos-iii sercos iii sercos iii is a real-time industrial ethernet protocol used for drives, servos, and i/o in machine tools and packaging machinery. passively decodes sercos iii frames and returns the slave count, cycle time, and vendor and device codes. udp ot passive" data-pl-transports="udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>sercos-iii</code> &mdash; SERCOS III</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">SERCOS III is a real-time industrial Ethernet protocol used for drives, servos, and I/O in machine tools and packaging machinery. Passively decodes SERCOS III frames and returns the slave count, cycle time, and vendor and device codes.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">ot</span><span class="nt-tag">passive</span></div>
</div>
<div class="nt-card" data-pl-search="servicetag sun service tag sun service tag is a discovery service used to inventory sun/oracle hardware and software. sends the discovery probe and returns the registered product instance, instance urn, and version. tcp udp discovery mgmt 6481" data-pl-transports="tcp udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>servicetag</code> &mdash; Sun Service Tag</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Sun Service Tag is a discovery service used to inventory Sun/Oracle hardware and software. Sends the discovery probe and returns the registered product instance, instance URN, and version.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 6481</span></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">mgmt</span></div>
</div>
<div class="nt-card" data-pl-search="sgsap sgsap (sctp) sgsap (sctp) is the sgs interface (3gpp ts 29.118) over sctp between mme and msc for sms over sgs and csfb. verifies the sctp association and sgsap payload protocol identifier and returns endpoint identification. sctp mobile-core 29118" data-pl-transports="sctp">
  <div class="nt-card-header">
    <div class="nt-title"><code>sgsap</code> &mdash; SGsAP (SCTP)</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="sctp">SCTP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">SGsAP (SCTP) is the SGs interface (3GPP TS 29.118) over SCTP between MME and MSC for SMS over SGs and CSFB. Verifies the SCTP association and SGsAP payload protocol identifier and returns endpoint identification.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 29118</span></div>
  <div class="nt-tags"><span class="nt-tag">mobile-core</span></div>
</div>
<div class="nt-card" data-pl-search="sip sip sip is a signaling protocol used to establish voice, video, and messaging sessions. sends an options request and returns the response code, server/user-agent strings, allowed methods, and any contact and via metadata disclosed. tcp udp tls voip 5060 5061" data-pl-transports="tcp udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>sip</code></div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">SIP is a signaling protocol used to establish voice, video, and messaging sessions. Sends an OPTIONS request and returns the response code, server/user-agent strings, allowed methods, and any contact and via metadata disclosed.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Ports:</span> 5060, 5061</span></div>
  <div class="nt-tags"><span class="nt-tag">tls</span><span class="nt-tag">voip</span></div>
</div>
<div class="nt-card" data-pl-search="slp slp slp is the service location protocol used to discover services on a lan (rfc 2608); commonly exposed by vmware esxi and printers. sends an attribute and service-type request and returns the slp version, advertised services, and per-service attribute summary. tcp udp discovery 427" data-pl-transports="tcp udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>slp</code></div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">SLP is the Service Location Protocol used to discover services on a LAN (RFC 2608); commonly exposed by VMware ESXi and printers. Sends an attribute and service-type request and returns the SLP version, advertised services, and per-service attribute summary.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 427</span></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span></div>
</div>
<div class="nt-card" data-pl-search="smb smb / cifs smb / cifs is the file-sharing and ipc protocol used by windows and samba. negotiates smb1/2/3 and reads tree/share metadata, returning the dialect, signing/encryption requirements, server os, netbios/computer name, domain, and (when permitted) the list of shares. tcp file storage 139 445" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>smb</code> &mdash; SMB / CIFS</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">SMB / CIFS is the file-sharing and IPC protocol used by Windows and Samba. Negotiates SMB1/2/3 and reads tree/share metadata, returning the dialect, signing/encryption requirements, server OS, NetBIOS/computer name, domain, and (when permitted) the list of shares.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Ports:</span> 139, 445</span></div>
  <div class="nt-tags"><span class="nt-tag">file</span><span class="nt-tag">storage</span></div>
</div>
<div class="nt-card" data-pl-search="smb1 smbv1 smbv1 is the legacy server message block dialect (cifs / nt lm 0.12) deprecated by microsoft and disabled by default since windows 10 1709 / server 2019. runzero flags this dialect specifically because it is required by the eternalblue and related exploits and should be disabled wherever possible. tcp clear mgmt 139 445" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>smb1</code> &mdash; SMBv1</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">SMBv1 is the legacy Server Message Block dialect (CIFS / NT LM 0.12) deprecated by Microsoft and disabled by default since Windows 10 1709 / Server 2019. runZero flags this dialect specifically because it is required by the EternalBlue and related exploits and should be disabled wherever possible.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Ports:</span> 139, 445</span></div>
  <div class="nt-tags"><span class="nt-tag">clear</span><span class="nt-tag">mgmt</span></div>
</div>
<div class="nt-card" data-pl-search="smb2 smbv2 smbv2 is the server message block dialect family introduced in windows vista / server 2008 (dialects 2.0.2 and 2.1). runzero records the negotiated dialect, signing requirements, server guid, and operating-system version reported during negotiate_protocol and session_setup. tcp clear mgmt 445" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>smb2</code> &mdash; SMBv2</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">SMBv2 is the Server Message Block dialect family introduced in Windows Vista / Server 2008 (dialects 2.0.2 and 2.1). runZero records the negotiated dialect, signing requirements, server GUID, and operating-system version reported during NEGOTIATE_PROTOCOL and SESSION_SETUP.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 445</span></div>
  <div class="nt-tags"><span class="nt-tag">clear</span><span class="nt-tag">mgmt</span></div>
</div>
<div class="nt-card" data-pl-search="smb3 smbv3 smbv3 is the server message block protocol family introduced in windows 8 / server 2012 (dialects 3.0, 3.0.2, 3.1.1). runzero records the negotiated dialect, signing and encryption capabilities, and any pre-auth integrity hash advertised by the server. tcp clear mgmt 445" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>smb3</code> &mdash; SMBv3</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">SMBv3 is the Server Message Block protocol family introduced in Windows 8 / Server 2012 (dialects 3.0, 3.0.2, 3.1.1). runZero records the negotiated dialect, signing and encryption capabilities, and any pre-auth integrity hash advertised by the server.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 445</span></div>
  <div class="nt-tags"><span class="nt-tag">clear</span><span class="nt-tag">mgmt</span></div>
</div>
<div class="nt-card" data-pl-search="smpp smpp smpp is the short message peer-to-peer protocol used between sms clients and smscs. sends a bind_transceiver probe and returns the smsc system identifier and smpp version. tcp messaging mobile-core tls 2775" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>smpp</code></div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">SMPP is the Short Message Peer-to-Peer protocol used between SMS clients and SMSCs. Sends a bind_transceiver probe and returns the SMSC system identifier and SMPP version.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 2775</span></div>
  <div class="nt-tags"><span class="nt-tag">messaging</span><span class="nt-tag">mobile-core</span><span class="nt-tag">tls</span></div>
</div>
<div class="nt-card" data-pl-search="smtp smtp smtp is the simple mail transfer protocol used to transfer email between servers and from clients to relays. reads the smtp greeting and runs ehlo, returning the server software, supported extensions, starttls availability, and supported authentication mechanisms. tcp email tls 25 465 587 2525" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>smtp</code></div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">SMTP is the Simple Mail Transfer Protocol used to transfer email between servers and from clients to relays. Reads the SMTP greeting and runs EHLO, returning the server software, supported extensions, STARTTLS availability, and supported authentication mechanisms.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Ports:</span> 25, 465, 587, 2525</span></div>
  <div class="nt-tags"><span class="nt-tag">email</span><span class="nt-tag">tls</span></div>
</div>
<div class="nt-card" data-pl-search="snmp snmp snmp is the simple network management protocol used to monitor and configure network devices and servers. walks system.* and selected enterprise oids over snmpv1/v2c (and snmpv3 when configured) and returns sysdescr, sysobjectid, sysname, location, contact, and a vendor/device-type fingerprint derived from the response. udp auth mgmt 161 162 10161 10162" data-pl-transports="udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>snmp</code></div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">SNMP is the Simple Network Management Protocol used to monitor and configure network devices and servers. Walks system.* and selected enterprise OIDs over SNMPv1/v2c (and SNMPv3 when configured) and returns sysDescr, sysObjectID, sysName, location, contact, and a vendor/device-type fingerprint derived from the response.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Ports:</span> 161, 162, 10161, 10162</span></div>
  <div class="nt-tags"><span class="nt-tag">auth</span><span class="nt-tag">mgmt</span></div>
</div>
<div class="nt-card" data-pl-search="snpp snpp snpp is the simple network paging protocol (rfc 1861) used to deliver pages to paging gateways. reads the snpp greeting and returns the gateway banner. tcp clear legacy light messaging 444" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>snpp</code></div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">SNPP is the Simple Network Paging Protocol (RFC 1861) used to deliver pages to paging gateways. Reads the SNPP greeting and returns the gateway banner.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 444</span></div>
  <div class="nt-tags"><span class="nt-tag">clear</span><span class="nt-tag">legacy</span><span class="nt-tag">light</span><span class="nt-tag">messaging</span></div>
</div>
<div class="nt-card" data-pl-search="socks socks proxy socks is a generic proxy protocol with two incompatible versions (socks4 and socks5). this entry captures sightings where only the socks family was identified; the version-specific decoders socks4 and socks5 record the negotiated authentication methods and supported commands. tcp clear mgmt 1080" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>socks</code> &mdash; SOCKS Proxy</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">SOCKS is a generic proxy protocol with two incompatible versions (SOCKS4 and SOCKS5). This entry captures sightings where only the SOCKS family was identified; the version-specific decoders socks4 and socks5 record the negotiated authentication methods and supported commands.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 1080</span></div>
  <div class="nt-tags"><span class="nt-tag">clear</span><span class="nt-tag">mgmt</span></div>
</div>
<div class="nt-card" data-pl-search="socks4 socks4 socks4 is a proxy protocol (socks version 4) used by client applications and proxy servers (squid, dante, ssh dynamic forwarding) to relay tcp connections through an intermediary. sends a connect request to a benign target and returns the proxy responsiveness and the socks reply status code observed. tcp clear light proxy 1080 1081" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>socks4</code></div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">SOCKS4 is a proxy protocol (SOCKS version 4) used by client applications and proxy servers (Squid, Dante, SSH dynamic forwarding) to relay TCP connections through an intermediary. Sends a CONNECT request to a benign target and returns the proxy responsiveness and the SOCKS reply status code observed.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Ports:</span> 1080, 1081</span></div>
  <div class="nt-tags"><span class="nt-tag">clear</span><span class="nt-tag">light</span><span class="nt-tag">proxy</span></div>
</div>
<div class="nt-card" data-pl-search="socks5 socks5 socks5 is a proxy protocol (socks version 5, rfc 1928) used by client applications, tor (9050/9150), and proxy servers such as dante, 3proxy, and squid to relay tcp and udp through an intermediary. sends a method-selection request and returns the socks version, supported authentication methods, and proxy reachability. tcp light proxy 1080 1081 9050 9150" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>socks5</code></div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">SOCKS5 is a proxy protocol (SOCKS version 5, RFC 1928) used by client applications, Tor (9050/9150), and proxy servers such as Dante, 3proxy, and Squid to relay TCP and UDP through an intermediary. Sends a method-selection request and returns the SOCKS version, supported authentication methods, and proxy reachability.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Ports:</span> 1080, 1081, 9050, 9150</span></div>
  <div class="nt-tags"><span class="nt-tag">light</span><span class="nt-tag">proxy</span></div>
</div>
<div class="nt-card" data-pl-search="solr apache solr apache solr is the lucene-based enterprise search platform. runzero attributes services as solr from the x-solr-version response header, the admin-ui banners, and the /solr/admin/info/system json, which exposes the solr and lucene versions, jvm details, and host operating system. tcp clear mgmt 8983" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>solr</code> &mdash; Apache Solr</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Apache Solr is the Lucene-based enterprise search platform. runZero attributes services as Solr from the X-Solr-Version response header, the admin-UI banners, and the /solr/admin/info/system JSON, which exposes the Solr and Lucene versions, JVM details, and host operating system.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 8983</span></div>
  <div class="nt-tags"><span class="nt-tag">clear</span><span class="nt-tag">mgmt</span></div>
</div>
<div class="nt-card" data-pl-search="some-ip autosar some/ip autosar some/ip is the scalable service-oriented middleware over ip used between automotive ecus on in-vehicle ethernet for service discovery and rpc. sends a some/ip-sd findservice and returns the advertised service ids and service count. udp automotive ot 30490 30491" data-pl-transports="udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>some-ip</code> &mdash; AUTOSAR SOME/IP</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">AUTOSAR SOME/IP is the Scalable service-Oriented MiddlewarE over IP used between automotive ECUs on in-vehicle Ethernet for service discovery and RPC. Sends a SOME/IP-SD FindService and returns the advertised service IDs and service count.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Ports:</span> 30490, 30491</span></div>
  <div class="nt-tags"><span class="nt-tag">automotive</span><span class="nt-tag">ot</span></div>
</div>
<div class="nt-card" data-pl-search="sonarqube sonarqube sonarqube is the static analysis and code-quality platform from sonarsource. runzero attributes services as sonarqube from the application&#39;s http banners and the /api/system/status endpoint, recovering the server version and edition. tcp clear mgmt 9000" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>sonarqube</code></div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">SonarQube is the static analysis and code-quality platform from SonarSource. runZero attributes services as SonarQube from the application&#39;s HTTP banners and the /api/system/status endpoint, recovering the server version and edition.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 9000</span></div>
  <div class="nt-tags"><span class="nt-tag">clear</span><span class="nt-tag">mgmt</span></div>
</div>
<div class="nt-card" data-pl-search="sonicwall-sgms sonicwall gms agent sonicwall gms agent is the global management system agent used to manage sonicwall firewalls. identifies the agent from its tcp banner. tcp light mgmt security 3023" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>sonicwall-sgms</code> &mdash; SonicWall GMS Agent</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">SonicWall GMS Agent is the Global Management System agent used to manage SonicWall firewalls. Identifies the agent from its TCP banner.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 3023</span></div>
  <div class="nt-tags"><span class="nt-tag">light</span><span class="nt-tag">mgmt</span><span class="nt-tag">security</span></div>
</div>
<div class="nt-card" data-pl-search="spice spice spice is the simple protocol for independent computing environments, used to access kvm virtual machines and virtual desktops. identifies spice servers from the link-handshake banner. tcp light remote-access 5930" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>spice</code></div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">SPICE is the Simple Protocol for Independent Computing Environments, used to access KVM virtual machines and virtual desktops. Identifies SPICE servers from the link-handshake banner.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 5930</span></div>
  <div class="nt-tags"><span class="nt-tag">light</span><span class="nt-tag">remote-access</span></div>
</div>
<div class="nt-card" data-pl-search="splunk splunk enterprise / universal forwarder web ui splunk enterprise / universal forwarder web ui is the http-served management interface for splunk&#39;s siem and log-collection platform. the http extractor inspects splunkd and splunk web responses and returns the product edition and version. tcp light siem tls web" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>splunk</code> &mdash; Splunk Enterprise / Universal Forwarder Web UI</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Splunk Enterprise / Universal Forwarder Web UI is the HTTP-served management interface for Splunk&#39;s SIEM and log-collection platform. The HTTP extractor inspects splunkd and Splunk Web responses and returns the product edition and version.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">light</span><span class="nt-tag">siem</span><span class="nt-tag">tls</span><span class="nt-tag">web</span></div>
</div>
<div class="nt-card" data-pl-search="spotify-connect spotify connect spotify connect is the device-discovery and remote-control protocol used by spotify clients to find playback endpoints (smart speakers, av receivers, set-top boxes). detected via the _spotify-connect._tcp mdns record and the /zc http endpoint exposed by the device. tcp discovery iot" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>spotify-connect</code> &mdash; Spotify Connect</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Spotify Connect is the device-discovery and remote-control protocol used by Spotify clients to find playback endpoints (smart speakers, AV receivers, set-top boxes). Detected via the _spotify-connect._tcp mDNS record and the /zc HTTP endpoint exposed by the device.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">iot</span></div>
</div>
<div class="nt-card" data-pl-search="ssdp ssdp ssdp is the simple service discovery protocol used by upnp devices to advertise services. sends an m-search and returns the advertised service types, usn, server string, and location urls of the responding devices. udp discovery iot light multicast 1900" data-pl-transports="udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>ssdp</code></div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">SSDP is the Simple Service Discovery Protocol used by UPnP devices to advertise services. Sends an M-SEARCH and returns the advertised service types, USN, server string, and Location URLs of the responding devices.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 1900</span></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">iot</span><span class="nt-tag">light</span><span class="nt-tag">multicast</span></div>
</div>
<div class="nt-card" data-pl-search="ssh ssh ssh is the secure shell remote-access and tunneling protocol. reads the ssh banner, runs a kex-init exchange, and (when credentials are configured) authenticates, returning the server software string, supported kex/host-key/cipher/mac algorithms, host keys and fingerprints, and accepted authentication methods. tcp encrypted remote-access 22 2222 22222" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>ssh</code></div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">SSH is the Secure Shell remote-access and tunneling protocol. Reads the SSH banner, runs a KEX-init exchange, and (when credentials are configured) authenticates, returning the server software string, supported KEX/host-key/cipher/MAC algorithms, host keys and fingerprints, and accepted authentication methods.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Ports:</span> 22, 2222, 22222</span></div>
  <div class="nt-tags"><span class="nt-tag">encrypted</span><span class="nt-tag">remote-access</span></div>
</div>
<div class="nt-card" data-pl-search="sstp sstp sstp is the microsoft secure socket tunneling protocol, a ppp-over-https remote-access vpn used by windows rras, mikrotik routeros, and softether. sends an sstp_duplex_post handshake over tls and returns the listener responsiveness, http server header, and inferred vendor (microsoft, mikrotik, softether). tls encrypted vpn 443" data-pl-transports="tls">
  <div class="nt-card-header">
    <div class="nt-title"><code>sstp</code></div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tls">TLS</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">SSTP is the Microsoft Secure Socket Tunneling Protocol, a PPP-over-HTTPS remote-access VPN used by Windows RRAS, MikroTik RouterOS, and SoftEther. Sends an SSTP_DUPLEX_POST handshake over TLS and returns the listener responsiveness, HTTP Server header, and inferred vendor (Microsoft, MikroTik, SoftEther).</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 443</span></div>
  <div class="nt-tags"><span class="nt-tag">encrypted</span><span class="nt-tag">vpn</span></div>
</div>
<div class="nt-card" data-pl-search="steam steam server discovery steam server discovery is the valve steam remote play / in-home streaming lan broadcast protocol. sends a cmsgremoteclientbroadcastdiscovery and returns the hostname, client/instance/device ids, client version, os type, public ip, and steam deck / vr / remote play status. udp discovery gaming light 27036" data-pl-transports="udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>steam</code> &mdash; Steam Server Discovery</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Steam Server Discovery is the Valve Steam Remote Play / In-Home Streaming LAN broadcast protocol. Sends a CMsgRemoteClientBroadcastDiscovery and returns the hostname, client/instance/device IDs, client version, OS type, public IP, and Steam Deck / VR / Remote Play status.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 27036</span></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">gaming</span><span class="nt-tag">light</span></div>
</div>
<div class="nt-card" data-pl-search="stun stun stun is the session traversal utilities for nat protocol (rfc 5389) used for nat discovery in webrtc and voip. sends a binding request and returns the software attribute and the observed xor-mapped-address reported by the server. udp voip 3478 3479 5349 5350" data-pl-transports="udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>stun</code></div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">STUN is the Session Traversal Utilities for NAT protocol (RFC 5389) used for NAT discovery in WebRTC and VoIP. Sends a binding request and returns the SOFTWARE attribute and the observed XOR-MAPPED-ADDRESS reported by the server.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Ports:</span> 3478, 3479, 5349, 5350</span></div>
  <div class="nt-tags"><span class="nt-tag">voip</span></div>
</div>
<div class="nt-card" data-pl-search="sua sua (sctp) sua (sctp) is the sccp user adaptation layer (rfc 3868) over sctp, used to carry ss7 sccp signaling over ip. verifies the sctp association and sua payload protocol identifier and returns endpoint identification. sctp mobile-core voip 2904 14001" data-pl-transports="sctp">
  <div class="nt-card-header">
    <div class="nt-title"><code>sua</code> &mdash; SUA (SCTP)</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="sctp">SCTP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">SUA (SCTP) is the SCCP User Adaptation Layer (RFC 3868) over SCTP, used to carry SS7 SCCP signaling over IP. Verifies the SCTP association and SUA payload protocol identifier and returns endpoint identification.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Ports:</span> 2904, 14001</span></div>
  <div class="nt-tags"><span class="nt-tag">mobile-core</span><span class="nt-tag">voip</span></div>
</div>
<div class="nt-card" data-pl-search="subversion apache subversion subversion is the apache version-control system. this entry covers detections produced by integration data and recog banners; runzero&#39;s active svn decoder negotiates the svnserve protocol on tcp/3690 to recover the repository uuid, root url, and supported capabilities. tcp clear mgmt 3690" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>subversion</code> &mdash; Apache Subversion</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Subversion is the Apache version-control system. This entry covers detections produced by integration data and Recog banners; runZero&#39;s active svn decoder negotiates the svnserve protocol on TCP/3690 to recover the repository UUID, root URL, and supported capabilities.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 3690</span></div>
  <div class="nt-tags"><span class="nt-tag">clear</span><span class="nt-tag">mgmt</span></div>
</div>
<div class="nt-card" data-pl-search="sunrpc sun rpc portmapper sun rpc portmapper (also known as rpcbind) is the legacy onc rpc service registry. this entry covers recog-only matches against banners that did not return a structured rpcbind dump; the active rpcbind decoder enumerates registered programs and their dynamic ports. udp clear mgmt 111" data-pl-transports="udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>sunrpc</code> &mdash; Sun RPC Portmapper</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Sun RPC Portmapper (also known as rpcbind) is the legacy ONC RPC service registry. This entry covers Recog-only matches against banners that did not return a structured rpcbind dump; the active rpcbind decoder enumerates registered programs and their dynamic ports.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 111</span></div>
  <div class="nt-tags"><span class="nt-tag">clear</span><span class="nt-tag">mgmt</span></div>
</div>
<div class="nt-card" data-pl-search="svn subversion subversion is the apache subversion svn:// version-control protocol. reads the svn greeting and returns the minimum and maximum supported protocol versions, supported capabilities, and offered authentication mechanisms. tcp file 3690" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>svn</code> &mdash; Subversion</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Subversion is the Apache Subversion svn:// version-control protocol. Reads the SVN greeting and returns the minimum and maximum supported protocol versions, supported capabilities, and offered authentication mechanisms.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 3690</span></div>
  <div class="nt-tags"><span class="nt-tag">file</span></div>
</div>
<div class="nt-card" data-pl-search="sybase sybase / sap ase (tds 5.0) sybase / sap ase (tds 5.0) is the tabular data stream 5.0 wire protocol used by sybase ase and sap adaptive server enterprise. sends a tds prelogin probe and returns the server version reported in the prelogin response. tcp database 5000" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>sybase</code> &mdash; Sybase / SAP ASE (TDS 5.0)</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Sybase / SAP ASE (TDS 5.0) is the Tabular Data Stream 5.0 wire protocol used by Sybase ASE and SAP Adaptive Server Enterprise. Sends a TDS prelogin probe and returns the server version reported in the prelogin response.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 5000</span></div>
  <div class="nt-tags"><span class="nt-tag">database</span></div>
</div>
<div class="nt-card" data-pl-search="syslog syslog syslog is a standard event-logging protocol used to forward log messages between hosts and collectors. identifies syslog listeners over udp/tcp and decodes rfc 3164/5424 messages to report the priority, facility, severity, version, hostname, and application name. tcp udp monitoring tls 514 6514" data-pl-transports="tcp udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>syslog</code></div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Syslog is a standard event-logging protocol used to forward log messages between hosts and collectors. Identifies syslog listeners over UDP/TCP and decodes RFC 3164/5424 messages to report the priority, facility, severity, version, hostname, and application name.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Ports:</span> 514, 6514</span></div>
  <div class="nt-tags"><span class="nt-tag">monitoring</span><span class="nt-tag">tls</span></div>
</div>
<div class="nt-card" data-pl-search="tcpmux tcpmux tcpmux is the tcp port service multiplexer (rfc 1078), a legacy diagnostic service. queries the registered service list and returns the disclosed names. tcp legacy light" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>tcpmux</code></div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">TCPMUX is the TCP Port Service Multiplexer (RFC 1078), a legacy diagnostic service. Queries the registered service list and returns the disclosed names.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">legacy</span><span class="nt-tag">light</span></div>
</div>
<div class="nt-card" data-pl-search="teamviewer teamviewer teamviewer is the proprietary binary protocol used by the teamviewer remote-access client to reach the teamviewer cloud over tcp/5938. sends a teamviewer ping/hello probe and identifies the service from the response magic and command byte. tcp light remote-access 5938" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>teamviewer</code></div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">TeamViewer is the proprietary binary protocol used by the TeamViewer remote-access client to reach the TeamViewer cloud over TCP/5938. Sends a TeamViewer ping/hello probe and identifies the service from the response magic and command byte.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 5938</span></div>
  <div class="nt-tags"><span class="nt-tag">light</span><span class="nt-tag">remote-access</span></div>
</div>
<div class="nt-card" data-pl-search="telnet telnet telnet is a remote-terminal protocol (rfc 854) that transmits credentials in cleartext. reads the negotiation banner and any login prompts, returning the device hostname, os or product banner, and supported telnet options. tcp clear remote-access tls 23 992 2323" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>telnet</code></div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Telnet is a remote-terminal protocol (RFC 854) that transmits credentials in cleartext. Reads the negotiation banner and any login prompts, returning the device hostname, OS or product banner, and supported telnet options.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Ports:</span> 23, 992, 2323</span></div>
  <div class="nt-tags"><span class="nt-tag">clear</span><span class="nt-tag">remote-access</span><span class="nt-tag">tls</span></div>
</div>
<div class="nt-card" data-pl-search="tenable-agent-id tenable agent identifier tenable agent identifier is the synthetic protocol runzero uses to track the unique agent uuid reported by tenable nessus and tenable.io agents observed via integrations. it is not a network protocol and has no associated wire-level scan. tcp integration" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>tenable-agent-id</code> &mdash; Tenable Agent Identifier</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Tenable Agent Identifier is the synthetic protocol runZero uses to track the unique agent UUID reported by Tenable Nessus and Tenable.io agents observed via integrations. It is not a network protocol and has no associated wire-level scan.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">integration</span></div>
</div>
<div class="nt-card" data-pl-search="tftp tftp tftp is the trivial file transfer protocol (rfc 1350) used for boot images, firmware, and config transfer. sends a benign read request and returns the responsiveness and any error-code metadata that discloses the server implementation. udp file 69" data-pl-transports="udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>tftp</code></div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">TFTP is the Trivial File Transfer Protocol (RFC 1350) used for boot images, firmware, and config transfer. Sends a benign read request and returns the responsiveness and any error-code metadata that discloses the server implementation.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 69</span></div>
  <div class="nt-tags"><span class="nt-tag">file</span></div>
</div>
<div class="nt-card" data-pl-search="thinprint thinprint thinprint is the cortado virtual-printing protocol used by citrix, vmware horizon, and microsoft rds deployments to redirect print jobs from session hosts to client-side printers. detected from the tpautoconnect listener banner on tcp/4000. tcp clear mgmt 4000" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>thinprint</code></div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">ThinPrint is the Cortado virtual-printing protocol used by Citrix, VMware Horizon, and Microsoft RDS deployments to redirect print jobs from session hosts to client-side printers. Detected from the TPAutoConnect listener banner on TCP/4000.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 4000</span></div>
  <div class="nt-tags"><span class="nt-tag">clear</span><span class="nt-tag">mgmt</span></div>
</div>
<div class="nt-card" data-pl-search="time time time is the legacy 32-bit time-of-day service (rfc 868). reads the response to confirm the service and detect amplification-capable hosts. tcp udp legacy light time 37" data-pl-transports="tcp udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>time</code></div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Time is the legacy 32-bit time-of-day service (RFC 868). Reads the response to confirm the service and detect amplification-capable hosts.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 37</span></div>
  <div class="nt-tags"><span class="nt-tag">legacy</span><span class="nt-tag">light</span><span class="nt-tag">time</span></div>
</div>
<div class="nt-card" data-pl-search="tls tls / ssl tls / ssl is the transport layer security encrypted-transport substrate used by https and most modern internet protocols. performs a tls handshake and returns the negotiated version and cipher suite, supported versions and extensions, and the full server-certificate chain with subject, issuer, sans, validity, and key metadata. tcp encrypted 443 5986 6443 8443 9443" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>tls</code> &mdash; TLS / SSL</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">TLS / SSL is the Transport Layer Security encrypted-transport substrate used by HTTPS and most modern Internet protocols. Performs a TLS handshake and returns the negotiated version and cipher suite, supported versions and extensions, and the full server-certificate chain with subject, issuer, SANs, validity, and key metadata.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Ports:</span> 443, 5986, 6443, 8443, 9443</span></div>
  <div class="nt-tags"><span class="nt-tag">encrypted</span></div>
</div>
<div class="nt-card" data-pl-search="tristation triconex tristation triconex tristation is the proprietary engineering protocol used to program and configure tricon and trident safety instrumented systems controllers. passively decodes tristation frames and returns the controller identification observed. tcp udp ot passive 1502" data-pl-transports="tcp udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>tristation</code> &mdash; Triconex TriStation</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Triconex TriStation is the proprietary engineering protocol used to program and configure Tricon and Trident Safety Instrumented Systems controllers. Passively decodes TriStation frames and returns the controller identification observed.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 1502</span></div>
  <div class="nt-tags"><span class="nt-tag">ot</span><span class="nt-tag">passive</span></div>
</div>
<div class="nt-card" data-pl-search="turn turn turn is the traversal using relays around nat protocol (rfc 5766) used as a media relay for webrtc and voip. sends an allocate request and returns the software attribute, mapped and relayed addresses, allocation lifetime, requested transport, and any error code. udp voip 3478 3479 5349 5350" data-pl-transports="udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>turn</code></div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">TURN is the Traversal Using Relays around NAT protocol (RFC 5766) used as a media relay for WebRTC and VoIP. Sends an Allocate request and returns the SOFTWARE attribute, mapped and relayed addresses, allocation lifetime, requested transport, and any error code.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Ports:</span> 3478, 3479, 5349, 5350</span></div>
  <div class="nt-tags"><span class="nt-tag">voip</span></div>
</div>
<div class="nt-card" data-pl-search="ubnt ubiquiti discovery ubiquiti discovery is a device-discovery protocol used by uisp/unms and the ubiquiti discovery tool. sends the discovery probe and returns the device hostname, model, firmware, mac, and ip configuration. udp discovery light mgmt 10001" data-pl-transports="udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>ubnt</code> &mdash; Ubiquiti Discovery</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Ubiquiti Discovery is a device-discovery protocol used by UISP/UNMS and the Ubiquiti Discovery Tool. Sends the discovery probe and returns the device hostname, model, firmware, MAC, and IP configuration.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 10001</span></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">light</span><span class="nt-tag">mgmt</span></div>
</div>
<div class="nt-card" data-pl-search="unitronics unitronics pcom unitronics pcom is the proprietary protocol used to communicate with unitronics vision and samba/unistream plc+hmi controllers. queries the controller identification and returns the model and os version. tcp ot 20256" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>unitronics</code> &mdash; Unitronics PCOM</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Unitronics PCOM is the proprietary protocol used to communicate with Unitronics Vision and Samba/UniStream PLC+HMI controllers. Queries the controller identification and returns the model and OS version.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 20256</span></div>
  <div class="nt-tags"><span class="nt-tag">ot</span></div>
</div>
<div class="nt-card" data-pl-search="upnp universal plug and play upnp is the device-control protocol layered on top of ssdp. runzero fetches the device-description xml referenced in the ssdp location header to recover the friendly name, manufacturer, model, serial number, upnp uuid, and the list of advertised services. tcp clear discovery iot" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>upnp</code> &mdash; Universal Plug and Play</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">UPnP is the device-control protocol layered on top of SSDP. runZero fetches the device-description XML referenced in the SSDP LOCATION header to recover the friendly name, manufacturer, model, serial number, UPnP UUID, and the list of advertised services.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">clear</span><span class="nt-tag">discovery</span><span class="nt-tag">iot</span></div>
</div>
<div class="nt-card" data-pl-search="uscan apple image capture (uscan) uscan is the airscan/mopria http scanner protocol used by macos image capture, ios notes, and mopria-compatible clients to discover and drive network scanners. detected via the _uscan._tcp mdns record and the /escl/scannercapabilities xml returned by the device. tcp clear discovery iot" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>uscan</code> &mdash; Apple Image Capture (uscan)</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">uscan is the AirScan/Mopria HTTP scanner protocol used by macOS Image Capture, iOS Notes, and Mopria-compatible clients to discover and drive network scanners. Detected via the _uscan._tcp mDNS record and the /eSCL/ScannerCapabilities XML returned by the device.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">clear</span><span class="nt-tag">discovery</span><span class="nt-tag">iot</span></div>
</div>
<div class="nt-card" data-pl-search="uscans apple image capture over https (uscans) uscans is the tls-protected variant of the airscan/mopria scanner discovery protocol, advertised via the _uscans._tcp mdns record. runzero fetches the https /escl/scannercapabilities document to recover the device make, model, firmware, and supported scan profiles. tcp discovery iot" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>uscans</code> &mdash; Apple Image Capture over HTTPS (uscans)</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">uscans is the TLS-protected variant of the AirScan/Mopria scanner discovery protocol, advertised via the _uscans._tcp mDNS record. runZero fetches the HTTPS /eSCL/ScannerCapabilities document to recover the device make, model, firmware, and supported scan profiles.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">iot</span></div>
</div>
<div class="nt-card" data-pl-search="vault hashicorp vault vault is hashicorp&#39;s secrets-management platform. runzero queries /v1/sys/health and /v1/sys/seal-status on the http api to recover the vault version, cluster name, cluster id, sealed/initialized state, and replication mode. tcp clear mgmt 8200" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>vault</code> &mdash; HashiCorp Vault</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Vault is HashiCorp&#39;s secrets-management platform. runZero queries /v1/sys/health and /v1/sys/seal-status on the HTTP API to recover the Vault version, cluster name, cluster ID, sealed/initialized state, and replication mode.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 8200</span></div>
  <div class="nt-tags"><span class="nt-tag">clear</span><span class="nt-tag">mgmt</span></div>
</div>
<div class="nt-card" data-pl-search="vmauthd vmware vmauthd vmware vmauthd is the authentication daemon listening on vmware esxi and workstation hosts. identifies the service from its 220 greeting banner. tcp light mgmt 902" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>vmauthd</code> &mdash; VMware vmauthd</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">VMware vmauthd is the authentication daemon listening on VMware ESXi and Workstation hosts. Identifies the service from its 220 greeting banner.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 902</span></div>
  <div class="nt-tags"><span class="nt-tag">light</span><span class="nt-tag">mgmt</span></div>
</div>
<div class="nt-card" data-pl-search="vmware vmware vsphere soap vmware vsphere soap is the vsphere web services soap api exposed by vcenter server and esxi hosts for management and automation. issues a retrieveservicecontent call to /sdk and returns the product name, full version and build, api type and version, os type, and product line. tcp tls auth mgmt 443" data-pl-transports="tcp tls">
  <div class="nt-card-header">
    <div class="nt-title"><code>vmware</code> &mdash; VMware vSphere SOAP</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span><span class="fd-badge fd-badge-sm" data-pl-transport="tls">TLS</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">VMware vSphere SOAP is the vSphere Web Services SOAP API exposed by vCenter Server and ESXi hosts for management and automation. Issues a RetrieveServiceContent call to /sdk and returns the product name, full version and build, API type and version, OS type, and product line.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 443</span></div>
  <div class="nt-tags"><span class="nt-tag">auth</span><span class="nt-tag">mgmt</span></div>
</div>
<div class="nt-card" data-pl-search="vnc vnc / rfb vnc / rfb is the virtual network computing remote-desktop protocol, also known as the remote frame buffer protocol. reads the protocol-version handshake and returns the rfb version, supported security types, and any disclosed vendor banner. tcp remote-access tls 5800 5900 5901 5902 5903" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>vnc</code> &mdash; VNC / RFB</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">VNC / RFB is the Virtual Network Computing remote-desktop protocol, also known as the Remote Frame Buffer protocol. Reads the protocol-version handshake and returns the RFB version, supported security types, and any disclosed vendor banner.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Ports:</span> 5800, 5900, 5901, 5902, 5903</span></div>
  <div class="nt-tags"><span class="nt-tag">remote-access</span><span class="nt-tag">tls</span></div>
</div>
<div class="nt-card" data-pl-search="vsdp vivotek search discovery protocol vsdp is the udp broadcast discovery protocol used by vivotek ip cameras and video servers. runzero parses the response to recover the camera model, firmware version, mac address, and ip configuration. udp discovery iot 3702" data-pl-transports="udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>vsdp</code> &mdash; Vivotek Search Discovery Protocol</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">VSDP is the UDP broadcast discovery protocol used by Vivotek IP cameras and video servers. runZero parses the response to recover the camera model, firmware version, MAC address, and IP configuration.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 3702</span></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">iot</span></div>
</div>
<div class="nt-card" data-pl-search="vxlan virtual extensible lan vxlan is the l2-over-udp tunneling protocol (rfc 7348) used by data-center overlay networks. runzero observes vxlan encapsulation on udp/4789 and records the vxlan network identifier (vni) of the inner ethernet frame. udp clear 4789" data-pl-transports="udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>vxlan</code> &mdash; Virtual eXtensible LAN</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">VXLAN is the L2-over-UDP tunneling protocol (RFC 7348) used by data-center overlay networks. runZero observes VXLAN encapsulation on UDP/4789 and records the VXLAN Network Identifier (VNI) of the inner Ethernet frame.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 4789</span></div>
  <div class="nt-tags"><span class="nt-tag">clear</span></div>
</div>
<div class="nt-card" data-pl-search="waveu wave/ue discovery waveu is the udp discovery service used by crestron airmedia and selected wave-branded conferencing endpoints to advertise their presence to companion mobile and desktop apps. runzero parses the response to recover the model and firmware revision. udp discovery iot" data-pl-transports="udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>waveu</code> &mdash; Wave/UE Discovery</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">WaveU is the UDP discovery service used by Crestron AirMedia and selected Wave-branded conferencing endpoints to advertise their presence to companion mobile and desktop apps. runZero parses the response to recover the model and firmware revision.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">iot</span></div>
</div>
<div class="nt-card" data-pl-search="wbsm ibm web-based system manager ibm web-based system manager (wsm/websm) is the remote-administration protocol used by the java wsm client to manage aix systems. identifies the service from its banner. tcp light mgmt 9090" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>wbsm</code> &mdash; IBM Web-Based System Manager</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">IBM Web-Based System Manager (WSM/WebSM) is the remote-administration protocol used by the Java WSM client to manage AIX systems. Identifies the service from its banner.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 9090</span></div>
  <div class="nt-tags"><span class="nt-tag">light</span><span class="nt-tag">mgmt</span></div>
</div>
<div class="nt-card" data-pl-search="wdbrpc vxworks wdb agent wdb rpc is the wind river workbench debug bridge agent built into many vxworks images and exposed (often unintentionally) on udp/17185. runzero issues a target-info query to recover the vxworks version, bsp name, cpu type, and target name; presence of wdb indicates the host can be remotely controlled without authentication. udp clear mgmt ot 17185" data-pl-transports="udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>wdbrpc</code> &mdash; VxWorks WDB Agent</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">WDB RPC is the Wind River Workbench Debug Bridge agent built into many VxWorks images and exposed (often unintentionally) on UDP/17185. runZero issues a target-info query to recover the VxWorks version, BSP name, CPU type, and target name; presence of WDB indicates the host can be remotely controlled without authentication.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 17185</span></div>
  <div class="nt-tags"><span class="nt-tag">clear</span><span class="nt-tag">mgmt</span><span class="nt-tag">ot</span></div>
</div>
<div class="nt-card" data-pl-search="webmin webmin webmin is a web-based unix administration suite that exposes a udp discovery service on udp/10000 alongside usermin and virtualmin. sends the &#34;webmin&#34; query and returns the advertised webmin server ip, port, and http/https scheme used to reach the management ui. udp light mgmt web 10000" data-pl-transports="udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>webmin</code></div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Webmin is a web-based Unix administration suite that exposes a UDP discovery service on UDP/10000 alongside Usermin and Virtualmin. Sends the &#34;webmin&#34; query and returns the advertised Webmin server IP, port, and HTTP/HTTPS scheme used to reach the management UI.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 10000</span></div>
  <div class="nt-tags"><span class="nt-tag">light</span><span class="nt-tag">mgmt</span><span class="nt-tag">web</span></div>
</div>
<div class="nt-card" data-pl-search="wireguard wireguard wireguard is a modern in-kernel vpn protocol. sends a benign handshake-initiation probe and returns the responsiveness and any rate-limited replies that confirm a wireguard endpoint. udp encrypted vpn 51820" data-pl-transports="udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>wireguard</code></div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">WireGuard is a modern in-kernel VPN protocol. Sends a benign handshake-initiation probe and returns the responsiveness and any rate-limited replies that confirm a WireGuard endpoint.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 51820</span></div>
  <div class="nt-tags"><span class="nt-tag">encrypted</span><span class="nt-tag">vpn</span></div>
</div>
<div class="nt-card" data-pl-search="wiznet wiznet discovery wiznet discovery is a device-discovery protocol used by wiznet serial-to-ethernet modules and embedded tcp/ip chips. sends the discovery probe and returns the raw advertised configuration fields. udp discovery iot light 5000 50001" data-pl-transports="udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>wiznet</code> &mdash; WIZnet Discovery</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">WIZnet Discovery is a device-discovery protocol used by WIZnet serial-to-Ethernet modules and embedded TCP/IP chips. Sends the discovery probe and returns the raw advertised configuration fields.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Ports:</span> 5000, 50001</span></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">iot</span><span class="nt-tag">light</span></div>
</div>
<div class="nt-card" data-pl-search="wsd web services dynamic discovery web services dynamic discovery (ws-discovery) is the soap-over-udp multicast discovery protocol used by windows printers, scanners, and onvif ip cameras. runzero issues a probe to ff02::c / 239.255.255.250 and parses the probematch response to recover the device&#39;s endpoint reference, types, scopes, and metadata urls. udp clear discovery iot 3702" data-pl-transports="udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>wsd</code> &mdash; Web Services Dynamic Discovery</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Web Services Dynamic Discovery (WS-Discovery) is the SOAP-over-UDP multicast discovery protocol used by Windows printers, scanners, and ONVIF IP cameras. runZero issues a Probe to ff02::c / 239.255.255.250 and parses the ProbeMatch response to recover the device&#39;s endpoint reference, types, scopes, and metadata URLs.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 3702</span></div>
  <div class="nt-tags"><span class="nt-tag">clear</span><span class="nt-tag">discovery</span><span class="nt-tag">iot</span></div>
</div>
<div class="nt-card" data-pl-search="wsman ws-management ws-management (ws-man) is the soap-over-http/https management protocol used by windows remote management (winrm), idrac, ilo, and ipmi baseboard controllers. runzero issues an identify request to recover the product vendor, product version, and supported protocol versions. tcp clear mgmt 5985 5986" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>wsman</code> &mdash; WS-Management</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">WS-Management (WS-Man) is the SOAP-over-HTTP/HTTPS management protocol used by Windows Remote Management (WinRM), iDRAC, iLO, and IPMI baseboard controllers. runZero issues an Identify request to recover the product vendor, product version, and supported protocol versions.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Ports:</span> 5985, 5986</span></div>
  <div class="nt-tags"><span class="nt-tag">clear</span><span class="nt-tag">mgmt</span></div>
</div>
<div class="nt-card" data-pl-search="x11 x11 / x window system x11 / x window system is the x window system display protocol used by unix graphical desktops; if exposed, it allows remote display capture and input injection. performs an x11 connection-setup probe and returns the x.org/xfree86 vendor string, protocol-major version, and the access state of the server. tcp clear light remote-access 6000 6001 6002 6003 6004 6005 6006 6007 6008 6009 6010 6011 6012 6013 6014 6015" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>x11</code> &mdash; X11 / X Window System</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">X11 / X Window System is the X Window System display protocol used by Unix graphical desktops; if exposed, it allows remote display capture and input injection. Performs an X11 connection-setup probe and returns the X.Org/XFree86 vendor string, protocol-major version, and the access state of the server.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Ports:</span> 6000, 6001, 6002, 6003, 6004, 6005, 6006, 6007, 6008, 6009, 6010, 6011, 6012, 6013, 6014, 6015</span></div>
  <div class="nt-tags"><span class="nt-tag">clear</span><span class="nt-tag">light</span><span class="nt-tag">remote-access</span></div>
</div>
<div class="nt-card" data-pl-search="x2ap x2ap (sctp) x2ap (sctp) is the x2 application protocol (3gpp ts 36.423) over sctp used between lte enodebs. verifies the sctp association and x2ap payload protocol identifier and returns endpoint identification. sctp mobile-core 36422" data-pl-transports="sctp">
  <div class="nt-card-header">
    <div class="nt-title"><code>x2ap</code> &mdash; X2AP (SCTP)</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="sctp">SCTP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">X2AP (SCTP) is the X2 Application Protocol (3GPP TS 36.423) over SCTP used between LTE eNodeBs. Verifies the SCTP association and X2AP payload protocol identifier and returns endpoint identification.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 36422</span></div>
  <div class="nt-tags"><span class="nt-tag">mobile-core</span></div>
</div>
<div class="nt-card" data-pl-search="xdmcp xdmcp xdmcp is the x display manager control protocol used by x window system login managers (xdm, gdm, kdm). sends an xdmcp query and returns the responding manager&#39;s hostname and supported authentication types. udp legacy light remote-access 177" data-pl-transports="udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>xdmcp</code></div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">XDMCP is the X Display Manager Control Protocol used by X Window System login managers (xdm, gdm, kdm). Sends an XDMCP query and returns the responding manager&#39;s hostname and supported authentication types.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 177</span></div>
  <div class="nt-tags"><span class="nt-tag">legacy</span><span class="nt-tag">light</span><span class="nt-tag">remote-access</span></div>
</div>
<div class="nt-card" data-pl-search="xmpp xmpp xmpp is the extensible messaging and presence protocol used by chat servers (jabber, openfire, ejabberd). sends a stream-start request and returns the server software banner, supported xmpp version, and starttls / sasl feature summary. tcp messaging tls 5222 5223 5269" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>xmpp</code></div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">XMPP is the Extensible Messaging and Presence Protocol used by chat servers (Jabber, Openfire, ejabberd). Sends a stream-start request and returns the server software banner, supported XMPP version, and STARTTLS / SASL feature summary.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Ports:</span> 5222, 5223, 5269</span></div>
  <div class="nt-tags"><span class="nt-tag">messaging</span><span class="nt-tag">tls</span></div>
</div>
<div class="nt-card" data-pl-search="zabbix zabbix agent zabbix agent is the monitoring agent used by the zabbix server to collect host metrics. sends an agent.version request and returns the agent version, derived cpe, and whether remote commands are enabled. tcp monitoring tls 10050 10051" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>zabbix</code> &mdash; Zabbix Agent</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Zabbix Agent is the monitoring agent used by the Zabbix server to collect host metrics. Sends an agent.version request and returns the agent version, derived CPE, and whether remote commands are enabled.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Ports:</span> 10050, 10051</span></div>
  <div class="nt-tags"><span class="nt-tag">monitoring</span><span class="nt-tag">tls</span></div>
</div>
<div class="nt-card" data-pl-search="zabbix-agent zabbix agent zabbix agent is the host-side collector polled by a zabbix server over tcp/10050. runzero requests the agent.version and agent.hostname items to recover the agent build and configured hostname from unauthenticated agents. tcp clear mgmt 10050" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>zabbix-agent</code> &mdash; Zabbix Agent</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Zabbix Agent is the host-side collector polled by a Zabbix server over TCP/10050. runZero requests the agent.version and agent.hostname items to recover the agent build and configured hostname from unauthenticated agents.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 10050</span></div>
  <div class="nt-tags"><span class="nt-tag">clear</span><span class="nt-tag">mgmt</span></div>
</div>
<div class="nt-card" data-pl-search="zebra zebra discovery zebra discovery is a network discovery protocol used by zebra technologies label and barcode printers. sends the discovery probe and returns the printer hostname disclosed in the response. udp discovery light printing 6101" data-pl-transports="udp">
  <div class="nt-card-header">
    <div class="nt-title"><code>zebra</code> &mdash; Zebra Discovery</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="udp">UDP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Zebra Discovery is a network discovery protocol used by Zebra Technologies label and barcode printers. Sends the discovery probe and returns the printer hostname disclosed in the response.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Port:</span> 6101</span></div>
  <div class="nt-tags"><span class="nt-tag">discovery</span><span class="nt-tag">light</span><span class="nt-tag">printing</span></div>
</div>
<div class="nt-card" data-pl-search="zookeeper apache zookeeper apache zookeeper is a distributed coordination service whose wire protocol exposes four-letter administrative commands. sends a four-letter (ruok/srvr/conf) command and returns the access state, mode (leader/follower/standalone), node count, and zookeeper version when the command is permitted. tcp database mgmt 2181 2888 3888" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>zookeeper</code> &mdash; Apache ZooKeeper</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Apache ZooKeeper is a distributed coordination service whose wire protocol exposes four-letter administrative commands. Sends a four-letter (ruok/srvr/conf) command and returns the access state, mode (leader/follower/standalone), node count, and ZooKeeper version when the command is permitted.</div></div></div>
  <div class="nt-detail-row"><span class="nt-detail"><span class="nt-detail-label">Ports:</span> 2181, 2888, 3888</span></div>
  <div class="nt-tags"><span class="nt-tag">database</span><span class="nt-tag">mgmt</span></div>
</div>
<div class="nt-card" data-pl-search="zyxel zyxel device web management zyxel device web management is the http management interface exposed by zyxel switches and routers (e.g. gs1200 series), serving a system_data.js endpoint that advertises model, firmware version, mac, hostname, and ip configuration. tcp light network tls web" data-pl-transports="tcp">
  <div class="nt-card-header">
    <div class="nt-title"><code>zyxel</code> &mdash; Zyxel Device Web Management</div>
    <div class="nt-meta"><span class="fd-badge fd-badge-sm" data-pl-transport="tcp">TCP</span></div>
  </div>
  <div class="nt-sections"><div class="nt-section"><div class="nt-section-body">Zyxel Device Web Management is the HTTP management interface exposed by Zyxel switches and routers (e.g. GS1200 series), serving a system_data.js endpoint that advertises model, firmware version, MAC, hostname, and IP configuration.</div></div></div>
  <div class="nt-tags"><span class="nt-tag">light</span><span class="nt-tag">network</span><span class="nt-tag">tls</span><span class="nt-tag">web</span></div>
</div>
</template>
<div class="nt-undocumented"><h3>Additional protocols</h3><ul class="nt-undocumented-list"><li><code>iec60870-5-104</code></li></ul></div>
<script>
(function(){var t=document.getElementById('pl-grid-content');var h=document.getElementById('pl-grid-host');if(t&&h){requestAnimationFrame(function(){h.innerHTML='';h.appendChild(t.content);t.remove();})}})();
var plActiveTransports=null;
function plToggleTransport(btn){
  if(plActiveTransports===null){
    plActiveTransports=new Set();
    document.querySelectorAll('[data-pl-transport]').forEach(function(b){if(b.tagName==='BUTTON')plActiveTransports.add(b.getAttribute('data-pl-transport'));});
  }
  var t=btn.getAttribute('data-pl-transport');
  if(plActiveTransports.has(t)){plActiveTransports.delete(t);btn.classList.remove('active');}
  else{plActiveTransports.add(t);btn.classList.add('active');}
  plFilter();
}
function plFilter(){
  var term=(document.querySelector('.pl-search').value||'').toLowerCase();
  var cards=document.querySelectorAll('[data-pl-search]');
  var shown=0;
  cards.forEach(function(c){
    var textMatch=!term||c.getAttribute('data-pl-search').indexOf(term)!==-1;
    var transportMatch=true;
    if(plActiveTransports!==null){
      var ts=(c.getAttribute('data-pl-transports')||'').split(' ').filter(Boolean);
      if(ts.length===0){transportMatch=false;}
      else{transportMatch=ts.some(function(t){return plActiveTransports.has(t);});}
    }
    var visible=textMatch&&transportMatch;
    c.classList.toggle('nt-hidden',!visible);
    if(visible) shown++;
  });
  var counter=document.getElementById('pl-match-count');
  if(counter) counter.textContent=shown;
}
function plFilterByTag(tag){
  var inp=document.querySelector('.pl-search');
  if(inp){inp.value=tag;plFilter();inp.scrollIntoView({behavior:'smooth',block:'center'});}
}
</script>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Passive sampling]]></title>
    <link href="https://www.runzero.com/docs/traffic-sampling/"/>
    <id>https://www.runzero.com/docs/traffic-sampling/</id>
      
      <published>2025-10-09T23:51:56+00:00</published>
      <updated>2025-10-09T23:51:56+00:00</updated>
      <summary type="html"><![CDATA[<p>runZero Explorers can identify assets, services, and vulnerabilities by passively monitoring network traffic. <span class="book-index" data-book-index="Passive sampling">Passive sampling</span> can be an alternative data source when active scanning is prohibited and helpful at identifying unknown IP ranges. Passive sampling tasks are limited to using a single CPU core and will temporarily skip packets when this limit is reached. If an active scan is run on an Explorer with a passive sampling task, the passive task will be interrupted, and then restarted once the active scan completes.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Using custom fingerprints]]></title>
    <link href="https://www.runzero.com/docs/using-custom-fingerprints/"/>
    <id>https://www.runzero.com/docs/using-custom-fingerprints/</id>
      
      <published>2026-04-11T03:07:33+00:00</published>
      <updated>2026-04-11T03:07:33+00:00</updated>
      <summary type="html"><![CDATA[<p class="licenses"><a href="https://www.runzero.com/product/pricing/"><span class="com">Community</span></a>&nbsp;<a href="https://www.runzero.com/product/pricing/"><span class="pla">Platform</span></a></p>
<p>Customers running a <span class="book-index" data-book-index="self-hosted">self-hosted</span> instance or using the standalone <span class="book-index" data-book-index="scanner">scanner</span> have the ability to use custom-written fingerprints. This can be useful in adding new fingerprint coverage for very unique or custom assets and services, such as device prototypes or proprietary applications/services. Custom fingerprints can also be used to override existing, similar runZero fingerprints by using a same-or-higher certainty value.</p>
<div class="alert alert-info">
<svg class="alert-icon" xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewbox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><circle cx="12" cy="12" r="10"></circle><line x1="12" y1="16" x2="12" y2="12"></line><line x1="12" y1="8" x2="12.01" y2="8"></line></svg>
<div class="alert-body">
When using the runZero standalone scanner with custom fingerprints, you&#39;ll need to use the `RUNZERO_EXTERNAL_FINGERPRINTS` value as an environment variable when launching the scanner.
</div>
</div>
<h2 id="custom-fingerprints-create">Create new fingerprints</h2>
<p>Custom fingerprints follow the structure and format of the <a href="https://github.com/rapid7/recog">open-source Recog fingerprint database</a>. You can author your own fingerprint XML entries in files of similar name and format to <a href="https://github.com/rapid7/recog/tree/main/xml">those found in Recog</a>. For cases where an asset or service matches both a built-in runZero fingerprint and a custom fingerprint of the same kind, preference will be given to the fingerprint with higher “certainty” value(s) (e.g. <code>hw.certainty</code>, <code>os.certainty</code>, <code>service.certainty</code>). In the event of a certainty “tie” (i.e. same certainty value(s)), the custom fingerprint will be given preference.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Scanning with SNMP]]></title>
    <link href="https://www.runzero.com/docs/scanning-snmp/"/>
    <id>https://www.runzero.com/docs/scanning-snmp/</id>
      
      <published>2026-04-17T11:10:41+00:00</published>
      <updated>2026-04-17T11:10:41+00:00</updated>
      <summary type="html"><![CDATA[<p><span class="book-index" data-book-index="SNMP">SNMP</span> is an open standard network protocol for collecting information about devices on a network.</p>
<p>There are three main versions of the protocol.</p>
<h2 id="snmp-versions-1-and-2">SNMP versions 1 and 2</h2>
<p>SNMP version 1 was designed in the 1980s as an interim protocol, intended to be replaced by ISO CMIP. It was built to be used across any network common at the time, not just TCP/IP networks, so security was left up to the host network. The protocol defined a community string for arbitrary organization of groups of assets, but didn’t specify how access should be granted.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Scanning with credentials]]></title>
    <link href="https://www.runzero.com/docs/scanning-credentials/"/>
    <id>https://www.runzero.com/docs/scanning-credentials/</id>
      
      <published>2025-01-14T23:22:27+00:00</published>
      <updated>2025-01-14T23:22:27+00:00</updated>
      <summary type="html"><![CDATA[<p>The <span class="book-index" data-book-index="Credentials">Credentials</span> page provides a single place to store any secure credentials needed by runZero, including:</p>
<ul>
<li>SNMPv3 credentials</li>
<li>Access secrets for cloud services like AWS and Azure</li>
<li>API keys for services such as Censys and Miradore</li>
</ul>
<p>Credentials are stored in encrypted form in the runZero database. Credentials, such as SNMP passwords, are used by runZero Explorers and are transmitted to them in encrypted form. For security reasons, the secret part of any credential cannot be viewed once entered.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Managing scan templates]]></title>
    <link href="https://www.runzero.com/docs/managing-scan-templates/"/>
    <id>https://www.runzero.com/docs/managing-scan-templates/</id>
      
      <published>2025-06-16T18:02:52+00:00</published>
      <updated>2025-06-16T18:02:52+00:00</updated>
      <summary type="html"><![CDATA[<p>A <span class="book-index" data-book-index="scan template">scan template</span> is a predefined set of scan options and settings. If you have a scan configuration you use often, you can create a scan template to save those settings. The next time you create a scan, you can choose a template instead of manually configuring your settings. Each update you make to the scan template is automatically applied to new and recurring scans based on the template, as well as any queued scans which were set up using the template but have not started yet. With scan templates, you can save time and reduce the likelihood of misconfiguring a scan.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Identifying gaps in scanning]]></title>
    <link href="https://www.runzero.com/docs/identify-gaps-in-scanning/"/>
    <id>https://www.runzero.com/docs/identify-gaps-in-scanning/</id>
      
      <published>2026-05-10T19:03:44+00:00</published>
      <updated>2026-05-10T19:03:44+00:00</updated>
      <summary type="html"><![CDATA[<h2 id="gapsbackground">Background</h2>
<p>After you have run a full network discovery scan, you can start to better understand your coverage and begin to optimize. By the end of this guide, you will understand how to use the out of the box reports in runZero to understand your gaps in network coverage.</p>
<h3 id="identifying-gaps-rfc1918"><span class="book-index" data-book-index="RFC 1918">RFC 1918</span> coverage</h3>
<p>The first report to look at is the <strong>RFC 1918 coverage</strong> report. This report shows you which internal IPv4 subnets have been scanned, which likely contain assets, and which are still unknowns.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Initial network scans]]></title>
    <link href="https://www.runzero.com/docs/running-initial-scans/"/>
    <id>https://www.runzero.com/docs/running-initial-scans/</id>
      
      <published>2026-04-11T03:07:33+00:00</published>
      <updated>2026-04-11T03:07:33+00:00</updated>
      <summary type="html"><![CDATA[<h2 id="firstscanbackground">Background</h2>
<p>Once you have an Explorer installed, you can start using it for network discovery. While our goal is to configure scheduled scans that we set and forget, we need to go about our first scans in a more structured manner.</p>
<p>The goals of our <span class="book-index" data-book-index="first scans">first scans</span> are to:</p>
<ul>
<li>Verify the Explorer is setup properly and has everything installed</li>
<li>Validate Explorer connectivity to varying parts of the network</li>
<li>Determine how long scans will take at varying sizes to help with future scheduling</li>
</ul>
<iframe src="https://demo.arcade.software/Q7h75Uukgz57Q82Qv4gH?embed" loading="lazy" allowfullscreen="" title="Walkthrough - Basic Scan Configuration"></iframe>
<h2 id="your-first-few-scans">Your first few scans</h2>
<p>To get started, you will want to scan a few smaller ranges to make sure everything is working as expected. Start with a few /24 network blocks from each of the <span class="book-index" data-book-index="RFC 1918">RFC 1918</span> ranges to make sure everything looks good.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Active scanning]]></title>
    <link href="https://www.runzero.com/docs/discovering-assets/"/>
    <id>https://www.runzero.com/docs/discovering-assets/</id>
      
      <published>2026-04-11T03:07:33+00:00</published>
      <updated>2026-04-11T03:07:33+00:00</updated>
      <summary type="html"><![CDATA[<p>An <span class="book-index" data-book-index="active scan">active scan</span> identifies all responsive devices on a given network, fingerprints these devices, and populates the asset, services, screenshot, and software inventory. Regular scans of internal and external networks is an important step in network management. Scans are configured by site, Explorer, and scan scope. The scan scope can include IP ranges, domain names, ASNs, and even entire country codes.</p>
<p>When creating a new scan, you have multiple parameters you can set, ranging from scheduling a date to more advanced options. To get started, login to the runZero Console, select Scan from the Data sources section of the navigation menu, and choose “Start Standard Scan”. Scans can also be launched from the Inventory views.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Network discovery]]></title>
    <link href="https://www.runzero.com/docs/gathering-data/"/>
    <id>https://www.runzero.com/docs/gathering-data/</id>
      
      <published>2025-01-14T23:22:27+00:00</published>
      <updated>2025-01-14T23:22:27+00:00</updated>
      <summary type="html"><![CDATA[<p>runZero can gather asset data through unauthenticated <span class="book-index" data-book-index="active scanning">active scanning</span>, <span class="book-index" data-book-index="passive">passive</span> <span class="book-index" data-book-index="traffic sampling">traffic sampling</span>, and inbound integrations.</p>
<h2 id="active-scanning">Active scanning</h2>
<p>The runZero Explorer and scanner perform <a href="/docs/discovering-assets/">unauthenticated active scanning</a> of your specified networks based on the configurations you set. They leverage various network protocols to discover and fingerprint assets connected to the network.</p>
<p>Active scans can be configured to run once or on a schedule. Scan templates can also be used to ensure consistency across multiple scan tasks.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Managing licenses]]></title>
    <link href="https://www.runzero.com/docs/managing-licenses/"/>
    <id>https://www.runzero.com/docs/managing-licenses/</id>
      
      <published>2026-04-11T03:07:33+00:00</published>
      <updated>2026-04-11T03:07:33+00:00</updated>
      <summary type="html"><![CDATA[<p>As a runZero superuser or billing user, you can access and manage your organization’s <span class="book-index" data-book-index="licensing">licensing</span>, plan, and <span class="book-index" data-book-index="billing information">billing information</span>.</p>
<p><strong>Not a superuser or billing user?</strong> Please contact your organization’s <a href="https://console.runzero.com/team/">superuser or billing user</a> to get help with licensing and billing information. These users are tagged with a yellow star.</p>
<h2 id="how-do-i-view-my-license">How do I view my license?</h2>
<p>If you’re a superuser or billing user, go to <a href="https://console.runzero.com/license">Account &gt; License</a> to view your runZero licensing information.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Setting up Okta SSO]]></title>
    <link href="https://www.runzero.com/docs/set-up-okta-saml-sso/"/>
    <id>https://www.runzero.com/docs/set-up-okta-saml-sso/</id>
      
      <published>2025-02-05T11:02:43+00:00</published>
      <updated>2025-02-05T11:02:43+00:00</updated>
      <summary type="html"><![CDATA[<p>Superusers can configure single sign-on to the runZero Console using an external SAML identity provider (IdP), such as <span class="book-index" data-book-index="Okta">Okta</span>, which enables authentication and user access control to the runZero Console without typing in credentials.</p>
<p>Here are the high-level steps to set up single sign-on (<span class="book-index" data-book-index="SSO">SSO</span>) using Okta to authenticate and manage user access to runZero:</p>
<ul>
<li><a href="/docs/set-up-okta-saml-sso/#step-1-add-and-configure-runzero-as-an-okta-app">Add runZero as an application in Okta.</a></li>
<li><a href="/docs/set-up-okta-saml-sso/#step-2-set-up-sso-in-runzero">Set up SSO in runZero.</a></li>
<li><a href="/docs/set-up-okta-saml-sso/#step-2-set-up-sso-in-runzero">Add users to the runZero app in Okta.</a></li>
</ul>
<h2 id="okta-requirements">Requirements</h2>
<p>Before you can set up Okta SAML:</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Setting up Microsoft Entra SSO]]></title>
    <link href="https://www.runzero.com/docs/set-up-azure-ad-saml-sso/"/>
    <id>https://www.runzero.com/docs/set-up-azure-ad-saml-sso/</id>
      
      <published>2025-05-27T12:44:51+00:00</published>
      <updated>2025-05-27T12:44:51+00:00</updated>
      <summary type="html"><![CDATA[<p>Superusers can configure single sign-on to the runZero Console using an external identity provider (IdP), which enables authentication and user access control to the runZero Console from your single sign-on (SSO) solution. By default, runZero has SSO functionality available, but it’s not a requirement to sign in to the console. You can make it a requirement or disable it completely.</p>
<p>Here are the high-level steps to set up SSO using Microsoft <span class="book-index" data-book-index="Entra">Entra</span> (formerly <span class="book-index" data-book-index="Azure AD">Azure AD</span>) to authenticate and manage user access to runZero:</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Managing SSO group mappings]]></title>
    <link href="https://www.runzero.com/docs/managing-sso-group-mappings/"/>
    <id>https://www.runzero.com/docs/managing-sso-group-mappings/</id>
      
      <published>2026-04-11T03:07:33+00:00</published>
      <updated>2026-04-11T03:07:33+00:00</updated>
      <summary type="html"><![CDATA[<p class="licenses"><a href="https://www.runzero.com/product/pricing/"><span class="pla">Platform</span></a></p>
<div class="alert alert-warning">
<svg class="alert-icon" xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewbox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M10.29 3.86L1.82 18a2 2 0 0 0 1.71 3h16.94a2 2 0 0 0 1.71-3L13.71 3.86a2 2 0 0 0-3.42 0z"></path><line x1="12" y1="9" x2="12" y2="13"></line><line x1="12" y1="17" x2="12.01" y2="17"></line></svg>
<div class="alert-body">
Only runZero administrators can automatically map users to user groups using SSO attributes and custom rules.
</div>
</div>
<p><span class="book-index" data-book-index="SSO group mapping">SSO group mapping</span> allows you to map your <span class="book-index" data-book-index="SAML">SAML</span> attributes to user groups in runZero. In runZero, user groups explicitly set the organizational <a href="/docs/managing-your-team/">role</a> and determines the tasks users can perform within each organization. When you set up SSO group mappings, you explicitly define the SSO attribute and value you want to use for mapping. If there is a match, runZero will apply the group settings for the user.  As a result, you can ensure that SSO users are mapped to their respective groups in runZero.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Implementing SSO]]></title>
    <link href="https://www.runzero.com/docs/implementing-sso/"/>
    <id>https://www.runzero.com/docs/implementing-sso/</id>
      
      <published>2026-04-11T03:07:33+00:00</published>
      <updated>2026-04-11T03:07:33+00:00</updated>
      <summary type="html"><![CDATA[<p>If you use a SAML2-compatible single sign-on (<span class="book-index" data-book-index="SSO">SSO</span>) implementation,
the <a href="https://console.runzero.com/team/sso/idp/">SSO Settings</a> page can be used to configure an SSO Identity Provider (IdP) and allow permitted users to sign in to the runZero console.</p>
<p>runZero’s SSO implementation is designed to work with common <span class="book-index" data-book-index="SAML">SAML</span> providers with minimal configuration, but there are a few requirements:</p>
<ul>
<li>Your users need to authenticate to a single domain such as <code>example.com</code>, not to multiple domains or a domain with many subdomains.</li>
<li>The domain name needs to be configured in the SSO identity provider settings in runZero. This is true even for self-hosted runZero deployments.</li>
<li>Your SAML IdP should provide something that looks like an email address in the standard <span class="book-index" data-book-index="NameID">NameID</span> parameter. It doesn’t need to be a valid email address, but it should be a unique value that has the same syntax as an email address (<code>user@example.com</code>). The field name <code>NameID</code> is case sensitive.</li>
<li>If the <code>NameID</code> does not look like an email address, runZero will check the fields <code>email</code>, <code>user.email</code>, <code>emailaddress</code> and <code>email address</code> for a suitable ID. These field names are not case sensitive.</li>
<li>runZero will check for the user’s full name in the fields <code>name</code>, <code>gecos</code>, <code>user.name</code> and <code>displayname</code>. If no full name field is found, runZero will proceed to check for a first name in <code>first_name</code>, <code>firstname</code>, <code>given_name</code>, <code>user.firstname</code>, <code>givenname</code> or <code>first name</code>; and for a last name in <code>last_name</code>, <code>lastname</code>, <code>family_name</code>, <code>user.lastname</code>, <code>surname</code>, <code>sn</code>, or <code>last name</code>. These field names are not case sensitive.</li>
</ul>
<p>Note that you must be <a href="/docs/managing-your-team/#superuser">a superuser</a> to manage runZero SSO settings.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Managing external users]]></title>
    <link href="https://www.runzero.com/docs/inviting-external-users/"/>
    <id>https://www.runzero.com/docs/inviting-external-users/</id>
      
      <published>2026-04-11T03:07:33+00:00</published>
      <updated>2026-04-11T03:07:33+00:00</updated>
      <summary type="html"><![CDATA[<p class="licenses"><a href="https://www.runzero.com/product/pricing/"><span class="com">Community</span></a>&nbsp;<a href="https://www.runzero.com/product/pricing/"><span class="pla">Platform</span></a></p>
<p>You can invite <span class="book-index" data-book-index="external users">external users</span> to join your runZero instance and view the organizational data available to them. The ability to add external users is useful for consultants, value-added resellers, and managed service providers who want to be able to share data from runZero with external partners and clients.</p>
<p>If you are a superuser, you can invite any user who has a runZero account to join your account. When you invite the user, they will receive an invitation to join your account via email. After they accept the invitation and sign in to runZero, they will see a new menu next to their organization switcher that lists all the clients they can access. Your client name will display in the list.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Bulk importing users]]></title>
    <link href="https://www.runzero.com/docs/bulk-importing-users/"/>
    <id>https://www.runzero.com/docs/bulk-importing-users/</id>
      
      <published>2025-06-16T18:02:52+00:00</published>
      <updated>2025-06-16T18:02:52+00:00</updated>
      <summary type="html"><![CDATA[<p class="licenses"><a href="https://www.runzero.com/product/pricing/"><span class="com">Community</span></a>&nbsp;<a href="https://www.runzero.com/product/pricing/"><span class="pla">Platform</span></a></p>
<p>Instead of manually adding users one at a time, runZero administrators can <span class="book-index" data-book-index="add multiple users">add multiple users</span> via bulk import. To <span class="book-index" data-book-index="bulk import users">bulk import users</span>, you will need to create a CSV (comma separated values) file that contains the user information, such as their first name, last name, email, role, and organizational access.</p>
<p>Bulk imports will only add new users; it will not update existing users. If the file contains a user that already exists in the system, the import will not complete. You’ll need to remove all duplicate users from your CSV file and import the file again.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Managing user groups]]></title>
    <link href="https://www.runzero.com/docs/managing-user-groups/"/>
    <id>https://www.runzero.com/docs/managing-user-groups/</id>
      
      <published>2026-04-11T03:07:33+00:00</published>
      <updated>2026-04-11T03:07:33+00:00</updated>
      <summary type="html"><![CDATA[<p><span class="book-index" data-book-index="User groups">User groups</span> help streamline the management of users who need the same set of permissions. A user group explicitly sets the organizational <a href="/docs/managing-your-team/">role</a> for users, which determines the tasks they can perform within each organization. You can assign roles at a per-organization level or assign a single role across all organizations. Single sign-on settings can also be applied to groups through <a href="/docs/managing-sso-group-mappings/">SSO group mappings</a>.</p>
<div class="alert alert-warning">
<svg class="alert-icon" xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewbox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M10.29 3.86L1.82 18a2 2 0 0 0 1.71 3h16.94a2 2 0 0 0 1.71-3L13.71 3.86a2 2 0 0 0-3.42 0z"></path><line x1="12" y1="9" x2="12" y2="13"></line><line x1="12" y1="17" x2="12.01" y2="17"></line></svg>
<div class="alert-body">
<strong>What happens if there are conflicting permissions?</strong>
<p>
runZero will always grant the role with the highest permissions level. For example, let&#39;s say an account has a viewer role for all organizations, but they&#39;ve been added to a user group that has a user role for all organizations. This user will now have user-level permissions for all organizations. If the user group expires, the user&#39;s role reverts back to their account-level role.
</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Managing access]]></title>
    <link href="https://www.runzero.com/docs/managing-your-team/"/>
    <id>https://www.runzero.com/docs/managing-your-team/</id>
      
      <published>2026-04-11T03:07:33+00:00</published>
      <updated>2026-04-11T03:07:33+00:00</updated>
      <summary type="html"><![CDATA[<p>runZero supports multiple concurrent users with a variety of <span class="book-index" data-book-index="roles">roles</span>. Roles can be set per-user on both a default and per-organization basis. The standard roles are administrator, user, billing, annotator, viewer, and no access. There is also a superuser role available to manage global settings.</p>
<p>Where there are multiple roles defined for a user, the access granted is based on most privilege.  For example, if a user has user access by being in a group, but admin access assigned directly, they will be given admin privileges.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Data retention]]></title>
    <link href="https://www.runzero.com/docs/data-retention/"/>
    <id>https://www.runzero.com/docs/data-retention/</id>
      
      <published>2025-11-13T17:23:51+00:00</published>
      <updated>2025-11-13T17:23:51+00:00</updated>
      <summary type="html"><![CDATA[<p>runZero allows the <span class="book-index" data-book-index="data retention">data retention</span> periods to be configured at the organization level. The organization settings page provides three ways to control how runZero manages your asset and scan data. Data expiration is processed as a nightly batch job based on the current settings for each organization in your account.</p>
<p>By default, data is retained for up to 1 year in the runZero Platform. This can be increased to up to 3 years for active subscriptions. The runZero Community Edition is limited to 30 days of retention.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Self-hosted troubleshooting]]></title>
    <link href="https://www.runzero.com/docs/self-hosting-collection/"/>
    <id>https://www.runzero.com/docs/self-hosting-collection/</id>
      
      <published>2024-02-22T16:30:44+00:00</published>
      <updated>2024-02-22T16:30:44+00:00</updated>
      <summary type="html"><![CDATA[<p>The runZero console includes a <span class="book-index" data-book-index="diagnostics collection">diagnostics collection</span> script inspired by the need to troubleshoot a self-hosted environment. Collecting the necessary performance statistics, log files, system configuration, and profile debug capture was difficult for customers since there are many different commands and files involved. After checking permissions and dependencies, the diagnostic script gathers and compresses troubleshooting data into a convenient archive file that can be provided to runZero support. The script provides a consistent method for data collection whether it be from a system running your self-hosted console or an Explorer.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[High-availability configuration]]></title>
    <link href="https://www.runzero.com/docs/self-hosting-ha/"/>
    <id>https://www.runzero.com/docs/self-hosting-ha/</id>
      
      <published>2026-04-11T03:07:33+00:00</published>
      <updated>2026-04-11T03:07:33+00:00</updated>
      <summary type="html"><![CDATA[<p>Self-hosted installations of runZero can be configured for <span class="book-index" data-book-index="high-availability">high-availability</span>. For this configuration, a load balancer is used to direct traffic to multiple console servers, which use a shared PostgreSQL cluster and storage backend. The following diagram illustrates an example architecture of a high-availability installation using AWS with two availability zones.</p>
<p><img src="/img/docs/img/self-hostedHA.svg" alt="Self-Hosted HA Architecture"></p>
<p>In this diagram, an application load balancer (ALB) is terminating TLS and pointing to a target group that consists of two runZero servers, each in separate availability zones. The runZero servers use a multi-availability-zone PostgreSQL RDS instance, also configured for the same two availability zones, and both servers point to the same set of S3 storage buckets.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Offline mode configuration]]></title>
    <link href="https://www.runzero.com/docs/self-hosting-offline/"/>
    <id>https://www.runzero.com/docs/self-hosting-offline/</id>
      
      <published>2026-05-10T19:03:44+00:00</published>
      <updated>2026-05-10T19:03:44+00:00</updated>
      <summary type="html"><![CDATA[<h2 id="offline-supported-operating-systems">Supported operating systems</h2>
<p>The runZero self-hosted console runs on the same operating systems whether you are installing online or offline. See <a href="/docs/self-hosting/#supported-operating-systems">Self-hosting runZero — Supported operating systems</a> for the full list (Ubuntu 18.04+, RHEL 7+, CentOS 7+, Oracle Linux 7+, Debian 9+, on x86_64).</p>
<p>Note that for offline installs, PostgreSQL packages must be available locally. The PostgreSQL.org RPM bundles linked below cover RHEL/CentOS 8, 9, and 10. On older or other distributions, supply PostgreSQL through your own offline mirror or use <code>--distro-packages-only</code> to install whatever PostgreSQL version your OS provides (must be PostgreSQL 14 or newer).</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Self-hosting runZero]]></title>
    <link href="https://www.runzero.com/docs/self-hosting/"/>
    <id>https://www.runzero.com/docs/self-hosting/</id>
      
      <published>2026-05-27T17:08:11+00:00</published>
      <updated>2026-05-27T17:08:11+00:00</updated>
      <summary type="html"><![CDATA[<p class="licenses"><a href="https://www.runzero.com/product/pricing/"><span class="pla">Platform</span></a></p>
<h2 id="background">Background</h2>
<p>The <span class="book-index" data-book-index="self-hosted">self-hosted</span> version of runZero allows you to run the entire platform <span class="book-index" data-book-index="on-premises">on-premises</span> or within your own cloud environment.
This platform is functionally identical to the hosted service, provides a fully-offline mode, and does not send any inventory data back to runZero.</p>
<p>While self-hosting is less common, here are a few reasons your company might choose to:</p>
<ul>
<li>ISO compliance requirement</li>
<li>Other compliance requirement</li>
<li>Prefer data on-premise</li>
</ul>
<p>Self-hosting must be explicitly enabled for your account. Self-hosting is available if you have a runZero Platform license, or if you are running an initial trial for a platform license. Please contact your runZero sales representative for further information.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Sites]]></title>
    <link href="https://www.runzero.com/docs/sites/"/>
    <id>https://www.runzero.com/docs/sites/</id>
      
      <published>2026-05-10T19:03:44+00:00</published>
      <updated>2026-05-10T19:03:44+00:00</updated>
      <summary type="html"><![CDATA[<p>By default, your account includes a single organization, which itself contains a single site, named Primary. If the only site in an organization is deleted, a replacement will be created automatically. Similarly, if the last organization is removed, a replacement will be created. You can rename organizations and sites at any time.</p>
<p>Every organization has at least one site, but may have multiple sites. A site represents a distinct network segment, usually defined by addressing or accessibility. Sites in runZero do not necessarily correspond to physical sites or locations. Instead, they are used to represent distinct networks that may have overlapping address space. This allows for multiple sites to use the same <span class="book-index" data-book-index="RFC1918">RFC1918</span> space, something common in retail, while still being possible to differentiate their assets within the inventory.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Organizations]]></title>
    <link href="https://www.runzero.com/docs/organizations/"/>
    <id>https://www.runzero.com/docs/organizations/</id>
      
      <published>2025-01-29T15:32:28+00:00</published>
      <updated>2025-01-29T15:32:28+00:00</updated>
      <summary type="html"><![CDATA[<p class="licenses"><a href="https://www.runzero.com/product/pricing/"><span class="com">Community</span></a>&nbsp;<a href="https://www.runzero.com/product/pricing/"><span class="pla">Platform</span></a></p>
<p>An organization represents a distinct entity; this can be your business, a specific <span class="book-index" data-book-index="department">department</span> within your business, or one of your customers. All actions, tasks, Explorers, scans, and other objects managed by runZero are tied to specific organizations and isolated from each other.</p>
<p>Your active organization can be switched by using the dropdown selector at the top right of the runZero Console. If your default role is Viewer or higher, you can select <strong>All Organizations</strong> from the dropdown to view the data for all of your organizations in the Dashboard and Inventory. The Queries page also supports the All Organizations view. Pages that are not compatible with the All Organizations view will be hidden until a single organization is selected.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[runZero 201 training]]></title>
    <link href="https://www.runzero.com/docs/training-201/"/>
    <id>https://www.runzero.com/docs/training-201/</id>
      
      <published>2026-05-22T14:50:01+00:00</published>
      <updated>2026-05-22T14:50:01+00:00</updated>
      <summary type="html"><![CDATA[<h2 id="prerequisites">Prerequisites</h2>
<p>Prior to starting this <span class="book-index" data-book-index="training">training</span>, we have two recommendations:</p>
<ol>
<li><strong>Superuser access</strong> to a runZero account. This can be a corporate account with a paid license, or you can use a personal email to create a community account which will make you the superuser.</li>
<li><strong>Completion of the</strong> <a href="https://help.runzero.com/docs/training/">runZero 101 training</a> is also recommended so that you understand the context behind all of the administrative actions you will learn about in this training.</li>
</ol>
<h3 id="introduction-to-the-training">Introduction to the training</h3>
<p>This video provides a brief introduction to what you will learn in this training.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[runZero 101 training]]></title>
    <link href="https://www.runzero.com/docs/training/"/>
    <id>https://www.runzero.com/docs/training/</id>
      
      <published>2025-12-04T14:33:33+00:00</published>
      <updated>2025-12-04T14:33:33+00:00</updated>
      <summary type="html"><![CDATA[<p>This training introduces the core components of the runZero platform. It provides the foundational concepts that help you understand how runZero gathers and structures asset data, how to explore the environment, and how to begin identifying risks and trends.</p>
<p>Each section includes an accompanying walkthrough and links to deeper documentation. <a href="/docs/training-201/">runZero 201</a> covers advanced workflows, automation, and deployment planning.</p>
<h2 id="platform-overview">Platform overview</h2>
<iframe src="https://demo.arcade.software/C1sifY0IIUZl4QzKVGK0?embed" loading="lazy" allowfullscreen="" title="Platform Overview"></iframe>
<p>Before using inventories, findings, reporting views, or dashboards, it’s important to understand the core concepts that shape how runZero organizes and processes data. This section provides short, conceptual introductions to:</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Use case library]]></title>
    <link href="https://www.runzero.com/docs/use-case-library/"/>
    <id>https://www.runzero.com/docs/use-case-library/</id>
      
      <published>2026-05-10T19:03:44+00:00</published>
      <updated>2026-05-10T19:03:44+00:00</updated>
      <summary type="html"><![CDATA[<h2 id="appendix">Appendix</h2>
<ul>
<li><a href="/docs/use-case-library/#use-case-library-visibility">Total attack surface visibility</a>
<ul>
<li><a href="/docs/use-case-library/#use-case-library-active-discovery">Active discovery on all internal assets</a></li>
<li><a href="/docs/use-case-library/#use-case-library-active-external">Active discovery on all externally facing assets</a></li>
<li><a href="/docs/use-case-library/#use-case-library-passive-discovery">Passive discovery and enrichment in key network segments</a></li>
<li><a href="/docs/use-case-library/#use-case-library-cloud-integration">Integrate with all cloud providers and other relevant data sources</a></li>
</ul>
</li>
<li><a href="/docs/use-case-library/#use-case-library-full-spectrum">Full-spectrum exposure detection</a>
<ul>
<li><a href="/docs/use-case-library/#use-case-library-rapid-response-pivot">Rapid Response findings and asset-level pivoting</a></li>
<li><a href="/docs/use-case-library/#use-case-library-network-gaps">Network misconfiguration findings and control coverage gaps</a></li>
<li><a href="/docs/use-case-library/#use-case-library-enriched-findings">Vulnerability enrichment and inside-out findings</a></li>
</ul>
</li>
<li><a href="/docs/use-case-library/#use-case-library-risk-insights">Risk prioritization and insights</a>
<ul>
<li><a href="/docs/use-case-library/#use-case-library-custom-dashboards">Custom dashboards</a></li>
<li><a href="/docs/use-case-library/#use-case-library-rules-alerts">Rules and alerts</a></li>
<li><a href="/docs/use-case-library/#use-case-library-asset-context">Setting asset criticality and ownership</a></li>
</ul>
</li>
<li><a href="/docs/use-case-library/#use-case-library-compliance">Compliance, Reporting, and KPIs</a>
<ul>
<li><a href="/docs/use-case-library/#use-case-library-asset-inventory">Comply with asset inventory and discovery requirements of relevant frameworks</a></li>
<li><a href="/docs/use-case-library/#use-case-library-secure-config">Comply with secure configuration requirements of relevant frameworks</a></li>
<li><a href="/docs/use-case-library/#use-case-library-malware-protection">Comply with malware protection requirements of relevant frameworks</a></li>
<li><a href="/docs/use-case-library/#use-case-library-vuln-management">Comply with vulnerability management requirements of relevant frameworks</a></li>
</ul>
</li>
</ul>
<h2 id="use-case-library-visibility">Total attack surface visibility</h2>
<p>Achieving complete visibility is essential for understanding and managing your organization’s attack surface. This encompasses internal and external assets, cloud amd security tooling integrations, and passive discovery methods to ensure comprehensive oversight and proactive threat mitigation.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Types of networks]]></title>
    <link href="https://www.runzero.com/docs/sample-networks/"/>
    <id>https://www.runzero.com/docs/sample-networks/</id>
      
      <published>2024-05-10T10:54:34+00:00</published>
      <updated>2024-05-10T10:54:34+00:00</updated>
      <summary type="html"><![CDATA[<p>It is often helpful to use <span class="book-index" data-book-index="network examples">network examples</span> as a starting point for planning your runZero implementation. This document breaks down a few standard network types and provides potential configurations for each. With that being said, every network has nuance, so it’s likely there will be some differences for your implementation.</p>
<p>This is a basic overview of how discovery will be done using Explorers and scanners. By default, one Explorer will be deployed with the goal of running discovery on as much of the network as possible. If needed, more Explorers can be added for areas the primary Explorer cannot get to. You can also use a scanner for offline environments where there is no internet connectivity.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Full-scale deployment]]></title>
    <link href="https://www.runzero.com/docs/deployment-plan/"/>
    <id>https://www.runzero.com/docs/deployment-plan/</id>
      
      <published>2025-11-13T10:35:40+00:00</published>
      <updated>2025-11-13T10:35:40+00:00</updated>
      <summary type="html"><![CDATA[<p>As you get started with runZero, we recommend kicking off with our standard <span class="book-index" data-book-index="deployment plan">deployment plan</span> and adding tasks as needed. The standard deployment plan is broken out into six stages which will help you plan out your requirements, execute the deployment, and optimize your environment based on runZero’s best practices.</p>
<h2 id="1-identify-key-success-outcomes">1. Identify key success outcomes</h2>
<p><strong>Total attack surface visibility</strong></p>
<ul>
<li><a href="https://help.runzero.com/docs/use-case-library/#use-case-library-active-discovery">Active discovery on all internal assets</a></li>
<li><a href="https://help.runzero.com/docs/use-case-library/#use-case-library-active-external">Active discovery on all externally facing assets</a></li>
<li><a href="https://help.runzero.com/docs/use-case-library/#use-case-library-passive-discovery">Passive discovery and enrichment in key network segments</a></li>
<li><a href="https://help.runzero.com/docs/use-case-library/#use-case-library-cloud-integration">Integrate with all cloud providers and other relevant data sources</a></li>
</ul>
<p><strong>Additional Resources</strong></p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Verifying binaries]]></title>
    <link href="https://www.runzero.com/docs/binary-verification/"/>
    <id>https://www.runzero.com/docs/binary-verification/</id>
      
      <published>2025-01-19T12:09:31+00:00</published>
      <updated>2025-01-19T12:09:31+00:00</updated>
      <summary type="html"><![CDATA[<p>runZero uses dynamically generated binaries for the runZero Console, CLI, and Explorer downloads. Although Windows
binaries have a valid Authenticode signature, all binaries also contain a secondary, internal signature. Dynamic
binaries make it easy to deploy Explorers that connect back to the right organization, but present a challenge for
independent integrity validation. To enable verification of the internal signature, we offer the <strong>runZero Verifier</strong>.
This verification tool can confirm whether a given binary contains a valid <span class="book-index" data-book-index="binary signature">internal signature</span>, in
addition to any existing Authenticode signatures.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Managing Explorers]]></title>
    <link href="https://www.runzero.com/docs/managing-explorers/"/>
    <id>https://www.runzero.com/docs/managing-explorers/</id>
      
      <published>2026-03-02T17:16:23+00:00</published>
      <updated>2026-03-02T17:16:23+00:00</updated>
      <summary type="html"><![CDATA[<p>The runZero Explorer is a lightweight scan engine that enables network and asset discovery. You should have at least one <span class="book-index" data-book-index="Explorer">Explorer</span> deployed. After deployment, you can manage your Explorers from the <a href="https://console.runzero.com/deploy/explorers">Deploy page</a> in your runZero web console.</p>
<h2 id="viewing-all-explorers">Viewing all Explorers</h2>
<p>For each Explorer, you can see:</p>
<ul>
<li>The Explorer status (whether it is communicating with runZero)</li>
<li>The OS it is running on</li>
<li>Its name</li>
<li>Any site it is associated with</li>
<li>Its IP addresses</li>
<li>The software version it is running</li>
<li>Whether the version of npcap installed is up-to-date, if the OS is Windows (see <a href="/docs/managing-explorers/#upgrading-npcap">upgrading npcap</a> below)</li>
<li>The CPU architecture of the host machine</li>
<li>Any tags associated with the Explorer</li>
<li>The status of its last scan</li>
<li>Its capabilities, like Chrome support</li>
</ul>
<h2 id="screenshot-capabilities">Screenshot capabilities</h2>
<p>To capture screenshots, Chrome must be installed. You can check if an Explorer has <span class="book-index" data-book-index="screenshot">screenshot</span> capabilities by looking for the Chrome icon in the <em>Capabilities</em> column.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Installing on a Raspberry Pi]]></title>
    <link href="https://www.runzero.com/docs/installing-explorer-on-raspberry-pi/"/>
    <id>https://www.runzero.com/docs/installing-explorer-on-raspberry-pi/</id>
      
      <published>2026-04-11T03:07:33+00:00</published>
      <updated>2026-04-11T03:07:33+00:00</updated>
      <summary type="html"><![CDATA[<p>The runZero Explorer enables discovery scanning. In most cases, you can deploy an Explorer on an existing system that has connectivity to the network you want to discover. However, there may be times when the traditional deployment model may not work for you. Some locations, like retail stores or customer sites, may not have staff or hardware available to install the Explorer, making remote deployment a bit tricky.</p>
<p>In these types of scenarios, you can install a runZero Explorer on a <span class="book-index" data-book-index="Raspberry Pi">Raspberry Pi</span> and send the device to the location for them to plug into their network.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Automated MSI deployments]]></title>
    <link href="https://www.runzero.com/docs/explorer-msi/"/>
    <id>https://www.runzero.com/docs/explorer-msi/</id>
      
      <published>2026-04-11T03:07:33+00:00</published>
      <updated>2026-04-11T03:07:33+00:00</updated>
      <summary type="html"><![CDATA[<p>runZero uses dynamically generated binaries for the runZero Explorer downloads and this doesn’t always play well
with MSI-based installation methods.</p>
<p>To work around this issue, we have provided a shim <span class="book-index" data-book-index="MSI package">MSI package</span> that can be used with <span class="book-index" data-book-index="automated installers">automated installers</span>. This package has a valid Authenticode signature and can also be verified using the <a href="/docs/binary-verification/">runZero Verifier</a>.</p>
<div class="alert alert-info">
<svg class="alert-icon" xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewbox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><circle cx="12" cy="12" r="10"></circle><line x1="12" y1="16" x2="12" y2="12"></line><line x1="12" y1="8" x2="12.01" y2="8"></line></svg>
<div class="alert-body">
Some components of the application still reference the name &#34;Rumble&#34; for backwards compatibility. All new installations will use runZero for directory, file, and user names.
</div>
</div>
<p>To use this package, deploy it with the <code>URL</code> parameter specified as the organization-specific download URL from the runZero Console Explorers section.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Installing an Explorer]]></title>
    <link href="https://www.runzero.com/docs/installing-an-explorer/"/>
    <id>https://www.runzero.com/docs/installing-an-explorer/</id>
      
      <published>2026-04-11T03:07:33+00:00</published>
      <updated>2026-04-11T03:07:33+00:00</updated>
      <summary type="html"><![CDATA[<p>runZero requires the use of at least one <span class="book-index" data-book-index="Explorer">Explorer</span> within your environment to enable active and passive network discovery. The Explorer should be installed on a system with reliable connectivity to the network you want to discover. For internal networks, runZero works best when installed on a system with a wired (vs wireless) connection.</p>
<p>For <span class="book-index" data-book-index="external network discovery">external network discovery</span>, nearly any cloud provider with a reliable connection should do. If the runZero Explorer is installed in a <span class="book-index" data-book-index="container">container</span> or <span class="book-index" data-book-index="virtualized system">virtualized system</span>, ensure that it has direct access to the network (host networking in <span class="book-index" data-book-index="Docker">Docker</span>, bridged networking in <span class="book-index" data-book-index="VMware">VMware</span>, etc). SaaS customers with a Platform license can use the runZero hosted Explorers at no additional cost.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Creating an account]]></title>
    <link href="https://www.runzero.com/docs/creating-account/"/>
    <id>https://www.runzero.com/docs/creating-account/</id>
      
      <published>2025-02-12T15:40:29+00:00</published>
      <updated>2025-02-12T15:40:29+00:00</updated>
      <summary type="html"><![CDATA[<p>To get started, you’ll need to <span class="book-index" data-book-index="sign up">sign up</span> for a runZero account. The default account is a trial of the full runZero Platform. After the trial expires, you will have the option to convert to the free Community Edition or purchase a subscription.</p>
<p><a href="https://www.runzero.com/try/">Sign up for a runZero account</a></p>
<iframe src="https://demo.arcade.software/kNfGJexlNYeIvr262DC8?embed" loading="lazy" allowfullscreen="" title="Walkthrough - Creating Account"></iframe>
<h2 id="activating-your-account"><span class="book-index" data-book-index="Activating your account">Activating your account</span></h2>
<p>After you sign up for an account, we’ll email you a link to activate your account. If you don’t see an email from us, check your spam folder.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[Getting started]]></title>
    <link href="https://www.runzero.com/docs/getting-started/"/>
    <id>https://www.runzero.com/docs/getting-started/</id>
      
      <published>2026-05-10T19:03:44+00:00</published>
      <updated>2026-05-10T19:03:44+00:00</updated>
      <summary type="html"><![CDATA[<p>To get started, you’ll need to <span class="book-index" data-book-index="sign up">sign up</span> for a runZero account. The default account is a trial of the full runZero Platform. After the trial expires, you will have the option to convert to the free Community Edition or purchase a subscription.</p>
<ul>
<li><a href="https://www.runzero.com/try/">Sign up for a runZero account</a></li>
<li>Read up on <a href="/docs/creating-account/">creating an account</a> for help activating your account, changing your password, and adding a profile picture.</li>
<li>Once your account is set up, there are a couple of paths you can take to deploy runZero.
<ul>
<li><a href="/docs/getting-started/#quickstart-guide">Quickstart</a></li>
<li><a href="/docs/getting-started/#full-deployment-plan">Full deployment plan</a></li>
</ul>
</li>
</ul>
<h2 id="quickstart-guide">Quickstart guide</h2>
<p>The quickstart path is ideal for those who want to jump into using runZero and explore its core functionalities. This section covers the initial setup, running basic scans, and configuring integrations.</p>]]></summary>
  </entry>
  <entry>
    <title type="html"><![CDATA[What is runZero?]]></title>
    <link href="https://www.runzero.com/docs/what-is-runzero/"/>
    <id>https://www.runzero.com/docs/what-is-runzero/</id>
      
      <published>2026-05-01T22:14:59+00:00</published>
      <updated>2026-05-01T22:14:59+00:00</updated>
      <summary type="html"><![CDATA[<h2 id="what-is-runzero-intro">runZero</h2>
<p>runZero is a total attack surface and exposure management platform that combines active scanning, passive discovery, and API integrations to deliver complete visibility into managed and unmanaged assets across IT, OT, IoT, cloud, mobile, and remote environments. runZero can be used as a hosted service (SaaS) or managed <a href="/docs/self-hosting/">on-premise</a>. The runZero stack consists of one more Consoles, linked <a href="/docs/installing-an-explorer/">Explorers</a> that run as light-weight services on network points-of-presence, and a <a href="/docs/using-the-cli/">command-line tool</a> that can be used for offline data collection. runZero can be managed through the web interface, via API, or for self-hosted customers, on the command line.</p>]]></summary>
  </entry>
</feed>
